Information processing device, control method for the same, and program
Patent Information
- Application Number
- JP2022093566
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-06-09
- Publication Date
- 2025-06-13
AI Technical Summary
Users are unaware of changes in security-related settings when performing batch settings on information processing devices, leading to potential relaxation or restriction of functions without their knowledge.
An information processing device that allows users to select a usage environment, performs batch settings based on associated setting values, and provides notifications of changes in setting values when switching environments.
Ensures users are informed about function availability changes, preventing unexpected restrictions or relaxations of security measures, thereby enhancing user convenience and control over settings.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device that performs settings for a plurality of setting items all at once. [Background technology]
[0002] Generally, information processing devices have a setting function that performs various settings based on user operations. Information processing devices are now installed in a variety of environments, such as telecommuting and public spaces shared by an unspecified number of people, and the required settings are becoming more complex. Therefore, Patent Document 1 discloses a technology that allows a user to specify a security level from a range of levels, and then collectively configures security-related functions of an image forming device according to the security level. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-185814 Summary of the Invention [Problem to be solved by the invention]
[0004] However, users may not be aware of what changes will occur in the future use of the information processing device when security-related collective settings are automatically performed by selecting a security level, usage environment, etc. For example, some security measures may be relaxed as a result of the collective settings, or some functions may be restricted by enabling some security measures, but the user may not be aware of this.
[0005] An object of the present invention is to provide a notification based on the changes to the setting values when at least some of the setting values are changed by performing batch setting by selecting items associated with the usage environment. [Means for solving the problem]
[0006] In order to achieve the above object, the information processing device of the present invention has a setting means that, when one item is selected from a plurality of items associated with different usage environments, performs collective setting on a plurality of setting items of the information processing device using a group of setting values associated with the usage environment corresponding to the selected item, and a notification means that, when at least some of the setting values of the group of setting values set for the plurality of setting items are changed by the collective setting, provides a notification based on the changes to the setting values. [Effects of the Invention]
[0007] According to the image processing device of the present invention, when at least some of the setting values are changed by performing bulk settings by selecting items corresponding to the usage environment, a notification can be made based on the changes to the setting values. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram illustrating an example of a usage environment of an information processing device. [Figure 2] 10 is a flowchart showing an example of conditions for classifying the usage environment of an information processing device. [Figure 3] FIG. 2 illustrates an example of a hardware configuration of an image forming apparatus 101. [Figure 4] FIG. 2 illustrates an example of a software configuration of the image forming apparatus 101. [Figure 5] FIG. 3 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the first embodiment. [Figure 6] FIG. 3 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the first embodiment. [Figure 7] 10 is a flowchart showing an example of processing executed by the image forming apparatus 101. [Figure 8] FIG. 10 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the second embodiment. [Figure 9] FIG. 10 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the second embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the third embodiment. [Figure 11] 10 is a flowchart showing an example of processing executed by the image forming apparatus 101 in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0009] The following describes embodiments of the present invention with reference to the drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0010] First Embodiment FIG. 1 is a configuration diagram illustrating an example of a usage environment of an information processing device according to this embodiment.
[0011] Image forming apparatuses 101 to 104, which are examples of information processing apparatuses in this embodiment, are installed in different usage environments 111 to 114. The usage environments 111 to 114 illustrated in Fig. 1 are an in-house intranet environment 111, a direct internet connection environment 112, an internet-prohibited environment 113, and a home environment 114, respectively.
[0012] The company intra environment 111 is an environment in which an image forming apparatus 101 and a PC 121 are connected via an in-company LAN (Local Area Network) 131. A firewall 141 is installed at the boundary between the LAN 131 and the Internet 100. That is, communication between each information processing apparatus in the company intra environment 111 and the Internet 100 is monitored and protected by the firewall 141. Therefore, in the company intra environment 111, threats such as access to each information processing apparatus by an attacker from the Internet 100 are greatly reduced.
[0013] On the other hand, no firewall is installed in the direct internet connection environment 112. The direct internet connection environment 112 is an environment in which the image forming apparatus 102 and the PC 122 are directly connected to the Internet 100 and communicate with each other. Therefore, information processing apparatuses such as the image forming apparatus 102 and the PC 122 need to take measures against threats such as access by attackers from the Internet 100, for example, by using a personal firewall function within each information processing apparatus.
[0014] The internet prohibited environment 113 is a closed network environment isolated from other networks such as the internet 100. Information processing devices such as the image forming device 103 and the PC 123 are connected via a LAN 133. In the internet prohibited environment 113, network communication is possible only between the information processing devices installed on the LAN 133. The information processing devices cannot be accessed by unspecified users on the internet 100.
[0015] The home environment 114 is an environment in which the image forming device 104 and the PC 124 are connected via a home LAN 134. The LAN 134 is a private network configured with a home router 144, but does not have security measures such as a strong firewall like the company intranet environment 111. Therefore, like the direct internet connection environment 112, the information processing devices installed in the home environment 114 need to take measures against threats such as access by attackers from the Internet 100, such as by using a personal firewall function within each information processing device.
[0016] In this embodiment, a public space environment and a highly confidential environment (not shown) are assumed in addition to the usage environments 111 to 114. The above six classifications of usage environments will be described in detail with reference to FIG.
[0017] In this embodiment, the usage environment of an information processing device is classified into six categories, and appropriate security settings are provided for each category. FIG. 2 is a flowchart illustrating the concept of classification when classifying and defining usage environments. Note that the following definitions of usage environments do not limit the present invention, and some or other usage environments exemplified in this embodiment may be defined. For example, assuming installation within a company, usage environments may be classified by industry, such as finance or government agencies.
[0018] S201 is a classification of whether the environment handles highly confidential information. An environment that handles highly confidential information can be said to be an environment in which security measures must be given the highest priority. Hereinafter, in this embodiment, an environment in which security measures must be given the highest priority is defined as a highly confidential information management environment 116.
[0019] If the environment does not handle highly confidential information, the classification of the usage environment is further subdivided. S202 classifies the environment as being entry-controlled or not. This is an example of classification based on whether or not unspecified users can physically access the information processing device, i.e., whether or not users who enter the location where the information processing device is installed are restricted. Therefore, the classification condition of whether or not physical access is possible is not limited to this embodiment, and conditions other than entry control may also be used as the classification condition. Furthermore, entry control in this embodiment is not limited to a card-based access / exit system. For example, an entry-controlled environment also includes an environment in which only people belonging to an organization work during business hours, limiting the number of people who can actually enter, and the door is locked outside of business hours.
[0020] When entry control is not performed, i.e., when unspecified users can physically access the information processing device, the usage environment is subdivided according to the classification conditions shown in S205. S205 classifies the environment based on whether unspecified users share and use the network within the environment. In this embodiment, an environment in which unspecified users share and use the network within the environment is defined as a public space environment 115. Furthermore, an environment in which unspecified users do not share the network within the environment is defined as a home environment 114. In this embodiment, an environment in which unspecified users do not share the network within the environment, such as the home environment 114, i.e., an environment in which the user can be identified, is defined as a private network environment.
