Information processing apparatus, image forming apparatus, and control method of information processing apparatus
By adding a secure second memory (such as a TPM) to the information processing device and moving the encryption key from the insecure EEPROM to the TPM under the user's instruction, the security problem of storing the encryption key in the EEPROM is solved, and the secure storage of the encryption key and data protection are achieved.
Patent Information
- Application Number
- CN202211237752.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-10-25
- Filing Date
- 2022-10-10
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-10-10
AI Technical Summary
In the existing technology, when security devices such as TPM are subsequently added to information processing devices or multifunction printers, there are security issues with the processing of encryption keys stored in the EEPROM that has already been set up.
In an information processing device, an encryption key is stored by adding a secure second memory (such as a TPM) after the device leaves the factory. The encryption key is moved from an insecure first memory (such as an EEPROM) to a secure second memory (such as a TPM) by the control unit under the user's instruction, and the corresponding menu options are displayed on the display unit to achieve secure storage.
This technology enables the secure storage of encryption keys in information processing devices, improving data security and protection strength, and preventing encryption keys from being decrypted or destroyed.
Smart Images

Figure CN116033087B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to an information processing apparatus, an image forming apparatus, and a control method of an information processing apparatus. BACKGROUND
[0002] In an information processing apparatus, a multifunction peripheral (an example of an image forming apparatus) in which the information processing apparatus is mounted, information encrypted by an encryption key is stored in a storage device (Storage).
[0003] In Japanese Patent Laid-Open No. 2008-234217, it is disclosed that, in an information processing apparatus or the like in which a TPM (Trust Platform Module) is mounted, an encryption key is protected at a high security level by being held in a secure device such as a TPM. SUMMARY
[0004] However, the TPM is not limited to being standardly mounted in an information processing apparatus or a multifunction peripheral, and in a case where a device such as a TPM is added to the apparatus later, the processing of an encryption key held in an EEPROM (Electrically Erasable and Programmable Read Only Memory) provided in the information processing apparatus or the multifunction peripheral becomes a problem.
[0005] An aspect of the present disclosure provides an information processing apparatus or the like that can securely hold an encryption key in view of the above-described actual situation.
[0006] One embodiment of the present disclosure is an information processing apparatus that holds secret information in the apparatus, including: a storage device that holds data and encrypts the data by an encryption key; a first storage section that is not secure and holds the encryption key; a second storage section that is secure, can be additionally installed, and holds the encryption key; a display section that displays various setting menus; an input section that receives various inputs from a user; and a control section that controls the holding of the encryption key and the display of the display section, wherein, in a state where the storage device is encrypted and the second storage section is installed, when an instruction to hold the encryption key in the second storage section is input in the input section, the control section holds the encryption key in the second storage section.
[0007] One embodiment of the present disclosure is an image forming apparatus characterized by mounting the information processing apparatus and holding image data in the storage device.
[0008] One aspect of this disclosure is a control method for an information processing device that stores confidential information within the device, comprising: a step of storing data in a storage device and encrypting the storage device using an encryption key; a step of storing the encryption key in a non-secure first storage unit; a step of storing the encryption key in a secure second storage unit that can be added and installed; a display step of displaying various setting menus on a display unit; an input step of the user making various inputs; and a control step of controlling the storage of the encryption key and the display of the display unit, wherein in the control step, when the storage device is encrypted and the second storage unit is installed, and an instruction to store the encryption key in the second storage unit is input into the input unit, the encryption key is stored in the second storage unit.
[0009] According to one aspect of this disclosure, an information processing apparatus is provided that can securely store encryption keys, etc. Attached Figure Description
[0010] Figure 1 This is an overall configuration diagram of an image forming apparatus equipped with the information processing apparatus according to the first embodiment.
[0011] Figure 2 It is a control block diagram.
[0012] Figure 3 This is an illustrative diagram comparing the devices used in the first and second memories.
[0013] Figure 4 This is a diagram illustrating the comparison of safe states.
