Information processing apparatus, method for controlling information processing apparatus, and program
Patent Information
- Application Number
- JP2022085058
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-05-25
- Publication Date
- 2025-05-21
- Estimated Expiration
- 2042-05-25
AI Technical Summary
Existing information processing devices struggle with inappropriate batch settings due to user inability to select the correct usage environment or changes in the environment after selection, leading to potential security vulnerabilities.
An information processing apparatus that includes a reception mechanism for setting changes and a display control to recommend batch settings based on predetermined values associated with the selected usage environment, ensuring compatible security settings are applied.
Facilitates appropriate batch settings by displaying recommendations for security configurations tailored to the device's usage environment, enhancing security and reducing vulnerabilities.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device that performs settings for a plurality of setting items all at once. [Background technology]
[0002] Generally, information processing devices have a setting function that performs various settings based on user operations. Information processing devices are now installed in a variety of environments, such as telecommuting and public spaces shared by an unspecified number of people, and the required settings are becoming more complex. Therefore, Patent Document 1 discloses a technology that diagnoses the settings based on a diagnostic policy that matches the characteristics of the management classification of the information processing device in order to respond to changes in the usage environment. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-095631 Summary of the Invention [Problem to be solved by the invention]
[0004] There are technologies that assist users in configuring information processing devices to suit their operating environments. For example, a system may be provided that allows a user to select an operating environment for the information processing device, and then collectively changes the settings of the information processing device to settings suitable for the selected operating environment. However, there are cases where such a system does not appropriately configure the settings. For example, this may be due to the user being unable to appropriately select the operating environment for the information processing device, or the operating environment changing after the selection.
[0005] An object of the present invention is to provide a mechanism for displaying a recommendation for batch setting based on a setting change made by a user to an information processing device. [Means for solving the problem]
[0006] In order to achieve the above object, the information processing device of the present invention has a reception means for receiving information indicating an instruction to change a setting value corresponding to a setting item of the information processing device, and a display control means for displaying a display recommending a batch setting of a group of setting values for multiple setting items of the information processing device when the changed setting value indicated by the information received by the reception means is a predetermined value, and the predetermined value is associated with the group of setting values. [Effects of the Invention]
[0007] The image processing device according to the present invention can provide a mechanism for displaying a recommendation for batch setting based on a setting change made by a user to the information processing device. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a usage environment of an information processing device. [Figure 2] 10 is a flowchart showing an example of conditions for classifying the usage environment of an information processing device. [Figure 3] FIG. 2 is a diagram illustrating an example of the hardware configuration of an MFP 101. [Figure 4] FIG. 2 is a diagram illustrating an example of the software configuration of an MFP 101. [Figure 5] FIG. 2 is a diagram showing an example of a screen displayed on an operation unit 320 of an MFP 101 in the first embodiment. [Figure 6] FIG. 2 is a diagram showing an example of a screen displayed on an operation unit 320 of an MFP 101 in the first embodiment. [Figure 7] 10 is a flowchart illustrating an example of security setting processing executed by the MFP 101. [Figure 8] 10 is a flowchart illustrating an example of security setting processing executed by the MFP 101. [Figure 9] FIG. 10 shows an example of a screen displayed on an operation unit 320 of an MFP 101 in a modified example. DETAILED DESCRIPTION OF THE INVENTION
[0009] The following describes embodiments of the present invention with reference to the drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0010] First Embodiment 1 is a network configuration diagram illustrating an example of a usage environment of an information processing device according to an embodiment of the present invention. MFPs 101 to 104, which are examples of information processing devices according to this embodiment, are installed in different usage environments 111 to 114. The usage environments 111 to 114 illustrated in FIG. 1 are an in-house intranet environment 111, a direct internet connection environment 112, an internet-prohibited environment 113, and a home environment 114, respectively.
[0011] The company intra environment 111 is an environment in which an MFP 101 and a PC 121 are connected via an in-company LAN (Local Area Network) 131. A firewall 141 is installed at the boundary between the LAN 131 and the Internet 100. That is, communication between each information processing device in the company intra environment 111 and the Internet 100 is monitored and protected by the firewall 141. Therefore, in the company intra environment 111, threats such as access to each information processing device by an attacker from the Internet 100 are greatly reduced.
[0012] On the other hand, no firewall is installed in the direct internet connection environment 112. The direct internet connection environment 112 is an environment in which the MFP 102 and the PC 122 are directly connected to the Internet 100 and perform communication. Therefore, the information processing devices such as the MFP 102 and the PC 122 need to take measures against threats such as access by attackers from the Internet 100, for example, by using a personal firewall function within each information processing device.
[0013] The internet prohibited environment 113 is a closed network environment isolated from other networks such as the internet 100. Information processing devices such as the MFP 103 and the PC 123 are connected via a LAN 133. In the internet prohibited environment 113, network communication is possible only between the information processing devices installed on the LAN 133. The information processing devices cannot be accessed by unspecified users on the internet 100.
[0014] The home environment 114 is an environment in which the MFP 104 and the PC 124 are connected via a home LAN 134. The LAN 134 is a private network configured with a home router 144, but does not have security measures such as a strong firewall like the company intranet environment 111. Therefore, like the direct internet connection environment 112, the information processing devices installed in the home environment 114 need to take measures against threats such as access by attackers from the Internet 100, such as by using a personal firewall function within each information processing device.