[0021] The usage environment classified as entry-controlled in S202 is further subdivided according to the classification conditions shown in S203. S203 classifies the environment based on whether or not the information processing device in the environment is connected to an external network such as the Internet. An environment that is not connected to an external network such as the Internet is defined as an Internet-prohibited environment 113. Note that the Internet-prohibited environment 113, which is entry-controlled and is based on a closed network, is a private network environment.
[0022] If the information processing device in the environment is connected to an external network such as the Internet, the usage environment is further subdivided according to the classification conditions shown in S204. S204 classifies the environment based on whether or not a firewall is installed. An environment in which a firewall is installed is defined as an in-house intra environment 111. An environment in which no firewall is installed is defined as a direct Internet connection environment 112. The in-house intra environment 111, in which users who use the network within the environment can be restricted by a firewall, is a private network environment.
[0023] Next, we will explain the six usage environments mentioned above and the security measures that should be taken for each usage environment using Table 1. Here, we will give seven examples of security measures.
[0024] [Table 1]
[0025] Communication path encryption is a security measure that prevents information leakage by encrypting communication content on a network. Transport Layer Security (TLS) is an example of a function that realizes communication path encryption. In an environment connected to the Internet, it is desirable to encrypt the communication path because there is a possibility that a third party may eavesdrop on the communication content. In other words, it is recommended to encrypt the communication path except in an Internet-prohibited environment 113.
[0026] Disabling legacy protocols is a security measure to prevent spoofing and information leakage by disabling functions that use insecure legacy communication protocols. An example of a legacy protocol is WINS (Windows Internet Name Service). As with encryption of communication paths, disabling legacy protocols is also desirable in environments connected to external networks such as the Internet. In other words, disabling legacy protocols is recommended except for Internet-prohibited environments 113.
[0027] A personal firewall is a firewall installed and used on an information processing device. Like a typical firewall, it monitors communication between the information processing device and external networks such as the Internet. Examples of firewalls include IP filters and port number filters. IP filters are a security measure that reads the destination and source information of communication packets and allows only pre-defined communication packets. This prevents unauthorized access and information leakage. Port number filters are a security measure that closes unused ports to prevent intrusion through those ports. This prevents DoS (Denial of Service), a cyber attack that creates vulnerabilities by imposing a large load. In environments connected to external networks but without a firewall, it is desirable to enable a personal firewall due to the possibility of information leakage and DoS. In other words, enabling a personal firewall is recommended except for Internet-prohibited environments 113 that are not connected to external networks and intranet environments 111 where a firewall is installed.
[0028] Strengthening the security of authentication means strengthening measures against spoofing, for example, by prohibiting password caching, specifying the minimum number of characters for passwords, etc. Except for the Internet-prohibited environment 113 connected within an isolated network, it is desirable to strengthen the security of authentication because there is a possibility of spoofing.
[0029] Countermeasures against physical attacks are security measures to physically prevent information from being leaked. The image forming apparatuses 101 to 104 generate temporary data, such as print jobs, on their hard disks. Each image forming apparatus is equipped with a complete erasure function that automatically and completely erases the generated temporary data upon job completion. The complete erasure function described above is an example of a countermeasure against physical attacks for the image forming apparatuses 101 to 104. With this function enabled, even if the hard disk is physically removed, the temporary data cannot be read. It is desirable to implement countermeasures against physical attacks in the home environment 114 and the public space environment 115, which are environments where entry management is not performed and physical access to information processing devices cannot be restricted. It is also desirable to implement countermeasures against physical attacks in the highly confidential information management environment 116, where reducing the risk of information leakage is given top priority.
[0030] The file sharing function is a function for sharing files over a network within an environment. In an environment where unspecified users share the network within the environment, it is desirable to disable the file sharing function to prevent information leakage. That is, it is recommended to disable the file sharing function except for private network environments where specific users share the network within the environment. As described above, the private network environments in this embodiment are the company intranet environment 111, the internet-prohibited environment 113, and the home environment 114. Therefore, it is recommended to disable the file sharing function in the other environments, namely the direct internet connection environment 112, the public space environment 115, and the highly confidential information management environment 116. Note that an example of settings related to the file sharing function is SMB (Server Message Block) server settings.
[0031] Disabling an external storage device means, for example, setting a USB (Universal Serial Base) storage device so that it cannot be used as an external storage device by an information processing device. This prevents information from being written to the external storage device, preventing information leakage. It also prevents computer virus infection via the USB storage device and the resulting information leakage. The threat of information leakage from external storage devices such as USBs is common to all usage environments. Therefore, it is desirable to disable them in all usage environments.
[0032] Table 2 shows the recommended setting items and values for each usage environment, which are based on the security measures described above. For items with recommended settings, the recommended setting value is indicated as "on," "off," "deny," etc. When the user selects a usage environment on the screen shown in Figure 5 (described later), the recommended setting value for the selected usage environment is applied by the process shown in Figure 7 (described later).
[0033] Image forming apparatuses 101 to 104, which are examples of information processing apparatuses, have a wide variety of setting items, such as setting items related to security functions and other setting items, and perform various controls according to the setting values corresponding to the setting items. In this embodiment, the target items for collective setting of security functions are the 22 items shown in Table 2.
[0034] [Table 2]
[0035] LPD, RAW, WSD, and IPP are printing protocols used for communication between client devices and printers. Unlike other protocols, IPP itself provides user authentication, access control, and communication data encryption functions, making it a more secure printing protocol than other protocols. For this reason, it is recommended that "Use IPP Printing" be set to "On" in environments requiring high security and high confidential information management. Furthermore, it is recommended that LPD, RAW, and WSD, which have weaker security than IPP, be set to "Off" except in trusted environments such as corporate intranet environments and environments where internet access is prohibited.
[0036] SNMP is a protocol for monitoring and controlling communication devices on a network, and allows you to check the number of pages printed by a printer and error information using a PC. SNMPv1 determines the communication range using information called a community name, but because the community name is sent over the network in plain text, there is a risk of information leakage. For this reason, it is recommended that you set this option to "Off" except in trusted environments such as company intranet environments and environments that do not connect to the Internet and where Internet access is prohibited.
[0037] A dedicated port is a port used to set and view printer information from the printer driver, etc. If the "Use dedicated port" option is set to "Off," printer information will not be available when using the printer driver, etc. over a network connection. In environments directly connected to the Internet or in public spaces, there is a risk of information leakage, so it is recommended that this option be set to "Off." It is also recommended that this option be set to "Off" in environments requiring high security and where highly confidential information is managed.
