Communication device, method of controlling a communication device, and storage medium
By setting up units and control units in the communication device and switching the communication path of the DNS server, the cumbersome and incomplete problems of DoH settings for devices such as MFP are solved, and flexible switching of encrypted communication and unified execution of security policies are realized.
Patent Information
- Application Number
- CN202180023977.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-04-01
- Filing Date
- 2021-03-22
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2041-03-22
AI Technical Summary
In the prior art, communication devices such as multi-functional peripheral devices (MFPs) are cumbersome and incomplete to set up when using DoH, and cannot uniformly switch the use/disuse of encrypted communication throughout the entire system or device, resulting in inconsistent execution of security policies.
A communication device is provided, including a setting unit, a storage unit, and a communication control unit. The setting unit sets the use/disuse of encrypted communication, the storage unit is used for exclusion conditions, and the communication path of the DNS server is switched when the conditions are met to achieve encrypted or plain text parsing.
It enables flexible switching of name resolution request destinations in communication devices, appropriately adapting to organizational security policies, avoiding incomplete and cumbersome settings, and improving security and operational efficiency.
Smart Images

Figure CN115336226B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a communication apparatus that transmits data to the outside. BACKGROUND
[0002] In recent years, when a name resolution of a host name is requested to a domain name system (hereinafter referred to as DNS), a mechanism such as a DNS based on a hypertext transfer protocol secure (HTTPS) (hereinafter referred to as DoH) is considered as a technique for preventing eavesdropping, impersonation, and forgery.
[0003] In DoH, a query such as a name resolution request to a DNS can be performed not through a plain text communication but through a communication path encrypted by HTTPS. A major web browser application can use DoH by switching a DNS setting of the web browser application from a DNS to DoH. When the web browser application performs a name resolution of a uniform resource locator (URL), this mechanism can prevent a third party from eavesdropping on a request content and prevent a request result from being forged by impersonation.
[0004] In addition, Patent Literature 1 discloses an apparatus that sets whether to allow a name resolution to a DNS server for each application installed in the apparatus from a security perspective.
[0005] LIST OF CITATIONS
[0006] PATENT LITERATURE
[0007] Patent Literature 1: Japanese Patent Laying-Open No. 2017-139648 SUMMARY
[0008] TECHNICAL PROBLEM
[0009] As described above, it is known that an operation setting using DoH is provided as a setting for a single application such as a web browser application.
[0010] In some cases, a communication apparatus such as a multifunction peripheral (MFP) and a personal computer (PC) communicates with a communication partner designated by a host name via a unit other than a web browser application, for example, accesses a file server. In addition, according to a security policy of an organization, a company, or the like, in some cases, it is recommended to use a more secure DoH for a name resolution of a host name in a communication apparatus. In this case, considering a setting of use / non-use of DoH as a setting of a single application or switching use / non-use of DoH at an application side, but this can cause problems such as a troublesome setting and an incomplete setting. In the related art, there is no specific mechanism of making a setting to use DoH in communication of an entire system or an entire apparatus.
[0011] The present application has been made in view of at least one of the above problems. One aspect of the present application relates to a mechanism that enables setting of use / non-use of encrypted communication for name resolution as an operation setting of a communication apparatus, and that enables appropriate switching of a request destination of name resolution of the communication apparatus.
[0012] Solution to the problem
[0013] To achieve at least one of the objects, there is provided a communication apparatus including: a setting unit configured to set whether or not to use encrypted communication for name resolution as an operation setting of the communication apparatus; a storage unit configured to store a condition for excluding a target of name resolution using encrypted communication; and a communication control unit configured to, in a case where name resolution of a host name requested from an application is performed, request a first Domain Name System (DNS) server to perform name resolution of the host name via an encrypted communication path established with the first DNS server based on at least the fact that use of encrypted communication is set by the setting unit, and request a second DNS server to perform name resolution of the host name in plain text based on the fact that non-use of encrypted communication is set by the setting unit, wherein in a case where a request of name resolution of the host name satisfies the condition stored in the storage unit, the communication control unit requests the second DNS server to perform name resolution of the host name in plain text even in a case where use of encrypted communication is set by the setting unit.
[0014] Advantageous effects of the invention
[0015] According to one aspect of the present application, by setting use / non-use of encrypted communication for name resolution as an operation setting of a communication apparatus, it is possible to appropriately switch a request destination of name resolution of the communication apparatus. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments of the application and, together with the description, serve to explain the principles of the application.
[0017] Figure 1 is a diagram illustrating an example of a communication system.
[0018] Figure 2 is a diagram illustrating an example of a hardware configuration of a multifunction peripheral (MFP) 101.
[0019] Figure 3 is a diagram illustrating an example of a software configuration of the MFP 101.
[0020] Figure 4 is a diagram illustrating an example of a setting screen regarding a network.
[0021] Figure 5A is a diagram showing an example of a setting screen regarding a network according to the first example embodiment.
[0022] Figure 5B is a diagram showing an example of setting information regarding a network according to the first example embodiment.
[0023] Figure 6 is a flowchart showing a control example of the MFP 101 according to the first example embodiment.
[0024] Figure 7A is a diagram showing an example of a setting screen regarding a network according to the second example embodiment.
[0025] Figure 7B is a diagram showing an example of setting information regarding a network according to the second example embodiment.
[0026] Figure 8 is a flowchart showing a control example of the MFP 101 according to the second example embodiment.
[0027] Figure 9 is a diagram showing an example of a setting screen regarding a security policy according to the third example embodiment.