[0015] It is assumed that the company intranet environment 111, the direct internet connection environment 112, and the internet-prohibited environment 113 have sufficient physical security measures in place, such as facility entry management, to restrict physical access to each environment. In other words, it is assumed that users can be identified. In addition, as environments not shown, a public space environment, which is an environment in which network users are not identified like the home environment 114, and a highly confidential management environment requiring the protection of highly confidential information are also envisioned. The classification of each environment will be described in detail using FIG. 2.
[0016] In this embodiment, the usage environment of an information processing device is classified into six categories, and appropriate security settings are provided for each category. FIG. 2 is a flowchart illustrating the concept of classification when classifying and defining usage environments. Note that the following definitions of usage environments do not limit the present invention, and some or other usage environments exemplified in this embodiment may be defined. For example, assuming installation within a company, usage environments may be classified by industry, such as finance or government agencies.
[0017] In this embodiment, the usage environment of the information processing device is classified into six types based on the characteristics for classifying the usage environment exemplified in steps S201 to S205. Furthermore, a set of security countermeasure settings to be applied to each usage environment is defined in advance based on threats that can occur in the usage environment, which are predicted from the characteristics of the usage environment. This definition will be described later.
[0018] S201 is a classification of whether the environment handles highly confidential information. An environment that handles highly confidential information can be said to be an environment in which security measures must be given the highest priority. Hereinafter, in this embodiment, an environment in which security measures must be given the highest priority is defined as a highly confidential information management type.
[0019] In environments other than those handling highly confidential information, the classification of usage environments is further subdivided. As shown in S202, the usage environment is classified based on user accessibility to the device. That is, the classification of usage environments is subdivided based on whether or not unspecified users can physically access the information processing device. In this embodiment, S202 classifies the environment based on whether or not it is an entry-controlled environment. This is an example of classification based on whether or not users are restricted from entering the location where the information processing device is installed. Therefore, the classification criterion of physical accessibility is not limited to this embodiment, and conditions other than entry control may also be used as classification conditions. Furthermore, the entry control in this embodiment is not limited to a card-based access / exit system. For example, an entry-controlled environment also includes an environment in which only people belonging to an organization work during business hours, limiting the number of people who can actually enter, and the door is locked outside of business hours.
[0020] When entry control is not performed, i.e., when unspecified users can physically access the information processing device, the usage environment is subdivided according to the classification criteria shown in S205. S205 classifies the environment based on whether unspecified users share and use the network within the environment. In this embodiment, an environment in which an information processing device is installed in a location where typical entry control is not performed and unspecified users share and use the network within the environment is defined as a public space type. In addition, an environment in which typical entry control is not performed and unspecified users do not share the network within the environment is defined as a home type. Note that a difference in network configuration between the home type and the public space type is whether the network on which the information processing device is installed is shared and used by an unspecified number of users. In this embodiment, an environment in which unspecified users do not share the network within the environment, such as the home type, i.e., an environment in which users can be identified, is defined as a private network environment. In other words, in this embodiment, the home type is a private network environment, and the public space type is not a private network environment.
[0021] Next, the classification of usage environments having accessibility characteristics such as entry control will be described. A usage environment classified as entry controlled in S202 is further subdivided according to the classification conditions shown in S203. S203 classifies the environment based on whether or not the information processing device in the environment is connected to an external network such as the Internet. An environment that is not connected to an external network such as the Internet is defined as an Internet-prohibited type. Note that an Internet-prohibited type that is entry controlled and is based on a closed network is a private network environment.
[0022] If the information processing devices in the environment are connected to an external network such as the Internet, the usage environment is further subdivided according to the classification conditions shown in S204. S204 classifies the environment based on whether or not a firewall is installed. An environment in which a firewall is installed is defined as an in-house intranet type. An environment in which a firewall is not installed is defined as an internet direct connection type. The in-house intranet type, in which users who use the network within the environment can be restricted by a firewall, is a private network environment.
[0023] Next, Table 1 shows the six usage environments classified based on the concept of Figure 2, along with examples of security measures that should be taken for each usage environment.
[0024] [Table 1]
[0025] As shown in Table 1, the policies for security measures to be taken for information processing devices vary greatly depending on the usage environment. In this embodiment, specific settings that should be made are defined based on the policies for security measures to be taken for each environment shown in Table 1, and are summarized in Table 2. Below, the reasons why each security measure is recommended will be described using Table 2.
[0026] [Table 2]
[0027] Communication path encryption is a security measure that prevents information leakage by encrypting communication content on a network. Transport Layer Security (TLS) is an example of a function that realizes communication path encryption. In an environment connected to the Internet, it is desirable to encrypt the communication path because there is a possibility that a third party may eavesdrop on the communication content. In other words, it is recommended to encrypt the communication path except in an Internet-prohibited environment 113.
[0028] Disabling legacy protocols is a security measure to prevent spoofing and information leakage by disabling functions that use insecure legacy communication protocols. An example of a legacy protocol is WINS (Windows Internet Name Service). As with encryption of communication paths, disabling legacy protocols is also desirable in environments connected to external networks such as the Internet. In other words, disabling legacy protocols is recommended except for Internet-prohibited environments 113.