[0038] Automatic deletion of interrupted jobs is a function that automatically deletes print jobs that are interrupted due to an error or other reason. This prevents an interrupted print job from being resumed after a period of time, leaving printed documents unattended, reducing the risk of information leakage. It is recommended that this setting be set to "On" in home environments and public space environments without access control, as well as in highly confidential information management environments that require high security.
[0039] A transmission result report is a report used to confirm whether a transmission to the intended recipient was successful. This setting determines whether or not to automatically print transmission result reports for fax, e-mail, and I-fax transmissions, as well as for saving to a file server or user box. By turning off the transmission result report, reports containing information such as the content of the transmission and the transmission history will not be left on the printer, reducing the risk of information leaks. It is recommended to turn off the report in home environments or public space environments without access control, or in highly confidential information management environments requiring high security.
[0040] Simple login is a method of logging in by pressing the user name displayed on the operation panel, which eliminates the need to enter the user name. Simple login allows you to set a PIN. This item allows you to set whether or not this PIN must be used. If a PIN is not used, users can simply log in by selecting the user name displayed on the operation panel, but this poses a risk of identity theft. Setting this item to "On" reduces the risk of identity theft. It is recommended that this setting be set to "On" in home environments and public space environments where entry is not controlled, and in highly confidential information management environments that require high security.
[0041] "Display job status before authentication" is an item that allows you to set whether or not to display a screen that allows you to check the job status before authentication, assuming that you are using a login service. By setting this item to "Off," you can prevent the job status from being viewed by an unspecified number of people, reducing the risk of information leakage. It is recommended that you set this to "Off" in home environments or public space environments that do not have access control, or in highly confidential information management environments that require high security.
[0042] Job history is the history of print jobs and includes information such as the username of the user who instructed printing and the document name of the printed document. Turning off the display of job history prevents information such as the document name and the name of the user who printed it from being seen by an unspecified number of people, reducing the risk of information leaks. It is recommended that this setting be set to "off" in home environments and public space environments without access control, and in highly confidential information management environments that require high security.
[0043] The audit log function makes it possible to audit security events. For example, the user authentication log can be used to check for unauthorized access to the device or attempts to do so, and the logs of device usage such as printing, document transmission, and setting changes can be used to audit for unauthorized use of the device. The key operation log is a log of key operations performed by the user, and includes, for example, the key operation log for login operations. By saving and analyzing these logs, it is possible to investigate how the printer was operated. By acquiring or saving the audit log and key operation log, it is possible to prevent users from denial of access or use in the event of unauthorized access or use. Because the risk of denial exists in all environments, these settings are recommended for all six environments.
[0044] Although not listed in Table 2, in a highly confidential information management environment requiring high security, it is possible to add the following setting items: For example, "Use Mopria," "Use AirPrint," "Use Remote UI," etc.
[0045] In addition, the following items can be added in a home environment. Examples include PJL (Printer Job Language) and Admin (Embedded Web Server) passwords, and SNMPv1 / v2 and SNMPv3-related settings. For example, you can prevent PJL and EWS administrator passwords from being changed from devices to which centralized settings for the home environment have been applied. SNMP is a device management protocol that allows administrators to retrieve and set settings for image forming devices such as printers over the network. Using SNMP allows administrators to freely change settings for image forming device functions, allowing them to manage the permissions required for each setting. To prevent general users working from home from changing settings after the settings set in accordance with company policy have been applied, you can also prevent changes to settings related to device management protocols in a home environment. It is also possible to add settings related to checking firmware versions and updates. It is also possible to add settings for selecting whether to restrict access to PJL commands and settings related to HTTPS redirection.
[0046] Note that the setting values are not limited to those in Table 2, as long as they are appropriate for each usage environment. For example, in Table 2, a firewall is installed in a company intranet environment, so personal firewall settings are not necessary. However, there may be cases where a firewall installed in the office is used in conjunction with a personal firewall. Given this, it is possible to perform centralized settings, including personal firewall settings, even in a company intranet environment or an environment where Internet access is prohibited. The same applies to other setting items.
[0047] Among the setting items shown in Table 2, TLS settings, personal firewall settings, etc. are setting items related to the network in general, while items related to print protocols and image forming device functions and device management, such as displaying print job history, are setting items specific to the image forming device.
[0048] In this embodiment, an information processing apparatus is provided that performs settings suitable for a selected usage environment based on the definitions of the above-described environment classifications and the recommended setting values of security functions. Specific explanations will be given below.
[0049] <Hardware Configuration of Image Forming Apparatus 101> The hardware configuration of an image forming apparatus 101, which is an example of an information processing apparatus in this embodiment, will be described with reference to Fig. 3. Note that while Fig. 3 only describes the image forming apparatus 101, the image forming apparatuses 102 to 104, and image forming apparatuses installed in public space environments and highly confidential information management environments (not shown) are also assumed to have the same configuration as the image forming apparatus 101.
[0050] The image forming apparatus 101 includes a printer 330 that outputs electronic data onto a paper medium, and a scanner 340 that reads the paper medium and converts it into electronic data. In this embodiment, the image forming apparatus 101 has multiple functions as an example of an information processing apparatus, but is not limited to this. For example, it may be a single-function printer, scanner, or other device. It may also be a 3D printer, 3D scanner, or other device.
[0051] A control unit 310 including a CPU (Central Processing Unit) 311 controls the overall operation of the image forming apparatus 101. A ROM (Read Only Memory) 312 is used to store programs executed by the CPU 311. The CPU 311 reads out control programs stored in the ROM 312 and performs various controls of the image forming apparatus 101, such as reading control and transmission control. A RAM (Random Access Memory) 313 is used as a temporary storage area such as the main memory and work area of the CPU 311. A HDD (Hard Disk Drive) 314 is a storage device that stores image data, various programs, and various setting information. Note that other storage devices such as an SSD (Solid State Drive) may also be included. In this way, the hardware such as the CPU 311, ROM 312, RAM 313, and HDD 314 constitute a so-called computer.
[0052] An operation unit I / F (interface) 315 connects an operation unit 320 and the control unit 310. The operation unit 320 is equipped with a liquid crystal display unit with a touch panel function, various hard keys, etc. The operation unit 320 functions as a display unit that displays information to the user and a reception unit that receives instructions from the user.
[0053] The printer I / F 316 connects the printer 330 and the control unit 310. Image data to be printed by the printer 330 is transferred from the control unit 310 via the printer I / F. The input image data is output onto a recording medium by the printer 330. The scanner I / F 317 connects the scanner 340 and the control unit 310. The scanner 340 reads an original placed on an original platen (not shown) and generates image data. The generated image data is input to the control unit 310 via the scanner I / F 317.
[0054] A network cable is connected to the network I / F 318, and communication with an external device on the LAN 131 can be performed. In this embodiment, it is assumed that the network I / F 318 is a communication interface that performs wired communication, but this is not limited to this. For example, it may be a wireless communication interface. Note that the network I / F 318 of the image forming apparatus 101 is connected to the LAN 131, but the network to which it is connected varies depending on the usage environment. For example, the image forming apparatus 102 is directly connected to the Internet 100. The image forming apparatuses 103 and 104 are connected to the LANs 133 and 134, respectively.