[0028] Figure 10 is a flowchart showing a control example of the MFP 101 according to the third example embodiment.
[0029] Figure 11A is a diagram showing a modification example of the setting screen.
[0030] Figure 11B is a diagram showing another modification example of the setting screen. DETAILED DESCRIPTION
[0031] Some example embodiments of the present application will be described below with reference to the accompanying drawings. The following example embodiments do not limit the present application according to the claims, and all combinations of characteristics described in the example embodiments are not essential to the means of solution of the present application.
[0032] <First Example Embodiment>
[0033] First, a description will be given of a setting screen regarding a network according to the first example embodiment with reference to Figure 1A configuration of a communication system according to the present application is described. In the communication system according to the present exemplary embodiment, a multifunction peripheral (MFP) 101, a domain name system (DNS) server 102, and a mail server 103 are communicably connected via a network 100. Further, a file server 104 and a print server 105 are communicably connected via the network 100. Host names managed by the DNS server 102 are assigned to the servers 103 to 105. Further, the MFP 101 is communicably connected to a DNS over Hypertext Transfer Protocol Secure (HTTPS) (DoH) server 107 and a web server 108 on the Internet 106 via the network 100, a wide area network (WAN), or the like. The network 100 is a local area such as a company and an organization. The servers 103 to 105 are servers provided to clients in the local area. Therefore, name resolution of host names corresponding to the servers 103 to 105 can be performed only by the DNS server in the local area. In other words, the DoH server 107 arranged on the Internet cannot perform name resolution of host names in the local area (host names operated for a company or an organization).
[0034] The MFP 101 is an example of a communication terminal. In the present exemplary embodiment, the MFP having a print function and a transmission function of transmitting an image obtained by scanning an original to an outside is described as an example; however, the communication terminal is not limited thereto. Communication apparatuses such as an Internet of Things (IoT) device, a personal computer, and a smartphone can be employed.
[0035] The MFP 101 includes a transmission function to transmit data based on an image obtained by scanning (also referred to as scan data) to a file server or transmit the data by attaching the data to a mail. Hereinafter, the transmission function of performing mail transmission or file transmission of data based on an image is also simply referred to as a transmission function.
[0036] The MFP 101 further includes a pull-print function to access the print server 105 and receive and print print data accumulated in the print server. Further, the MFP 101 includes a web browser application, and can display web contents acquired from the web server 108 or the like on an operation unit 116 of the MFP 101.
[0037] When data is transmitted by the transmission function, the MFP 101 performs transmission by using a destination that specifies the host name of the server. Further, when mail with attached data is transmitted, the MFP 101 performs name resolution of the host name of the mail server 103, and acquires an Internet Protocol (IP) address for communication with the mail server 103. Subsequently, the MFP 101 communicates with the mail server 103 using the IP address, and transmits the mail. When a network content is displayed, the MFP 101 receives a Uniform Resource Locator (URL) of a network server (for example, the network server 108), and specifies a network content providing server. A method of performing name resolution of the host name at this time will be described below.
[0038] <Hardware configuration of MFP 101>
[0039] Subsequently, the MFP 101 will be described with reference to Figure 2 Figure 2 is a block diagram showing a hardware configuration of the MFP 101. The MFP 101 includes a reading function of reading an image on a sheet and a file transmission function of transmitting the read image to an external communication device. The MFP 101 also includes a printing function of printing an image on a sheet.
[0040] A control unit 110 including a Central Processing Unit (CPU) 111 controls the operation of the entire MFP 101. The CPU 111 performs various controls such as printing control and reading control by reading out a control program stored in a Read Only Memory (ROM) 112 or a storage 114. The ROM 112 stores a control program executable by the CPU 111. A Random Access Memory (RAM) 113 is a main memory accessed by the CPU 111, and functions as a work area or a temporary storage area for loading various control programs. The storage 114 stores print data, image data, various programs, and various setting information. As described above, the hardware such as the CPU 111, the ROM 112, the RAM 113, and the storage 114 constitutes a computer.
[0041] In the MFP 101 according to the present exemplary embodiment, one CPU 111 performs the processes in the flowcharts described below by using one memory (RAM 113); however, other modes can also be employed. For example, a plurality of processors, memories, and storages can cooperate with each other to perform the processes in the flowcharts described below. Alternatively, a part of the processes can be performed using a hardware circuit.
[0042] A printer interface (I / F) 119 connects a printer 120 (printer engine) and the control unit 110. The printer 120 prints an image on a sheet fed from a feeding cassette (not shown) based on print data input via the printer I / F 119. The print method can be an electrophotographic method of transferring and fusing toner to a sheet, or can be an inkjet method of performing printing by jetting ink to a sheet. Further, the printer 120 can be a three-dimensional (3D) printer that generates an output product having a 3D shape by using a shaped material. In this case, the print data is print data indicating a 3D shape, and the printer 120 generates an output product having a 3D shape by using a shaped material and a support material instead of a color material such as toner and ink.
[0043] A scanner I / F 117 connects a scanner 118 and the control unit 110. The scanner 118 reads a document placed on a platen (not shown) and generates image data. The image data generated by the scanner 118 is printed by the printer 120, stored in the storage 114, or transmitted to an external device via the network I / F 121.
[0044] An operation unit I / F 115 connects an operation unit 116 and the control unit 110. The operation unit 116 includes a liquid crystal display unit having a touch panel function and various hardware keys. The operation unit 116 functions as a display unit that displays information to a user and a reception unit that receives an instruction from the user. The CPU 111 cooperates with the operation unit 116 to perform information display control and user operation reception control.
