Information processing apparatus, method performed by information processing apparatus, and computer program product
By dynamically adjusting the encrypted communication algorithm in the information processing device, the problem that the device management system cannot communicate normally in FIPS 140-3 mode is solved, ensuring security and compatibility in FIPS 140-3 mode.
Patent Information
- Application Number
- CN202510028718.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-10
- Filing Date
- 2025-01-08
- Publication Date
- 2025-07-11
AI Technical Summary
The existing device management system cannot support hashing algorithms such as SHA1/SHA2-256/SHA2-384/SHA2-512 under the FIPS 140-3 standard, resulting in the inability to communicate normally in systems operating in FIPS 140-3 mode.
An information processing device is provided. By selecting a suitable encrypted communication algorithm in the operating system, the hashing algorithm of SNMPv3 is dynamically adjusted according to different versions of FIPS 140 mode (FIPS 140-2 or FIPS 140-3), ensuring that the SHA1 algorithm is excluded in FIPS 140-3 mode, and the SHA2-256, SHA2-384 or SHA2-512 algorithms are selected.
It realizes normal communication of the device management system in FIPS 140-3 mode, avoids exceptions caused by SHA1 unavailability, and ensures system security and compatibility.
Smart Images

Figure CN120301978A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, a method performed by the information processing apparatus, and a computer program product. Background Art
[0002] In the prior art, there are known a device management system and a management device for acquiring and managing data of operation information of image forming apparatuses (hereinafter referred to as devices) such as printers or multifunction peripherals. In such a device management system, an address book including a plurality of information such as the status, setting values, firmware, and mail addresses of network devices to be managed can be managed.
[0003] The device management system can acquire data from a network device to be managed via a network or send data to the network device to be managed, and encrypt communication with the network device during acquisition or transmission of information.
[0004] Japanese Unexamined Patent Application Publication No. 2019-29879 discloses a configuration in which, for security purposes, an image processing apparatus switches an operation screen provided to an operation terminal device according to a communication level between the image processing apparatus and the operation terminal device.
[0005] On the other hand, there are Federal Information Processing Standards (FIPS), which are standards established by the National Institute of Standards and Technology (NIST), a U.S. government agency. FIPS includes version FIPS140-2 and version FIPS140-3.
[0006] The device management system uses the Simple Network Management Protocol (SNMP) or various communication protocols to monitor and manage a TCP / IP network environment.
[0007] In such protocols, a hash algorithm can be selected from SHA1 / SHA2-256 / SHA2-384 / SHA2-512, etc. The environment (or subsystem) including network devices managed by the device management system does not support FIPS140-3. Summary of the Invention
[0008] There is provided an information processing apparatus in which an operating system and an application for managing information of network devices are executed, the information processing apparatus including:
[0009] one or more memories that store instructions; and
[0010] One or more processors capable of executing the instructions, the instructions causing the information processing apparatus to perform the following processing:
[0011] Causing the application to perform processing for providing a plurality of selections for an algorithm for encrypted communication; and
[0012] Causing the application to set the algorithm selected in response to the provision as the communication setting with the network device,
[0013] wherein the combination of the plurality of selections provided in the processing performed by the application is different between when the operating system is not operating in the FIPS140 mode and when the operating system is operating in the FIPS140 mode of FIPS 140-3.
[0014] Other features of the present invention will become apparent from the following description of embodiments with reference to the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a diagram schematically showing an example of the configuration of a device management system according to a first embodiment of the present invention.
[0016] Figure 2 is a diagram showing an example of the hardware configuration of the device management server 1000 according to the first embodiment.
[0017] Figure 3 is a functional block diagram showing an example of the configuration of software modules of the device management server 1000 according to the first embodiment.
[0018] Figure 4 is a functional block diagram showing an example of the internal configuration of the device 2000 according to the first embodiment.
[0019] Figure 5 is a diagram showing an example of a display UI associated with a device search result according to the first embodiment.
[0020] Figure 6A is a diagram showing an example of a display UI associated with the setting of communication with a device according to the first embodiment.