[0055] <Software Configuration of Image Forming Apparatus 101> Next, the software configuration of the image forming apparatus 101, which is an example of an information processing apparatus in this embodiment, will be described with reference to Fig. 4. Each unit shown in Fig. 4 is realized by the CPU 311 executing a program corresponding to each unit stored in the ROM 312.
[0056] The operation control unit 410 displays a screen for the user on the operation unit 320. It also detects user operations, and switches the screen or updates the display based on the detection result.
[0057] The data storage unit 420 stores data in the HDD 314 and reads data from the HDD 314 in response to requests from other control units. The data storage unit 420 stores information related to security function settings in addition to setting information for determining the operation of the image forming apparatus 101. Specifically, the data storage unit 420 stores a recommended setting value database 421, restore data 422, and current operation setting data 423.
[0058] The recommended setting value database 421 is a database such as that shown in Table 2 above. That is, it is a database in which combinations of setting items and setting values of security functions suitable for the usage environment of the image forming apparatus 101 are associated with a plurality of classified usage environments. Here, the setting items refer to items such as TLS settings and WINS settings. Setting values are indicated as "on," "off," "reject," etc. in Table 2. Setting items in Table 2 in which the setting value is blank and indicated by diagonal lines indicate that they do not have a recommended setting value. That is, the setting value for the setting item is not changed, and the setting value before the setting change is retained. In this embodiment, the recommended setting value database 421 is defined in advance by the vendor of the image forming apparatus 101 and stored in the data storage unit 420.
[0059] The restore data 422 is data of a combination of setting items and setting values that was applied before the user selected an environment type on a screen 500 in FIG. 5 (described later). In this embodiment, the restore data 422 is stored when an environment type is selected for the first time on the image forming apparatus 101. Although not illustrated in this embodiment, the restore data 422 may be stored when an environment type is selected for the first time after a cancel button displayed on the screen for selecting an environment type is pressed. In this embodiment, the restore data 422 is not updated when the user selects an environment type consecutively. In this embodiment, the restore data is used when changing the environment type set on the image forming apparatus 101 by selecting an environment type for the second or subsequent time. The recommended setting data suitable for the newly selected environment type is overwritten on the restore data 422 to determine the new setting data to be applied to the image forming apparatus 101.
[0060] The current operation setting data 423 is data of a combination of setting items and setting values currently applied to the image forming apparatus 101. When a setting is changed, the current operation setting data 423 is rewritten. When the image forming apparatus 101 is then restarted, the rewritten current operation setting data 423 is read by a program, and the image forming apparatus operates with the applied settings.
[0061] The security setting control unit 430 performs collective setting of security functions of the image forming apparatus 101 in accordance with instructions from the user detected by the operation control unit 410. Specific setting control will be described later with reference to FIG. 7. Note that the collective setting in this embodiment is a function that allows recommended setting values of typical security functions defined by a vendor to be set in a collective manner. Hereinafter, this function will also be referred to as a collective setting function. This function is different in nature from a function that applies a security policy edited by a user and prohibits changing settings for specific security setting items to settings that do not conform to the policy. In other words, even if a user such as an administrator performs collective setting using the collective setting function, the user can change the setting values of individual setting items to different setting values again via an individual setting change screen (not shown) depending on the actual usage situation.
[0062] In this embodiment, when a user selects a usage environment on a screen 500 (described later), the security setting control unit 430 creates new operational setting data using recommended setting data suitable for the selected usage environment. Specifically, the security setting control unit 430 first reads the current operational setting data 423, the restore data 422, and the recommended setting data suitable for the selected usage environment from the data storage unit 420. If an environment type is selected on the screen 500 when batch settings based on environment selection have not been applied to the image forming apparatus 101, the security setting control unit 430 overwrites the recommended setting data over the current operational setting data 423. If an environment type is selected when batch settings based on environment selection have already been applied to the image forming apparatus 101, the security setting control unit 430 overwrites the recommended setting data over the restore data 422. In this embodiment, when overwriting a value, if the recommended setting data has a value for a setting item of a security function (item marked "On," "Off," or "Reject" in Table 2), the setting value is changed to the recommended setting value. If the recommended setting data does not have a value (items indicated by diagonal lines in Table 2), the setting value remains unchanged from the current value in the operational setting data 423 or the restore data 422. Through the above processing, the security setting control unit 430 determines the combination of setting items and setting values for the security functions to be newly set. Note that the method for determining the newly set setting data is not limited to the above method. For example, even when a batch setting based on the environment selection has been applied to the image forming apparatus 101, it is also possible to configure the recommended setting data to overwrite the current operational setting data 423.
[0063] A web UI (User Interface) control unit 440 controls a setting screen displayed on an external information processing device such as the PC 121 via the network I / F 318. A user can refer to and change settings of the image forming apparatus 101 using a setting screen on a web browser provided by the web UI control unit 440. The web UI control unit 440 may also have a function for importing and exporting the recommended setting value database 421. This function allows the user to create and edit a data file related to the recommended setting value database 421 on the PC 121. The edited recommended setting value database 421 can also be sent to the image forming apparatus 101 and stored in the data storage unit 420. The web UI control unit 440 may be omitted in this embodiment.
[0064] Next, a setting screen displayed on the operation unit 320 of the image forming apparatus 101 will be described with reference to Fig. 5. Note that, although the setting screen displayed on the operation unit 320 of the image forming apparatus 101 will be described in this embodiment, the present invention is not limited to this. For example, it is also possible to use the web UI control unit 440 to provide a web page similar to the setting screen to a web browser of an external information processing apparatus, and to perform setting operations via the web page.
[0065] A screen 500 is a screen that the operation control unit 410 displays on the operation unit 320. A usage environment list button 501 is a button that the user uses to select a usage environment. The user selects the usage environment of the image forming apparatus 101 from the usage environment list button 501 on the screen 500 and presses an execute button 502. The screen 500 illustrates an example in which the user has selected a direct internet connection type as the usage environment for the image forming apparatus 101, for which a home type is set. When the operation control unit 410 of the image forming apparatus 101 detects that the execute button 502 has been pressed, it transmits information indicating the user's selection of the usage environment to the security setting control unit 430. The security setting control unit 430 determines whether any setting values will be changed when applying the recommended settings for the usage environment selected by the user, and displays a screen corresponding to the change of the setting values according to the environment selection. The process of determining whether any setting values will be changed will be described later with reference to FIG. 7.