[0045] A network cable is connected to the network I / F 121, and the network I / F 121 can communicate with an external device on a network 100 or on the Internet. In the present exemplary embodiment, it is assumed that the network I / F 121 is a communication interface that performs wired communication conforming to the ; however, the network I / F 121 is not limited thereto. For example, the network I / F 121 can be a wireless communication interface conforming to the Institute of Electrical and Electronics Engineers (IEEE) 802.11 series. Further, the network I / F 121 can be a communication interface that performs mobile communication (for example, a third generation (3G) network such as Code Division Multiple Access (CDMA), a fourth generation (4G) network such as Long Term Evolution (LTE), or a fifth generation New Radio (5G NR)).
[0046] <Software Configuration of MFP 101>
[0047] Subsequently, the software configuration of the MFP 101 will be described with reference to Figure 3 FIG. 8. The functional blocks shown in FIG. 8 are realized when the CPU 111 executes a program loaded on the RAM 113. Figure 3
[0048] An operating system (OS) 1020 is a program that performs basic control of a computer. The OS 1020 includes a module function for managing a process of an application and middleware, a module function of a transmission control protocol (TCP) / IP protocol stack that serves as network communication, and an OS standard DNS client 1021 for name resolution. The middleware 1030 is a module group located at an upper layer of the OS 1020. The middleware 1030 includes a module for managing an operation setting of the MFP 101 and a DoH client 1080 for performing name resolution through an encrypted communication path. The MFP 101 also includes middleware such as a module for controlling printing (not shown due to lack of space). The application 1010 is a group of applications that operate on the OS 1020 to realize functions of the MFP.
[0049] First, the group of applications held by the MFP 101 will be described. A web browser application 1010a is a web browser that displays web contents acquired from a web server on a network. A send application 1010b is an application that sends data based on an image obtained by scanning an original with the scanner 118 through a file server or a mail server. The send application 1010b can send a file based on an image obtained by reading an original with the scanner 118 to a send destination specified by a user. The send destination can be specified by a user operation via a send setting screen (not shown). The user specifies the destination by inputting a host name of a file server or a mail server in a fully qualified domain name (FQDN) format. In response to selection of a key to start sending after setting the send destination via the send setting screen, the send application 1010b requests the scanner 118 to read an original. Subsequently, the send application 1010b sends data based on an image obtained by reading the original to the send destination specified by the user. In the present exemplary embodiment, as an example of the send process, it is assumed that file sending using a transmission protocol such as a file transfer protocol (FTP) and a secure shell (SSH) FTP (SFTP) is assumed. Further, it is assumed that mail sending processing using a simple mail transfer protocol (SMTP) via a mail server 103 is assumed. However, the send process is not limited thereto, and file sending using a communication protocol such as web-based distributed authoring and versioning (webDAV) can be employed.
[0050] The pull printing application 1010c is a printing application that receives print jobs accumulated in the print server 105 and performs printing via the printer 120. The pull printing application 1010c performs an inquiry about a print job to the print server 105 on the network 100, and downloads job data specified in a URL format from a cloud server or a cloud storage, and prints the job data. In this case, communication with a destination specified by a host name or a URL is performed. The name resolution and data transmission processing at the time when these applications perform communication are performed in cooperation with the middleware 1030 and the OS 1020.
[0051] As described above, in some cases, a communication device such as the MFP 101 communicates with a communication partner specified by a host name via a unit other than a web browser application, for example, access to a file server. In addition, according to a security policy of an organization, a company, or the like, in some cases, it is recommended to use a more secure DoH for name resolution of a host name in a communication device. In this case, it is possible to consider setting use / non-use of DoH as a setting for an individual application, or to switch use / non-use of DoH at the application side, but this can cause problems such as troublesome setting and incomplete setting.
[0052] In the present exemplary embodiment, a mechanism is provided that enables use / non-use of encrypted communication for name resolution to be set as an operation setting of a communication device, and enables appropriate switching of a request destination of name resolution of the communication device.
[0053] Returning to refer to Figure 3 , the OS 1020 includes a TCP / IP protocol stack for network communication and an OS standard DSN client 1021 for name resolution. In the present exemplary embodiment, it is assumed that the DNS client 1021 is the case where a standard DNS client in the system is used. When name resolution of a domain name is performed using these clients, a description of "name server 'IP address of the DNS server'" is added in a file located at " / etc / resolve.conf" to specify a DNS server. For redundancy, a plurality of DNS servers to be used can be specified. In the present exemplary embodiment, a description will be given by assuming that the IP address of the DNS server 102 is set. The DNS client 1021 has a function of requesting a specified DNS server to perform name resolution of plain text.
[0054] Subsequently, the operation of the middleware group 1030 will be described. The setting value database (DB) 1050 stores the operation settings of the MFP 101 including the communication settings. The communication settings include the settings of the communication interface and the settings regarding the DNS. The DoH client 1080 establishes an encrypted communication path with the DoH server 107 that supports DoH, and requests the server 107 to perform name resolution by HTTP communication via the established communication path.
[0055] The DNS control unit 1040 has a function of displaying a setting screen on the operation unit 116, receiving a change of various network settings from a user such as an administrator, and storing the change in the setting value DB 1050. Further, the control unit 1040 includes a DNS setting control unit 1040a. The DNS setting control unit 1040a refers to the values in the setting value DB 1050, and performs startup control and operation setting control of the DoH client 1080 and the DNS client 1021. Further, the DNS control unit 1040 has a function of determining whether to request the DNS client 1021 or the DoH client 1080 to perform name resolution of a host name received from an application.