[0021] Figure 6B is a diagram showing an example of a display UI associated with details of authentication information according to the first embodiment.
[0022] Figure 6C is a diagram showing an example of a display UI associated with the setting of communication with a device according to the first embodiment.
[0023] Figure 7A is a flowchart showing an example of the processing flow of a device management method according to the first embodiment.
[0024] Figure 7B is a flowchart showing an example of the detailed process of step S703 in Figure 7A
[0025] Figure 7C is a flowchart showing an example of the detailed process of step S708 in Figure 7A
[0026] Figure 7D is a flowchart showing an example of the detailed process of step S705 in Figure 7A
[0027] Figure 8A is a diagram showing a display example of the "authentication algorithm" of FIPS140-3.
[0028] Figure 8B is a diagram showing a display example of the "authentication algorithm" of FIPS140-2.
[0029] Figure 9 is a flowchart showing an example of the processing flow of the device management method according to the second embodiment.
[0030] Figure 10 is a diagram showing another example of the display UI according to the first embodiment. DETAILED DESCRIPTION
[0031] Hereinafter, advantageous modes of the present invention will be described using embodiments with reference to the accompanying drawings. In the respective drawings, the same reference numerals are assigned to the same components or elements, and repeated descriptions will be omitted or simplified.
[0032] <First Embodiment>
[0033] Figure 1 is a diagram schematically showing an example of the configuration of a device management system according to the first embodiment of the present invention. The device management system according to the first embodiment includes a device management server 1000 (which includes a device management application 101) and a plurality of proxy applications (hereinafter simply referred to as proxies) 106 and 107.
[0034] The device management system according to the first embodiment manages devices 102, 103, 110, and 111 (hereinafter collectively referred to as devices 2000) connected to a network. The device management server 1000, the proxy 106, and the devices 102 and 103 are interconnected via a network 104.
[0035] The proxy 107 and the devices 110 and 111 are interconnected via a network 108. The network 104 and the network 108 are connected by a router 109 (the network 104 and the network 108 are collectively referred to as communication lines 3000).
[0036] The router connects two networks to each other and can be configured, for example, to allow communication between the proxy 107 and the device management server 1000 and to prohibit communication with the devices 110 and 111 on the network 108.
[0037] Here, the proxies 106 and 107 are associated with the devices 102, 103, 110, and 111 based on the addresses of the devices, etc. For example, it is assumed that the proxy 106 is associated with the devices 102 and 103, and the proxy 107 is associated with the devices 110 and 111.
[0038] The reference numeral 105 denotes a directory server, and the device management server 1000 can be set so that the users of the directory server 105 can access the device management server 1000.
[0039] An example of operating the device 102 by the proxy 106 will be described below. The device management server 1000 instructs the proxy 106 to operate the device 102. The proxy 106 operates to send a request to the device 102 based on the instruction, etc., and sends the result to the device management server 1000.
[0040] Examples of operations include obtaining information from the device 102, changing the setting value of the device 102, instructing to install an application in the device 102, and instructing to update the firmware of the device 102.
[0041] The device 102 does not communicate directly with the device management server 1000, but communication occurs between the device management server 1000 and the proxy 106 and between the proxy 106 and the device 102.
[0042] Figure 1 Two proxies and four devices are shown, but a configuration in which tens of thousands of devices are managed via dozens of proxies can be adopted. In this case, the configuration or operation is the same as that described in this embodiment.
[0043] Figure 2 FIG. is an example showing the hardware configuration of the device management server 1000 according to the first embodiment. The CPU 10 uses the RAM 12 as a work area and executes various computer programs such as the OS or device management software stored in the ROM 11 or the HDD 19. The reference numeral 13 denotes a system bus.
[0044] The device management server 1000 is connected to the display device (LCD) 15 via a video card (VC) 14 and is connected to the keyboard (KB) 17 or a pointing device such as a mouse (not shown) via a keyboard controller (KBC) 16.
[0045] The device management server 1000 can control the disk drive 20 via a disk controller (DKC) 18. In the disk drive 20, a storage medium such as a CD-ROM, DVD, magnetic tape, or IC memory card can be installed.