[0066] In this embodiment, an example of a screen to be displayed when a setting value is changed, causing the new setting value to be turned off and a function to become unavailable will be described. If there is a setting item whose setting value is changed to be turned off, a screen 510 shown in FIG. 5b is displayed. Otherwise, a screen 520 shown in FIG. 5c is displayed. When the operation control unit 410 detects a user operation of pressing a cancel button 511 on the screen 510, the operation control unit 410 displays the screen 500. When the operation control unit 410 detects a user operation of pressing a button 512 for applying the type of usage environment on the screen 510, the operation control unit 410 transmits information indicating the user's selection results to the security setting control unit 430. The security setting control unit 430 collectively configures the security functions suitable for the usage environment selected by the user, which are received from the operation control unit 410. After the collective configuration, the operation control unit 410 displays a screen 540 shown in FIG. 5e.
[0067] Similarly, when the operation control unit 410 detects a user operation of pressing a cancel button 521 on the screen 520, the operation control unit 410 displays the screen 500. Furthermore, when the operation control unit 410 detects a user operation of pressing a button 522 for applying the type of usage environment, the operation control unit 410 transmits information indicating the user's selection results to the security setting control unit 430. The security setting control unit 430 collectively sets the security functions appropriate for the usage environment selected by the user, which are received from the operation control unit 410. After the collectively setting, the operation control unit 410 displays the screen 540 shown in FIG. 5e. The screen 540 illustrates an example in which the usage environment of the image forming apparatus 101 has been set to the direct internet connection type.
[0068] Returning to the description of screen 510, notification 514 on screen 510 notifies the user that some functions will become unavailable when the environment type selected on screen 500 is applied. Button 513 notifies the user that setting values will change when the selected environment is applied. When the operation control unit 410 detects that button 513 has been pressed, it displays screen 530 shown in FIG. 5d. Screen 530 displays the setting items that will be changed when the environment type is applied, as well as the setting values before and after the change. In other words, screen 530 is a screen that notifies the user of the changes to setting values when the environment type is applied. On screen 530, the user can confirm the setting values that will become unavailable when the recommended settings for the selected environment are applied. FIG. 5d shows an example in which the setting value for the setting item "Use SMB Server" is changed from ON to OFF when the recommended settings for the direct internet connection type are applied to the image forming apparatus 101. When the operation control unit 410 detects that button 531 has been pressed, it redisplays screen 510.
[0069] In this manner, in this embodiment, if a function becomes unavailable due to a change in security settings, the user can be notified of the change in setting value. This allows the user to intuitively understand that there is a function that will become unavailable. This allows the user to take appropriate measures, such as reviewing the setting change or revising the business flow to avoid using the function after knowing in advance that it will become unavailable.
[0070] 5b, a screen including a button 601 shown in FIG. 6a may be displayed. The button 601 is a button for transitioning to a function that assists the user in selecting a usage environment. When the button 601 is pressed, the image forming apparatus 101 identifies the usage environment and provides a question wizard (not shown) for notifying the user of a recommended usage environment.
[0071] Specifically, a question wizard is provided in accordance with the classification categories described in Fig. 2. For example, the image forming apparatus 101 first inquires of the user as to whether or not highly confidential information is handled. If the inquiry result indicates that highly confidential information is handled, the image forming apparatus 101 determines that the recommended usage environment type is a highly confidential information management environment. On the other hand, if the inquiry result indicates that the information is not handled, the image forming apparatus 101 inquires of the user as to whether or not the apparatus is installed in an access-controlled environment. Thereafter, in accordance with the classifications in Fig. 2, inquiries are made as appropriate regarding whether or not the environment is connected to the Internet, whether or not a firewall is installed, whether or not a large number of unspecified users share the network, and the like, and the recommended usage environment type is notified to the user.
[0072] Also, instead of the screen of Fig. 5d, the screen shown in Fig. 6b may be configured to be displayed. Screen 610 shown in Fig. 6b further displays a notice 611 indicating the reason why the setting change is recommended to the user, i.e., the reason why the setting change will be made by applying the environment type.
[0073] Next, the process from when the user selects the usage environment on screen 500 to when the security functions are all set at once will be described with reference to Fig. 7. Each operation (step) shown in the flowchart of Fig. 7 is realized by CPU 311 calling into RAM 313 a program for realizing each control unit stored in ROM 312 or HDD 314 and executing it. In addition, in cases where it is desired to clarify the subject of the process, the description will be made with the software module executed by CPU 311 as the subject.
[0074] When the operation control unit 410 detects that an operation to display screen 500 has been performed on a menu screen (not shown) displayed on the operation unit 320, and the operation control unit 410 displays screen 500 on the operation unit 320, the processing shown in Figure 7 is started.
[0075] In S701, the security settings control unit 430 waits until a usage environment other than the currently set usage environment is selected, and once selected, the process proceeds to S702. Specifically, the operation control unit 410 accepts a selection operation for a type of usage environment other than the type of the currently set usage environment and a selection operation for the execute button 502 via the screen 500 illustrated in FIG. 5a. When the operation control unit 410 detects that this operation has been performed, it determines that a different usage environment has been selected, and transmits information indicating the selection result to the security settings control unit 430. When the security settings control unit 430 receives this information, the process proceeds to S702.
[0076] In S702, the security setting control unit 430 reads the current operational setting data 423 and the restore data 422 stored in the data storage unit 420. In addition, the security setting control unit 430 extracts and reads from the recommended setting value database 421 the recommended setting values stored in association with the usage environment selected in S701.
[0077] In S703, the security setting control unit 430 determines whether there are any setting values that will be changed by applying the usage environment selected in S701. Specifically, the security setting control unit 430 first creates new setting data to be set in the image forming apparatus 101 based on the environment selection in S701. This flow proceeds to S702 when an environment type different from the environment type already applied to the image forming apparatus 101 is selected in S701. Therefore, the security setting control unit 430 creates new setting data by overwriting the recommended setting data on the restore data 422 read in S702. Next, the security setting control unit 430 compares the newly created setting data with the current operation setting data 423 read in S702 and determines whether there are any setting items with different values. If there are any setting items with different values, the security setting control unit 430 determines that there are any setting values that will be changed by applying the usage environment selected in S701, and proceeds to S705. If there are no setting items with different values, the flow proceeds to S704.
[0078] In S705, the operation control unit 410 displays a screen corresponding to the change of the setting value according to the selected environment. In this embodiment, if there is a setting value that will be turned off by the change of the setting value, the screen 510 is displayed on the operation unit 320, and the process proceeds to S706. Specifically, it is determined whether the value after the change of the setting value determined in S703 is off, and if it is off, the screen 510 is displayed. Note that if there is no setting value that will be turned off by the change of the setting value, the process proceeds to S704, and the subsequent steps may be configured to proceed as shown in the flow of FIG. 7. In S706, the operation control unit 410 determines whether the display of the setting value to be changed has been selected. Specifically, the operation control unit 410 makes this determination based on whether it has detected that the button 513 on the screen 510 has been pressed. If the operation control unit 410 has detected that the button 513 has been pressed, the process proceeds to S707. If it has not detected that the button 513 has been pressed, the process proceeds to S712.