[0056] The control unit 1040 can also cooperate with a web server function (not shown) to provide a web page for confirming and changing the settings regarding name resolution. In this case, a user such as an administrator can access the web page provided by the MFP 101 from a client such as a PC, and can change the settings regarding name resolution.
[0057] The DNS server automatic acquisition unit 1070 has a function of acquiring the address of the DNS server or the DoH server from a dynamic host configuration protocol (DHCP) server or an IPv6 router. The control unit 1040 cooperates with the acquisition unit 1070 to acquire the IP address of the DNS server or the host name / IP address of the DoH server from the DHCP server or the IPv6 server, and stores the IP address of the DNS server or the host name / IP address of the DoH server as the operation settings regarding the DNS. In the case where the DNS server automatic acquisition is enabled, the DNS server automatic acquisition unit 1070 acquires the settings of the DNS server from the network. The automatic acquisition unit 1070 includes a DHCP client. The DHCP client of the automatic acquisition unit 1070 transmits a request including a DHCP option that inquires a name resolution server to a DHCP server on the network, and acquires the address of the DNS server or the DoH server. Note that in the case where IPv6 is adopted as the protocol stack, the address of the DNS server or the DoH server can be acquired by exchanging a router solicitation (RS) and a router advertisement (RA).
[0058] <Operation Settings Regarding DNS in the MFP 101>
[0059] An example of the operation setting regarding DNS of the screen provided via the control unit 1040a will be described with reference to Figure 4
[0060] The key 401a is a key for enabling (ON) the operation setting of using DoH, and the key 401b is a key for disabling (OFF) the operation setting of using DoH. Any one of the keys 401a and 401b is enabled, and the other is disabled. In this example, a case where the operation setting of using DoH for name resolution is enabled is exemplified.
[0061] The key 402a is a key for enabling (ON) the operation setting of performing automatic acquisition of the DoH server address from a DHCP server, RA, or the like. The key 402b is a key for disabling (OFF) the operation setting of automatic acquisition of the DoH server address. Any one of the keys 402a and 402b is enabled, and the other is disabled. In the screen 400, a case where automatic acquisition is set is exemplified.
[0062] The region 403 is a region that displays the settings of DoH. Further, in a case where the key 401b is enabled and automatic acquisition is disabled, the region 403 functions as a region for manually setting the host name or IP address of the DoH server. In this case, the user can manually set the DoH server address by inputting the IP address or host name via a software keyboard (not shown) displayed on the operation unit 116.
[0063] The key 404 is a key for performing exception settings of DoH. Details thereof will be described below. The keys 405a and 405b are keys for switching whether to automatically acquire the IP address of the DNS server that performs plain text name resolution. In the present exemplary embodiment, a case where the operation setting for performing automatic acquisition is set is exemplified. The region 407 is a region that displays the settings of the DNS server. In a case where automatic acquisition is disabled, the region 407 also functions as a region for manually setting the IP address of the DNS server. When it is detected that the enter key is pressed after the setting operation is performed via the screen 400, the control unit 1040a stores the settings performed via the screen in the setting value DB 1050 as the operation setting of the MFP 101.
[0064] Subsequently, an example of the screen regarding exception settings of DoH will be described with reference to Figure 5A and Figure 5B Exception settings of DoH will be described. Figure 5A An example of the screen regarding exception settings of DoH is shown, Figure 5B An example of the setting value stored in the setting value DB 1050 is shown.
[0065] When it is detected that the key 404 in the screen 400 is selected, the CPU 111 of the MFP 101 changes the screen displayed on the operation unit 116 to a setting screen 500. The screen 500 is a screen for setting exceptions to the name resolution of the DoH client 1080. By performing a touch operation on the area 501, the user can set an exception application that does not perform name resolution by DoH for each application held by the MFP 101. The user can specify an application to be excluded from the target of name resolution using DoH by an operation via the screen. In the present exemplary embodiment, a case where the sending application 1010b is set as an exception application is exemplified. For example, an administrator or the like can perform a setting so as not to use DoH for an application that mainly communicates with a server in a local area based on a result of utilization by a user. This makes it possible to prevent a host name of a server that provides a service in a local area from being leaked to the DoH server 107.
[0066] The area 502 is an area for explicitly specifying a host name to be excluded from the target of a name resolution request to the DoH server. Hereinafter, a host name to be excluded from the target of a name resolution request to the DoH server is also simply referred to as an exception host name or the like. An administrator who wants to add an exception host name presses an add key and inputs an exception host name via an input screen (not shown). An edit key is a key for editing a registered exception host name. A delete key is a key for deleting one or more registered exception host names selected by a touch operation on the area 502. In the case of using a screen via a network, an exception host name can be registered by importing a csv file in which exception host names are listed in a comma separation. When it is detected that an enter key is pressed after a setting operation is performed via the screen 500, the control unit 1040a stores the setting performed by the screen as an operation setting of the MFP 101 in the setting value DB 1050.
