Information processing apparatus, storage medium, information processing method, and computer program product
By automatically acquiring and applying security policies corresponding to the attributes of the image processing device through the information processing device, the burden on operators to select security policies in unsafe environments is eliminated, enabling secure image processing without human intervention, preventing information leakage and ensuring information exposure.
Patent Information
- Application Number
- CN202010080696.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-04-23
- Filing Date
- 2020-02-05
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2040-02-05
AI Technical Summary
In unsafe environments of image processing devices, operators need to select strict safety strategies, which increases the operational burden. Existing technologies cannot automatically adapt to the conditions of image processing devices to apply safety strategies.
The information processing device receives image data transmission requests, obtains security policies corresponding to the attribute information of the image processing device, controls the transmission and processing of image data, and automatically applies security policies corresponding to the setup environment of the image processing device and the relationship between the operator and the user.
Operators do not need to manually select security policies; the image processing device can automatically adapt to the situation and perform image processing, reducing the operational burden and effectively preventing information leakage and exposure of sensitive information.
Smart Images

Figure CN111832008B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to an information processing device, a storage medium, and an information processing method. Background Technology
[0002] Patent Document 1 discloses a document management system that manages access to files. The document management system is characterized by comprising: a selection unit for selecting a hypothetical security policy prepared in each device set in the file; an acquisition unit for acquiring access permission information that determines the permissions to access the file based on the hypothetical security policy selected by the selection unit and authentication information of the person who set the hypothetical security policy; a conversion unit for converting the hypothetical security policy into an actual security policy that can be commonly interpreted within the document management system based on the access permission information acquired by the acquisition unit; and a management unit for setting the actual security policy converted by the conversion unit in the file and managing access to the file.
[0003] Patent Document 2 discloses a security policy allocation system, characterized in that a management device manages security policies applicable to multiple different types of devices and the applicable locations of the security policies. When a security policy is allocated from the management device, the management device notifies the applicable location device of the allocation of the security policy. The applicable location device that is notified of the allocation of the security policy obtains the security policy from the management device. Furthermore, a device that needs a security policy actively obtains the security policy from the management device upon startup and uses the obtained security policy for access control.
[0004] Patent Document 1: Japanese Patent Application Publication No. 2008-102871
[0005] Patent Document 2: Japanese Patent Application Publication No. 2004-094401
[0006] Image processing devices that are instructed by operators to perform image processing are installed in environments that are not considered safe for the operators. In such unsafe situations, image processing requires stricter safety measures compared to performing image processing with a safe device. In these cases, requiring the operator to choose a safety strategy is a burden. Summary of the Invention
[0007] The purpose of this invention is to provide an information processing apparatus, storage medium, and information processing method that allows operators to perform image processing without having to select a security policy, but rather by applying a security policy corresponding to the status of the image processing device.
[0008] The information processing apparatus according to the first method comprises: a receiving unit that receives a request to send image data from an image processing apparatus instructed by an operator to perform image processing; an acquiring unit that, upon receiving the sending request, acquires a security policy corresponding to attribute information related to the attributes of the image processing apparatus; and a control unit that controls the image processing apparatus to send the image data to the image processing apparatus and to perform the image processing in the image processing apparatus according to the security policy acquired by the acquiring unit.
[0009] In the information processing apparatus of the second method, which is the same as that of the first method, the attribute information includes at least one of the following: the setup environment of the image processing apparatus and the relationship between the operator and the image processing apparatus.
[0010] In the information processing apparatus of the third method, the information related to the setting environment in the information processing apparatus of the second method is information indicating the setting location of the image processing apparatus.
[0011] In the information processing apparatus of the fourth method, compared to the information processing apparatus of the second method, the information relating to the relationship between the operator and the image processing apparatus is information indicating whether the image processing apparatus is located at the operator's location.
[0012] In the information processing apparatus of any of the first to fourth methods, the security policy is a predetermined security policy for processing that prevents at least one of the operator and the number of images from being identified.
[0013] In the information processing apparatus of the sixth method, which is the information processing apparatus of the fifth method, the predetermined processing is the process of sending information to the image processing apparatus, which is determination information that excludes determination information related to at least one of the operator and the image data from information related to the image data.
[0014] In the information processing apparatus of the seventh method, which is the information processing apparatus of the sixth method, the determining information includes at least one of the name of the operator and the name of the image data.