[0046] The device management server 1000 can perform data communication with devices on the communication line 3000 via a network interface card (NIC) 21.
[0047] Figure 3 FIG. is a functional block diagram showing an example of the software module configuration of the device management server 1000 according to the first embodiment. The device management server 1000 includes a UI control unit 30, a device control unit 31, a progress control unit 32, and a function control unit 33 as components of software modules for managing the device 2000.
[0048] These modules are implemented by causing the CPU 10 to execute device management software, which is a computer program stored in Figure 2 the RAM 12, ROM 11, and HDD 19 shown.
[0049] On the other hand, some or all of the modules can be implemented by hardware. A dedicated circuit (ASIC), a processor (such as a reconfigurable processor or DSP), etc. can be used as the hardware.
[0050] Figure 3 The functional blocks shown may not be included in the same housing and can be implemented by different devices interconnected via signal lines. The description above with reference to Figure 3 also applies to Figure 4 .
[0051] The UI control unit 30 includes a device display unit 301, a schedule display unit 302, and a function display unit 303. The device control unit 31 includes a device connection unit 311, a device data management unit 312, and a device data storage unit 313.
[0052] The progress control unit 32 includes a progress management unit 321 and a progress storage unit 322. The function control unit 33 includes a device setting transfer unit 331, an address book transfer unit 332, and a function information storage unit 333.
[0053] The UI control unit 30 performs UI control in the device control unit 31, the progress control unit 32, and the function control unit 33 using the device display unit 301, the schedule display unit 302, and the function display unit 303. The UI control can be implemented as a web-based application. In this case, the UI control can be used via a web browser.
[0054] The device connection unit 311 has functions such as device search, collecting information from devices, and setting execution. Examples of the functions of the device connection unit 311 are the device search function for the device 2000 using SNMP, IP broadcast, SLP / multicast, etc.
[0055] At this time, the device connection unit 311 searches for the device 2000 at any timing. Then, the device connection unit 311 has the function of acquiring / changing device information such as management information base (MIB) information or security policy information via a communication line 3000 such as a LAN.
[0056] The device connection unit 311 acquires device information such as device name, product name, and IP address as a result of communication settings and device search for the device 2000, and stores the acquired device information in the device data storage unit 313. The device data management unit 312 manages the data in the device data storage unit 313.
[0057] The progress management unit 321 collaborates with the functions of the function control unit 33 to generate and manage the progress input from the progress display unit 302, and stores the progress in the progress storage unit 322. The device setting transfer unit 331 of the function control unit 33 transfers settings to the device based on the input from the function display unit 303.
[0058] The address book transfer unit 332 transfers the address book to the device based on the input from the function display unit 303. At this time, information is stored in the function information storage unit 333. Here, the device data storage unit 313, the progress storage unit 322, and the function information storage unit 333 are data recording media (such as databases operating on the HDD 19), and a progress list, a device list, function information, etc. are stored in this data recording medium.
[0059] Figure 4 is a functional block diagram showing an example of the internal structure of the device 2000 according to the first embodiment, and shows an example of the software structure of the information control unit 40 operating in the device 2000. The device 2000 includes an information control unit 40 for managing a plurality of information groups that change dynamically, as a software module. The device 2000 according to the first embodiment is, for example, a printer.
[0060] The counter information management unit 401 manages the number of printed pages, etc., and stores the number of printed pages in the counter storage unit 402. The MIB information management unit 403 manages the MIB information as device information, and stores the MIB information in the MIB information storage unit 404. The power information management unit 405 manages power-off information or restart information, and stores the power-off information or restart information in the power information storage unit 406.
[0061] The status information management unit 407 manages status information such as online, offline, and error, and stores the status information in the status information storage unit 408. The address book information management unit 409 manages information such as the structure or data of the address book, and stores the information in the address book information storage unit 410. The information of the sent address book is also managed and stored therein.