[0029] A personal firewall is a firewall installed and used on an information processing device. Like a typical firewall, it monitors communication between the information processing device and external networks such as the Internet. Examples of firewalls include IP filters and port number filters. IP filters are a security measure that reads the destination and source information of communication packets and allows only pre-defined communication packets. This prevents unauthorized access and information leakage. Port number filters are a security measure that closes unused ports to prevent intrusion through those ports. This prevents DoS (Denial of Service), a cyber attack that creates vulnerabilities by imposing a large load. In environments connected to external networks but without a firewall, it is desirable to enable a personal firewall due to the possibility of information leakage and DoS. In other words, enabling a personal firewall is recommended except for Internet-prohibited environments 113 not connected to external networks and intranet environments 111 where a firewall is installed.
[0030] Strengthening the security of authentication means strengthening measures against spoofing, for example, by prohibiting password caching, specifying the minimum number of characters for passwords, etc. Except for the Internet-prohibited environment 113 connected within an isolated network, it is desirable to strengthen the security of authentication because there is a possibility of spoofing.
[0031] Countermeasures against physical attacks are security measures to prevent physical information leakage. In the MFPs 101 to 104, temporary data such as print jobs is generated on the hard disk. Each MFP is equipped with a complete erasure function that automatically and completely erases the generated temporary data upon job completion. The complete erasure function described above is an example of a countermeasure against physical attacks for the MFPs 101 to 104. With this function enabled, temporary data cannot be read even if the hard disk is physically removed. It is desirable to implement countermeasures against physical attacks in the home environment 114 and the public space environment 115, which are environments where entry management is not performed and physical access to information processing devices cannot be restricted. It is also desirable to implement countermeasures against physical attacks in the highly confidential information management environment 116, where reducing the risk of information leakage is given top priority.
[0032] The file sharing function is a function for sharing files over a network within an environment. In an environment where unspecified users share the network within the environment, it is desirable to disable the file sharing function to prevent information leakage. That is, it is recommended to disable the file sharing function except for private network environments where specific users share the network within the environment. As described above, the private network environments in this embodiment are the company intranet environment 111, the internet-prohibited environment 113, and the home environment 114. Therefore, it is recommended to disable the file sharing function in the other environments, namely the direct internet connection environment 112, the public space environment 115, and the highly confidential information management environment 116. Note that an example of settings related to the file sharing function is SMB (Server Message Block) server settings.
[0033] Disabling an external storage device means, for example, setting a USB (Universal Serial Base) storage device so that it cannot be used as an external storage device by an information processing device. This prevents information from being written to the external storage device, preventing information leakage. It also prevents computer virus infection via the USB storage device and the resulting information leakage. The threat of information leakage through external storage devices such as USBs is common to all installation environments. Therefore, it is desirable to disable them in all installation environments.
[0034] In this embodiment, a mechanism is provided in which recommended setting data defined based on the above-described concept is stored in an information processing device, and appropriate recommended setting data is reflected when a usage environment is selected.
[0035] The hardware configuration of MFP 101, which is an example of an information processing device in this embodiment, will be described with reference to Fig. 3. Note that while only MFP 101 will be described in Fig. 3, MFPs 102 to 104 and MFPs installed in public space environments and highly confidential information management environments (not shown) are also assumed to have the same configuration as MFP 101.
[0036] The MFP 101 includes a printer 330 that outputs electronic data to paper media and a scanner 340 that reads paper media and converts it into electronic data. In this embodiment, the MFP 101 has multiple functions as an example of an information processing device, but is not limited to this. For example, the MFP 101 may be an image processing device equipped with a single-function printer or scanner. It may also be a device such as a 3D printer or 3D scanner.
[0037] A control unit 310 including a CPU (Central Processing Unit) 311 controls the overall operation of the MFP 101. A ROM (Read Only Memory) 312 is used to store programs executed by the CPU 311. The CPU 311 reads out control programs stored in the ROM 312 and performs various controls of the MFP 101, such as reading control and transmission control. A RAM (Random Access Memory) 313 is used as a temporary storage area such as the main memory and work area of the CPU 311. A HDD (Hard Disk Drive) 314 is a storage device that stores image data, various programs, and various setting information. Note that other storage devices such as an SSD (Solid State Drive) may also be provided. In this way, the hardware such as the CPU 311, ROM 312, RAM 313, and HDD 314 constitute a so-called computer.
[0038] An operation unit I / F (interface) 315 connects an operation unit 320 and the control unit 310. The operation unit 320 is equipped with a liquid crystal display unit with a touch panel function, various hard keys, etc. The operation unit 320 functions as a display unit that displays information to the user and a reception unit that receives instructions from the user.
[0039] The printer I / F 316 connects the printer 330 and the control unit 310. Image data to be printed by the printer 330 is transferred from the control unit 310 via the printer I / F 316. The input image data is output onto a recording medium in the printer 330. The scanner I / F 317 connects the scanner 340 and the control unit 310. The scanner 340 reads an original placed on an original platen (not shown) and generates image data. The generated image data is input to the control unit 310 via the scanner I / F 317.
[0040] A network cable is connected to the network I / F 318, and it is possible to communicate with an external device on the LAN 131. In this embodiment, it is assumed that the network I / F 318 is a communication interface that performs wired communication, but this is not limited to this. For example, it may be a wireless communication interface. Note that the network I / F 318 of the MFP 101 is connected to the LAN 131, but the network to which it is connected varies depending on the installation environment. For example, the MFP 102 is directly connected to the Internet 100. The MFPs 103 and 104 are connected to the LANs 133 and 134, respectively.
[0041] The software configuration of the MFP 101 will be described with reference to Fig. 4. Each unit shown in Fig. 4 is realized by the CPU 311 executing a program according to the present invention stored in the ROM 312.