[0015] In the information processing apparatus of the eighth method, the predetermined processing is a non-deterministic processing in which the processing result of the image processing is output in a manner in which at least one of the operator and the image data is not determined.
[0016] In the information processing apparatus of the 9th method, the non-deterministic processing is a process of hiding at least one of the operator's name and the name of the image data in the display section of the image processing apparatus.
[0017] In the information processing apparatus of the 10th method, which is the information processing apparatus of the 5th method, the predetermined processing is a process that prevents information relating to at least one of the operator and the image data from being stored in the image processing apparatus.
[0018] In the information processing apparatus of any one of the first to tenth methods, the acquisition unit acquires a default security policy of at least one of a first default security policy preset by the operator and a second default security policy preset by the logical image processing device; the logical image processing device receives the image data sent by the operator; and the control unit generates a new security policy based on the default security policy acquired by the acquisition unit and the security policy corresponding to the attribute information.
[0019] In the information processing apparatus of the 12th method, a priority order is set among the security policy corresponding to the attribute information, the first default security policy, and the second default security policy, and the control unit generates the new security policy according to the priority order.
[0020] The storage medium involved in the 13th method stores an information processing program for enabling a computer to function as a component of any one of the information processing apparatuses in Schemes 1 to 12.
[0021] The information processing method involved in Method 14 includes the following steps:
[0022] The receiving step involves receiving a request to send image data from the image processing device that is instructed by the operator to perform image processing.
[0023] In the acquisition step, if the sending request is received in the receiving step, a security policy corresponding to the attribute information is acquired, wherein the attribute information is related to the attributes of the image processing device; and
[0024] The control steps are as follows: the image data is sent to the image processing device, and the image processing is performed in the image processing device according to the security policy obtained in the acquisition step.
[0025] Invention Effects
[0026] According to methods 1, 13, and 14, the operator does not need to select a safety policy, but can apply a safety policy corresponding to the status of the image processing device to perform image processing.
[0027] According to the second method, the image processing device can perform image processing according to a security policy, the security policy corresponding to at least one of the following: the setup environment of the image processing device and the relationship between the operator and the image processing device.
[0028] According to the third method, the image processing device can perform image processing based on a security policy corresponding to information indicating the location where the image processing device is installed.
[0029] According to the fourth method, the image processing device can perform image processing based on a security policy corresponding to information indicating whether it is located at the operator's location.
[0030] According to the fifth method, when the image processing device performs image processing, it is possible to make at least one of the operator and the image data unidentifiable.
[0031] According to the sixth method, it is possible to suppress the leakage of determination information related to the determination of at least one of the operator and the image data to a third party in the information related to the image data.
[0032] According to the seventh method, it is possible to prevent the leakage of at least one of the following information, including the name of the operator and the name of the image data, to a third party.
[0033] According to the eighth method, the image processing result can be output in at least one uncertain manner, that is, the operator or the image data.
[0034] According to the ninth method, at least one of the operator's name and the name of the image data can be made unrecognizable on the display unit of the image processing device.
[0035] According to the 10th method, it is possible to suppress information leakage related to at least one of the operators and image data.
[0036] According to the 11th method, compared with the case where the image processing device performs image processing only according to the security policy corresponding to the attribute information, the image processing device can perform image processing according to the security policy that takes into account at least one of the operator and the logical image processing device.
[0037] According to the 12th method, compared with the case where no priority order is preset in the security policy corresponding to the attribute information, the first default security policy and the second default security policy, the important security policy can be applied first when performing image processing. Attached Figure Description
[0038] The embodiments of the present invention will be described in detail with reference to the following figures.
[0039] Figure 1 It is a schematic diagram representing the structure of an information processing system;
[0040] Figure 2 This is a block diagram representing the main structure of the power system for the information processing device;
[0041] Figure 3 It is a block diagram representing the functional structure of an information processing device;
[0042] Figure 4 This is a flowchart illustrating an example of an information processing flow;
[0043] Figure 5 This is a diagram illustrating an example of a location directory;
[0044] Figure 6 This is a diagram representing an example of security policy information;
[0045] Figure 7 This is a diagram representing an example of security policy information;
[0046] Figure 8 This is a diagram representing an example of priority information.