[0067] The setting of an exception application and an exception host name performed by a user operation of the screen in Figure 5A is stored as an operation setting of the MFP 101 in the setting value DB 1050. Figure 5B It is shown that the setting of the exception application and the exception host name is reflected in the screen via Figure 4 and Figure 5AThe settings performed via the region 502 are stored as data having a list structure in which an exceptional host name (hereinafter also referred to as an exceptional host name list) is listed. The setting of DoH is an operation setting indicating whether or not DoH is used. The setting of DNS provider is a setting indicating the IP address of the DNS server used by the MFP 101. The setting of DoH provider is a setting indicating the host name or IP address of the DoH server used by the MFP 101. The setting of exceptional application is a setting indicating a name as identification information for identifying an application excluded from the DoH target. The information stored in the setting value DB 1050 can be an identifier (ID) that identifies and specifies an application. Reference is made to this setting in the flowchart described below as appropriate.
[0068] The specific control will be described with reference to the flowchart in Figure 6 When the CPU 111 calls a program for implementing the control module stored in the ROM 112 or the storage 114 to the RAM 113 and executes the program, the operations (steps) shown in the flowchart in Figure 6 are implemented. The data transmission / reception processing and other processing are implemented in cooperation with the network I / F 121. Further, in a case where the subject to be explicitly processed, the description will be given as the subject by using the software module executed by the CPU 111. Figure 6 The flowchart in
[0069] In step S601, the DNS control unit 1040 refers to the setting value DB 1050 and determines whether or not the use of DoH is set. In a case where the setting value corresponding to the setting item DoH is ON, the DNS control unit 1040 determines that the use of DoH is set (YES in step S601), and the processing proceeds to step S602. In a case where the setting value corresponding to the setting item DoH is OFF, the DNS control unit 1040 determines that the use of DoH is not set (NO in step S601), and the processing proceeds to step S606.
[0070] In step S602, the control unit 1040 determines whether or not the host name that is the name resolution target requested by the application includes in the exceptional host name list. In a case where the host name matching the requested host name resolution is registered in the exceptional host name list (YES in step S602), the processing proceeds to step S606. In a case where the host name is not registered (NO in step S602), the processing proceeds to step S603.
[0071] In step S603, the control unit 1040 specifies the type of the request source application that has requested name resolution, and determines whether an application of the specific type is designated as an exceptional application. In a case where an application of the specific type is designated as an exceptional application (YES in step S603), the processing proceeds to step S606. In a case where an application of the specific type is not designated as an exceptional application (NO in step S603), the processing proceeds to step S604. As a specific method of specifying the request source application in step S603, the following method can be employed. For example, the control unit 1040 functioning as the middleware 1030 provides each application with an API function to be called when name resolution is requested. The API function is configured so that identification information for specifying the application is settable as a parameter. When the API function is called (i.e., name resolution is requested), each application sets the identification information for identifying the application to the parameter. The control unit 1040 can specify the type of the request source application by referring to the parameter.
[0072] In step S604, the control unit 1040 transmits the name resolution request requested by the application to the DoH client 1080. Subsequently, in step S605, the DoH client 1080 that has received the name resolution request requests the DoH server 107 to perform name resolution using encrypted communication. At this time, communication for name resolution is performed via a communication path of HTTPS.
[0073] In step S608, the control unit 1040 receives the result of name resolution from the DoH client 1080, and determines whether an IP address has been acquired as a result of name resolution. In a case where an IP address corresponding to the host name has been acquired as a result of name resolution by the DoH server 107 (YES in step S608), the processing proceeds to step S609. In a case where an IP address corresponding to the host name has not been acquired (NO in step S608), the processing proceeds to step S606. The control unit 1040 determines that an IP address has not been acquired, in a case where, for example, communication with the DoH server cannot be performed, or in a case where the result of name resolution received from the DoH server indicates that the destination cannot be found. The processing in step S608 is processing that realizes transition to plain text name resolution in a case where the DoH cannot find the destination.
[0074] In step S606, the control unit 1040 requests the DNS client 1021 to perform name resolution. Subsequently, in step S607, the DNS client 1021 transmits a name resolution request to the DNS server 102. As described above, the name resolution request is performed in plain text. When the host name is a domain name managed by the DNS server 102, the DNS server 102 returns an IP address corresponding to the domain. Otherwise, the DNS server 102 transmits a query to a host DNS server and performs name resolution.
[0075] Finally, in step S609, the control unit 1040 returns a response to the name resolution request transmitted in step S607 or S605 to the source application of the request. Through the series of processes described above, it is possible to flexibly switch whether to perform name resolution through DoH or not to attempt name resolution through DoH and to perform name resolution through the existing plain text, based on the settings of the exception application and the settings of the exception host name.
[0076] <Second Exemplary Embodiment>
[0077] In the first exemplary embodiment, a case where the use / non-use of DoH is set for each application is exemplified. In the second exemplary embodiment, a case where the use / non-use of DoH is set for each protocol is described. The hardware configuration and the software configuration in the second exemplary embodiment are similar to those in the first exemplary embodiment. Therefore, the description thereof will be omitted.
[0078] Figure 7A and Figure 7B are diagrams illustrating exception settings of DoH in the second exemplary embodiment. Figure 7A An example of a screen displayed instead of the screen in Figure 5A in accordance with the first exemplary embodiment is illustrated. Figure 7B An example of a setting value stored in the setting value DB 1050 in the second exemplary embodiment is illustrated.
[0079] When it is detected that the key 404 in the screen 400 described in Figure 4 is selected, the CPU 111 of the MFP 101 switches the screen displayed on the operation unit 116 to the setting screen 700. The setting of the exception host name in the area 702 is similar to that in the first exemplary embodiment. Therefore, the description of the setting will be omitted.