[0042] The operation control unit 401 displays a screen for the user on the operation unit 320. It also detects user operations and switches the screen or updates the display based on the detection result.
[0043] The data storage unit 402 stores data in the HDD 314 and reads data from the HDD 314 in response to requests from other control units. For example, if a user wants to change some device setting, the operation control unit 401 detects the content input by the user to the operation unit 320, and in response to a request from the operation control unit 401, the data storage unit 402 saves the content as a setting value in the HDD 314. The data storage unit 402 stores information related to settings in addition to setting information for determining the operation of the MFP 101. Specifically, it stores user setting data and recommended setting data. The data storage unit 402 also stores a database for estimating the environment, which will be described later.
[0044] The user setting data is setting information for determining the operation of the MFP 101 that can be set by the user via the operation unit 320. Each program on the MFP 101 provides various functions by operating based on the setting values of the user setting data.
[0045] The recommended setting data is a set of setting values recommended for each usage environment. When a user selects a usage environment, information on multiple setting values managed in the recommended setting data is overwritten on the user setting data, enabling the MFP 101 to operate with the settings recommended for that usage environment. Table 3 shows an example of recommended setting data in this embodiment. The recommended setting data associates multiple setting items with multiple setting values corresponding to the multiple setting items and the usage environment. The setting values are set to values appropriate for each usage environment. In this embodiment, the setting items refer to items such as TLS settings and WINS settings in Table 3. The setting values refer to values indicated as "on," "off," "reject," etc. in Table 3. In Table 3, the diagonal lines indicate that the item does not have a recommended setting value. In other words, when a usage environment is selected and batch settings are performed, the setting values in the user setting data for the setting item are not changed, and the setting values before the setting change are retained. For example, the TLS setting is set to on in environments other than the Internet-prohibited type, but is not changed in the Internet-prohibited type, maintaining the original setting value. In this embodiment, the recommended setting data is defined in advance by the vendor of the MFP 101 and stored in the data storage unit 402 .
[0046] [Table 3]
[0047] Returning to the explanation of Figure 4, the job control unit 403 controls job execution in accordance with instructions from the other control units. The image processing unit 404 processes image data into a format suitable for each application in accordance with instructions from the job control unit 403. The print processing unit 405 prints and outputs an image on paper media via the printer I / F 316 in accordance with instructions from the job control unit 403. The read control unit 406 reads a placed document via the scanner I / F 317 in accordance with instructions from the job control unit 403. The network control unit 407 sets network settings such as an IP address in the TCP / IP control unit 408 at system startup or when a setting change is detected, in accordance with setting values stored in the data storage unit 402. The TCP / IP control unit 408 performs network packet transmission and reception processing via the network I / F 318 in accordance with instructions from other control units.
[0048] The security setting control unit 409 performs collective setting of the security functions of the MFP 101 in accordance with instructions from the user detected by the operation control unit 401. After managing the correspondence between usage environments such as an internal LAN, home, or public space and the corresponding security-related setting items, the corresponding security-related settings can be set in a collective manner when the user specifies the usage environment. The security setting control unit 409 uses the data storage unit 402 to refer to and change setting values. Specific control will be described later with reference to FIG. 8. Note that the collective setting in this embodiment is a function that can collective set recommended setting values for typical security functions defined by a vendor. It is different in nature from a function that applies a security policy edited by the user and prohibits changing the settings for specific security setting items to settings that do not comply with the policy.
[0049] Next, screens displayed on the operation unit 320 of the MFP 101 will be described with reference to FIGS. 5 and 6. A screen 500 shown in FIG. 5 is a recommended security settings screen 500 that the operation control unit 401 displays on the operation unit 320. When a user performs an operation to display the screen 500 on a menu screen (not shown), the operation control unit 401 detects the operation and displays the screen 500. The environment list 501 is a list that allows the user to select a usage environment for the MFP 101. In this embodiment, the user selects from the six usage environment options shown in FIG. 2. The operation control unit 401 of the MFP 101 detects the user's operation and transmits information indicating the user's selection to the security setting control unit 409. The security setting control unit 409 collectively configures security functions suitable for the usage environments selected by the user, as received from the operation control unit 401. Thus, the user can collectively configure recommended security settings for each usage environment by selecting the usage environment for the MFP 101 from the list 501 and pressing an execute button 503. The cancel button 502 is a button that the user can use to cancel the recommended security settings. When the operation control unit 401 detects that the user has pressed the cancel button 502, it displays a menu screen (not shown) on the operation unit 320.
[0050] A screen 600 shown in FIG. 6(a) is a recommended environment type change proposal screen 600 that the operation control unit 401 displays on the operation unit 320. The screen 600 is a screen for proposing to the user a recommended environment type determined based on a setting change made by the user in the processing of FIG. 8 described later, and for receiving an instruction from the user as to whether or not to change the environment type for batch setting. The screen 600 has a Yes button 601 and a No button 602. The operation control unit 401 receives information indicating the user's selection of the Yes button 601 or the No button 602. The operation control unit 401 then transmits information indicating the user's selection to the security setting control unit 409. When the security setting control unit 409 receives information from the operation control unit 401 that the user has selected the Yes button 601, the security setting control unit 409 performs batch setting of security functions suitable for the usage environment recommended on the screen 600. When the security setting control unit 409 receives information that the user has selected the No button 602, the security setting control unit 409 does not perform the setting.