[0079] In S707, the operation control unit 410 displays the screen 530. In S708, the operation control unit 410 determines whether or not the back button 531 has been pressed on the screen 530. If the operation control unit 410 detects that the back button 531 has been pressed, the process returns to S705 and displays the screen 510. If the process does not detect that the back button 531 has been pressed, the process returns to S708 and the screen 530 remains displayed.
[0080] In S712, if the operation control unit 410 detects that the Yes button 512 has been selected on the screen 520, it sends information indicating the selection result to the security setting control unit 430 and proceeds to S714. If it does not detect that the Yes button 512 has been selected, it proceeds to S713. If the operation control unit 410 detects in S713 that the Cancel button 511 has been selected, it ends this flow and displays the screen 500. If it does not detect that the Cancel button 511 has been selected, it returns to S706.
[0081] In S714, the security setting control unit 430 applies the recommended setting data suitable for the usage environment selected by the user in S701 to the image forming apparatus 101. The method for determining new setting data to be set in the image forming apparatus 101 is as described above. The recommended setting data suitable for the usage environment selected by the user in S701 is overwritten on the restore data 422 read in S702. Then, the current operation setting data 423 is rewritten with the newly determined data and applied to the image forming apparatus 101. Note that the method for determining new setting data is not limited to the method described above.
[0082] Next, a flow will be described for the case where the security setting control unit 430 determines in S703 that there are no setting values to be changed. In S704, the operation control unit 410 displays the screen 520 on the operation unit 320, and the flow proceeds to S709. S709 to S711 are the same processes as S712 to S714. However, if the operation control unit 410 does not detect that the cancel button 521 has been pressed in S710, the flow returns to S709.
[0083] Through the above-described series of processes, the user is prompted to select the operating environment of the information processing device, and the security-related function settings can be collectively configured to settings appropriate for the selected operating environment. Furthermore, by notifying the user that there are functions that will become unavailable, problems such as the user becoming unaware that a desired function will become unavailable can be prevented. Furthermore, by displaying the setting items and setting values that will be turned off, the user can know which functions will become unavailable. In this way, the convenience of configuring security functions can be improved.
[0084] <Second embodiment> In the first embodiment, as shown in the setting screen 500 of FIG. 5a, when changing the usage environment from the currently set environment type to another environment type, an example of notifying that there is a function that will become unavailable when the setting value is turned off is shown. In the second embodiment, an example of notification different from that of the first embodiment in S705 will be described. There are three possible examples of notification in S705, including the first embodiment. Below, three examples of notification will be described.
[0085] The first is an example of the first embodiment. Here, the setting items of functions that become unavailable when the setting value is turned off include "SMB Server Settings" and "Display Job History" from Table 2. When these are turned off, the SMB server and job history functions become unavailable.
[0086] The second example is a notification when security measures are strengthened and functions are restricted, regardless of whether the setting value is turned off. For example, although not listed in Table 2, an authentication setting item such as "Prohibit authentication using department ID and PIN" can be considered. When this setting value is turned on, authentication functions using department ID and PIN are restricted. Furthermore, when the number of characters increases, for example, when the minimum password length is changed from 8 to 16 characters, the convenience of the password setting function decreases, and functions are restricted. S705 may be configured to display a screen corresponding to a change in setting value that strengthens security measures while restricting functions. In this case, a notification similar to notification 514 is displayed on the screen. That is, the screen notifies the user that applying the usage environment selected on screen 500 will restrict the use of at least some functions. A method for determining whether the change in setting value determined in S703 strengthens security measures and restricts functions is described below. For this determination, the data storage unit 420 stores a database of setting values that restrict functions when set. For example, an excerpt from the database can be written as shown in the table below.
[0087] [Table 3]
[0088] In S705, the security setting control unit 430 reads the database. Then, the security setting control unit 430 compares the changed value of the setting value determined in S703 with the value in the database. If the changed value for a certain setting item matches the value in the database, it can be determined that there is a function that is restricted by the environment selection. Note that, regarding the minimum password length, instead of comparing the stored value with the changed value as in Table 3, it may also be determined that the function is restricted if the number of characters increases between the value before and after the change.
[0089] The two types of notification described above can prevent problems such as a desired function being restricted without the user's knowledge, and can improve the convenience of setting security functions.
[0090] The third example is when security measures are relaxed by changing the setting values in response to a change in the environment type. A notification can be configured to notify users when security measures are relaxed in this way. Specifically, this occurs when "SMB Server Settings" is turned on or when "Prohibit Authentication by Department ID and PIN" is turned off. Another example of a relaxed security measure is when the number of characters is reduced, such as when "Minimum Password Length" is changed from 16 to 8 characters. When security measures are relaxed, a method can be considered in which a database of setting values that relax security measures is stored and used to make a judgment, just as in the case of the previously mentioned function restrictions.
[0091] Alternatively, the following determination method is also possible. For example, when the direct internet connection type is applied, the setting value for "Use SMB Server" is off. When the home-based type is applied from that state, the recommended setting data for the home-based type is overwritten in the restore data 422, and new setting data is determined. In Table 2, the recommended setting value for the SMB server setting for the home-based type is indicated by diagonal lines. That is, the setting value in the restore data 422 for that setting item is maintained. If the value in the restore data 422 is on, the setting value after the home-based type is applied will be on. If the default setting value is a value that relaxes security measures, the following determination method is possible. If the setting value is changed in response to the environment selection and returns to the default, it is determined that security measures will be relaxed. Specifically, if the changed setting value determined in S703 matches the restore data 422, it can be determined that security measures will be relaxed due to the environment selection. Note that the default setting value does not necessarily relax security measures. Therefore, if returning to the default setting value strengthens security measures, the notification in S705 may not be sent.
[0092] The third example, a screen configuration in which security measures are relaxed, will be described. Note that the hardware and software configurations of the image forming apparatus 101 according to this embodiment are the same as those in the first embodiment, and therefore a description thereof will be omitted. Furthermore, the processing flow is also the same except for the processing of S705 described above, and therefore a description thereof will be omitted.
[0093] The screen configuration in this embodiment will be described with reference to FIG. 8. The setting screen 800 is a screen that the operation control unit 410 displays on the operation unit 320, and is similar to the screen 500. The setting screen 800 illustrates an example in which a user has selected the at-home type as the usage environment for the image forming apparatus 101 for which the direct internet connection type has been set. The usage environment list button 801 is a button that the user uses to select the usage environment. On the setting screen 500, the user selects the usage environment of the image forming apparatus 101 from the usage environment list button 501 and presses the execute button 502. The setting screen 800 illustrates an example in which the user has selected the at-home type as the usage environment. When the operation control unit 410 of the image forming apparatus 101 detects that the execute button 802 has been pressed, it transmits information indicating the result of the user's selection of the usage environment to the security setting control unit 430. The security setting control unit 430 compares the current operational setting data 423 currently set in the image forming device 101 with new setting data created using the recommended settings for the usage environment selected by the user, and determines whether there are any setting values that will relax security measures.