[0062] The setting value information management unit 411 stores various setting values (such as print settings of the device or settings associated with the network) in the setting value information storage unit 412. In response to a request from the device management server 1000, data is sent to the device management server 1000 using SNMP or other protocols.
[0063] Figure 5 FIG. is an example of a display UI associated with the device search result according to the first embodiment, while Figures 6A to 6C FIG. is an example of a display UI associated with the communication settings according to the first embodiment. The device search processing flow will be described below with reference to Figure 5 and Figures 6A to 6C FIGs.
[0064] The device management server 1000 searches for devices 2000 to be managed on the network. That is, the device search settings are set in the Figure 5 menu "Task", and then the devices are searched. SNMP is used as the algorithm for this search.
[0065] An example of the UI associated with the device search result is shown in Figure 5 FIG. Here, information of such devices (such as device name, product name, IP address, and serial number) is displayed together with the found device name. On this screen, a specific device can be specified and excluded from the management target.
[0066] Before the search, the communication with the device is set in advance. Select "Communication Settings with Device" in the "Device" menu. Figure 6A FIG. is an example of a UI for the communication settings with the device. Here, necessary settings such as SNMPv1, SNMPv3, and user authentication settings are set as the authentication settings.
[0067] In the example shown in Figure 6A FIG., SNMPv1 has been set as the authentication method. Here, when performing SNMPv3, select SNMPv3 as the authentication method, for example, select "Read Only" as the access restriction, and click the "Add" button.
[0068] When the "Add" button in Figure 6A FIG. is clicked, a detailed screen of the authentication information is displayed. Figure 6BFIG. is an example of a display UI associated with details of authentication information according to the first embodiment. In Figure 6B "User Name", "Authentication Password", "Encrypted Password", "Context Name", "Scope" (target agent scope), and "Description" are input, and the Figure 6B "Add" button in is clicked. Accordingly, a new authentication method is added, and the screen switches to the Figure 6C screen shown. Figure 6C FIG. is an example of a display UI associated with settings for communication with a device according to the first embodiment.
[0069] In Figure 6B , one of SHA1 / SHA2-256 / SHA2-384 / SHA2-512 can be selected as the hash algorithm in "Authentication Password". Based on the communication settings preset in this way, device search and information acquisition are performed.
[0070] Figure 7A FIG. is a flowchart showing an example of a processing flow of a device management method according to the first embodiment. In this embodiment, Figure 1 the device management server 1000 shown in manages a device management method for managing a plurality of devices connected to a network.
[0071] By causing a CPU or the like (i.e., a computer in the device management server 1000) to execute device management software (i.e., a computer program stored in a memory), the operations of the steps in the Figures 7A to 7D flowchart shown are sequentially performed.
[0072] When the device management server 1000 manages a device, as described above with reference to Figure 5 , device search is first performed. Before that, communication with the device is set. That is, in the Figure 5 "Device" button, "Communication Settings with Device" is selected. Then, as described above, in the Figure 6A device communication settings screen shown, the authentication method "SNMPv3" is selected and the "Add" button is clicked.
[0073] When the selection display 601 of the "Authentication Algorithm" of the "Authentication Password" in Figure 6B is clicked, the device connection unit 311 obtains the system encryption settings in the Figure 7A step S701 in.
[0074] That is, in the device management system, the device management server 1000 obtains information on whether the operation window is operating in FIPS140 mode. Here, step S701 serves as an encryption setting acquisition step (encryption setting acquisition unit).
[0075] In step S702, the device connection unit 311 determines whether the device management system is operating in the FIPS140 mode based on the information obtained in step S701. When the determination result of step S702 is "yes", the processing flow proceeds to step S703. Otherwise, the processing flow proceeds to step S707. Here, step S702 serves as the first determination step (first determination unit) for determining whether the device management system is in the FIPS140 mode.
[0076] In step S703, the device connection unit 311 confirms the version of FIPS140. Here, step S703 serves as the version confirmation step (version confirmation unit) for confirming the version of FIPS140.