[0014] Figure 5 This is an explanatory diagram of the settings menu screen.
[0015] Figure 6 It is a control flow diagram.
[0016] Figure 7 This is a control flowchart of the information processing device according to the second embodiment.
[0017] Figure 8 This is an explanatory diagram of the settings menu screen in the second embodiment. Detailed Implementation
[0018] Hereinafter, an embodiment for carrying out the present disclosure will be described with reference to the accompanying drawings.
[0019] Furthermore, the following embodiments are examples used to illustrate this disclosure, and the technical scope of the invention described in the claims is not limited to the following description.
[0020] [1. First Implementation Method]
[0021] [1.1 Overall Configuration] First, the configuration of an image forming apparatus 10 to which the information processing apparatus 200 according to the first embodiment is mounted will be described.
[0022] As shown in Figure 1 , the image forming apparatus 10 is a multifunction printer (MFP: Multifunction Printer) such as a multifunction peripheral that has a document reading section 112 in an upper portion of the image forming apparatus 10 to read an image of a document and outputs the image by an electrophotographic method. The MFP is a structure that integrates functions of a copier, a printer, an image scanner, a facsimile, and the like in one housing.
[0023] As will be described later, the image forming apparatus 10 is a multifunction peripheral in which a storage device 162 has an encryption function, and in a case where an encryption key is held in a non-secure EEPROM (Electrically Erasable Programmable Read-Only Memory) memory device, that is, a first memory 164, in the image forming apparatus 10, a menu item for holding in a secure memory device, that is, a second memory 166, is displayed on a display section 150, and when the menu item is selected by a user, the encryption key is moved from the first memory 164 to the second memory 166, and thereafter, display of the menu item of the display section 150 is set to be grayed out or non-displayed.
[0024] As shown in Figure 2 , the image forming apparatus 10 mainly has a control section 100, an image input section 110, the document reading section 112, an image processing section 120, an image forming section 130, an operation section 140, the display section 150, the storage section 160, and a communication section 170.
[0025] The control section 100 is a functional section for controlling the entire image forming apparatus 10.
[0026] Further, the control section 100 realizes various functions by reading out and executing various programs, and is configured by one or a plurality of arithmetic devices such as a CPU (Central Processing Unit), and the like. As will be described later, the storage device 162 of the storage section 160 has a function of encryption by an encryption key. For the encryption key, the encryption key is initially held in the non-secure first memory 164, but if the secure second memory 166 is additionally provided (additionally installed) after shipment of the image forming apparatus 10, a function of holding the encryption key in the second memory 166 is exerted by an instruction input of a user.
[0027] The image input section 110 is a functional section for inputting image data input in the image forming apparatus 10. Also, the image input section 110 is connected to the original reading section 112 which is a functional section for reading an image of an original, and inputs image data output by the original reading section 112.
[0028] In addition, the image input section 110 can input image data from a recording medium such as a USB memory, an SD card, or the like. Also, it is possible to input image data from another terminal device using the communication section 170 which is connected to the other terminal device.
[0029] The original reading section 112 has a function of optically reading an original placed on a contact glass (not shown) or the like and transferring the read data to the image processing section 120.
[0030] The image forming section 130 is a functional section for forming output data based on image data on a recording medium such as a recording sheet. For example, as shown in Figure 1 , a recording sheet is supplied from the paper feed cassette 122, and after an image is formed on the surface of the recording sheet in the image forming section 130, the recording sheet is discharged from the paper discharge tray 124. The image forming section 130 is constituted by, for example, a laser printer using an electrophotographic method or the like.
[0031] The image processing section 120 has a function of converting image data read by the original reading section 112 into a set file form (TIFF, GIF, JPEG, or the like). Also, an output image is formed based on image data on which image processing has been performed.
[0032] The operation section (corresponding to "input section") 140 is a functional section for accepting an instruction based on a user's operation, and is constituted by various key switches, a device for detecting input by contact, or the like. The user inputs a function to be used, an output condition, or the like via the operation section 140.