[0080] In the area 701, communication protocols used by the MFP 101 are listed. The user can set an exceptional communication protocol by performing a touch operation on the area 701. In this example, a case where SMB and FTP / SFTP are set as the exceptional communication protocols is shown. For example, an administrator or the like can perform the setting so as not to use DoH for a communication protocol mainly used for communication with a server in the local area, based on the utilization result of the user. After the setting operation is performed via the screen 700, when it is detected that the enter key is pressed, the control unit 1040a stores the setting performed via the screen as the operation setting of the MFP 101 in the setting value DB 1050. The setting of the exceptional protocol and the exceptional host name performed via the screen in Figure 7A is stored in the setting value DB 1050 as the operation setting of the MFP 101. Figure 7B An example of the operation setting of the name resolution performed via the screen in Figure 4 and Figure 7A is shown.
[0081] A specific control in the second example embodiment will be described with reference to the flowchart in Figure 8 When the CPU 111 calls a program for implementing the control module stored in the ROM 112 or the storage 114 to the RAM 113 and executes the program, the operation (step) shown in the flowchart in Figure 8 is implemented. As with the first example embodiment, the data transmission / reception processing and other processing are implemented in cooperation with the network I / F 121. In a case where the main body of the processing is to be made clear, the description will be given using a software module as the main body.
[0082] The processing in steps S801 and S802 is similar to that in steps S601 and S602 according to the first example embodiment. Therefore, the description of the processing will be omitted.
[0083] In step S803, the control unit 1040 specifies the communication protocol corresponding to the host name for which the name resolution is requested, and determines whether the communication protocol is specified as an exceptional protocol. In a case where the communication protocol is specified as an exceptional protocol (YES in step S803), the processing proceeds to step S806. In a case where the communication protocol is not specified as an exceptional protocol (NO in step S803), the processing proceeds to step S804. The specification of the communication protocol can be performed by calling an API function of the name resolution in which the type of the communication protocol is set as a parameter by the requesting source application, and notifying the control unit 1040 of the communication protocol, by a mechanism similar to that in the first example embodiment.
[0084] The subsequent name resolution processing using DoH or DNS in steps S804 to S809 is similar to the name resolution processing in the first example embodiment. Therefore, the description of the name resolution processing will be omitted.
[0085] As described above, in the second example embodiment, based on the settings of the exception protocol and the exception host name, it is possible to flexibly switch whether to perform name resolution by DoH or not to attempt name resolution by DoH and to perform name resolution by the existing plain text.
[0086] <Third Example Embodiment>
[0087] In the first example embodiment and the second example embodiment, the case where the setting of whether to perform name resolution by DoH is set through the setting screen with respect to the network is described as an example. The communication device such as an MFP has various settings, and even a user such as a network administrator who is familiar with the network can perform incomplete settings and make a setting error.
[0088] In view of this, the MFP 101 has a function of setting a security policy that collectively changes a plurality of settings with respect to security, for example, the setting of the network such as direct connection, the setting of the number of bits of the password of the authorized user, and the setting of the lock. In the third example embodiment, in addition to the setting control described in the first example embodiment and the second example embodiment, it is possible to change the setting of whether to use encryption for name resolution via the screen for setting the security policy. A specific description will be given below.
[0089] Figure 9 An example of a screen 900 for setting a security policy displayed on the operation unit 116 is shown. In the present example embodiment, whether to use encrypted communication for name resolution can be set in the screen for setting the operation policy of communication. The check box 901 is a display item selected to use encrypted communication for name resolution. Further, the user can also set other operation policies via the screen in Figure 9 In the case where the policy of ensuring the verification of the server certificate during the Transport Layer Security (TLS) communication is set, the setting of blocking the TLS communication by the self-signed certificate and the expired certificate is performed. Further, the individual setting with respect to the pull printing application 1010c and the like is also changed to the setting of requiring the verification of the certificate at the time of communication with the print server. In the case where the policy of prohibiting plain text authentication is set in the server function, a plurality of setting values of the MFP 101 are changed to uniformly prohibit the server function using plain text authentication and the server function using plain text authentication.
[0090] Reference will be made to Figure 10The flowchart in FIG. 10 describes specific control according to the third exemplary embodiment. When the CPU 111 calls a program for implementing the control module stored in the ROM 112 or the storage 114 to the RAM 113 and executes the program, the operations (steps) shown in the flowchart of FIG. 10 are implemented. As with the first exemplary embodiment, the data transmission / reception processing and other processing are implemented in cooperation with the network I / F 121. Figure 10
[0091] In step S1001, the CPU 111 determines whether a user operation reflecting a setting change of the policy has been received. In the case where a user operation reflecting a setting change of the policy has been received (YES in step S1001), the processing proceeds to step S1002. In the case where a user operation has not been received (NO in step S1001), the CPU 111 waits for a setting change. The user operation reflecting a setting change of the policy is, for example, a user operation of pressing the enter key in the screen 900.
[0092] In step S1002, the CPU 111 determines whether a policy using encrypted communication for name resolution has been specified. In the case where a policy using encrypted communication for name resolution has been specified (YES in step S1002), the processing proceeds to step S1006. In the case where a policy has not been specified (NO in step S1002), the processing proceeds to step S1003.
[0093] In step S1003, the CPU 111 changes the setting value stored in the setting value DB 1050 to an operation setting value using DoH. More specifically, the CPU 111 enables setting of automatic acquisition of a DoH server address, and enables setting of use of DoH. Further, the CPU 111 changes the setting of a port filter (not shown), and changes the setting to one that allows communication in the port 443 required for HTTPS communication. In the present exemplary embodiment, a case where automatic acquisition is enabled is exemplified; however, the setting is not limited to this. In the case where a DoH server address has been manually input, the setting of disabling automatic acquisition can be maintained without enabling automatic acquisition.
