Security management method and device, system and computer storage medium

By implementing control policies on the computer and image forming apparatus sides to control the sharing and use of access ports, the problem of confidential information leakage caused by the sharing of image forming apparatus is solved, security control is achieved, and the risk of information leakage is avoided.

CN115437584BActive Publication Date: 2026-04-14ZHUHAI PANTUM ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In the field of security, the shared use of image forming devices may lead to the leakage of confidential information, which is difficult to effectively control with existing technologies.

Method used

By implementing control policies on the computer and image forming apparatus sides, the sharing and use of access ports are controlled, including a first control policy on the first computer side, a second control policy on the second computer side, and a third control policy on the image forming apparatus side, respectively controlling whether the access ports of the image forming apparatus are allowed to be shared, whether shared use is allowed, and whether image forming operations are allowed.

Benefits of technology

This achieves secure control over the image forming apparatus, avoids the risk of leakage of confidential information due to unauthorized use, and ensures information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115437584B_ABST
    Figure CN115437584B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of image forming, and provides a safe control method, device, system and computer program medium. The method comprises: executing a first control policy on the first computer side, the first control policy being used for controlling whether an access port of the image forming device in the first computer is allowed to be shared; and / or executing a second control policy on the second computer side, the second control policy being used for controlling whether the second computer allows to share and use the access port of the image forming device in the first computer; and / or executing a third control policy on the image forming device side, the third control policy being used for controlling whether the image forming device allows to perform an image forming operation based on preset image forming data. Therefore, by controlling the shared image forming device, the source of the job processed by the image forming device is safely controlled, and the problem of information leakage is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to the field of image forming technology, and in particular to a security control method, security control device, security control system, and computer storage medium. [Background Technology]

[0002] With the development of imaging technology, image forming devices are increasingly used in offices and daily life. Common image forming devices include, but are not limited to, printers, copiers, scanners, fax machines, or multifunction printers that integrate printing, copying, scanning, and faxing functions.

[0003] In the prior art, there is a scenario where, for convenient communication, multiple computer devices can be connected via a network. To facilitate the use of an image forming apparatus, a printer driver corresponding to the image forming apparatus can be installed on one computer device, and the image forming apparatus can be shared with other computer devices connected to that computer device. Thus, other computer devices do not need to install the printer driver corresponding to the image forming apparatus to perform printing operations, which is quite convenient.

[0004] However, if the above scenario occurs in security fields such as government, banking, and finance, users of other computer devices may use the aforementioned image forming device to print out documents carrying confidential information, raising information security issues. [Summary of the Invention]

[0005] This invention provides a security management method, security management device, security management system, and computer storage medium to address the potential information leakage problem in the prior art.

[0006] The first aspect of this application provides a security control method applied to a security control system, the security control system including a computer and / or an image forming apparatus, the computer including a first computer and / or a second computer, comprising:

[0007] A first control policy is executed on the first computer side, the first control policy being used to control whether the access port of the image forming apparatus in the first computer is allowed to be shared; and / or

[0008] A second control policy is executed on the second computer side, the second control policy being used to control whether the second computer allows shared use of the access port of the image forming apparatus in the first computer; and / or

[0009] A third control strategy is executed on the image forming apparatus side. The third control strategy is used to determine whether the image forming apparatus allows the image forming operation to be performed based on preset image forming data. The second computer sends the preset image forming data to the image forming apparatus through the access port of the image forming apparatus in the first computer. The first computer is used to be directly connected to the image forming apparatus, and the second computer is used to be indirectly connected to the image forming apparatus through the first computer.

[0010] A second aspect of this application provides a security control device, included in a security control system, the security control system comprising a computer and / or an image forming apparatus, the computer comprising a first computer and / or a second computer, including:

[0011] The control unit is configured to execute a first control policy on the first computer side, the first control policy being configured to control whether the access port of the image forming apparatus in the first computer is allowed to be shared, and / or

[0012] The control unit is configured to execute a second control policy on the second computer side, the second control policy being configured to control whether the second computer allows shared use of the access port of the image forming apparatus in the first computer, and / or

[0013] The control unit is used to execute a third control strategy on the image forming apparatus side. The third control strategy is used to determine whether the image forming apparatus allows the image forming operation to be performed based on preset image forming data. The second computer sends the preset image forming data to the image forming apparatus through the access port of the image forming apparatus in the first computer. The first computer is used to be directly connected to the image forming apparatus, and the second computer is used to be indirectly connected to the image forming apparatus through the first computer.

[0014] A third aspect of this application provides a computer storage medium including a stored computer program, wherein the program, when running, controls the device where the storage medium is located to execute the method described in the first aspect.

[0015] The fourth aspect of this application provides a security management system, including:

[0016] Image forming apparatus for performing one or more operations such as printing, copying, scanning, and faxing; and / or

[0017] A first computer, configured to be directly connected to the image forming apparatus; and / or

[0018] A second computer is used to be indirectly connected to the image forming apparatus via the first computer;

[0019] The security control device provided in the second aspect above is installed in the first computer;

[0020] And / or the security control device is installed in the second computer;

[0021] And / or the security control device is installed within the image forming apparatus.

[0022] Compared with the prior art, this application has at least the following beneficial effects:

[0023] By controlling whether the access port of the image forming apparatus in the first computer is allowed to be shared and used, and / or controlling whether the second computer is allowed to share and use the access port of the image forming apparatus in the first computer, and / or controlling whether the image forming apparatus is allowed to perform image forming operations based on preset image forming data, the shared image forming apparatus can be managed, the source of the work processed by the image forming apparatus can be securely controlled, and the risk of confidential information being leaked through the image forming apparatus due to illegal use of the image forming apparatus can be avoided. [Attached Image Description]

[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of a security management system provided in an embodiment of this application.

[0026] Figure 2 This is a flowchart illustrating a security control method provided in an embodiment of this application.

[0027] Figure 3 This is a flowchart illustrating yet another security control method for embodiments of this application.

[0028] Figure 4 This is a flowchart illustrating yet another security control method for embodiments of this application.

[0029] Figure 5 This is a flowchart illustrating yet another security control method for embodiments of this application.

[0030] Figure 6 This is a flowchart illustrating yet another security control method for embodiments of this application.

[0031] Figure 7 This is a flowchart illustrating yet another security control method for embodiments of this application.

Detailed Implementation Methods

[0032] To better understand the technical solution of the present invention, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0033] It should be understood that the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0034] Figure 1 The security control system shown in this application embodiment includes a first computer 100 and a second computer 200, as well as an image forming apparatus 300. The first computer 100 and the second computer 200 are interconnected by wired and / or wireless means, and the first computer 100 and the image forming apparatus 300 are also interconnected by wired and / or wireless means.

[0035] The connection between the first computer 100 and the second computer 200 can be established by directly connecting the first computer 100 and the second computer through a means such as a USB cable or a network cable, or by connecting the first computer 100 and the second computer 200 to the same access device such as a router, or by establishing the connection through other means. This application does not limit the specific methods described herein.