[0033] The display section 150 is a functional section for displaying various information to the user, and is constituted by, for example, an LCD (Liquid crystal display) or the like.
[0034] That is, the operation section 140 provides a user interface for operating the image forming apparatus 10, and various setting menu screens, messages of the image forming apparatus are displayed in the display section 150.
[0035] Further, as shown in Figure 1 , the image forming apparatus 10 can also be provided with a touch panel formed integrally with the operation panel 141 and the display section 150 as a constitution of the operation section 140. In this case, the manner of detecting input of the touch panel is, for example, a conventional detection manner such as a resistive film method, an infrared method, an electromagnetic induction method, an electrostatic capacity method, or the like.
[0036] The storage section 160 is a functional section that saves (stores) various programs including a control program required for the operation of the image forming apparatus 10, various data including read data, user information, and the like in a storage device 162.
[0037] The storage section 160 is constituted by, for example, a non-volatile ROM (Read Only Memory), a RAM (Random Access Memory), an EEPROM (Electrically Erasable Programmable Read-Only Memory) that is a non-volatile memory, an HDD (Hard Disk Drive), an SSD (Solid State Drive), or the like. The storage device 162 can use various large-capacity storage devices such as an HDD, an SSD, or the like.
[0038] The storage section 160 has an encryption function in the storage device 162 for saving data. The encryption function encrypts the storage device 162 itself by an encryption key, thereby taking a security countermeasure to protect the data inside. That is, in a case where this storage function is effective, when a regular user accesses the storage device, the data is displayed in a decrypted state, and on the other hand, when an irregular third party accesses the storage device, the data is made undecryptable, so that the storage device becomes in a secure state.
[0039] Further, in a case where the storage device 162 does not include hardware having a data encryption function, the data can be encrypted in the control section 100, and then the encrypted data can be directly written to the storage device 162, and the data can be decrypted in the control section 100 at the time of reading out the data.
[0040] The encryption key for encryption is initially stored in a first memory (corresponding to "first storage section") 164 constituted by a non-secure non-volatile memory constituted by an EEPROM mounted in the image forming apparatus from the time of shipment. Also, in order to additionally install a second memory ("second storage section") 166 in the image forming apparatus at an appropriate time after shipment, a structure is adopted in which the encryption key can be stored by menu selection, in which, in order to store the encryption key, the second memory uses a secure TPM (Trusted Platform Module). Further, a non-secure storage medium other than an EEPROM can be used in the first memory 164. Also, in the second memory 166, the TPM chip is a secure encryption processor suitable for being designed to perform encryption operations, but as long as it is a recording module capable of securely storing the encryption key, various configurations can of course be used.
[0041] Figure 3 is a diagram showing a comparison of the chip of the EEPROM used in the first memory 164 and the TPM chip used in the second memory 166 in terms of function, security, and cost of the chip.
[0042] As Figure 3 shown, an EEPROM (Electronically Erasable Programmable ROM) is a type of non-volatile memory that allows any portion to be electrically rewritten at low frequency, and has the function of a non-volatile memory that stores binary data. The chip is inexpensive and low in cost, but since anyone can freely read and write, there is a possibility that the encryption key will be decrypted or destroyed, and thus the security is low.
[0043] In contrast to this, a TPM is a device that has various security functions in the chip, and although the chip is expensive, it is possible to read and write stored data, for example, only in the case where the hash value of the firmware is equal to a value registered in advance. It has high security such that the encryption key cannot be acquired if the firmware is tampered with.
[0044] The communication section 170 is communicatively connected with an external device. A communication interface (communication I / F) for transmission and reception of data is provided as the communication section 170. Via the communication I / F, by operation in the image forming apparatus 10 by a user, it is possible to transmit and receive data stored in the storage section of the image forming apparatus 10 to and from other computer devices connected via a network.