[0051] A screen 610 shown in FIG. 6(b) is a setting change confirmation screen 610 that the operation control unit 410 displays on the operation unit 320. The screen 610 is a screen for confirming whether to change the settings even if the changes made by the user do not match the current environment type when the user changes the settings. In this embodiment, the screen 610 is displayed when the No button 602 is selected on the screen 600. The screen 610 has a Yes button 611 and a No button 612. The operation control unit 401 accepts information indicating the user's selection of the Yes button 611 or the No button 612. The operation control unit 401 then transmits information indicating the user's selection to the security setting control unit 409. When the security setting control unit 409 receives information from the operation control unit 401 that the user has selected the Yes button 611, the security setting control unit 409 changes the settings. When the security setting control unit 409 receives information that the user has selected the No button 612, the security setting control unit 409 does not change the settings.
[0052] In the present embodiment, the screens 500, 600, and 610 are configured to be displayed on the operation unit 320 of the MFP 101, but the present invention is not limited to this. For example, the same screens can be displayed on a web browser of an external information processing device via a web server (not shown) that the MFP 101 has, and operations can be performed via the web browser.
[0053] Next, the process from when the user selects the usage environment on screen 500 until the collective setting of security functions is performed will be described with reference to Fig. 7. Then, the process in which MFP 101 proposes a change of the environment type based on a setting change made by the user will be described with reference to Fig. 8. Each operation (step) shown in the flowcharts of Fig. 7 and 8 is realized by CPU 311 calling into RAM 313 a program for realizing each control unit stored in ROM 312 or HDD 314 and executing the program.
[0054] 7 starts when the user performs an operation to display screen 500 on a menu screen (not shown) displayed on the operation unit 320 and the operation control unit 401 detects this operation. In S701, the operation control unit 401 displays screen 500 on the operation unit 320. In S702, when the operation control unit 401 detects that the user has selected a usage environment from the list 501 and pressed the execute button 503, the operation control unit 401 transmits information indicating the user's selection to the security setting control unit 409, and the process proceeds to S703. Otherwise, when the operation control unit 401 detects that the user has pressed the cancel button 502, the operation control unit 401 displays a menu screen (not shown) on the operation unit 320 and ends this flow. If the operation control unit 401 does not detect that the cancel button 502 has been pressed, the process returns to S702.
[0055] In S703, the security setting control unit 409 reads out recommended setting data corresponding to the usage environment selected by the user from the data storage unit 402 based on the information received from the operation control unit 401. Then, the process proceeds to S704, where the read recommended setting data is overwritten on the user setting data. By the above processing, when the user selects a usage environment on the screen 500, setting values of security functions suited to that usage environment are collectively set in the MFP 101.
[0056] In S702, when the user selects a usage environment on screen 500, a program that executes the flowchart shown in Fig. 8 is activated. In S801, the operation control unit 401 waits until it receives information indicating an instruction to change a setting value corresponding to a setting item of the MFP 101 from the user, and if it receives information indicating an instruction to change a setting value, it notifies the security setting control unit 409. The security setting control unit 409 that has received the notification executes S802. Note that the setting change in S801 may be a change to a setting value corresponding to a setting item included in the recommended setting data described above, among the setting items of the MFP 101. Alternatively, a setting value corresponding to a setting item determined by the user or the vendor may be changed.
[0057] In S802, the security setting control unit 409 determines whether the setting changes instructed by the user in S801 are compatible with the current environment type. The current environment type refers to the environment type selected in S702. Information about the current environment type is applied to the user setting data in S704 and then saved in the data storage unit 402. In S802, the saved information about the current environment type is read from the data storage unit 402 and used for the determination.
[0058] Table 4 shows a data table for determining whether the changed setting values specified by the user are compatible with the current environment type. The data table shown in Table 4 is stored in the data storage unit 402. Table 4 is a data table in which the current environment type, the proposed environment type, and predetermined setting values corresponding to predetermined setting items are stored in association with each other. In Table 4, the predetermined setting items are shown in "corresponding setting examples," and the predetermined setting values are shown in "setting change cases." If the changed setting values specified by the user match the predetermined setting values associated with the current environment type, the security setting control unit 409 determines that the changed setting values are not compatible with the current environment type.
[0059] The security setting control unit 409 also uses Table 4 to determine the recommended environment type in S803. If the changed setting value matches a predetermined setting value, the security setting control unit 409 presumes that the proposed environment type stored in association with the predetermined setting value is the recommended environment type. The following describes the processes performed in S802 and S803 for each current type.
[0060] In S802, the security settings control unit 409 performs the following check if the current environment type is the Internet prohibition type. If the setting value instructed by the user to be changed is a function configured by the server and client, and a global IP address is specified in the server connection destination setting, it determines that the instructed change may not be compatible with the current environment type, and executes S803. In this case, the security settings control unit 409 recommends an environment type other than the Internet prohibition type in S803. In this case, it is also possible to display the recommended security settings screen 500 in which the Internet prohibition type is not selectable in S804, and have the user set the environment type. Specific examples of settings include connection destination settings for SMB and LDAP (Lightweight Directory Access Protocol) servers.
[0061] In S802, if the current environment type is other than the highly confidential information management type, the security settings control unit 409 performs the following check. If a stronger security setting is enabled, it determines that the setting values requested by the user to be changed may not be compatible with the current environment type, and executes S803. In this case, the security settings control unit 409 sets the highly confidential information management type as the recommended environment type in S803. Examples of stronger security settings include when IPSec (Security Architecture for Internet Protocol) or IEEE802.1X settings are enabled.