[0036] The connection between the first computer 100 and the image forming apparatus 300 can be established via wired means such as USB cable or network cable, or via wireless means such as Wi-Fi Direct or LAN connection, or by connecting the first computer 100 and the image forming apparatus 300 to the same access device such as a router, or by establishing a connection in other ways. This application does not limit the specific methods used.

[0037] The first computer 100 and the second computer 200 can be computer devices such as laptops, desktop computers, tablets, and servers.

[0038] The image forming apparatus 300 includes, but is not limited to, a printer, copier, scanner, fax machine, or a multifunction office machine that integrates printing, copying, scanning, and faxing functions.

[0039] The first computer 100 has a print driver installed in the image forming apparatus 300, which is used to convert the image forming data to be output to the image forming apparatus 300 in the first computer 100 into a format that the image forming apparatus can recognize. Thus, after the first computer 100 and the image forming apparatus 300 are connected, the image forming data can be output to the image forming apparatus 200 through the print driver installed in the first computer 100 to realize the printing operation.

[0040] In some scenarios, the first computer 100 can also manage the sharing permissions of the image forming apparatus 300, such as whether to allow the image forming apparatus 300 to be shared with the second computer 200.

[0041] When the first computer 100 shares the image forming apparatus 300 with the second computer 200, the second computer 200 can perform image forming operations using the image forming apparatus 300 even if the second computer 200 does not have a printer driver corresponding to the image forming apparatus 300 installed.

[0042] However, when the above scenario occurs in security fields such as government, banking, and finance, the user of the second computer 200 may print out documents carrying confidential information through the image forming apparatus 300, causing security problems.

[0043] It should be noted that the terms "first" and "second" mentioned in the embodiments of this application are merely for the purpose of facilitating understanding of the invention by those skilled in the art, and are not intended to limit the scope of the invention. For example, the order of "first" and "second" can be interchanged; furthermore, there can be one or more "first" computers, and one or more "second" computers. The first computer is directly connected to the first image forming apparatus and indirectly connected to the second image forming apparatus, while the second computer can be directly connected to the third image forming apparatus and indirectly connected to the fourth image forming apparatus. The first image forming apparatus can be the same as or different from the third and fourth image forming apparatuses, and similarly, the second image forming apparatus can be the same as or different from the third and fourth image forming apparatuses. Thus, the same sharing strategy can be adopted for the image forming apparatus connected to the first computer and the image forming apparatus connected to the second computer, or different sharing strategies can be adopted based on permissions, device attributes, etc.

[0044] To address the aforementioned issues and ensure the controlled sharing of the image forming apparatus 300, thereby preventing the leakage of confidential information, this application provides the following security control solutions.

[0045] Option 1:

[0046] The first control policy is implemented only on the first computer 100 side to prevent malicious use of the image forming apparatus 300.

[0047] Based on the aforementioned security control scenario, when the first computer 100 shares the access port of the image forming apparatus 300 with other computer devices connected to the first computer 100, such as the second computer 200, the second computer 200 can establish communication with the image forming apparatus 300 based on the access port.

[0048] Therefore, in order to effectively avoid information leakage caused by the malicious use of the image forming apparatus 300, the sharing of the access port of the image forming apparatus 300 can be controlled by the first computer 100, including directly prohibiting the sharing of the access port, allowing only a small-scale sharing, requiring a designated person to review the sharing, allowing sharing but requiring the recording of information related to the sharing for subsequent traceability, or determining whether to allow sharing based on the security level between the first computer 100 and the second computer 200.

[0049] Specifically, a first background management application can be set in the first computer 100 to perform security control on the image forming apparatus 300 side.

[0050] The first background management application may be a separate program installed on the first computer 100, or it may be part of the printer driver corresponding to the image forming apparatus 300, or it may be a program included in the operating system of the first computer 100, and there is no limitation on this.

[0051] The following are the methods for managing the shared access ports of the image forming device 300:

[0052] In some implementations, the first background management application can detect the sharing attribute parameters of the image forming apparatus 300. When the sharing attribute parameters of the image forming apparatus 300 are configured to allow sharing, that is, when the access port of the image forming apparatus 300 is configured to allow sharing, the application can forcibly configure the sharing attribute parameters of the image forming apparatus 300 to prohibit sharing, or directly disable the sharing attribute parameters that allow sharing, or directly disable the sharing attribute parameter configuration function of the image forming apparatus 300.

[0053] In some implementations, the first background management application can detect the shared attribute parameters of the image forming apparatus 300. When the shared attribute parameter configuration function of the image forming apparatus 300 is enabled, that is, when the access port of the image forming apparatus 300 can be configured to allow sharing, the shared attribute parameter configuration function can be forcibly disabled.

[0054] Specifically, the first background management application can determine whether the sharing attribute parameters of the image forming apparatus 300 are configured to allow sharing by detecting whether the option to share the image forming apparatus is triggered on the attribute parameter interface of the image forming apparatus 300.

[0055] Furthermore, the first background management application can also determine whether the sharing attribute parameter configuration function of the image forming apparatus 300 is enabled by detecting whether the sharing attribute configuration interface of the image forming apparatus 300 is enabled, that is, whether the sharing of the image forming apparatus 300 can be set through the sharing attribute configuration interface of the image forming apparatus 300.

[0056] In some implementations, when the image forming apparatus 300 is added on the first computer 100 side, the first background management application immediately disables the image forming apparatus 300's default shared attribute parameters that allow sharing.

[0057] In some implementations, after the first computer 100 completes the action of adding the image forming apparatus 300, the first background management application periodically checks the sharing attribute parameters of the image forming apparatus 300. Once it finds that the sharing attribute parameters of the image forming apparatus 300 are configured to allow sharing, it immediately configures the sharing attribute parameters of the image forming apparatus 300 to disable sharing, or directly disables the allowed sharing state. Alternatively, once it finds that the sharing attribute parameter configuration interface of the image forming apparatus 300 is enabled, it immediately controls the sharing attribute parameter configuration interface of the image forming apparatus 300 to be disabled.

[0058] In some implementations, when the first background management application detects that the sharing attribute parameter of the image forming apparatus 300 is configured to allow sharing or the sharing attribute parameter configuration interface is enabled, it can output a request message indicating whether to allow sharing of the image forming apparatus 300 through the display unit of the first computer 100, and determine whether to perform the aforementioned port sharing control of the image forming apparatus 300 based on the response information corresponding to the request message. Specifically, if the currently logged-in user of the first computer 100 selects to allow sharing, the aforementioned port sharing control of the image forming apparatus 300 is not performed; if the currently logged-in user of the first computer 100 selects not to allow sharing, the aforementioned port sharing control of the image forming apparatus 300 is performed.