[0045] [1.2 Functional Configuration]
[0046] As Figure 2As shown in a functional block diagram, the information processing apparatus according to the embodiment is an information processing apparatus 200 that holds secret information in the apparatus mounted on the image forming apparatus 10.
[0047] 〔Storage device 162, first memory 164, and second memory 166〕
[0048] The information processing apparatus 200 includes a storage device 162 for holding various data such as image data, which is encrypted by an encryption key; a first memory 164 that is non-secure and holds the encryption key; a second memory 166 that is secure, can be additionally installed after shipment, and holds the encryption key; a display section 150 that displays various setting menus; an operation section (corresponding to "input section") 140 that allows a user to make various inputs; and a control section 100 that controls the holding of the encryption key and the display of the display section. When the second memory 166 is installed in a state where the storage device 162 is encrypted and the encryption key is held in the first memory 164, the control section 100 causes the display section 150 to display a setting menu for holding the encryption key in the second memory 166. When an instruction for holding the encryption key in the second memory is input in the operation section 140, the control section 100 transfers the encryption key held in the first memory 164 to the second memory 166.
[0049] 〔Secure state〕
[0050] Here, Figure 4 The respective outlines and respective purposes of use of the secure states (standard mode state, standard secure state, DSK effective state, and HCD-PP compliant state) in the information processing apparatus 200 are described.
[0051] In Figure 4 In the present embodiment, "DSK" refers to a data security kit for enhancing the data security function of an MFD (Multifunction Device, synonymous with MFP).
[0052] Further, HCD-PP (Protection Profile for Hardcopy Devices) is a security requirement formulated by IPA (Independent Administrative Agency Information Processing Promotion Agency), National Information Assurance Partnership (NIAP) as an IT security certification agency of the U.S. government, and manufacturers and the like in cooperation.
[0053] 〔Setting menu screen〕
[0054] Figure 5An example of a setting menu screen 210 for saving an encryption key into the second storage 166 is shown as displayed on the display section 150 of the operation panel (touch panel) 141.
[0055] In the setting menu screen 210, a menu item 210a for making the protection of the storage device encryption key effective is displayed. When a check box 210al displayed together with the menu item 210a is checked, the setting is effective. Further, a menu item 210b for refusing to receive a request from an external site, a menu item 210c for performing repair when a breakage of firmware is detected, and a menu item 210d for backup of the encryption key, and the like are displayed, and when check boxes displayed together with the menu items are checked, the selected functions are effective. Further, the operation of the setting menu screen 210 on each menu item can of course be performed by the switches of the operation section 140 other than the operation panel (touch panel) 141, and the input from the other terminal can also be similarly accepted and set.
[0056] Figure 6 is a flowchart showing a flow of a setting menu display process performed by the control section 100 in the information processing apparatus 200 of the embodiment. In the following and Figure 6 , each step 100 is simply written as S100.
[0057] First, in the image forming apparatus 10 after shipment, the control section 100 determines whether the information processing apparatus 200 has encrypted the storage device 162 (S100). In the embodiment, the storage device 162 encryption time is the time when the storage device 162 is changed to the standard security state or the DSK effective state. Further, at the storage device 162 encryption time, the encryption key is also saved in the first storage 164. Thus, even if the password key is not saved in the storage other than the first storage 164, the saving place of the password key can be temporarily ensured before the second storage 166 is installed.
[0058] In S100, in the case where it is determined that the storage device 162 is not encrypted (S100: No), the menu item 210a (refer to Figure 5 ) for saving the encryption key in the second storage 166 composed of the TPM is made non-displayed in the setting menu screen 210 of the display section 150 (S160). Thereafter, the setting menu display process is ended.
[0059] Thus, by making the menu item 210a, which saves the encryption key in the second memory 166, non-displayed in the setting menu screen 210, it is possible to notify the user that the storage device 162 is not encrypted. With this notification, it is possible to prompt the user to perform an operation such as encrypting the storage device 162, and in addition, it is possible to recognize the possibility that a problem has occurred in the storage device 162, and the like, and the user can perform an appropriate operation that should be performed next.