[0077] In step S704, the device connection unit 311 determines whether the version of FIPS140 is FIPS 140-3. Here, step S704 serves as the second determination step (second determination unit) for determining whether the version of FIPS140 is FIPS140-3.
[0078] When the determination result of step S704 is "yes", the processing flow proceeds to step S705. Otherwise, the processing flow proceeds to step S708.
[0079] In step S705, the device display unit 301 displays the "authentication algorithm" of FIPS140-3. In step S706, the device connection unit 311 selects the "authentication algorithm", and the screen returns to the authentication information details screen. Here, step S706 serves as the selection step (selection unit) for selecting the authentication algorithm displayed by the authentication algorithm display step (authentication algorithm display unit).
[0080] In step S707, the device display unit 301 displays the normal authentication algorithm. In step S708, the device display unit 301 displays the authentication algorithm of FIPS140-2.
[0081] Here, steps S705, S707, and S708 serve as the authentication algorithm display steps (authentication algorithm display unit) for displaying the authentication algorithm based on the determination results from the first determination unit and the second determination unit. The authentication algorithm display unit can display the authentication algorithm of FIPS140-3 and the authentication algorithm of FIPS140-2.
[0082] Figure 7B Is a flowchart showing an example of the detailed processing flow of step S703 Figure 7A and when the device connection unit 311 confirms the version of FIPS140 in step S703, it performs the SHA1 hash calculation in step S709.
[0083] Subsequently, in step S710, the device connection unit 311 determines whether an abnormality has occurred. More specifically, the device connection unit 311 performs SHA1 hash calculation using the library of the operating system.
[0084] At this time, when the operating system operates in FIPS140-3 mode, an abnormality is returned to the device connection unit 311 as a calculation result. For example, when the operating system is Windows 11 or the like, the return value InvalidOperationException is returned as an abnormality.
[0085] The device connection unit 311 determines whether an abnormality has occurred based on this process. Steps S709 and S710 are used as the third determination step (third determination unit) for performing SHA1 hash calculation and determining whether an abnormality has occurred.
[0086] When the determination result of step S710 is "Yes", the processing flow proceeds to step S712. Otherwise, the processing flow proceeds to step S711.
[0087] In step S711, the device connection unit 311 determines that the version is FIPS140-2, ends Figure 7B the shown processing flow, and makes the processing flow enter step S704. On the other hand, in step S712, the device connection unit 311 determines that the version is FIPS140-3, ends Figure 7B the shown processing flow, and makes the processing flow enter step S704.
[0088] That is, the device connection unit 311 determines that the operating system operates in FIPS140-3 mode when the third determination unit determines that an abnormality has occurred, and determines that the operating system operates in FIPS140-2 mode when the third determination unit determines that no abnormality has occurred.
[0089] Figure 7C is a flowchart showing Figure 7A an example of the detailed processing flow of step S708. When the authentication algorithm of FIPS140-2 is displayed in step S708, SHA1 / SHA2-256 / SHA2-384 / SHA2-512 are displayed in step S713 (in a list).
[0090] That is, when the authentication algorithm of FIPS140-2 is displayed, at least one of SHA2-256, SHA2-384, and SHA2-512 is displayed together with SHA1. Thereafter, Figure 7C the shown processing flow ends, and the processing flow enters step S706.
[0091] Figure 7D is a flowchart showing Figure 7AFlowchart of an example of the detailed processing procedure in step S705. When the authentication algorithm of FIPS140-3 is displayed in step S705, SHA2-256 / SHA2-384 / SHA2-512 is displayed (in a list) in step S714.
[0092] That is, when the authentication algorithm of FIPS140-3 is displayed, at least one of SHA2-256, SHA2-384, and SHA2-512 is displayed. Thereafter, Figure 7D The processing procedure shown ends, and the processing procedure proceeds to step S706.
[0093] In this embodiment, it is possible to determine under which FIPS version the operating system is operating, and it is possible to change the display or selection of the SNMPv3 hash algorithm.
[0094] The operations in an example of the supplementary description of the UI will be described below with reference to Figures 5 to 8B Here, it is assumed that Windows is operating in FIPS140-3 mode. As described above, before device management, in Figure 5 the "Device" menu, select "Communication Settings with the Device" to set the communication with the device.