[0059] In some implementations, when the first backend management application detects that the sharing attribute parameter of the image forming apparatus 300 is configured to allow sharing or the sharing attribute parameter configuration interface is enabled, it can output a request message indicating whether to allow sharing of the image forming apparatus 300 to a specific administrator, and determine whether to perform the aforementioned port sharing control of the image forming apparatus 300 based on the response information corresponding to the request message. Specifically, if the currently logged-in user of the first computer 100 selects to allow sharing, the aforementioned port sharing control of the image forming apparatus 300 is not performed; if the currently logged-in user of the first computer 100 selects not to allow sharing, the aforementioned port sharing control of the image forming apparatus 300 is performed.

[0060] The specific administrator account mentioned above can be stored directly in the first backend management application, or in the print driver of the image forming apparatus 300, or in the memory of the first computer 100, without any limitation.

[0061] In some implementations, when the first background management application detects that the sharing attribute parameter of the image forming apparatus 300 is configured to allow sharing or the sharing attribute parameter configuration interface is enabled, the first background management application obtains the currently logged-in user account information of the first computer 100, directly determines whether the currently logged-in user account information of the first computer 100 is included in a preset whitelist. If it is included, the access port sharing of the image forming apparatus 300 is allowed. If it is not included, the aforementioned port sharing control of the image forming apparatus 300 is executed, or a request message containing the currently logged-in user account information of the first computer 100 is sent to the aforementioned specific management to request whether the user account information or the user corresponding to the user account information is allowed to control the access port of the image forming apparatus 300.

[0062] In some implementations, the first background management application can directly detect whether an access port sharing event of the image forming apparatus 300 has occurred, i.e., whether the sharing attribute parameter of the image forming apparatus 300 is configured to allow sharing or the sharing attribute parameter configuration interface is enabled. If it occurs, the sharing of the access port of the image forming apparatus 300 is allowed, but relevant information including the currently logged-in user account information of the first computer 100, the sharing status of the first computer 100, and the computer device information connected to the first computer 100 needs to be recorded. Based on the saved information, an audit log is provided to facilitate subsequent tracing and investigation.

[0063] In some implementations, the first background management application may also determine whether to run the shared access port of the image forming apparatus 300 based on the security level of the first computer 100 and / or the currently logged-in user of the first computer 100. If the security level of the first computer 100 and / or the logged-in user of the first computer meets the requirements, sharing the access port of the image forming apparatus 300 is allowed; if the security level of the first computer and / or the logged-in user of the first computer does not meet the requirements, sharing the access port of the image forming apparatus 300 is prohibited.

[0064] In some implementations, the first background management application may also determine whether to run the shared access port of the image forming apparatus 300 based on the security level of the second computer 200 and / or the currently logged-in user of the second computer 200. If the security level of the second computer 200 and / or the logged-in user of the second computer 200 meets the requirements, sharing the access port of the image forming apparatus 300 is allowed; if the security level of the second computer and / or the logged-in user of the second computer does not meet the requirements, sharing the access port of the image forming apparatus 300 is prohibited.

[0065] In some implementations, the sharing of the access port of the image forming apparatus 300 can be determined based on the security level between the first computer 100 and the second computer 200.

[0066] Specifically, the security levels of the first computer 100 and the second computer 200 can be obtained by the preset management software set on the server side, and then it can be determined whether the security level of the first computer 100 matches the security level of the second computer 200. The determination result is sent to the first background management application. If the first background management application determines that the security levels do not match, it can prohibit the sharing of the access port of the image forming apparatus 300 and / or disable the sharing configuration function of the access port of the image forming apparatus 300. Alternatively, the first background management application can obtain the security levels of the first computer 100 and the second computer 200 by communicating with the preset management software set on the server side, and then determine whether the security level of the first computer 100 matches the security level of the second computer 200. If the determination result is that they do not match, it can prohibit the sharing of the access port of the image forming apparatus 300 and / or disable the sharing configuration function of the access port of the image forming apparatus 300.

[0067] Therefore, if a second computer 200 with a security level that does not match that of the first computer 100 appears in the local area network, the sharing of the access port of the image forming apparatus 300 is prohibited.

[0068] Of course, the shared management of the access ports of the image forming apparatus 300 can also be combined with one or more of the aforementioned embodiments, and is not limited here.

[0069] To effectively prevent information leakage caused by the malicious use of the image forming apparatus 300, in addition to controlling the sharing of the access port of the image forming apparatus 300, the use of the access port of the image forming apparatus 300 can also be controlled. Specifically, only image forming data from the first computer 100 is allowed to be sent to the image forming apparatus 300; sending classified data to the image forming apparatus 300 is prohibited; only image forming data approved by a designated person is allowed to be sent; image forming data received by the access port of the image forming apparatus 300 is allowed to be sent, but relevant information must be recorded for subsequent traceability; when the image forming data from the second computer 200 is highly confidential, sending image forming data to the image forming apparatus 300 through the access port of the image forming apparatus 300 is prohibited.

[0070] In some implementations, the first background management application can also detect whether the image forming data received by the print driver of the image forming apparatus 300 originates from the local machine. If it does, the print driver processes the received image forming data and sends the processed data to the image forming apparatus 300. If the source is not local, sending the image forming data to the image forming apparatus 300 is prohibited. Specifically, the first background management application determines whether the image forming data originates from the local machine of the first computer 100 by obtaining parameters contained in the image forming data.

[0071] Furthermore, when the image forming data source is not local, the confidentiality level corresponding to the image forming data can be obtained. When the confidentiality level exceeds the preset level, the image forming data is prohibited from being sent to the image forming device 300.

[0072] Furthermore, the first background management application can also directly discard the image data and output a prompt message indicating an abnormal data source through the display interface of the first computer 100.

[0073] Specifically, the first backend management application determines whether the image forming data originates from the local machine by detecting parameters representing the host type contained in the job attribute parameters of the image forming data.

[0074] In some implementations, the first background management application can also detect whether the image forming data received by the print driver of the image forming apparatus 300 is classified data. If not, the print driver processes the received image forming data and sends the processed data to the image forming apparatus 300. If so, the action of sending the image forming data to the image forming apparatus 300 is not performed.

[0075] Specifically, to determine whether the image forming data received by the print driver of the image forming apparatus 300 is classified data, it is possible to determine whether the image forming data received by the print driver involves a preset confidential keyword. If it does, the image forming data is determined to be classified data.

[0076] Specifically, the detection of whether the image forming data received by the print driver of the image forming apparatus 300 is classified data can also be achieved by obtaining the security level of the first computer 100 and / or the currently logged-in user account of the first computer 100 and the security level of the image forming data. If the security level of the image forming data is equal to or lower than the security level of the first computer 100 and / or the currently logged-in user account of the first computer 100, then the image forming data is determined to be non-classified data. If the security level of the image forming data is higher than the security level of the first computer 100 and / or the currently logged-in user account of the first computer 100, then the image forming data is determined to be classified data.

[0077] In some implementations, the first backend management application can directly allow the use of the access port of the image forming apparatus 300, but only records the usage information of the access port of the image forming apparatus 300 for subsequent traceability. The usage information to be recorded includes the currently logged-in user account information of the first computer 100, the sharing status of the first computer 100, the computer device information connected to the first computer 100, image forming data and other related information. Based on the saved information, an audit log is provided to facilitate subsequent tracing and investigation.