[0062] In S802, if the current environment type is other than the Internet prohibition type, the security settings control unit 409 performs the following check. If a command to change the settings to a weaker algorithm is received, it determines that the setting values requested by the user may not be compatible with the current environment type, and executes S803. In this case, the security settings control unit 409 sets the Internet prohibition type as the recommended environment type in S803. An example of a weak algorithm setting is when a protocol that has already been compromised is selected in the settings for a protocol used in TLS, SMB, or the like.
[0063] In S802, the security setting control unit 409 performs the following check if the current environment type is the home type or public space type. If a setting that is thought to be related to entry / exit management is enabled, it determines that the setting value instructed by the user to be changed may not be compatible with the current environment type, and executes S803. In this case, the security setting control unit 409 recommends an environment type other than the home type or public space type in S803. Note that in this case, in S804, the recommended security setting screen 500 may be displayed in which the home type and public space type are not selectable, and the user may set the environment type. Specific examples of settings include settings that are thought to be related to management of use of the image forming apparatus by multiple people, such as card authentication and departmental ID management.
[0064] In S802, if a setting that appears to be due to a change in network configuration or installation location is enabled regardless of the current environment type, the security setting control unit 409 determines that the setting value requested by the user may not be compatible with the current environment type, and executes S803. In this case, the security setting control unit 409 proposes an environment type different from the current environment type in S803. Specific examples of such settings include when a previously unused secondary line is configured or when device location information settings are changed. In this case, the recommended security setting screen 500 may be displayed in S804 to allow the user to set an environment type different from the current one.
[0065] If the above conditions are not met in S802, the security setting control unit 409 determines that the setting changes are compatible with the current environment type, and executes S809.
[0066] As described above, the security setting control unit 409 determines the recommended environment type in S803, and then performs S804.
[0067] [Table 4]
[0068] Returning to the description of FIG. 8, in S804, the security setting control unit 409 performs display control to propose the recommended environment type determined in S803 to the user. Specifically, a recommended environment type change proposal screen 600 is displayed on the operation unit 320, and S805 is performed. The screen 600 displayed in S804 displays a message recommending that a group of setting values suitable for the recommended environment type be set collectively for multiple setting items of the MFP 101. Here, the group of setting values suitable for the recommended environment type refers to the recommended setting data stored in the data storage unit 402 in association with the environment type, as shown in Table 3. In other words, the security setting control unit 409 displays a message recommending that a group of recommended setting data suitable for the recommended environment type associated with the predetermined setting values shown in "Case of setting change" in Table 4 be set collectively.
[0069] In S805, if the operation control unit 401 detects that the user has pressed the Yes button 601 on the screen 600, or if the operation control unit 401 detects that the user has performed an operation to change the environment type to an environment type different from the current one, it determines that the proposal has been accepted and proceeds to S806. On the other hand, if the operation control unit 401 detects that the user has pressed the No button 602 on the screen 600, or if the operation control unit 401 does not detect that the user has performed an operation to change the environment type to an environment type different from the current one, it determines that the proposal has not been accepted and proceeds to S807.
[0070] In S806, the security setting control unit 409 merges the user setting data stored in the data storage unit 402 with the recommended setting data for the environment type determined in S803, and saves the merged setting value in the user setting data. Specifically, the security setting control unit 409 performs a process of overwriting the user setting data with the recommended setting data. If the recommended setting data for a setting item of a security function has a value (corresponding to a case other than the "diagonal line" in Table 3), the setting value of the user setting data is changed to the recommended setting value. If the recommended setting data indicates a blank (corresponding to a case other than the "diagonal line" in Table 3), the setting value of the user setting data remains unchanged. Through the process described above, security is collectively configured based on the recommended setting data.
[0071] Note that the method for determining the user setting data in S806 is not limited to the above-described method. For example, when the operation control unit 401 detects in S702 that the user has selected an environment on the screen 500, the default setting data before the recommended setting data is overwritten is stored in the data storage unit 402. In S806, when the recommended setting data for the environment type to be changed is applied to the user setting data, the default setting data is read from the data storage unit 402. Then, new user setting data may be determined by overwriting the recommended setting data over the default setting data. It is also possible for the user to change the settings of individual setting items. Individual setting changes made by the user may be saved and managed in the data storage unit 402, and the individual setting changes made by the user may be maintained when determining the user setting data in S806.
[0072] In S807, the security setting control unit 409 displays a setting change confirmation screen 610 on the operation unit 320 to confirm whether the setting changes made by the user are not compatible with the current environment type, and then executes S808. Note that if the proposed recommended environment type in S804 is an arbitrary environment type, it may be determined that the setting changes do not affect the current environment type, and this step may be omitted.
[0073] In S808, if the user presses the Yes button 611 on the screen 610, the security setting control unit 409 executes S809, and if the user presses the No button 612, the process ends.
[0074] In S809, the security setting control unit 409 sets the changed setting values instructed by the user in S801 to the user setting data stored in the data storage unit 402.
[0075] Through the above flow, the MFP 101 can assist the user in setting by presenting an appropriate environment type to the user.