[0095] In Figure 6A the "Device Communication Settings" screen shown, select "SNMPv3" as the authentication method and click the "Join" button. In Figure 6B the "Details of Authentication Information" screen shown, click on the selection display 601 of "Authentication Algorithm" in "Authentication Password".
[0096] Then, it is determined through steps S701 and S702 that the operating system is operating in FIPS140 mode, and when confirming the FIPS140 version in step S703, the SHA1 hash calculation in Figure 7B step S709 is performed.
[0097] Since Windows is operating in FIPS140-3 mode, SHA1 is an inoperable algorithm, and an exception (error) occurs in the SHA1 hash calculation. Therefore, through steps S710 and S712, it is determined that the operating system is operating in FIPS140-3 mode.
[0098] Thereafter, the "Authentication Algorithm" of FIPS140-3 is displayed in steps S704 and S705. Figure 8A is a diagram showing an example of the display of the "Authentication Algorithm" of FIPS140-3. As Figure 8A shown by 801 in
[0099] By selecting one of the listed algorithms and then adding the selected algorithm to the device communication settings screen, the communication settings with the device shown in Figure 6C are stored in step S706.
[0100] When Windows operates in FIPS140-2 mode, no exception (error) occurs in the SHA1 hash calculation in step S709, so it is determined that the operating system operates in FIPS140-2 mode. Through steps S704 and S708, the "authentication algorithm" of FIPS140-2 is displayed.
[0101] Figure 8B FIG. is a display example showing the "authentication algorithm" of FIPS140-2. As shown at 802 in Figure 8B , through the process of step S713, SHA1 / HA2-256 / SHA2-384 / SHA2-512 are listed.
[0102] Similarly, by selecting one of the listed algorithms and then adding the selected algorithm to the device communication settings screen, the communication settings with the device shown in Figure 6C are stored in step S706. As described above, according to the present embodiment, when setting the operation of the FIPS140-3 version through the above series of operations, SHA1 can be excluded from the selection display.
[0103] <Second Embodiment>
[0104] In the second embodiment, when updating device information to exclude SHA1 by setting based on a pre-stored algorithm in the FIPS operation mode, it is assumed that the FIPS version is updated due to an update of Windows or the device, etc. Then, an icon or a warning is displayed to prompt the user to switch to the communication settings screen.
[0105] Figure 9 FIG. is a flowchart showing an example of a processing flow in the device management method according to the second embodiment. The processing flow shown is implemented by causing the CPU 10 of a computer to execute device management software stored in a memory as a storage medium. Figure 9 shown.
[0106] Similar to the first embodiment, it is assumed that the communication with the device is set as shown in Figure 6C . It is also assumed that the device has been searched and managed (as shown in the device list display screen of Figure 5 ), and periodic device updates have been set.
[0107] When the device list shown in Figure 5 is displayed, the processing flow shown in Figure 9 starts. InFigure 9 In step S901, the device connection unit 311 obtains the system encryption settings. In step S902, the device connection unit 311 determines whether the device management system is in the FIPS140 mode based on the information obtained in step S901.
[0108] When the determination result of step S902 is "yes", the processing flow proceeds to step S903. When the determination result of step S902 is "no", Figure 9 the processing flow shown ends, and the device list display screen continues to be displayed. Assume Figure 9 that the processing of steps S901 to S908 is periodically repeated.
[0109] In step S903, the device connection unit 311 selects the target device for which the icon and warning are to be displayed according to the user's operation. Here, step S903 serves as a device selection step (device selection unit) for selecting the target device.
[0110] In step S904, the device connection unit 311 determines whether an SHA1 exception has occurred in the target device selected in step S903. Here, step S904 serves as an exception determination step (exception determination unit) for determining whether an SHA1 exception has occurred in the target device.
[0111] When the determination result of step S903 is "yes", the processing flow proceeds to step S905. When the determination result of step S903 is "no", Figure 9 the processing flow shown ends, and the device list screen continues to be displayed.