[0060] On the other hand, in the case where it is determined in S100 that the storage device 162 is encrypted (S100: Yes), it is determined whether the second memory (TPM) 166 is installed in the information processing device 200 (S110).
[0061] In the case where it is determined that the second memory 166 has been installed in the information processing device 200 (S110: Yes), it is determined whether the encryption key has been saved in the second memory 166 (S120).
[0062] In the case where it is determined that the encryption key has not been saved in the second memory 166 (S120: No), the menu item 210a for saving the encryption key to the second memory 166 (S130) is displayed in the setting menu screen 210 of the display section 150. According to the above, in the state where the storage device 162 is encrypted and the encryption key is saved in the first memory 164 composed of an EEPROM, the setting menu for saving the encryption key in the second memory 166 composed of a TPM is displayed. Figure 5
[0063] Next, it is determined whether the menu item 210a saved in the second memory (TPM) 166 is valid (S140), and in the case where it is determined that it is not made valid (S140: No), the setting menu display processing is ended.
[0064] On the other hand, in the case where it is determined that the menu item 210a saved in the second memory (TPM) 166 is valid (S140: Yes), the encryption key is moved from the first memory (EEPROM) 164 to the second memory (TPM) 166 (S150). If the setting menu of the menu item 210a is made valid, the encryption key is transferred from the first memory 164 to the second memory 166.
[0065] At the time of transferring the encryption key saved in the first memory 164 to the second memory 166, processing for erasing the encryption key saved in the first memory is performed. Thus, it is possible to reliably eliminate the state where the encryption key saved in the second memory 166 is saved in the first memory 164, which is not secure, and it is possible to quickly eliminate the state where the security state is low.
[0066] Further, in a case where it is determined in S110 that the second memory 166 is not installed in the information processing apparatus 200 (S110: No), S160 is entered. In S160, in the setting menu screen 210, the menu item 210a to save the encryption key in the second memory 166 is set to be non-displayed. With this processing of S160, even if the storage apparatus 162 is encrypted, since the menu item 210a is not displayed, the operation to save the encryption key in the second memory 166 cannot be performed or is difficult to perform, and the user can be notified that the encryption of the storage apparatus 162 is not completed. By the notification, the user can be prompted to install the second memory 166.
[0067] Further, in S120, in a case where it is determined that the encryption key is already saved in the second memory 166 (S120: Yes), S170 is entered. In S170, display processing (gray processing) is performed in which the menu item 210a to save the encryption key in the second memory 166 is overlaid with display in gray scale in the setting menu screen 210. Thereafter, the setting menu display processing is ended. Further, after the processing of S140, S150, S160, S170 is ended, the processing is returned to the start of the processing, and standby is performed until the next operation is input.
[0068] With the above-described gray processing, the display of the menu item 210a is different from normal, and the user can be notified that the encryption key is already saved in the second memory 166 and prompted to pay attention. In addition to the gray processing, specific display such as "TPM in use" can be performed.
[0069] Thus, in a state where the storage apparatus 162 is encrypted and the encryption key is saved in the second memory 166, specific display can be performed in the setting menu screen to notify the user that the state is made secure by the specific display. The specific display can be various displays other than "TPM in use".
[0070] Further, there is no setting menu to return the encryption key saved in the second memory 166 to the first memory 164. In this case, display expressing that it is not returned to the first memory before moving to the second memory 166 is performed. For example, display of "encryption key saved in TPM is not returned to EEPROM" is performed.
[0071] Thus, after the encryption key is saved in the secure state with the second memory 166, the secure state can be maintained to improve the secure state.
[0072] Further, the control section 100 can also save the backup of the encryption key saved in the second memory in the third memory (storage section), and in this case, it is preferable to display the setting menu on the display section because of the high convenience, and the third memory is constituted by a USB memory which is detachably provided with respect to the information processing apparatus 200.
[0073] [2. Second Embodiment]
[0074] Figure 7 is a flowchart of the information processing apparatus according to the second embodiment. Figure 8 is a setting menu screen 210' according to the second embodiment.
[0075] In Figure 7 the second embodiment shown in FIG. 10, the encryption key can be selectively saved in the first memory 164 or the second memory 166 at the time of encryption of the storage apparatus 162. The same step number is attached to the same step as Figure 6
[0076] As Figure 7 shown in FIG. 10, the second embodiment differs from the first embodiment in that, when it is determined that the storage apparatus 162 is encrypted (S100: YES), it is determined whether the encryption key is saved in the first memory 164 constituted by an EEPROM (S200).
[0077] Specifically, as Figure 8 shown in FIG. 11, the menu item 210e (Save encryption key in EEPROM) of the setting menu screen 210' of the display section 150 is displayed, and it is determined whether the setting of the menu item 210e is set to be valid by the user. In the case where the setting of the menu item 210e is set to be valid, the encryption key is saved in the first memory 164 (S210), and the process proceeds to S160. Figure 8
[0078] On the other hand, in the case where it is determined in S200 that the encryption key is not saved in the first memory 164, the process proceeds to S110, and the subsequent process is performed.
[0079] The second embodiment is convenient in that the encryption key can be saved in the first memory 164 constituted by a non-secure EEPROM in the case where it is not problematic to save the encryption key in the first memory 164 or in the state where the second memory is not installed. On the other hand, in the case where it is desired to save it in a secure TPM, the encryption key can be selectively saved in the second memory 166 constituted by a TPM, and it is convenient.
[0080] Further, as Figure 8 In the illustrated example, the menu item 210a' indicating whether or not to store the password key in the second memory and the menu item 210e indicating whether or not to store the password key in the first memory 164 (EEPROM) are displayed on the setting menu screen 210 of the display section 150, but the present application is not limited to this example and only the menu item 210e can be displayed.
[0081] In addition to the first and second embodiments, various modifications can be implemented.
[0082] For example, in the second embodiment, the process of S200 can be appropriately set to be performed between S110 and S120, and the like.
[0083] The above describes the embodiments, but the detailed configuration is not limited to the embodiments and any design and the like within a range not departing from the gist of the present application is included in the scope of the patent claim.
[0084] In the embodiments, the program in which each device performs an operation is a program that controls a CPU or the like in a manner to realize the functions of the above-described embodiments (a program that causes a computer to function). Further, the information processed in these devices is temporarily stored in a temporary storage device (for example, a RAM) at the time of processing, and thereafter, is stored in various ROMs, HDDs, or the like, and is read out by the CPU as necessary, and is corrected and written.
[0085] Here, as a recording medium that stores a program, any one of a semiconductor medium (for example, a ROM, a nonvolatile memory card, or the like), an optical recording medium or a magneto-optical recording medium (for example, a DVD (Digital Versatile Disc), a MO (magneto Optical Disc), an MD (Mini Disc), a CD (Compact Disc), a BD (Blu-ray (registered trademark) Disc), or the like), a magnetic recording medium (for example, a magnetic tape, a flexible disk, or the like), or the like can be used.
[0086] In addition, by executing the downloaded program, not only the functions of the above-described embodiments can be realized, but also the functions of the present disclosure can be realized by common processing by an operating system or another application program, or the like, based on the instructions of the program.
[0087] In addition, in a case where the program is circulated on the market, the program can be circulated by being stored in a removable storage device or transmitted to a server computer connected via a network such as the Internet. At this time, the storage device of the server computer is of course included in the present application.
[0088] In addition, a part or all of each device in the above-described embodiments can also be implemented as an LSI (Large Scale Integration) of an integrated circuit, typically. Each functional block of each device can be individually chipized, or a part or all thereof can be integrated and chipized. In addition, the method of integrated circuitization is not limited to LSI, and can be implemented by a dedicated circuit or a general-purpose processor. In addition, when an integrated circuit technology replacing LSI emerges due to advances in semiconductor technology, an integrated circuit according to the technology can of course be used.