[0076] In the above flow, the recommended environment type is estimated in S803 and then proposed to the user in S804. However, S803 can be omitted. That is, it is also possible to configure the system to recommend batch configuration or notify the user of a change in the environment type without estimating the recommended environment type. For example, when a change is made to the secondary line configuration or location information configuration, as shown in the last row of Table 4, the recommended environment type is not specified as a single type, but it is determined that the environment type has changed. Therefore, S804 can be configured to display a message recommending batch configuration or to notify the user that the environment type has changed. Alternatively, if a single recommended environment type cannot be specified as described above, a screen can be displayed that allows the user to select one environment type from candidate environment types. In this case, the environment type selected by the user is set as the recommended environment type, and the system proceeds to S806.
[0077] In this case, the database used in S802 may have a different configuration from that of Table 4. Table 4 is a data table in which the current environment type, the proposed environment type, and predetermined setting values corresponding to predetermined setting items are stored in association with each other. However, it is also possible to store only predetermined setting values such as changes to sub-line settings and location information settings, and when a setting change to the predetermined setting value is made, a display recommending batch setting or a notification that the environment type has changed may be displayed.
[0078] The database used in S802 and S803 may have other configurations. For example, it may be configured to store predetermined setting values and predetermined usage environments in association with each other. If the predetermined setting values match the changed setting values instructed in S801 and are stored in the data storage unit 402, the predetermined usage environment may be estimated to be the recommended environment type. If the recommended environment type is different from the current environment type, a display may be displayed notifying the user of the recommended environment type and recommending that a group of setting values suitable for the recommended environment type be set all at once. Alternatively, if the changed setting values instructed in S801 are setting values included in recommended setting data associated with a usage environment different from the usage environment set in the information processing device, it is also possible to notify the user that the environment type has changed in S804.
[0079] Also, as described above, when the user selects a usage environment on screen 500 in S702, the program that executes the flowchart shown in Fig. 8 becomes active. However, even when no usage environment is selected on screen 500, the program that executes the flowchart shown in Fig. 8 may be active.
[0080] If the setting change accepted in S801 is a setting change accepted by selecting an environment type for batch setting, it is possible to configure so that the processing from S802 onwards is not performed.
[0081] <Second embodiment> In the first embodiment, the processing shown in FIG. 8 is performed by the MFP 101. However, similar processing may be performed by an information processing apparatus other than the MFP 101. For example, the security settings control unit 409 is implemented as an application that can be installed and executed by the information processing apparatus. This application is assumed to be a server application (hereinafter referred to as a server application) that manages network devices such as the MFP 101. By executing the server application on the information processing apparatus, the processing that was performed by the security settings control unit 409 of the MFP 101 in the first embodiment can be realized on the information processing apparatus. Specifically, the security settings control unit of the server application performs the processing described below.
[0082] First, the server application collects information about setting values set in the MFP 101 from the MFP 101. For example, a configuration is possible in which when a setting value of the MFP 101 is changed by a user, the information about the setting value is sent to the server application via a network. Alternatively, a configuration in which the server application periodically collects information about the setting values of the MFP 101 is possible. A device management protocol such as SNMP (Simple Network Management Protocol) is used to collect the setting information from the MFP 101. In this manner, the server application collects information about the setting values of the MFP 101. The collected information about the setting values includes information about setting values after changes instructed by the user and information about the usage environment already set in the MFP 101.
[0083] When the server application receives the setting values of the MFP 101, it executes the process shown in Fig. 8. Note that Fig. 8 was also used in the explanation of the first embodiment, but the subject in this embodiment is different from that in the first embodiment. In S801, the server application receives the setting values after the change instructed by the user from the MFP 101. If the setting values have been received, the process proceeds to S802.
[0084] In S802 to S804, the server application determines whether the setting changes instructed by the user in S801 are compatible with the current environment type, estimates a recommended environment type, and proposes the recommended environment type to the user. In S802 and S803, the server application performs the determination and estimation using a database stored in the server application. This database is the same as the database described using Table 4 in the first embodiment. In S804, the server application provides a screen similar to screen 600. The screen of the server application is provided to a display device connected to the server application itself, a web browser running on an external PC, or the like.
[0085] In S805, the web browser detects that the user has performed an operation on the screen 600 to accept the proposed environment type. When the server application receives information indicating that this operation has been detected, the process proceeds to S806. In S806, the server application transmits recommended setting data suitable for the recommended environment type, which is stored in the server application, to the MFP 101. Having received the recommended setting data, the MFP 101 applies the recommended setting data to the MFP 101.
[0086] In S805, if the server application does not receive information indicating that an operation by the user to accept the proposed environment type has been detected, the process proceeds to S807. In S807, the server application provides a screen similar to screen 610. In S808, the web browser receives from the user an instruction to apply the setting change instructed by the user in S801. If the server application receives information indicating the instruction, the process proceeds to S809. If the server application does not receive the instruction, the process terminates this flow. In S809, the server application transmits information indicating the setting change instruction by the user received in S801 to the MFP 101. Having received the information indicating the setting change instruction, the MFP 101 applies the setting change to the MFP 101.
[0087] As in the first embodiment, the method of estimating the recommended environment type is not limited to the above-described method. In addition, in S804, the recommended environment type may not be displayed, and only a notification that the environment type has changed may be displayed, or only a display recommending batch setting may be displayed.