[0094] Subsequently, in step S1004, the CPU 111 determines whether communication with the DoH server is executable with the current operation setting value. More specifically, the CPU 111 attempts to establish an encrypted communication path with the DoH server, and checks whether encrypted communication can be established. Alternatively, the CPU 111 can actually attempt name resolution of the DoH server, and in the case where name resolution is executable, the CPU 111 can determine that communication is executable.
[0095] In a case where the CPU 111 determines that the communication is executable (YES in step S1004), the process proceeds to step S1006. In a case where the CPU 111 judges that the communication is not executable (NO in step S1004), the process proceeds to step S1005. In step S1005, the CPU 111 displays an error screen on the operation unit 116. An error message indicating the cause of the error is displayed on the error screen. Further, a display item for changing the screen displayed on the operation unit 116 to the DNS setting screen can be displayed on the error screen. The display item is useful when the user manually sets the DoH server location in a case where the DoH server address cannot be automatically acquired.
[0096] In step S1006, the CPU 111 determines whether an operation to enable another policy has been received. In a case where the operation to enable another policy has been received (YES in step S1006), the process proceeds to step S1007. In contrast, in a case where the operation to enable another policy has not been received (NO in step S1006), the series of processes ends.
[0097] In step S1007, the CPU 111 changes the operation setting value of the MFP 101 based on the other policy enabled. Then, the series of processes ends.
[0098] Through the above-described processes, it is possible to more easily enable the DoH setting that affects all the functions of the MFP 101.
[0099] <Variant>
[0100] In addition to the control according to the first example embodiment, the control according to the second example embodiment can be executed. In this case, the administrator or the like can set an application, a communication protocol, and a host name as an exception setting. In this case, after the determination step of step S603, the determination processing in the determination step of step S803 is further executed.
[0101] In the first and second exemplary embodiments, the cases illustrate the scenario where a user, such as an administrator, selects the exceptions to the DoH name resolution targets and the exception protocols to exclude. However, the method of setting whether to use DoH name resolution or existing plaintext name resolution can be appropriately modified. For example, a user, such as an administrator, can select the applications or communication protocols that should use DoH name resolution. In this case, a target application list including applications that should use DoH name resolution and a target protocol list including communication protocols that should use DoH name resolution are stored in the setting value DB 1050. In this case, instead of the process in step S603 according to the first exemplary embodiment, the process of determining whether the requesting source application is included in the target application list is performed. If the requesting source application is included in the target application list, the process proceeds to step S604. If the requesting source application is not included in the target application list, the process proceeds to step S606. Similarly, in the second exemplary embodiment, instead of the process in step S803, the process of determining whether the communication protocol corresponding to the hostname is included in the target protocol list is performed.
[0102] In addition, it can be like Figure 11A and Figure 11B The selection method has been modified as shown. Figure 11A and 11B Variant examples replacing screen 500 are shown. Screen 1100 displays a settings area 1101 for selecting whether to use DNS or DoH for each application. Users can determine via the screen whether to use DoH or DNS for each application held by the MFP 101. The control unit 1040 of the MFP 101 generates the aforementioned list of exception applications based on the settings performed via the screen and stores the list in the settings value DB 1050. In settings area 1101, it is clearly described in parentheses that DNS uses plain text while DoH uses encryption. Therefore, users such as administrators can intuitively set whether to use name resolution via plain text or the highly secure name resolution via DoH for each application.
[0103] Furthermore, the selection method can be modified as shown in screen 1110. Area 1111 is the display area for selecting the primary communication partner for each application. The administrator selects "Intranet" for applications that primarily communicate with the local area where the MFP 101 is installed. For example, the administrator can specify a local area for a pull-to-print application that communicates with the print server 105 installed in the local area. On the other hand, the administrator selects "Internet" for applications that primarily communicate with servers on the Internet.
[0104] The message is displayed in screen 1110, which indicates that name resolution by the DNS server in plain text is given priority even if the use of DoH is set, in the case where the intranet is designated as the primary destination.
[0105] In the case where the selection method is modified to this selection method, the control unit 1040 of the MFP 101 generates an exception application list including applications whose primary communication partner is designated as “intranet” based on the setting performed via the screen, and stores the exception application list in the setting value DB 1050.
[0106] The modification described in Fig. 11 can be applied to the second example embodiment. In this case, the selection method used by the MFP 101 for each communication protocol can be modified to any of the selection methods shown in Fig. 11. In this case, the method of generating an exception protocol list to be stored in the setting value DB 1050 is similar to the method of generating an exception application list. Therefore, the description thereof will be omitted.
[0107] Finally, in the present example embodiment, DoH is described as an example of a method of using encrypted communication for name resolution; however, the method is not limited thereto. The present example embodiment can be applied to the case of using DNS over TLS (DoT), in which only the communication path is encrypted by TLS, and a DNS packet in plain text is transmitted to the communication path.
[0108] <Other Example Embodiments>
[0109] The present application can be implemented by providing a program that implements one or more functions of the above-described example embodiments to a system or an apparatus via a network or a storage medium, and causing one or more processors in a computer of the system or the apparatus to read out and execute the program. Furthermore, the present application can be implemented by a circuit (for example, an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA)) that implements one or more functions.
[0110] The present application is not limited to the above-described example embodiments, and various substitutions and modifications can be made without departing from the spirit and scope of the present application. Therefore, in order to disclose the scope of the present application, the following claims are attached.