[0078] In some implementations, after the first background management application determines that the image forming device 300 has received image forming data through its access port, it directly sends the received image forming data to a designated approver for approval. Only after the approval is passed can the image forming data be sent to the image forming device 300.

[0079] The account of the designated auditor can be stored directly in the first back-end management application, or in the print driver of the image forming apparatus 300, or in the memory of the first computer 100, without limitation.

[0080] In some implementations, after the first background management application determines that the image forming apparatus 300 has received image forming data through its access port, it can directly prompt the first computer 100 with a request for permission to print. If the response information corresponding to the request information is "allowed", then the image forming data can be sent to the image forming apparatus 300.

[0081] Of course, the use and control of the access ports of the image forming apparatus 300 can also be combined with one or more of the aforementioned embodiments, and are not limited here.

[0082] Furthermore, the control method of the first computer 100 over the image forming apparatus 300 includes the shared control and / or usage control of the access ports of the aforementioned image forming apparatus 300, which is not limited here.

[0083] In some implementations, after controlling the access ports of the image forming apparatus 300, the first background management application can output a prompt message indicating that the second computer 200 is prohibited from sharing the image forming apparatus 300 through the display interface of the first computer 100.

[0084] In some implementations, after controlling the access ports of the image forming apparatus 300, the first backend management application can also send feedback information to the second computer 200 to output a prompt message indicating that the second computer 200 is prohibited from sharing the image forming apparatus 300 through the display interface of the second computer 200. For example, "Your host is an illegal host and is prohibited from using the shared printing function. Please contact the administrator to authorize printing permission." It also informs the administrator that the second computer 200 without access is attempting to make a shared connection, so that the administrator notices the second computer 200 without access and can further coordinate or authorize the second computer 200 without access.

[0085] In some implementations, after controlling the access ports of the image forming apparatus 300, the first background management application can also send feedback information to the image forming apparatus 300 to display operational abnormalities on the operation interface of the image forming apparatus 300.

[0086] Option 2:

[0087] The second control policy is implemented only on the second computer 200 side to prevent malicious use of the image forming apparatus 300.

[0088] After obtaining the access port of the image forming apparatus 300, the second computer 200 can send image forming apparatus data to the image forming apparatus 300, which may lead to information leakage.

[0089] To effectively prevent information leakage, a second background management application can be set up in the second computer 200 for security control. For example, it can prohibit the addition of the image forming apparatus 300, prohibit the sending of image forming data to the access port of the image forming apparatus 300, and allow the sending of image forming data to the access port of the image forming apparatus 300 but need to record relevant information for subsequent traceability. Secondly, the second background management application can also determine whether to use the access port of the image forming apparatus 300 based on the whitelist of shared image forming apparatus 300, the security level of the first computer 100 and / or the currently logged-in user of the first computer 100, the security level of the second computer 200 and / or the currently logged-in user of the second computer 200, and the security level between the first computer 100 and the second computer 200. The specific principle is similar to that of the first background management program, and will not be elaborated here.

[0090] The second background management application can be a separate program installed on the second computer 200, or it can be a program included in the operating system of the second computer 200; there is no limitation on this.

[0091] In some implementations, the second background management application detects whether an action of adding the image forming apparatus 300 has occurred on the second computer 200 side. If so, the action of adding the image forming apparatus 300 is directly withdrawn, specifically by directly deleting the addition of the image forming apparatus 300 on the second computer 200 side.

[0092] In some implementations, the second background management application detects whether the second computer 200 has accessed the image forming apparatus 300 via a message sent by another computer device (first computer 100) connected to the second computer 200, executes the access operation of the image forming apparatus 300 access port, and if so, immediately deletes the computer program that can access the image forming apparatus 300 access port, and / or prompts the deletion of the computer program that can access the image forming apparatus 300 access port.

[0093] In some implementations, the second background management application queries other image forming apparatuses available in the network connected to the second computer 200 and guides the user to install the corresponding drivers for the image forming apparatuses available in the network.

[0094] In some implementations, the second computer 200 may also directly send image forming data to the image forming apparatus 300 via the access port of the image forming apparatus 300 sent by other computer devices. However, the second computer 200 performs the recording of information such as the access port information of the image forming apparatus 300 used to send the image forming data, and the image forming data information, on the other computer devices connected to the second computer 200, in order to provide an audit log for subsequent traceability.

[0095] When the second computer 200 establishes an access connection with the access port of the image forming apparatus 300, the second computer 200 can send image forming data to the access port of the image forming apparatus 300 through methods such as driving or cloud printing.

[0096] In some implementations, the second computer 200 first sends image forming data to the first computer 100. After the second computer 200 obtains permission to use the access port of the image forming apparatus 300, the first computer 100 sends the image forming data to the image forming apparatus 300 to perform image forming operations.

[0097] In some implementations, after the second computer 200 obtains permission to use the access port of the image forming apparatus 300, the second computer 200 directly sends image forming data to the image forming apparatus 300 for image forming operation.

[0098] In some embodiments, after the second computer 200 obtains access to the image forming apparatus 300's access port, the first computer 100 authorizes the second computer 200 with its own unique identification information. The second computer can then use the first computer 100's unique identification information to perform image forming operations and / or communicate with the image forming apparatus 300. The unique identification information is information that indicates the uniqueness of the device, such as the device's MAC address, IP address, etc.

[0099] Option 3:

[0100] The corresponding control policies are executed on both the first computer 100 and the second computer 200. That is, the first control policy is executed on the first computer 100 while the second control policy is executed on the second computer 200, so as to avoid malicious use of the image forming apparatus 300.

[0101] The specific implementation method can refer to the aforementioned implementation method, that is, a first background management application is installed on the first computer 100 side to perform security management in accordance with any of the security management strategies mentioned in the aforementioned scheme 1, and a second background management application is installed on the second computer 200 side to perform management in accordance with any of the security strategies mentioned in the aforementioned scheme 2.

[0102] In one possible implementation, the same background management application can be installed on both the first computer 100 and the second computer 200, having two different functional modes. One functional mode corresponds to the aforementioned first background management application, and the other functional mode corresponds to the aforementioned second background management application.

[0103] Specifically, the background management application can determine the specific functional mode based on the user's manual selection.

[0104] Furthermore, in some implementations, the background management application can also detect the connection between the current computer and the image forming apparatus 300 to determine whether the current computer is the first computer 100 or the second computer 200, thereby automatically entering different functional modes and managing them according to different control strategies. The specific steps of this implementation are as follows:

[0105] First, the connection attributes between the current computer and the image forming apparatus 300 are obtained. The connection attributes include direct connection and indirect connection through other computers. Direct connection can be divided into the current computer and the image forming apparatus 300 being directly connected via wired (e.g., USB communication cable, Net connection cable) and / or wireless (e.g., Wi-Fi Direct, LAN connection). Indirect connection through other computers includes: other computers being directly connected to the image forming apparatus 300 via wired (e.g., USB communication cable, Net connection cable) and / or wireless (e.g., Wi-Fi Direct, LAN connection), while the current computer is directly connected to other computers via wired (e.g., USB communication cable, Net connection cable) and / or wireless (e.g., Wi-Fi Direct, LAN connection).