[0094] In this embodiment, if there are setting values that will relax security measures, a screen 810 is displayed instead of the screen 510 shown in FIG. 5b. When the operation control unit 410 detects a user operation of pressing a cancel button 811, it displays a setting screen 800. The operation control unit 410 detects a user operation of pressing a button 812 on the screen 810 and transmits information indicating the user's selection to the security setting control unit 430. The security setting control unit 430 collectively configures the security functions appropriate for the usage environment selected by the user, as received from the operation control unit 410. The notification 813 is a display notifying the user that some security functions will be relaxed due to a change in the usage environment, but that security will be maintained if the selected usage environment matches the actual usage environment. The button 814 notifies the user that there are setting values that will relax security measures by applying the recommended settings for the selected usage environment. When the operation control unit 410 detects that the button 814 has been pressed, it displays a screen 830 shown in FIG. 8d.
[0095] On screen 830, the user checks the setting values that will ease security measures by applying the recommended settings for the selected usage environment. Fig. 8d shows an example in which security measures related to the SMB server are eased by applying the recommended settings for the home type to the image forming apparatus 101. Note that an explanation regarding changing the setting values may be displayed, as in screen 900 shown in Fig. 9. When the operation control unit 410 detects that button 831 has been pressed, it redisplays screen 810.
[0096] If there is no setting value that relaxes the security measures, screen 820 shown in Fig. 8c is displayed. When the operation control unit 410 detects a user operation of pressing a cancel button 821, it displays setting screen 800. The operation control unit 410 detects a user operation of pressing a button 822 on screen 820, and transmits information indicating the user's selection results to the security setting control unit 430. The security setting control unit 430 collectively sets the security functions that are suitable for the usage environment selected by the user and that are received from the operation control unit 410.
[0097] As explained above, a user-friendly screen can be provided by notifying the user that security measures will be relaxed due to a change in the usage environment, and by notifying the user that safety will be maintained even if the measures are relaxed.
[0098] In this embodiment, three examples of notifications are described for display on the screen in step S705. A configuration may be adopted in which a combination of two or more of these three types of notifications are displayed on the screen. For example, consider a case in which the environment type is changed from a direct Internet connection environment to a home environment based on the database shown in Table 2. At this time, if the setting value of the restore data 422 for "SMB Server Settings" is on, the setting value is changed from off to on. This is a setting change that relaxes security measures. On the other hand, if the setting value of the current operation setting data 423 for "Display Job History" is on, the setting value is changed from on to off. This is a setting change that strengthens security measures, and this setting change restricts functionality. When changing the environment type in this way, it is also possible to configure the system to display both a notification that relaxes security measures and a notification that restricts functionality.
[0099] <Third embodiment> In the first and second embodiments, examples were shown in which a screen corresponding to the change of setting values according to the selection of the usage environment was displayed. In the third embodiment, a configuration is described in which the setting values to be applied to the setting items whose setting values are to be changed are determined by a user's instruction, and a bulk setting that reflects the user's instruction is performed. In particular, as shown in the "Disable File Sharing Function" column in Table 1, in the case of a home-based type, the user may arbitrarily determine whether to turn on or off the SMB server setting. In cases where security measures are relaxed, for items whose setting values the user may arbitrarily determine, accepting the user's instruction and reflecting it in the bulk setting reduces the effort required for the user to open a separate setting screen and reset the settings. The hardware and software configurations of the image forming apparatus 101 according to this embodiment are the same as those in the first embodiment, and therefore will not be described here.
[0100] The screen configuration in this embodiment will be described with reference to Fig. 10. Fig. 10(a) illustrates an example of a setting screen displayed on the operation unit 320 of the image forming apparatus 101 in place of the screen 530 when the setting value is turned off as in the first embodiment. Note that, although the setting screen displayed on the operation unit 320 of the image forming apparatus 101 is described in this embodiment, the present invention is not limited to this. For example, it is also possible to use the web UI control unit 440 to provide a web page similar to the setting screen 500 to a web browser of an external information processing apparatus, and to perform setting operations via this web page.
[0101] Due to space limitations, Fig. 10 shows an example of a screen that may be displayed on the operation unit 320. In this example, Fig. 10 indicates that the SMB server setting is turned off by applying the recommended settings for the direct internet connection type.
[0102] A setting value change button 1001 on the setting screen 1000 accepts the user's response to a setting value. The operation control unit 410 can configure new setting data by detecting the values of each setting value selected by the user. Specifically, a case can be considered in which "Use SMB Server" is set to OFF when the recommended settings for a direct internet connection type are applied, but the user selects ON using the setting value change button 1001. In this case, "Use SMB Server" is overwritten with ON in the recommended settings for a direct internet connection type, and new setting data is configured.
[0103] 10(b) shows an example of a setting screen displayed on the operation unit 320 in place of the screen 830 in a case where there is a setting item for which security measures are relaxed, as in the second embodiment. In this example, application of the home type means that the SMB server setting is turned on. A setting value change button 1011 on the setting screen 1010 accepts setting value instructions from the user. The operation control unit 410 can configure new setting data by detecting the values of each setting value selected by the user.
[0104] The display of the screen shown in Fig. 10 and the processing related to the collective setting of security functions will be described with reference to Fig. 11. Each operation (step) shown in Fig. 11 is realized by CPU 311 calling into RAM 313 a program for realizing each control unit stored in ROM 312 or HDD 314 and executing it.
[0105] The steps shown in Fig. 11 are an example of processing that is executed in place of the steps from S705 onwards that were described in Fig. 7 of the first embodiment. The same processing as in Fig. 7 is illustrated using the same reference numerals. Fig. 11 differs from the flowchart in Fig. 7 in that after the display processing in S707, setting change processing in S1101 and S1102 is further performed.
[0106] In S707, the security setting control unit 430 displays a screen showing the changed setting values. In this embodiment, the screen in Fig. 10 is displayed instead of the screen in Fig. 5d that was displayed in the first example. When the display is complete, the security setting control unit 430 advances the process to S1101.
[0107] In S1101, the operation control unit 410 determines whether or not a user operation to change the recommended setting value to another setting value has been received via the screen illustrated in Fig. 10. Specifically, when an operation on the back button is detected via the screen of Fig. 10, it determines whether or not a user operation to change the setting has been performed via the screen of Fig. 10. If it is determined that a user operation to change the setting has been performed, the process proceeds to S1102, and if it is determined that a user operation to change the setting has not been performed, the process proceeds to S705.
[0108] In S1102, the security setting control unit 430 overwrites the recommended setting data read out in S702 with the setting values changed by the user via the screen of Fig. 10. When the process is complete, the process proceeds to S705.