[0112] In step S905, the device display unit 301 displays the icon. In step S906, the device display unit 301 determines whether the cursor is placed on the icon displayed in step S905.
[0113] When the determination result of step S906 is "yes", the processing flow proceeds to step S907. When the determination result of step S906 is "no", Figure 9 the processing flow shown ends, and the device list screen continues to be displayed. In step S907, the device display unit 301 displays a warning message. In step S908, the device display unit 301 displays a link to the "certification information details screen".
[0114] The following will refer to Figure 5 、 Figures 6A to 6C and Figure 10 to supplement the description of the operation according to the second embodiment shown in Figure 9 shown. Assume as Figure 6CSet the SNMPv3 communication settings as shown. Assume that the operating system has been operating in FIPS 140-2 mode before this, and set SHA1 as its authentication algorithm. Also assume that the search and management devices (such as Figure 5 in the device list display screen shown), and set regular device updates.
[0115] In Figure 9 steps S901 and S902, it is determined that the operating system is operating in FIPS 140 mode. And for example, assume that in step S903, device 2 in Figure 5 is selected. Then, in step S904, it is determined whether a SHA1 exception has occurred.
[0116] Here, assume that an exception has occurred. Then, in step S905, an icon is displayed. This example is as Figure 10 shown. For example, an icon "!" is displayed at the right end of the row of device 2.
[0117] In step S906, it is determined whether the cursor is placed on the icon. Here, assume that the user moves the cursor to the icon. Then, the determination result of step S906 is "yes".
[0118] Then, in step S907, a warning message is displayed. That is, as Figure 10 shown, for example, a message 1001 such as "SHA1 algorithm error. The FIPS version may have been updated." is displayed below the icon of device 2.
[0119] In step S908, as Figure 10 shown in message 1001, a link to the "authentication information details screen" is displayed, and by clicking on this link, the screen changes to the Figure 6B 、 Figure 8A and Figure 8B shown "authentication information details" screen (authentication information setting screen). Then, the setting of the authentication algorithm can be changed.
[0120] Here, steps S904 to S908 are used as a notification step (notification unit) to notify the user when it is determined in the exception determination step (exception determination unit) that a SHA1 exception has occurred. The notification unit only needs to display at least one of an icon, a warning, and a link to the authentication information setting screen.
[0121] In the second embodiment, when excluding SHA1 by updating device information based on the pre-stored algorithm settings through this processing flow, assume that the FIPS version is updated due to an update of Windows or the device, etc. Then, an icon or a warning is displayed to prompt the user to change to the communication settings screen.
[0122] As described above, according to the first embodiment, it is possible to prevent an algorithm that cannot operate in a Windows environment corresponding to FIPS140-3 from being set. According to the second embodiment, when the update of device information based on a pre-stored algorithm setting fails, it is possible to determine that the corresponding FIPS version has been updated due to an update of Windows or the device, etc., and prompt the user to correct the authentication information.
[0123] <Other Embodiments>
[0124] The present invention can be applied to a system including multiple devices (such as a host, an interface device, a reader, and a printer), or can be applied to a single complex machine (such as a multifunction peripheral device of a copier and a fax device).
[0125] The present invention can also be implemented by providing a recording medium storing program codes for implementing the functions according to the above embodiments to a system or a device, and causing a computer of the system or the device to read and execute the program codes stored in the storage medium.
[0126] In this case, the program codes read from the storage medium implement the functions according to the above embodiments, and the program codes and the storage medium storing the program codes constitute the present invention.
[0127] The present invention includes the following situation: an operating system (OS) operating in a computer performs part or all of the actual processing according to the instructions of the program codes, and implements the functions according to the above embodiments through these processes.
[0128] The present invention is also applied to the following situation: the program codes read from the storage medium are written into a function expansion card inserted into a computer or a memory included in a function expansion unit connected to the computer.
[0129] In this case, a CPU, etc. provided in the function expansion card or the function expansion unit can perform part or all of the actual processing according to the instructions of the written program codes, and can implement the functions according to the above embodiments through these processes.