[0106] It should be noted that obtaining the connection attributes between the current computer and the image forming apparatus 300 can directly determine the physical connection relationship between the current computer and the image forming apparatus 300, thereby determining whether the current computer is directly connected to the image forming apparatus 300 or indirectly connected through another computer. Alternatively, elimination methods or techniques such as whitelists and blacklists can be used to determine whether the current computer and the image forming apparatus 300 are directly connected. Taking the image forming apparatus 300 as a printer as an example, this scenario is also called determining whether the printer to be determined is a local printer. The system interface can be called to enumerate all local printers, and then the printer to be used can be compared to whether it belongs to this enumerated list. If not, it is determined to be a non-directly connected printer.

[0107] The specific connection methods include wired connection and / or wireless connection.

[0108] The connection can be established before the image forming control method (security management) is executed, or it can be established during the inspection process; or the method provided in this embodiment can be executed when a connection action is detected.

[0109] Next, the connection relationship between the image forming apparatus 300 and the current computer is determined. This connection relationship includes: the current computer being the first computer 100, directly connected to the image forming apparatus 300 (i.e., direct connection), or the current computer being the second computer 200, indirectly connected to the image forming apparatus 300 through the first computer 100 (i.e., indirect connection, or connection via a shared method). Specifically, this determination can be made independently or coupled together from a module among the driver application, security management control program, system printing service, port management control module, and driver interface. Specifically, if the current computer is directly connected to the image forming apparatus 300, then the current computer is determined to be the first computer 100. Consequently, the background management application automatically enters the corresponding functional mode of the first background management application and performs security management according to the corresponding control policy. If the current computer is indirectly connected to the image forming apparatus 300 through another computer, then the current computer is determined to be the second computer 200. Consequently, the background management application automatically enters the corresponding functional mode of the first background management application and performs security management according to the corresponding control policy.

[0110] The control strategies for the first and second backend management applications are the same as those in Scheme 1 and Scheme 2 mentioned above, and will not be repeated here.

[0111] In some implementations, whether the first computer 100 or the second computer 200 sends image forming data to the image forming apparatus 300, a background management application in the computer verifies the security status of the image forming apparatus 300. For example, before sending the image forming data, it obtains the status of the security module inside the image forming apparatus 300. If the status does not meet the security requirements, the background management application will prompt the user that the printer is insecure. Security processing is then performed on the job; for example, the background management application automatically cancels the user's job request, or it encrypts the data. The firmware inside the image forming apparatus 300 decrypts the data upon receiving it before printing, thereby preventing the job data from being transmitted through the shared access of the image forming apparatus 300, thus preventing information leakage.

[0112] In some implementations, the background management application in the computer may first collect information about the image forming apparatus 300, such as whether the image forming apparatus 300 has attribute information characterizing a security scenario, or whether the image forming apparatus 300 has processed imaging operations with a high security level; if the image forming apparatus 300 itself is a device to be used in a security scenario and / or has previously processed operations that require confidentiality, the first background management application controls whether the access port of the image forming apparatus 300 in the first computer 100 is allowed to be shared.

[0113] Option 4

[0114] In addition, to further avoid the risk of information leakage caused by the printing of shared image forming data by the image forming apparatus, a third control strategy can also be implemented on the image forming apparatus side.

[0115] In some embodiments, after receiving image forming data, the image forming apparatus 300 further determines the source of the image forming data. If it originates directly from the first computer 100, it performs processing on the image forming data. If it originates from the second computer 200, it prohibits the execution of image forming operations based on the image forming data and can perform operations such as deleting the image forming data.

[0116] In some implementations, the firmware of the image forming apparatus 300 can require a background management application on a computer to add additional verification information to the image forming data. For example, in a direct connection scenario, the background management application can obtain the unique identifier. Before initiating a job, the computer obtains a dynamic unique identifier from the firmware of the image forming apparatus 300. The background management application adds this dynamic unique identifier information to the image forming data. When the image forming apparatus 300 receives the image forming data, it parses the unique identifier information and can then perform the imaging operation corresponding to the job. This imaging operation could be printing, scanning, faxing, etc. In an indirect connection scenario, the background management application on the computer cannot directly communicate with the image forming apparatus 300, nor can it obtain a dynamic unique identifier from the firmware of the image forming apparatus 300. Therefore, the image forming data sent by the background management application on the computer does not recognize the unique identifier; and the firmware of the image forming apparatus 300, upon receiving the data and not recognizing the unique identifier, can reject the image processing operation.

[0117] like Figure 2 As shown in the embodiment of this application, a security management method is provided, applied to a security management system. The security management system includes a computer and / or an image forming apparatus 300. The computer includes a first computer 100 and / or a second computer 200. The method includes the following steps:

[0118] S201, a first control policy is executed on the first computer 100 side. The first control policy is used to control whether the access port of the image forming apparatus 300 in the first computer 100 is allowed to be shared; and / or

[0119] A second control policy is executed on the second computer 200 side. The second control policy is used to control whether the second computer 200 allows shared use of the access port of the image forming apparatus 300 in the first computer 100; and / or

[0120] A third control strategy is executed on the image forming apparatus 300 side. The third control strategy is used to determine whether the image forming apparatus 300 allows the image forming operation to be performed based on preset image forming data.

[0121] The second computer 200 sends preset image forming data to the image forming apparatus 300 through the access port of the image forming apparatus 300 in the first computer 100; the first computer 100 is used to be directly connected to the image forming apparatus 300, and the second computer 200 is used to be indirectly connected to the image forming apparatus 300 through the first computer 100.

[0122] In some possible implementations, the first control strategy could be to directly block access to the image forming apparatus 300 in the first computer 100.

[0123] In some possible implementations, such as Figure 3 As shown, the first control strategy includes the following steps:

[0124] S301, Determine whether the access port of the image forming apparatus 300 can be configured to allow sharing?

[0125] If so, then execute S302.

[0126] S302, the access port of the image forming apparatus 300 is configured to a disabled sharing state, or the enabled sharing state of the access port of the image forming apparatus 300 is not enabled, or the access port sharing configuration function of the image forming apparatus 300 is not enabled.

[0127] In some possible implementations, the first control strategy may include: when the access port sharing configuration function of the image forming apparatus 300 is enabled, disabling the access port sharing configuration function of the image forming apparatus 300; or, after an addition action is performed on the image forming apparatus 300, checking at preset intervals whether the access port of the image forming apparatus 300 is in a sharing-allowed state, and if so, closing the access port.

[0128] In some possible implementations, such as Figure 4As shown, the first control strategy includes the following steps:

[0129] S401, Determine whether the first computer 100 or the currently logged-in user account of the first computer 100 is included in the preset whitelist.