[0047] Symbol Explanation
[0048] 1-Information processing system, 10-Information processing device, 12-Controller, 16-Storage unit, 16A-Information processing program, 16B-Image data, 16C-Setting location directory, 16D-Security policy information, 20-Operator terminal device, 30-Image processing device, 40-Receiving unit, 42-Acquisition unit, 44-Control unit, 50-Priority sequence information. Detailed Implementation
[0049] Hereinafter, with reference to the accompanying drawings, a detailed description of the methods for carrying out the present invention will be provided.
[0050] Figure 1 This is a structural diagram of information processing system 1. The structure of information processing system 1 is as follows: information processing device 10, multiple operator terminal devices 20 and multiple image processing devices 30 are connected via network N.
[0051] When an operator instructs on image processing of image data, they first operate the operator terminal device 20 to send image data from the operator terminal device 20 to the information processing device 10. Here, image data refers to data including at least one of characters and images. Image processing refers to the processing performed on the image data. Examples of image processing include output processing and analysis processing of image data. Specifically, examples of output processing of image data include printing processing of printed image data, processing of image data for fax transmission, and processing of image data for mail transmission. Examples of analysis processing of image data include OCR (Optical Character Recognition) processing of image data. In this embodiment, the image processing is described as printing processing. That is, in this embodiment, the information processing device 10 functions as a print server, and the image processing device 30 functions as a printer.
[0052] The information processing device 10 functions as a logical image processing device that receives and stores image data sent from the operator terminal device 20. When the image processing is printing processing, the information processing device 10 generates and stores data for printing the image data using the image processing device 30, which functions as a printer. That is, in this embodiment, the information processing device 10 functions as a logical printer.
[0053] An operator operates the image processing device 30 and instructs it to perform image processing, which involves processing the image data sent to the information processing device 10. Thus, the image processing device 30 receives image data from the information processing device 10 and performs the image processing instructed by the operator, i.e., performs printing processing.
[0054] Figure 2 This is a structural diagram of the information processing device 10. The information processing device 10 is composed of a device including a conventional computer.
[0055] like Figure 2 As shown, the information processing device 10 includes a controller 12. The controller 12 includes a CPU (Central Processing Unit) 12A, a ROM (Read Only Memory) 12B, a RAM (Random Access Memory) 12C, a non-volatile memory 12D, and an input / output interface (I / O) 12E. Furthermore, the CPU 12A, ROM 12B, RAM 12C, non-volatile memory 12D, and I / O 12E are respectively connected via a bus 12F.
[0056] Furthermore, a communication unit 14 and a storage unit 16 are connected to the I / O 12E.
[0057] The communication unit 14 is an interface for data communication with external devices.
[0058] The storage unit 16 is composed of a non-volatile storage device such as a hard disk, and stores information processing programs 16A, image data 16B, location directory 16C, and security policy information 16D, which will be described later.
[0059] CPU 12A reads and executes information processing program 16A stored in storage unit 16.
[0060] Next, the functional structure of CPU 12A when the information processing device 10 executes information processing program 16A will be explained.
[0061] like Figure 3 As shown, the CPU12A functionally includes a receiving unit 40, an acquisition unit 42, and a control unit 44.
[0062] The receiving unit 40 receives a request to send image data from the image processing device 30, which is instructed by the operator to perform image processing.
[0063] When the receiving unit 40 receives a request to transmit image data, the acquiring unit 42 acquires a security policy corresponding to attribute information related to the attributes of the image processing device 30. Here, attribute information refers to information representing characteristics related to the security policy of the image processing device 30. For example, attribute information includes at least one of the following: the installation environment of the image processing device 30 and the relationship between the operator and the image processing device 30. Specifically, information related to the installation environment may be, for example, information indicating the installation location of the image processing device 30, but is not limited thereto. Examples of information indicating the installation location include GPS (Global Positioning System) information, i.e., latitude and longitude information. Furthermore, information regarding the relationship between the operator and the image processing device 30 may be, for example, information indicating whether the image processing device is installed at the operator's location, but is not limited thereto. Here, "location" refers to the organization to which the operator belongs, specifically, for example, a company or department.
[0064] A security policy refers to measures defined to address security concerns when processing image data. A security policy may be, for example, a predetermined process designed to prevent the identification of at least one of the operator and the image data. In this case, the predetermined process may, for example, send information related to the image data that excludes information related to the identification of at least one of the operator and the image data to the image processing apparatus 30, but is not limited to this. Furthermore, the identification information may, for example, include at least one of the operator's name and the name of the image data, but is not limited to this.