[0109] Steps S706, S712, and S713 are the same as those in the first embodiment. If application of the environment type is selected in step S712, the process proceeds to step S1103. In step S1103, if the processing of step S1102 has not been executed, the security setting control unit 430 overwrites the current operational setting data 423 or the restore data 422 with the recommended setting data, as in the first embodiment. If the processing of step S1102 has been executed, the current operational setting data 423 or the restore data 422 is overwritten with the data created by overwriting the setting values changed in step S1102. In this way, new setting data to be applied to the image forming apparatus 101 is determined. The determined new setting data is then applied to the image forming apparatus 101.
[0110] The above process allows the user to select setting values for predetermined setting items when setting recommended setting data for the usage environment in a batch in the image forming apparatus 101. This allows the user to realize a process for setting security functions in a batch that is suited to the user's usage situation.
[0111] <Modification> In the above-described embodiment, the screen display and batch setting processing shown in FIG. 7 are performed on the image forming apparatus 101 or on a web page provided to a web browser of an external information processing apparatus using the web UI control unit 440 of the image forming apparatus 101. However, similar processing may be performed on an information processing apparatus other than the image forming apparatus 101. For example, the security setting control unit 430 is implemented as an application that can be installed and executed on the information processing apparatus. The display of the setting screen and the generation of current operation setting data are configured to be performed on the application. By executing the application on the information processing apparatus, the processing performed by the security setting control unit 430 of the image forming apparatus in the first embodiment can be realized on the information processing apparatus. Specifically, the security setting control unit of the external application performs the processing described below.
[0112] First, in S701, an external application provides a screen similar to the setting screen shown in Fig. 5 or 8. The application screen is provided to a display device connected to the device itself, or to a web browser running on an external PC, etc. The web browser then detects that an environment type different from the currently set type has been selected on screen 500 or screen 800. When the application receives information indicating that this operation has been detected, it proceeds to S702.
[0113] In S702, the application reads current operational setting data and recommended setting data from a database stored in the application. Then, in S703, the application determines whether there are any setting values that will be turned off. The database stored in the application contains data similar to the recommended setting value database 421, restore data 422, and current operational setting data 423 in the first embodiment. The external application obtains data similar to the current operational setting data 423 from the image forming apparatus 101 via the network. To collect information from the image forming apparatus 101, a device management protocol such as SNMP (Simple Network Management Protocol) is used, for example.
[0114] If it is determined in S703 that there is a setting value that turns off, the process proceeds to S705, and the application displays a screen similar to screen 510. If it is determined in S703 that there is no setting value that turns off, the process proceeds to S704, and the application displays a screen similar to screen 520.
[0115] In the subsequent processing, the web browser detects a user operation on screen 510 or screen 520. The application proceeds with the same processing as in the first embodiment based on whether or not it has received information indicating that the operation has been detected. In S711 or S714, the application sends an instruction to change the operation settings to the image forming apparatus 101 based on the generated new setting data. For example, the instruction to change the operation settings is sent using a SetRequest operation of SNMP (Simple Network Management Protocol). Note that the communication protocol used for changing the settings and the method for issuing the instruction for changing the settings are not limited to SNMP. For example, a configuration is possible in which a data file for importing setting values that lists setting items and setting values is generated and sent to the image forming apparatus 101. The image forming apparatus 101, upon receiving this data file, changes its own settings based on the data file.
[0116] The image forming apparatus 101 receives new setting data from the external application and applies it to the settings of the image forming apparatus 101. The image forming apparatus 101 is restarted, and the applied settings are reflected in the operation of the image forming apparatus 101.
[0117] Through the above processing, the user can set the security functions of the image forming apparatus 101 on an application of an external information processing apparatus.
[0118] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of each of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC or FPGA) that realizes one or more functions. [Explanation of symbols]
[0119] 101 Image forming device 410 Operation control section 420 Data storage unit 430 Security setting control section
Claims
1. An information processing apparatus, comprising: a reception unit that receives a selection of one environment from a plurality of different environments as a usage environment of the information processing apparatus; an extraction unit that extracts a value of a security setting item that is changed by setting a plurality of setting values corresponding to the selected one environment; a provision unit that provides notification of the extracted value; The information processing apparatus having the above.
2. The notification notifies that the extracted value is changed from a first value to a second value included in the plurality of values corresponding to the selected one environment. The information processing apparatus according to claim 1, characterized in that.
3. By changing the extracted value by setting the plurality of values corresponding to the selected one environment, a change regarding the use of the function corresponding to the security setting item is made. The information processing apparatus according to claim 1, characterized in that.
4. The provision unit further provides notification of a change regarding the use of the function corresponding to the security setting item. The information processing apparatus according to claim 3, characterized in that.
5. The provision unit further provides notification of the function corresponding to the security setting item. The information processing apparatus according to claim 3, characterized in that.
6. The change regarding the use of the function includes a limitation of the function. The information processing apparatus according to claim 3, characterized in that.
7. A second reception unit that receives a user instruction to set the plurality of values corresponding to the selected one environment; A setting unit that sets the plurality of values corresponding to the selected one environment based on receiving the user instruction; Further comprising: The notification is provided before receiving the user instruction. The information processing apparatus according to claim 1, characterized in that.
8. The plurality of different environments are three or more environments, and when the usage environment is changed from a second environment to a first environment, the first value is notified as the extracted value, when the usage environment is changed from a third environment to the first environment, a second value different from the first value is notified as the extracted value. The information processing apparatus according to claim 1, characterized in that.
9. The provision unit further provides notification of the reason for the change of the extracted value. The information processing apparatus according to claim 1, characterized in that.
10. The information processing apparatus is a printing apparatus, The extracted value includes a value of a security setting item related to communication between the printing device and an external device. The information processing apparatus according to claim 1, characterized in that.
11. The extracted value includes at least one of a value of a security setting item related to a printing protocol used for communication between the printing device and the external device, a value of a security setting item related to a device management protocol used by an administrator of the printing device, and a value of a security setting item related to a file sharing protocol used between the printing device and the external device. The information processing apparatus according to claim 10, characterized in that.
12. The information processing apparatus is a printing device, The extracted value includes at least one of a value of a security setting item related to display of a print job history and a value of a security setting item related to automatic deletion of an interrupted job. The information processing apparatus according to claim 1, characterized in that.
13. A control method for an information processing apparatus, Receiving means for receiving a selection of one environment from a plurality of different environments as the usage environment of the information processing apparatus; Extracting means for extracting a value of a security setting item that is changed by setting a plurality of setting values corresponding to the selected one environment; Providing means for providing a notification of the extracted value; A control method having.
14. A program for causing a computer to execute the control method according to claim 13.
15. An information processing apparatus, Receiving means for receiving a selection of one environment from a plurality of different environments as the usage environment of the information processing apparatus; Providing means for providing a notification of a first plurality of security setting values corresponding to the selected one environment and a second plurality of security setting values to be replaced by the security setting values; An information processing apparatus having.