Claims
1. An information processing apparatus which is an information processing apparatus that holds secret information within the apparatus, characterized by comprising: including: a storage device for holding data and encrypting by an encryption key; a first storage section which is not secure and which holds the encryption key; a second storage section which is secure, which can be additionally installed, and which holds the encryption key; a display section which displays various setting menus; an input section which is used by a user to make various inputs; and a control section which controls holding of the encryption key and display of the display section, the control section is configured to, in a state where the storage device is encrypted and the second storage section is installed, hold the encryption key in the second storage section when an instruction to hold the encryption key in the second storage section is input in the input section, the control section is configured to, in a state where the storage device is encrypted and the second storage section is installed, cause the display section to display a setting menu to hold the encryption key in the second storage section, the control section is configured to, when an instruction to hold the encryption key in the second storage section is input in the input section, transfer the encryption key held in the first storage section to the second storage section, the control section is configured to, when the encryption key held in the first storage section is transferred to the second storage section, erase the encryption key held in the first storage section, the control section is configured to, in the setting menu, cause the display section to display a specific display which is a display to inform the user that a secure state of the encryption key has been established.
2. The information processing apparatus according to claim 1, wherein the control section is configured to, when the storage device is not encrypted, cause the display section to not display a setting menu to transfer the encryption key to the second storage section.
3. The information processing apparatus according to claim 1, wherein the control section is configured to, when the storage device is encrypted, hold the encryption key in the first storage section.
4. The information processing apparatus according to claim 1, wherein the control section is configured to, when the storage device is encrypted, be able to selectively hold the encryption key in the first storage section or the second storage section.
5. The information processing apparatus according to claim 1, wherein the control section is configured to, in a state where the storage device is encrypted and the encryption key is held in the second storage section, make a specific display in the setting menu.
6. The information processing apparatus according to claim 1, wherein the control section is configured to, after the encryption key held in the first storage section is transferred to the second storage section, not return the encryption key to the first storage section.
7. The information processing apparatus according to claim 1, wherein the control section is configured to cause the display section to display a setting menu to hold the encryption key held in the second storage section in a third storage section which is detachably provided with respect to the information processing apparatus.
8. An image forming apparatus characterized by comprising: An information processing apparatus according to any one of claims 1 to 7 is mounted, and image data is held in the storage device.
9. A control method of an information processing apparatus, which is a control method of an information processing apparatus that holds secret information in the apparatus, characterized by, including: a step of holding data in a storage device and encrypting the storage device by an encryption key; a step of holding data in a storage device and encrypting the storage device by an encryption key; a step of storing the encryption key in a first storage section which is not secure; a step of storing the encryption key in a second storage section which is capable of being additionally installed and is secure; a display step of displaying various setting menus on a display section; an input step in which a user performs various inputs; and a control step of controlling storage of the encryption key and display of the display section, in the control step: when an instruction to store the encryption key in the second storage section is input in an input section in which a user performs various inputs, in a state in which the storage device is encrypted and the second storage section is installed, the encryption key is stored in the second storage section, when the second storage section is installed in a state in which the storage device is encrypted and the encryption key is stored in the first storage section, the display section is caused to display a setting menu for storing the encryption key in the second storage section, when an instruction to store the encryption key in the second storage section is input in the input section, the encryption key stored in the first storage section is transferred to the second storage section, when the encryption key stored in the first storage section is transferred to the second storage section, the encryption key stored in the first storage section is erased, in the setting menu, the display section is caused to display a specific display which is a display for notifying the user that a secure state of the encryption key has been established.
Citation Information
Patent Citations
Information processor, method of protecting information, and image processor
JP2008234217A
Data management apparatus, data management method
CN1825291A