[0130] Although the present invention has been described with reference to exemplary embodiments, it should be understood that the present invention is not limited to the disclosed exemplary embodiments. The scope of the appended claims should be given the broadest interpretation to cover all such variations and equivalent structures and functions.
[0131] In addition, as part or all of the control according to the embodiments, a computer program for implementing the functions of the above embodiments can be provided to an information processing device, etc. through a network or various storage media. Then, a computer (or a CPU, an MPU, etc.) of the information processing device, etc. can be configured to read and execute the program. In this case, the program and the storage medium storing the program constitute the present invention.
[0132] In addition, the present invention includes functions implemented using at least one processor or circuit configured to perform the functions of the above embodiments. For example, multiple processors can be used for distributed processing to perform the functions of the above embodiments.
[0133] This application claims priority to Japanese Patent Application No. 2024-001956, filed on January 10, 2024, the entire content of which is incorporated herein by reference.
Claims
1. An information processing apparatus, in which an operating system and an application for managing information of a network device are executed, the information processing apparatus comprising: a providing unit that causes the application to perform processing for providing a plurality of selections for an algorithm for encrypted communication; and a setting unit that causes the application to set the algorithm selected in response to the providing as a communication setting with the network device, wherein a combination of the plurality of selections provided in the processing performed by the application is different between when the operating system is not operating in the FIPS140 mode and when the operating system is operating in the FIPS140 mode of FIPS 140-3.
2. The information processing apparatus according to claim 1, wherein, When the operating system is operating in the FIPS140 mode of FIPS 140-3, the plurality of selections provided in the processing performed by the application do not include SHA1, and wherein when the operating system is not operating in the FIPS140 mode of FIPS 140-3, the plurality of selections provided in the processing performed by the application include SHA1.
3. The information processing apparatus according to claim 2, wherein, When the operating system is operating in the FIPS140 mode of FIPS 140-3, the plurality of selections provided in the processing performed by the application include at least two of SHA2-256, SHA2-384, and SHA2-512.
4. The information processing apparatus according to claim 1, wherein A case where the operating system is not operating in the FIPS140 mode of FIPS 140-3 includes a case where the operating system is operating in the FIPS140 mode of FIPS 140-2.
5. The information processing apparatus according to claim 4, wherein, When the operating system is operating in the FIPS140 mode of FIPS 140-2, in addition to SHA1, the plurality of selections provided in the processing performed by the application further include at least one of SHA2-256, SHA2-384, and SHA2-512.
6. The information processing apparatus according to claim 1, wherein, The information processing apparatus causes the application to determine whether the operating system is operating in the FIPS140 mode of FIPS 140-3, and wherein when an exception occurs during processing of a predetermined algorithm using a library of the operating system, it is determined that the operating system is operating in the FIPS140 mode of FIPS 140-3.
7. A method performed by an information processing apparatus, in which an operating system and an application for managing information of a network device are executed, the method comprising the steps of: causing the application to perform processing for providing a plurality of selections for an algorithm for encrypted communication; and causing the application to set the algorithm selected in response to the providing as a communication setting with the network device, wherein a combination of the plurality of selections provided in the processing performed by the application is different between when the operating system is not operating in the FIPS140 mode and when the operating system is operating in the FIPS140 mode of FIPS 140-3.
8. A computer program product comprising a computer program for controlling an information processing device, in which an operating system and an application for managing information of a network device are executed, the computer program comprising instructions for performing the following processing: causing the application to perform processing for providing a plurality of selections for an algorithm for encrypted communication; and causing the application to set the algorithm selected in response to the provision as a communication setting with the network device, Among them, wherein a combination of the plurality of selections provided in the processing performed by the application is different between when the operating system is not operating in the FIPS 140 mode and when the operating system is operating in the FIPS 140 mode of FIPS 140-3.
Citation Information
Patent Citations
Image processing apparatus, image processing system and program
JP2019029879A
Electrolyzed water generator and electrolyzed water generation method
JP2024001956A