[0130] If it does not belong to the category, then execute S402.

[0131] S402, prohibit sharing the access port of the image forming apparatus 300 in the first computer 100.

[0132] In some possible implementations, the first control policy may include: determining the security level of the first computer 100 and / or the currently logged-in user account of the first computer 100; if the security level does not meet the requirements, then prohibiting the sharing of the access port of the image forming apparatus 300 in the first computer 100; or, determining the security level of the second computer 200 and / or the currently logged-in user account of the second computer 200; if the security level does not meet the requirements, then prohibiting the sharing of the access port of the image forming apparatus 300 in the first computer 100; or, determining whether the security levels of the first computer 100 and the second computer 200 match; if they do not match, then prohibiting the sharing of the access port of the image forming apparatus 300 in the first computer 100.

[0133] In some possible implementations, such as Figure 5 As shown, the first control strategy includes:

[0134] S501, outputs request information indicating whether sharing the image forming apparatus 300 is permitted.

[0135] S502, determine whether the response information to the request information indicates permission.

[0136] If not allowed, then execute S503.

[0137] S503, prohibit sharing the access port of the image forming apparatus 300 in the first computer 100.

[0138] In some possible implementations, such as Figure 6 As shown, the first control strategy includes:

[0139] S601, determine whether the received image forming data originates from the local machine of the first computer 100.

[0140] If not, then execute S602.

[0141] S602, prohibiting the transmission of image forming data to the image forming apparatus 300.

[0142] In some possible implementations, the first control strategy may include: determining whether the image forming data is classified data, and prohibiting the transmission of the image forming data to the image forming apparatus 300 if the determination is yes; or, determining whether the confidentiality level of the image forming data exceeds a preset level, and prohibiting the transmission of the image forming data to the image forming apparatus 300 if the determination is yes; or, outputting a request message for whether printing is allowed for the image forming data, and if the response message for the request message does not allow printing, prohibiting the transmission of the image forming data to the image forming apparatus 300 or directly discarding the image forming data.

[0143] In some possible implementations, the second control strategy may include: directly prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100.

[0144] In some possible implementations, the second control strategy may include: withdrawing the action of adding the image forming apparatus 300 after an action of adding the image forming apparatus 300 has occurred; or deleting the computer program used to access the access port of the image forming apparatus 300, and / or prompting the deletion of the computer program used to access the access port of the image forming apparatus 300; or prohibiting the transmission of image forming data to the access port of the image forming apparatus 300.

[0145] In some possible implementations, the second control strategy may include: querying available image forming devices in the connection network with the second computer 200, and guiding the user to install the driver corresponding to the available image forming device.

[0146] In some possible implementations, the second control strategy may include: determining whether the second computer 200 or its currently logged-in user account is included in a preset whitelist; if not, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining the security level of the first computer 100 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining the security level of the second computer 200 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining whether the security levels of the first computer 100 and the second computer 200 match; if they do not match, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100.

[0147] In some possible implementations, such as Figure 7As shown, before executing the first control policy on the first computer 100 side or the second control policy on the second computer 200 side, the method further includes the following steps:

[0148] S701, Obtain the connection attributes between the current computer and the image forming apparatus 300. The connection attributes include direct connection or indirect connection via another computer.

[0149] S702, the current computer is directly connected to the image forming apparatus 300 and is defined as the first computer 100; the current computer is indirectly connected to the image forming apparatus 300 through another computer and is defined as the second computer 200.

[0150] In some possible implementations, the third control strategy may include: determining the source of the received image forming data; if the image forming data originates from the first computer 100, performing an image forming operation on the image forming data; if the image forming data originates from the second computer 200, prohibiting the execution of an image forming operation on the image forming data.

[0151] This application also provides a security control device, included in a security control system. The security control system includes a computer and / or an image forming apparatus 300. The computer includes a first computer 100 and / or a second computer 200, comprising:

[0152] The control unit is configured to execute a first control policy on the first computer 100 side, the first control policy being used to control whether the access port of the image forming apparatus 300 in the first computer 100 is allowed to be shared, and / or

[0153] The control unit is used to execute a second control policy on the second computer 200 side. The second control policy is used to control whether the second computer 200 allows shared use of the access port of the image forming apparatus 300 in the first computer 100, and / or

[0154] The control unit is used to execute a third control strategy on the image forming apparatus 300 side. The third control strategy is used to determine whether the image forming apparatus 300 allows the image forming operation to be performed based on preset image forming data. The second computer 200 sends the preset image forming data to the image forming apparatus 300 through the access port of the image forming apparatus 300 in the first computer 100. The first computer 100 is used to be directly connected to the image forming apparatus 300, and the second computer 200 is used to be indirectly connected to the image forming apparatus 300 through the first computer 100.

[0155] In some possible implementations, the first control strategy includes: determining whether the first computer 100 or its currently logged-in user account is included in a preset whitelist; if not, prohibiting the sharing of the access port of the image forming apparatus in the first computer 100; or, determining the security level of the first computer 100 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of the access port of the image forming apparatus in the first computer 100; or, determining the security level of the second computer 200 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of the access port of the image forming apparatus in the first computer 100; or, determining whether the security levels of the first computer 100 and the second computer 200 match; if they do not match, prohibiting the sharing of the access port of the image forming apparatus in the first computer 100.

[0156] In some possible implementations, the first control strategy includes: outputting a request message on whether to allow sharing of the image forming apparatus; if the response message to the request message does not allow sharing, then prohibiting the sharing of the access port of the image forming apparatus 300 in the first computer 100.

[0157] In some possible implementations, the first control strategy includes: determining whether the received image forming data originates from the local machine of the first computer 100, and prohibiting the transmission of the image forming data to the image forming apparatus 300 if the determination is no; or determining whether the image forming data is classified data, and prohibiting the transmission of the image forming data to the image forming apparatus 300 if the determination is yes; or determining whether the confidentiality level of the image forming data exceeds a preset level, and prohibiting the transmission of the image forming data to the image forming apparatus 300 if the determination is yes; or outputting a request message regarding whether printing is permitted for the image forming data, and if the response message to the request message does not permit printing, prohibiting the transmission of the image forming data to the image forming apparatus 300 or directly discarding the image forming data.

[0158] In some possible implementations, the second control strategy includes: directly prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100.

[0159] In some possible implementations, the second control strategy includes: withdrawing the action of adding the image forming apparatus 300 after an action of adding the image forming apparatus 300 has occurred; or deleting the computer program used to access the access port of the image forming apparatus 300, and / or prompting the deletion of the computer program used to access the access port of the image forming apparatus 300; or prohibiting the transmission of image forming data to the access port of the image forming apparatus 300.

[0160] In some possible implementations, the second control strategy includes: querying the available image forming apparatus 300 in the network connected to the second computer 200, and guiding the user to install the driver corresponding to the available image forming apparatus 300.

[0161] In some possible implementations, the second control strategy includes: determining whether the second computer 200 or its currently logged-in user account is included in a preset whitelist; if not, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining the security level of the first computer 100 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining the security level of the second computer 200 and / or its currently logged-in user account; if the security level does not meet the requirements, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100; or, determining whether the security levels of the first computer 100 and the second computer 200 match; if they do not match, prohibiting the sharing of access ports of the image forming apparatus 300 in the first computer 100.

[0162] In some possible implementations, the security control device further includes an acquisition unit, which is used to acquire the connection attributes between the current computer and the image forming apparatus 300 before executing the first control policy on the first computer 100 side or the second control policy on the second computer 200 side. The connection attributes include direct connection or indirect connection through other computers. The control unit is used to define the current computer according to the connection attributes. Specifically, defining the current computer according to the connection attributes includes: if the current computer is directly connected to the image forming apparatus 300, the current computer is defined as the first computer 100; if the current computer is indirectly connected to the image forming apparatus 300 through other computers, the current computer is defined as the second computer 200.

[0163] In some possible implementations, the third control strategy includes: determining the source of the received image forming data; if the image forming data originates from the first computer 100, performing an image forming operation on the image forming data; if the image forming data originates from the second computer 200, prohibiting the execution of an image forming operation on the image forming data.

[0164] This application also provides a computer storage medium, which includes a stored computer program, wherein the program controls the method described in the foregoing embodiments of the device where the storage medium is located when it is running.

[0165] This application also provides a security management system, including:

[0166] Image forming apparatus 300 is used to perform one or more operations such as printing, copying, scanning, and faxing; and / or

[0167] First computer 100, for direct connection to image forming apparatus 300; and / or

[0168] The second computer 200 is used to be indirectly connected to the image forming apparatus 300 via the first computer 100;

[0169] The security control device provided in the second aspect above is installed inside the first computer 100;

[0170] And / or security control devices are installed inside the second computer 200;

[0171] And / or security control devices are installed within the image forming apparatus 300.

[0172] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A security management method applied to a security management system, the security management system comprising a computer and an image forming apparatus, the computer comprising a first computer and a second computer, the first computer having a print driver corresponding to the image forming apparatus installed thereon, wherein when the first computer shares the image forming apparatus with the second computer, the second computer, even without having the print driver corresponding to the image forming apparatus installed, can still use the image forming apparatus to perform image forming operations, characterized in that... include: A first control policy is executed on the first computer side, the first control policy being used to control whether the access port of the image forming apparatus in the first computer is allowed to be shared; and / or A second control policy is executed on the second computer side, the second control policy being used to control whether the second computer allows shared use of the access port of the image forming apparatus in the first computer; and / or A third control strategy is executed on the image forming apparatus side. The third control strategy is used to determine whether the image forming apparatus allows the image forming operation to be performed based on preset image forming data. The second computer sends the preset image forming data to the image forming apparatus through the access port of the image forming apparatus in the first computer. The first computer is used to be directly connected to the image forming apparatus, and the second computer is used to be indirectly connected to the image forming apparatus through the first computer.

2. The security control method according to claim 1, characterized in that, The first control strategy includes: Directly disable the access port of the image forming apparatus in the first computer; Alternatively, when the access port of the image forming apparatus can be configured to allow sharing, the access port of the image forming apparatus can be configured to disable sharing, or the allow sharing state of the access port of the image forming apparatus can be disabled, or the access port sharing configuration function of the image forming apparatus can be disabled. Alternatively, when the access port sharing configuration function of the image forming apparatus is enabled, the access port sharing configuration function of the image forming apparatus is disabled. Alternatively, after an action is performed on the image forming apparatus, the access port of the image forming apparatus is checked at preset intervals to see if it is in a shared state. If so, the access port is closed.

3. The security control method according to claim 1, characterized in that, The first control strategy includes: Determine whether the first computer or the currently logged-in user account of the first computer is included in a preset whitelist. If not, then prohibit sharing the access port of the image forming device in the first computer. Alternatively, determine the security level of the first computer and / or the currently logged-in user account of the first computer; if the security level does not meet the requirements, then prohibit sharing the access port of the image forming apparatus in the first computer. Alternatively, determine the security level of the currently logged-in user account of the second computer and / or the second computer, and if the requirements are not met, prohibit sharing the access port of the image forming apparatus in the first computer; Alternatively, determine whether the security levels of the first computer and the second computer match; if they do not match, then prohibit sharing the access port of the image forming apparatus in the first computer.

4. The security control method according to claim 1, characterized in that, The first control strategy includes: Output a request message indicating whether sharing the image forming apparatus is permitted. If the response message to the request message does not permit sharing, then sharing the access port of the image forming apparatus in the first computer is prohibited.

5. The security control method according to claim 1, characterized in that, The first control strategy includes: Determine whether the received image forming data originates from the local machine of the first computer; if the determination is no, prohibit the transmission of the image forming data to the image forming device. Alternatively, determine whether the image forming data is classified data; if so, prohibit the transmission of the image forming data to the image forming device. Alternatively, determine whether the confidentiality level of the image forming data exceeds a preset level, and if so, prohibit the image forming data from being sent to the image forming device; Alternatively, for the image forming data, a request message is output asking whether printing is allowed. If the response message to the request message does not allow printing, then sending the image forming data to the image forming apparatus is prohibited, or the image forming data is discarded directly.

6. The security control method according to claim 1, characterized in that, The second control strategy includes: Directly prohibit the sharing of access ports of the image forming apparatus in the first computer.

7. The security control method according to claim 1, characterized in that, The second control strategy includes: Once an action to add the image forming apparatus has occurred, the action to add the image forming apparatus is withdrawn. Alternatively, delete the computer program used to access the access port of the image forming apparatus, and / or prompt the deletion of the computer program used to access the access port of the image forming apparatus; Alternatively, sending image forming data to the access port of the image forming apparatus may be prohibited.

8. The security control method according to claim 1, characterized in that, The second control strategy includes: The system queries the available image forming apparatuses in the network connected to the second computer and guides the user to install the corresponding drivers for those available image forming apparatuses.

9. The security control method according to claim 1, characterized in that, The second control strategy includes: Determine whether the currently logged-in user account of the second computer is included in the preset whitelist. If not, prohibit the sharing of the access port of the image forming device in the first computer. Alternatively, determine the security level of the first computer and / or the currently logged-in user account of the first computer; if the security level does not meet the requirements, then prohibit the sharing of the access port of the image forming apparatus in the first computer. Alternatively, determine the security level of the second computer and / or the currently logged-in user account of the second computer; if the requirements are not met, prohibit the sharing of the access port of the image forming apparatus in the first computer. Alternatively, determine whether the security levels of the first computer and the second computer match. If they do not match, prohibit sharing the access port of the image forming apparatus in the first computer.

10. The security control method according to claim 1, characterized in that, Before executing the first control policy on the first computer side or the second control policy on the second computer side, the method further includes: Obtain the connection attributes between the current computer and the image forming apparatus, including direct connection or indirect connection via another computer; The current computer is defined based on the connection attributes; The step of defining the current computer based on the connection attribute includes: defining the current computer as the first computer when the current computer is directly connected to the image forming apparatus, and defining the current computer as the second computer when the current computer is indirectly connected to the image forming apparatus through other computers.

11. The security control method according to claim 1, characterized in that, The third control strategy includes: Determine the source of the received image data. If the image forming data originates from the first computer, perform an image forming operation on the image forming data. If the image forming data originates from the second computer, image forming operations on the image forming data are prohibited.

12. A security control device, included in a security control system, the security control system comprising a computer and an image forming apparatus, the computer comprising a first computer and a second computer, the first computer having a print driver corresponding to the image forming apparatus installed thereon, wherein when the first computer shares the image forming apparatus with the second computer, the second computer, even without having the print driver corresponding to the image forming apparatus installed, can still use the image forming apparatus to perform image forming operations, characterized in that... include: The control unit is configured to execute a first control policy on the first computer side, the first control policy being configured to control whether the access port of the image forming apparatus in the first computer is allowed to be shared, and / or The control unit is configured to execute a second control policy on the second computer side, the second control policy being configured to control whether the second computer allows shared use of the access port of the image forming apparatus in the first computer, and / or The control unit is used to execute a third control strategy on the image forming apparatus side. The third control strategy is used to determine whether the image forming apparatus allows the image forming operation to be performed based on preset image forming data. The second computer sends the preset image forming data to the image forming apparatus through the access port of the image forming apparatus in the first computer. The first computer is used to be directly connected to the image forming apparatus, and the second computer is used to be indirectly connected to the image forming apparatus through the first computer.

13. The safety control device according to claim 12, characterized in that, The first control strategy includes: Directly disable the access port of the image forming apparatus in the first computer; Alternatively, when the access port of the image forming apparatus can be configured to allow sharing, the access port of the image forming apparatus can be configured to disable sharing, or the allow sharing state of the access port of the image forming apparatus can be disabled, or the access port sharing configuration function of the image forming apparatus can be disabled. Alternatively, when the access port sharing configuration function of the image forming apparatus is enabled, the access port sharing configuration function of the image forming apparatus is disabled. Alternatively, after an action is performed on the image forming apparatus, the access port of the image forming apparatus is checked at preset intervals to see if it is in a shared state. If so, the access port is closed.

14. The safety control device according to claim 12, characterized in that, The first control strategy includes: Determine whether the first computer or the currently logged-in user account of the first computer is included in a preset whitelist. If not, then prohibit sharing the access port of the image forming device in the first computer. Alternatively, determine the security level of the first computer and / or the currently logged-in user account of the first computer; if the security level does not meet the requirements, then prohibit sharing the access port of the image forming apparatus in the first computer. Alternatively, determine the security level of the currently logged-in user account of the second computer and / or the second computer, and if the requirements are not met, prohibit sharing the access port of the image forming apparatus in the first computer; Alternatively, determine whether the security levels of the first computer and the second computer match; if they do not match, then prohibit sharing the access port of the image forming apparatus in the first computer.

15. The safety control device according to claim 12, characterized in that, The first control strategy includes: Output a request message indicating whether sharing the image forming apparatus is permitted. If the response message to the request message does not permit sharing, then sharing the access port of the image forming apparatus in the first computer is prohibited.

16. The safety control device according to claim 12, characterized in that, The first control strategy includes: Determine whether the received image forming data originates from the local machine of the first computer; if the determination is no, prohibit the transmission of the image forming data to the image forming device. Alternatively, determine whether the image forming data is classified data; if so, prohibit the transmission of the image forming data to the image forming device. Alternatively, determine whether the confidentiality level of the image forming data exceeds a preset level, and if so, prohibit the image forming data from being sent to the image forming device; Alternatively, for the image forming data, a request message is output asking whether printing is allowed. If the response message to the request message does not allow printing, then sending the image forming data to the image forming apparatus is prohibited, or the image forming data is discarded directly.

17. The safety control device according to claim 12, characterized in that, The second control strategy includes: Directly prohibit the sharing of access ports of the image forming apparatus in the first computer.

18. The safety control device according to claim 12, characterized in that, The second control strategy includes: Once an action to add the image forming apparatus has occurred, the action to add the image forming apparatus is withdrawn. Alternatively, delete the computer program used to access the access port of the image forming apparatus, and / or prompt the deletion of the computer program used to access the access port of the image forming apparatus; Alternatively, sending image forming data to the access port of the image forming apparatus may be prohibited.

19. The safety control device according to claim 12, characterized in that, The second control strategy includes: The system queries the available image forming apparatuses in the network connected to the second computer and guides the user to install the corresponding drivers for those available image forming apparatuses.

20. The safety control device according to claim 12, characterized in that, The second control strategy includes: Determine whether the currently logged-in user account of the second computer is included in the preset whitelist. If not, prohibit the sharing of the access port of the image forming device in the first computer. Alternatively, determine the security level of the first computer and / or the currently logged-in user account of the first computer; if the security level does not meet the requirements, then prohibit the sharing of the access port of the image forming apparatus in the first computer. Alternatively, determine the security level of the second computer and / or the currently logged-in user account of the second computer; if the requirements are not met, prohibit the sharing of the access port of the image forming apparatus in the first computer. Alternatively, determine whether the security levels of the first computer and the second computer match. If they do not match, prohibit sharing the access port of the image forming apparatus in the first computer.

21. The safety control device according to claim 12, characterized in that, It also includes an acquisition unit, which is used to acquire the connection attributes between the current computer and the image forming apparatus before executing the first control policy on the first computer side or executing the second control policy on the second computer side. The connection attributes include direct connection or indirect connection through other computers. The control unit is used to define the current computer according to the connection attributes; The step of defining the current computer based on the connection attribute includes: defining the current computer as the first computer when the current computer is directly connected to the image forming apparatus, and defining the current computer as the second computer when the current computer is indirectly connected to the image forming apparatus through other computers.

22. The safety control device according to claim 12, characterized in that, The third control strategy includes: Determine the source of the received image data. If the image forming data originates from the first computer, perform an image forming operation on the image forming data. If the image forming data originates from the second computer, image forming operations on the image forming data are prohibited.

23. A computer storage medium comprising a stored computer program, wherein, When the program is running, it controls the device containing the storage medium to perform the method described in any one of claims 1 to 11.

24. A security control system, characterized in that, include: An image forming apparatus for performing one or more operations such as printing, copying, scanning, and faxing; and / or A first computer, configured to be directly connected to the image forming apparatus; and / or A second computer is used to be indirectly connected to the image forming apparatus via the first computer; The security control device as described in any one of claims 12 to 22, wherein the security control device is installed in the first computer; And / or the security control device is installed in the second computer; And / or the security control device is installed within the image forming apparatus.

Citation Information

Patent Citations

  • Image forming device as well as authentication system and method of image forming device

    CN107590378A

  • Method for sharing account of cloud printing service, and cloud server for performing same

    US20190146725A1