[0111] This application is based upon and claims the benefit of priority from Japanese Patent Application No. 2020-066185, filed on April 1, 2020, in the Japan Patent Office, the disclosure of which is incorporated herein in its entirety by reference.
Claims
1. A communication apparatus comprising: a setting unit configured to set whether or not to use encrypted communication for name resolution as an operation setting of the communication apparatus; a storage unit configured to store a condition for excluding a target of name resolution using encrypted communication; and a communication control unit configured to, in a case where name resolution of a host name requested from an application is executed, request a first Domain Name System (DNS) server to execute name resolution of the host name via an encrypted communication path established with the first DNS server based on at least the fact that use of encrypted communication is set by the setting unit, and request a second DNS server to execute name resolution of the host name by plain text based on the fact that use of encrypted communication is not set by the setting unit, wherein, in a case where the request of name resolution of the host name satisfies the condition stored in the storage unit, the communication control unit requests the second DNS server to execute name resolution of the host name by plain text even in a case where use of encrypted communication is set by the setting unit, wherein the storage unit stores identification information of a communication protocol to be excluded from the target of name resolution using encrypted communication as the condition, wherein the communication apparatus further comprises a determination unit configured to determine whether or not a source application of the request is a communication protocol to be excluded from the target of name resolution using encrypted communication based on the identification information stored in the storage unit and a type of a communication protocol used for communication with a partner designated by the host name, and wherein, in a case where the determination unit determines that the source application of the request is a communication protocol to be excluded from the target of name resolution using encrypted communication, the communication control unit requests the second DNS server to execute name resolution of the host name by plain text even in a case where use of encrypted communication is set by the setting unit.
2. The communication apparatus according to claim 1, wherein, the storage unit stores identification information of an application to be excluded from the target of name resolution using encrypted communication as the condition, wherein the communication apparatus further comprises a determination unit configured to determine whether or not a source application of the request is an application to be excluded from the target of name resolution using encrypted communication based on the identification information stored in the storage unit and a type of the source application, and wherein, in a case where the determination unit determines that the source application of the request is an application to be excluded from the target of name resolution using encrypted communication, the communication control unit requests the second DNS server to execute name resolution of the host name by plain text even in a case where use of encrypted communication is set by the setting unit.
3. The communication apparatus according to claim 2, further comprising: a reception unit configured to receive designation of an application to be excluded from the target of name resolution using encrypted communication, wherein the storage unit stores identification information of the application whose designation is received by the reception unit.
4. The communication apparatus according to claim 3, wherein, the communication apparatus includes at least a transmission application and a web browser application, the transmission application transmits scan data to a destination designated by a host name, and wherein the transmission application and the web browser application can be designated as an exceptional application excluded by the reception unit.
5. The communication apparatus according to claim 1, further comprising: a receiving unit configured to receive a designation of a communication protocol to be excluded from a target of name resolution using encrypted communication, wherein the storage unit stores identification information of the communication protocol whose designation is received by the receiving unit.
6. The communication apparatus according to claim 5, wherein, The receiving unit designates at least a File Transfer Protocol (FTP) as the communication protocol to be excluded.
7. The communication apparatus according to any one of claims 2 to 6, wherein, the storage unit further stores a list of hostnames to be excluded from a target of name resolution using encrypted communication as the condition, and wherein in a case where the hostname whose name resolution is requested is included in the list of hostnames to be excluded stored in the storage unit, the communication control unit requests the second DNS server to perform name resolution of the hostname in plain text regardless of the setting performed by the setting unit, in a case where the hostname whose name resolution is requested is not included in the list of hostnames to be excluded stored in the storage unit, the communication control unit requests the first DNS server to perform name resolution of the hostname via the encrypted communication path established with the first DNS server in a case where the name resolution of the hostname is requested by an application, and in a case where the name resolution of the hostname is not requested by an application.
8. A method of controlling a communication apparatus, comprising: a first setting step of setting whether to use encrypted communication for name resolution as an operation setting of the communication apparatus; a second setting step of setting a condition for excluding a target of name resolution using encrypted communication; and a communication control step of, in a case where name resolution of a hostname is requested by an application, requesting a first DNS server to perform name resolution of the hostname via an encrypted communication path established with the first DNS server in a case where the use of encrypted communication is set by the first setting step and the request for name resolution of the hostname does not satisfy the condition set in the second setting step, and requesting a second DNS server to perform name resolution of the hostname in plain text in a case where the use of encrypted communication is not set by the first setting step and in a case where the use of encrypted communication is set by the first setting step and the request for name resolution of the hostname satisfies the condition set in the second setting step, wherein the second setting step sets identification information of a communication protocol to be excluded from a target of name resolution using encrypted communication as the condition, wherein the method further includes a determination step of determining whether a source application that requests a partner to communicate is a communication protocol to be excluded from a target of name resolution using encrypted communication, based on the identification information set in the second setting step and a type of communication protocol used to communicate with the partner designated by the hostname, and wherein in a case where it is determined in the determination step that the source application that requests the partner to communicate is a communication protocol to be excluded from a target of name resolution using encrypted communication, the second DNS server is requested to perform name resolution of the hostname in plain text even in a case where the use of encrypted communication is set in the first setting step.
9. A computer-readable storage medium storing a program that causes a computer to execute the method of controlling a communication apparatus according to claim 8.
Citation Information
Patent Citations
Communication apparatus, DNS processing method and program
JP2017139648A
Mold opening / closing control method of injection molding machine and injection molding machine
JP2020066185A