[0065] Furthermore, the predetermined processing can be set as a non-deterministic processing method that outputs the image processing result in a manner in which at least one of the operator and the image data is not determined. In this case, the non-deterministic processing can be set as, for example, a process that hides at least one of the operator's name and the name of the image data in the display unit of the image processing device 30.
[0066] Furthermore, the predetermined process can be configured to prevent information related to at least one of the operator and image data from being stored in the image processing device 30.
[0067] The control unit 44 controls the image data to be sent to the image processing device 30, and performs image processing in the image processing device 30 according to the security policy acquired by the acquisition unit 42. Specifically, an image processing instruction based on the security policy acquired by the acquisition unit 42 is sent to the image processing device 30. Thus, the image processing device 30 performs image processing on the image data according to the image processing instruction sent from the information processing device 10. Therefore, the operator does not need to select a security policy, but instead applies a security policy corresponding to the status of the image processing device 30 to perform image processing.
[0068] Furthermore, the acquisition unit 42 acquires at least one default security policy, namely a first default security policy preset by the operator and a second default security policy preset by the logical image processing device for receiving image data sent by the operator. The control unit 44 can be configured to generate a new security policy based on the default security policy acquired by the acquisition unit 42 and the security policy corresponding to the attribute information. In this case, a priority order is preset among the security policy corresponding to the attribute information, the first default security policy, and the second default security policy, and the control unit 44 can be configured to generate a new security policy according to the priority order.
[0069] Next, the operation of the information processing apparatus 10 according to this embodiment will be explained. For example... Figure 2 As shown, the information processing program 16A is stored in the storage unit 16. The CPU 12A reads and executes the information processing program 16A, thereby performing... Figure 4 The information processing is shown. Additionally, each time image data is received, or each time a request to send image data is received, the following steps are performed: Figure 4 The information processing is shown.
[0070] When an operator wants to print image data through the image processing device 30, the operator operates the operator terminal device 20 to send image data from the operator terminal device 20 to the information processing device 10.
[0071] Therefore, in step S100, it is determined whether image data has been received from the operator terminal device 20. Furthermore, if image data has been received from the operator terminal device 20, the process proceeds to step S102; otherwise, it proceeds to step S104.
[0072] In step S102, data for printing the image data received in step S100 by the image processing device 30 is generated and stored in the storage unit 16 as image data 16B.
[0073] An operator operates the image processing device 30 to instruct the printing of image data. If instructed to print image data, the image processing device 30 requests the information processing device 10 to send the instructed image data. Specifically, the image processing device 30 sends information determining its location, such as GPS information, along with information identifying the instructed image data, such as the filename, as a transmission request to the information processing device 10. Alternatively, if the information uniquely identifies the image processing device 30, it is not limited to GPS information; a unique identification ID assigned to the image processing device 30 may also be used.
[0074] In step S104, it is determined whether an image data transmission request has been received from the image processing device 30. If an image data transmission request has been received from the image processing device 30, the process proceeds to step S106; if no image data transmission request has been received from the image processing device 30, the procedure ends.
[0075] In step S106, it is determined whether the location of the image processing device 30, the source of the transmission request received in step S104, is a safe location. Specifically, referring to the safe location directory 16C stored in the storage unit 16, it is determined whether the latitude and longitude consistent with those represented by the GPS information included in the transmission request received in step S104 are registered in the location directory 16C, thereby determining whether it is a safe location. Furthermore, in Figure 5The image shows an example of a location directory 16C. For example... Figure 5 As shown, Location Directory 16C is a list of information on the latitude and longitude of safe locations.
[0076] Furthermore, if the latitude and longitude that match the latitude and longitude represented by the GPS information included in the transmission request received in step S104 are registered in the installation location directory 16C, it is determined that the installation location of the image processing device 30, the source of the transmission request received in step S104, is a safe installation location. On the other hand, if the latitude and longitude that match the latitude and longitude represented by the GPS information included in the transmission request received in step S104 are not registered in the installation location directory 16C, it is determined that the installation location of the image processing device 30, the source of the transmission request received in step S104, is not a safe installation location.
[0077] Furthermore, if the location of the image processing device 30, the source of the transmission request received in step S104, is a safe location, the process proceeds to step S108; if the location of the image processing device 30, the source of the transmission request received in step S104, is not a safe location, the process proceeds to step S110.
[0078] Here, a secure installation location refers to a location where, when image processing of image data is performed, information related to the image data will not be leaked to any third party unrelated to the operator who instructed the image processing. For example, suppose the operator instructed to perform image processing is an employee of Company A, and the image processing device 30 is installed within Company A. In this case, it can be said that information related to the image data will not be leaked to any third party unrelated to the operator who instructed the image processing, and therefore, the image processing device 30 can be considered a secure installation location. On the other hand, suppose the image processing device 30 is installed in a public place such as a convenience store. In this case, it can be said that information related to the image data may be leaked to any third party unrelated to the operator who instructed the image processing, and therefore, the image processing device 30 can be considered an unsecured installation location.
[0079] In step S108, a default security policy is read from the security policy information 16D stored in the storage unit 16. Here, the default security policy refers to the security policy that should be applied when the image processing device 30 is in a secure setting.
[0080] exist Figure 6 The example shown is the default security policy 16D1. Figure 6 As shown, the default security policy 16D1 defines instructions for nondeterministic processing, which outputs the image processing result in a manner where at least one of the operator and image data is uncertain. The image processing device 30 executes nondeterministic processing indicated as "ON" and does not execute nondeterministic processing indicated as "OFF".
[0081] exist Figure 6 In the example, non-deterministic processes are defined as "setting the operator's name to a hidden word," "setting the image data name to a hidden word," "printing with the printing surface facing down," and "not emitting any operating sounds." Furthermore, the instructions for each non-deterministic process are set to "OFF." Therefore, while the image data name and other details may be visible to others, the image processing device 30, which processes the image data, is located in a secure location, so there is no particular problem.
[0082] In step S110, a secure security policy is read from the security policy information 16D stored in the storage unit 16. Here, the secure security policy is the security policy used for insecure settings, which defines a more stringent policy than the default security policy.
[0083] exist Figure 7 The example shown is security strategy 16D2. Figure 7 As shown, in the secure security policy 16D2, the instructions for each non-deterministic process are set to "ON". That is, since the image processing device 30 that processes image data is located in an insecure location, non-deterministic processes such as making the image data name a hidden word are performed. As a result, the possibility of the operator's name, etc., being seen by others is reduced.
[0084] In step S112, image data requested to be sent from the image processing device 30 is read from image data 16B stored in the storage unit 16. Furthermore, the read image data and image processing instructions based on the security policy read in step S108 or step S110 are sent to the image processing device 30.
[0085] Therefore, the image processing device 30 processes the image data according to the security policy sent from the information processing device 10.
[0086] Thus, when an image data transmission request is received from the image processing device 30, the information processing device 10 according to this embodiment obtains a security policy corresponding to the location where the image processing device 30 is installed, and sends an image processing instruction based on the security policy to the image processing device 30. Therefore, the operator does not need to select a security policy, but performs image processing according to the security policy corresponding to the location where the image processing device 30 is installed.
[0087] Furthermore, in this embodiment, the information processing device 10 will process data according to a predefined method such as... Figure 6 , 7 The image processing instruction for the security policy of non-deterministic processing shown is sent to the image processing device 30. The image processing device 30 performs image processing on the image data according to the received image processing instruction, as described above, but is not limited to this. For example, the information processing device 10 may perform a process that excludes information related to the determination of at least one of the operator and the image data from the information related to the image data, such as at least one of the operator's name and the image data's name, as a predetermined process to prevent at least one of the operator and the image data from being determined. This suppresses the leakage of the operator's name, etc., to third parties.
[0088] Furthermore, the image processing instruction sent from the information processing device 10 to the image processing device 30 may include an instruction to perform a process that prevents information related to at least one of the operator and image data from being stored in the image processing device 30, as a predetermined process for determining whether at least one of the operator and image data is certain. Therefore, after image processing is performed by the image processing device 30, no information related to at least one of the operator and image data is stored, and no information related to at least one of the operator and image data is leaked.
[0089] Furthermore, in this embodiment, the acquisition of a security policy corresponding to the location of the image processing device 30 and the sending of image processing instructions according to the security policy to the image processing device 30 have been described, but it is not limited to this. For example, at least one of a first default security policy preset by the operator and a second default security policy preset by the logic printer may be stored in the storage unit 16 of the information processing device 10, and the logic printer may receive image data sent from the operator terminal device 20 according to the operator's instructions.
[0090] Furthermore, the information processing device 10 can be configured to retrieve at least one of a first default security policy preset by the operator and a second default security policy preset by the logic printer from the storage unit 16, and generate a new security policy based on the retrieved default security policy and the security policy corresponding to the attribute information. The logic printer receives image data sent from the operator terminal device 20 according to the operator's instructions. For example, a priority order is preset among the security policy corresponding to the attribute information, the first default security policy related to the operator, and the second default security policy related to the logic printer, and a new security policy is generated according to the preset priority order.
[0091] Specifically, for example, when the attribute information is information related to the installation location of the image processing device 30, according to such Figure 8 The new security policy is generated based on the priority order set in the priority information 50 shown. Figure 8 In this example, a priority order is set based on the location of the operator, the logic printer, and the image processing device 30. That is, the operator has the highest priority, and the location of the image processing device 30 has the lowest priority. Here, for example, the security strategies set for the locations of the operator, the logic printer, and the image processing device 30 are as follows: Figure 6 , 7 The diagram illustrates a security policy that defines instructions for non-deterministic processing. In this case, for example, the instruction to "hide the operator's name" in the security policy related to the logic printer and the security policy related to the location of the image processing device 30 is set to "OFF," while the instruction to "hide the operator's name" in the security policy related to the operator is set to "ON." In this case, the instruction to "hide the operator's name" in the regenerated security policy adopts the security policy related to the operator with the highest priority, and is therefore set to "ON." Furthermore, the priority order can be preset, or the operator can set any arbitrary priority order.
[0092] The embodiments have been described above, but the technical scope of the present invention is not limited to the scope described in the above embodiments. Various changes or improvements can be made to the above embodiments without departing from the spirit of the invention, and such changes or improvements are also included in the technical scope of the present invention.
[0093] Furthermore, the above embodiments do not limit the invention covered by the claims (requests), and all the feature combinations described in the embodiments are not essential to the solution of the invention. The foregoing embodiments include inventions at various stages, and various inventions are extracted by combining the disclosed multiple constituent elements. Even if several constituent elements are deleted from all the constituent elements shown in the embodiments, as long as the effect is obtained, the structure in which those constituent elements are deleted can be extracted as an invention.
[0094] Furthermore, in the above embodiments, the case where the information processing program is pre-installed in the storage unit 16 has been described, but the present invention is not limited thereto. For example, the information processing program may be provided in a manner that is stored in a storage medium such as a CD-ROM (Compact Disc Read Only Memory) or provided via a network.
[0095] Furthermore, in the above embodiments, the case of information processing being implemented by executing a program and utilizing a computer through a software structure has been described, but the present invention is not limited thereto. For example, information processing may also be implemented through a hardware structure or a combination of a hardware structure and a software structure.
[0096] In addition, the structure of the information processing device 10 described in the above embodiments (see reference) Figure 2 (This is just one example.) Without departing from the spirit of the invention, unnecessary parts may be deleted or new parts may be added.
[0097] Furthermore, the processing flow of the information processing program described in the above embodiments (refer to...) Figure 4 This is also an example. Without departing from the spirit of the invention, unnecessary steps can be deleted, new steps can be added, or the processing order can be changed.
[0098] The embodiments of the present invention described above are provided for illustrative purposes. Furthermore, these embodiments do not encompass the entirety of the invention, nor do they limit the invention to the disclosed methods. It will be apparent to those skilled in the art that various modifications and variations will be readily understood. These embodiments were chosen and described to most readily explain the principles and applications of the invention. Thus, those skilled in the art can understand the invention through various modifications that are assumed to be optimized for specific uses of various embodiments. The scope of the invention is defined by the foregoing claims and their equivalents.
Claims
1. An information processing device comprising: The receiving unit receives image data transmission requests from the image processing device that performs image processing as instructed by the operator. The acquisition unit, upon receiving the transmission request from the receiving unit, acquires a security policy corresponding to attribute information, which is related to the attributes of the image processing device; and The control unit controls the image processing device to send the image data to the image processing device and to perform image processing in the image processing device according to the security policy acquired by the acquisition unit. The acquisition unit acquires a default security policy of at least one of a first default security policy preset by the operator and a second default security policy preset by the information processing device; in, A priority order is set among the security policies corresponding to the attribute information, the first default security policy, and the second default security policy. The control unit generates a new security policy based on the priority order, using the default security policy acquired by the acquisition unit and the security policy corresponding to the attribute information. In the new security policy, for the same non-deterministic processing in the default security policy and the security policy corresponding to the attribute information, the indication of the non-deterministic processing with the highest priority is adopted.
2. The information processing apparatus according to claim 1, wherein, The attribute information includes information relating to at least one of the setup environment of the image processing device and the relationship between the operator and the image processing device.
3. The information processing apparatus according to claim 2, wherein, Information related to the setup environment refers to information indicating the location where the image processing device is set.
4. The information processing apparatus according to claim 2, wherein, Information relating to the relationship between the operator and the image processing device includes information indicating whether the image processing device is located at the operator's location.
5. The information processing apparatus according to any one of claims 1 to 4, wherein, The security policy is a pre-determined security policy for processing that prevents at least one of the operators and the number of images from being identified.
6. The information processing apparatus according to claim 5, wherein, The predetermined process is to send information to the image processing device that excludes determination information related to the determination of at least one of the operator and the image data from information relating to the image data.
7. The information processing apparatus according to claim 6, wherein, The determining information includes at least one of the operator's name and the name of the image data.
8. The information processing apparatus according to claim 5, wherein, The predetermined processing is a non-deterministic processing method in which the processing result of the image processing is output in a manner in which at least one of the operator and the image data is not determined.
9. The information processing apparatus according to claim 8, wherein, The non-deterministic processing is a process of hiding at least one of the operator's name and the name of the image data in the display section of the image processing device.
10. The information processing apparatus according to claim 5, wherein, The predetermined process is a process that prevents information related to at least one of the operator and the image data from being stored in the image processing device.
11. The information processing apparatus according to any one of claims 1 to 4, wherein, The information processing device receives the image data sent by the operator.
12. A storage medium storing an information processing program for enabling a computer to function as a component of any one of the information processing apparatuses claimed in claims 1 to 11.
13. An information processing method, comprising the following steps: The receiving step involves receiving a request to send image data from the image processing device that is instructed by the operator to perform image processing. In the acquisition step, if the sending request is received in the receiving step, a security policy corresponding to the attribute information is acquired, wherein the attribute information is related to the attributes of the image processing device; and The control steps are as follows: sending the image data to the image processing device, and performing image processing in the image processing device according to the security policy obtained in the acquisition step. The acquisition step acquires a default security policy for at least one of the first default security policy preset by the operator and the second default security policy preset by the information processing device. in, A priority order is set among the security policies corresponding to the attribute information, the first default security policy, and the second default security policy. The control step generates a new security policy based on the priority order, using the default security policy obtained in the acquisition step and the security policy corresponding to the attribute information. In the new security policy, for the same non-deterministic processing in the default security policy and the security policy corresponding to the attribute information, the indication of the non-deterministic processing with the highest priority is adopted.
14. A computer program product comprising a program for causing a computer to function as a unit: The receiving unit receives image data transmission requests from the image processing device that performs image processing as instructed by the operator. The acquisition unit, upon receiving the transmission request from the receiving unit, acquires a security policy corresponding to attribute information, which is related to the attributes of the image processing device; and The control unit controls the image processing device to send the image data to the image processing device and to perform image processing in the image processing device according to the security policy acquired by the acquisition unit. The acquisition unit acquires a default security policy of at least one of a first default security policy preset by the operator and a second default security policy preset by the information processing device; in, A priority order is set among the security policies corresponding to the attribute information, the first default security policy, and the second default security policy. The control unit generates a new security policy based on the priority order, using the default security policy acquired by the acquisition unit and the security policy corresponding to the attribute information. In the new security policy, for the same non-deterministic processing in the default security policy and the security policy corresponding to the attribute information, the indication of the non-deterministic processing with the highest priority is adopted.
Citation Information
Patent Citations
Security policy distributing system, device operating on the basis of security policy, security policy distributing method, security policy distributing program, and recording medium with program recorded thereon
JP2004094401A
Document management system, document management method, document management program and storage medium
JP2008102871A
Print system, processing method of the same, and program
JP2011113153A