[0088] Furthermore, in the present embodiment, a configuration has been described in which steps S801 to S809 are performed by a server application, but some steps may also be performed by an information processing device other than the MFP 101. For example, some steps may be implemented by JavaScript on a web browser on an external PC. The web browser on the PC executes JavaScript to inquire of the MFP 101 about information on whether the changed setting values instructed by the user to the MFP 101 are compatible with the already set usage environment, and about information on recommended environment types. The web browser on the PC can then display a recommendation for batch setting on the web browser based on the received information.
[0089] According to the second embodiment, it is possible to perform at least a part of the processing shown in FIG.
[0090] <Modification> In the first embodiment, the screen 600 and the screen 610 shown in Fig. 6 are displayed separately in S804 and S807. However, for example, if the setting is changed to a weak algorithm in S803 while a type other than the Internet prohibition type is set, the screen 900 shown in Fig. 9 may be displayed in S804.
[0091] In S804, the operation control unit 401 displays the following message on the operation unit 320. This message indicates that the changed setting values are not compatible with the current environment type, that a change to an Internet prohibition type is recommended, and that operation should be performed without being connected to the Internet. When the operation control unit 401 detects that the user has pressed button 901, the security setting control unit 409 does not change the setting values to the changed value and ends the processing. When the operation control unit 401 detects that the user has pressed button 902, the security setting control unit 409 performs processing similar to that of S806. Specifically, the recommended setting data suitable for the recommended environment type is merged with the current user setting data and applied to the MFP 101. When the operation control unit 401 detects that the user has pressed button 903, the security setting control unit 409 performs processing similar to that of S809.
[0092] By the above processing, it is possible to receive user instructions by displaying only screen 900, rather than displaying screens 600 and 610 separately, thereby reducing the burden of user operations.
[0093] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of each of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC or FPGA) that realizes one or more functions. [Explanation of symbols]
[0094] 101 MFP 401 Operation control section 402 Data storage unit 409 Security Settings Control Unit
Claims
1. An information processing device, a reception means for receiving an instruction to set a predetermined value in the information processing device; a display control means for performing a display recommending collective setting of a plurality of values corresponding to the predetermined value in the information processing device in response to the instruction being received; An information processing device having the above configuration.
2. Further comprising an estimation means for estimating a usage environment of the information processing device based on the predetermined value, The information processing apparatus according to claim 1 , wherein the display control means further performs a display for notifying the estimated usage environment.
3. The present invention further comprises a setting means for setting a plurality of values corresponding to a selected usage environment in the information processing device in response to the selection of one usage environment from among a plurality of usage environments; The information processing device according to claim 2, characterized in that the display control means, based on the fact that the estimated usage environment is different from the selected usage environment, displays a display notifying the user of the estimated usage environment, and then displays a display recommending collective setting of a plurality of values corresponding to the specified value and corresponding to the estimated usage environment in the information processing device.
4. 4. The information processing apparatus according to claim 2, further comprising a storage unit for storing the predetermined value in association with a predetermined usage environment.
5. The information processing device according to claim 4, characterized in that, upon receiving an instruction to set the specified value, the estimation means estimates that the specified usage environment stored in the storage means in correspondence with the specified value is the usage environment of the information processing device.
6. When information indicating an instruction not to accept the recommendation is received in the display recommending the collective setting, the display control means further displays a display for confirming whether or not to set the predetermined value in the information processing device; The information processing device according to any one of claims 1 to 5, characterized in that, when information indicating an instruction to set the specified value in the information processing device is received in the confirmation display, the specified value is set in the information processing device.
7. 7. The information processing apparatus according to claim 1, wherein the information processing apparatus is an image processing apparatus having at least one of a scanner and a printer.
8. 8. The information processing device according to claim 1, further comprising a providing means for providing a notification indicating that a usage environment of the information processing device has changed based on the specified value in response to receiving an instruction to set the specified value.
9. A method for controlling an information processing device, comprising: a receiving step of receiving an instruction to set a predetermined value in the information processing device; a display control step of displaying a display recommending a batch setting of a plurality of values corresponding to the predetermined value in the information processing device in response to the reception of the instruction; The control method includes:
10. A program for causing a computer to execute the control method according to claim 9.
11. A system including a first information processing device and a second information processing device capable of communicating with the first information processing device via a network, a receiving means for receiving an instruction to set a predetermined value in the first information processing device; a display control means for performing a display recommending collective setting of a plurality of values corresponding to the predetermined value in the first information processing device in response to the instruction received; A system having
12. 12. The system according to claim 11, wherein the second information processing device comprises the display control means.
13. A method for controlling a system including a first information processing apparatus and a second information processing apparatus capable of communicating with the first information processing apparatus via a network, comprising: a receiving step of receiving an instruction to set a predetermined value in the first information processing device; a display control step of displaying a display recommending collective setting of a plurality of values corresponding to the predetermined value in the first information processing device in response to the reception of the instruction; The control method includes:
14. A system including an information processing device, a reception means for receiving an instruction to set a predetermined value in the information processing device; a providing means for providing a notification indicating that the usage environment of the information processing device has changed, based on the fact that the predetermined value instructed to be set by the accepting means is a value included in a plurality of values corresponding to a usage environment different from the usage environment already set in the information processing device; A system having
15. A method for controlling a system including an information processing device, comprising: a receiving step of receiving an instruction to set a predetermined value in the information processing device; a providing step of providing a notification indicating that the usage environment of the information processing device has changed, based on the fact that the predetermined value instructed to be set in the receiving step is a value included in a plurality of values corresponding to a usage environment different from the usage environment already set in the information processing device; The control method includes: