Web Browsing System, Communication Terminal, and Method

JP2024016354A5Pending Publication Date: 2025-07-23CANON KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022118398
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-07-26
Publication Date
2025-07-23

AI Technical Summary

Technical Problem

Existing web browsing systems, such as those described in Patent Document 1, do not adequately address the use in special network environments, particularly under proxy management, leading to potential security risks and restricted access to web pages.

Method used

A web browsing system that includes an image generation server and a communication terminal, with a communication path constructed via a virtual proxy, allowing the terminal to download web content and render results based on the server's rendering, while ensuring compliance with proxy settings and access permissions.

Benefits of technology

Enables secure browsing in various network environments, including proxy-managed networks, by allowing the communication terminal to access web pages through a virtual proxy, ensuring security and access to local network content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a web browsing system and a communication terminal that browse a web page by using an image creation server, and can perform browsing in conformity to a communication environment of a communication terminal.SOLUTION: A cloud browser system 1-00 is a web browsing system having an image creation server 1-30, and image forming apparatuses 1-01 to 1-03, and the system has means that constructs a tunnel between each of the image forming apparatuses and the image creation server so that the image creation server can perform communication via a virtual proxy provided by the image forming apparatus, and means that, in the image creation server, downloads a web content from a web server via the tunnel and provides a rendering result based on the web content to the image forming apparatus.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a communication terminal used in a Web browsing system. This communication terminal can be applied to image processing devices such as printers, scanners, FAX machines, and multifunction devices thereof, as well as general-purpose information processing devices such as personal computers and mobile terminals. [Background technology]

[0002] Conventionally, communication terminals such as image processing devices (information processing devices) equipped with a web browser (hereinafter referred to as a browser) and having a function for browsing web pages on the browser are known. A communication terminal that accesses a web page of an external service through the web browser can expand its functions by linking with the external service. In addition, when using such a web browser, in certain environments, methods such as restricting access or leaving an access history through a proxy are sometimes used to ensure security.

[0003] Recently, a mechanism called a cloud browser that uses an image generation server that generates rendering results of a web page on a cloud server is being considered. Patent Document 1 discloses a system that renders a web page on a virtual machine on a network different from that of a communication terminal and displays the rendering results on the communication terminal. With such a system, processes with high computational loads, such as analysis and execution of a web page, are executed on the server, so that the required specifications of the communication terminal can be reduced. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2022-41717 Summary of the Invention [Problem to be solved by the invention]

[0005] Patent Document 1 does not consider use in a special network environment, and there is room for improvement. It is desirable for a web browsing system to be able to be used appropriately even in a special network environment.

[0006] For example, in Patent Document 1, when a communication terminal is under proxy management, it is desirable to devise a way to make communication by a web browsing system conform to proxy management. This is because when a communication terminal under proxy management uses a cloud browser function, access permission to the image generation server is set. Then, when the communication terminal notifies the image generation server of the URL of a web page that should be access-restricted, this communication is permitted. Furthermore, the image generation server transmits the rendering result of the web page to the communication terminal, but this communication is permitted. Therefore, the communication terminal can access the web page that should be access-restricted, which may cause a security risk.

[0007] Furthermore, if a communications terminal wishes to render a web page on a web server within a local network, the web content cannot be obtained unless the image generation server has access to the local network.

[0008] The present invention has been made in consideration of the above problems, and has an object to provide a system that enables browsing of Web pages using an image generation server in a manner conforming to the communication environment of a communication terminal. [Means for solving the problem]

[0009] The present invention provides a Web browsing system having an image generation server that renders Web content and a communication terminal that communicates with the image generation server and displays the Web content based on the results of the rendering, characterized in that the system also has a means for establishing a predetermined communication path between the communication terminal and the image generation server so that the image generation server can communicate via a virtual proxy provided by the communication terminal, and a means in the image generation server for downloading Web content from a Web server via the predetermined communication path and providing the communication terminal with rendering results based on the Web content. Effect of the Invention

[0010] According to the present invention, it is possible to provide a system that allows browsing of Web pages using an image generation server in accordance with the communication environment of a communication terminal. [Brief description of the drawings]

[0011] [Figure 1] 1 is a block diagram showing an overall configuration of a cloud browser system. [Diagram 2] 2A and 2B are block diagrams showing the hardware and software configurations of a virtual machine. [Diagram 3] Fig. 3A is a block diagram showing a hardware configuration of the image forming apparatus, and Fig. 3B is a block diagram showing a software configuration of the image forming apparatus. [Figure 4] FIG. 4 illustrates an example of a home screen of the image forming apparatus. [Diagram 5] FIG. 2 is a diagram showing the configuration of a cloud browser screen. [Figure 6] FIG. 13 is a diagram showing a setting screen of a cloud browser. [Figure 7] Fig. 7A is a diagram showing an example of virtual proxy information managed by a virtual machine, and Fig. 7B is a diagram showing an example of session and browser association management information managed by a virtual machine. [Figure 8] FIG. 1 is a diagram showing a usage sequence of a cloud browser system. [Figure 9] FIG. 11 is a flowchart showing a Proxy process of the image forming apparatus. [Figure 10] FIG. 11 is a flowchart showing a process of establishing a tunnel between an image forming apparatus and a virtual machine. [Figure 11] Fig. 11(A) is a diagram showing a setting screen of a cloud browser in another embodiment, and Fig. 11(B) is a diagram showing a setting screen of a virtual machine in another embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] Hereinafter, the embodiment of the present invention will be described in detail with reference to the drawings. Note that the scope of the present invention is not limited to the configurations described in the embodiments. As long as the same effect is obtained, modifications such as replacing part of the configuration or part of the processing with an equivalent or omitting it may be made.

[0013] (Example) FIG. 1 is a diagram showing the overall configuration of a cloud browser system. The cloud browser system 1-00 is a web browsing system that renders web content on the cloud. The cloud browser system 1-00 includes multiple image forming devices 1-01 to 1-03 and an image generation server 1-30 to which these image forming devices are connected. The cloud browser system 1-00 also includes a web page server 1-05 and a local web page server 1-09 that provide web pages, and a proxy server 1-04. FIG. 1 shows an example in which there is one image generating server 1-30, while three image forming devices 1-01 to 1-03 are connected. However, the number of image forming devices connected to the image generating server 1-30 may be any number. The image generating server 1-30 is configured to provide services to multiple image forming devices in parallel or in a time-sharing manner. Therefore, in the cloud browser system 1-00, the number of image generating servers 1-30 is relatively small compared to the number of image forming devices. In addition, multiple image generation servers may be arranged in the cloud browser system 1-00 for the purpose of distributing the load, etc. In the following, the relationship with the image generation server 1-30 will be described using the image forming device 1-01 as an example representing multiple image forming devices.

[0014] The image generation server 1-30 is a system on the cloud that provides a service that substitutes for the rendering of web content. The image generation server 1-30 includes a gateway 1-06 and a virtual machine 1-07. Although details will be described later, a browser engine, which is a software module, runs on the virtual machine 1-07 of the image generation server 1-30. The browser engine receives a URL transmitted from the image forming device 1-01 via the gateway 1-06. The browser engine then accesses a web page corresponding to the received URL via the gateway 1-06 and receives web content such as HTML from the web page. After that, a rendering result (rendered image) of the received web content is generated by a software module that performs rendering, which is separately prepared. The rendering result is transmitted to the image forming device 1-01 via the gateway 1-06.

[0015] The image forming apparatus 1-01 is an image processing apparatus (information processing apparatus, communication terminal) having a function of forming (printing) an image on a sheet (paper) or a function of sending image data generated by scanning to an arbitrary destination. The image forming apparatus 1-01 may be a printer of either MFP or SFP type. The printing method of the image forming apparatus 1-01 may be either electrophotographic method or inkjet method. The image forming apparatus 1-01 of this embodiment is characterized in that it browses and displays web content on the Internet by using an image generation server 1-30. Details will be described later.

[0016] The image forming device 1-01 is also present in an intranet 1-20 and can communicate with other devices in the same intranet. For example, the image forming device 1-01 can access a web page provided by a local web page server. The image forming device 1-01 can also provide a web page to a user terminal 1-08 by functioning as a web server.

[0017] The proxy server 1-04 is a server that monitors and restricts communication going inside and outside the intranet 1-20. The proxy server 1-04 performs URL filtering (web filtering) to restrict access to websites. This access restriction is performed using a list of websites that are prohibited from being accessed or a list of websites that are permitted to be accessed. Each device in the intranet 1-20 connects to the Internet via or without the proxy server 1-04 according to the settings that each device holds. For example, in FIG. 1, assume that a user operates the image forming device 1-01 to input a request to view a web page server 1-05 that the user wants to view. Then, the image forming device 1-01 transmits the address (hereinafter referred to as URL) of the web page server 1-05 to the image generation server 1-30 via the proxy server 1-04. The proxy server 1-04 is set in the DMZ 1-10. The DMZ (Demilitarized Zone) 1-10 is a segment isolated from the intranet 1-20 for security enhancement.

[0018] <Virtual Machine> FIG. 2A is a block diagram showing the hardware configuration of a virtual machine.

[0019] The virtual machine 1-07 includes a CPU 2-01, a storage 2-02, a RAM 2-03, an interface 2-04, and a communication interface 2-05. Each component is communicatively connected via a bus 2-06.

[0020] A CPU (Central Processing Unit) 2-01 executes various processes using computer programs and data stored in the storage. As a result, the CPU 2-01 controls the operation of the entire virtual machine 1-07, and executes or controls each process to be described later as being performed by the virtual machine 1-07.

[0021] The storage 2-02 stores setting data for the virtual machine 1-07, computer programs and data related to the startup of the virtual machine 1-07, computer programs and data related to the basic operation of the virtual machine 1-07, etc. The RAM 2-03 has an area for storing computer programs and data loaded from the storage 2-02, and data received from an external device via the communication interface 2-05. The RAM 2-03 also has a work area used when the CPU 2-01 executes various processes. In this way, the RAM 2-03 can provide various areas (storage regions) as appropriate.

[0022] The interface 2-04 is an interface including a display unit for displaying the processing results by the CPU 2-01 as images and characters, an operation unit operated by the user to perform various operation inputs, etc. The display unit includes a liquid crystal screen and a touch panel screen, and the operation unit includes a user interface such as a keyboard, a mouse, and a touch panel screen.

[0023] The communication interface 2-05 is an interface for performing data communication with an external device.

[0024] The configuration shown in FIG. 2(A) is merely an example of a configuration applicable to a virtual machine, and is not intended to be limited to the configuration shown in FIG. 2(A). For example, in the configuration shown in FIG. 2(A), a memory device may be further connected to the bus 2-06. The memory device includes, for example, a hard disk drive, a USB memory, a magnetic card, an optical card, an IC card, a memory card, and a drive device (a drive device for a storage medium such as an optical disk such as a flexible disk (FD) or a compact disk (CD)). The virtual machine 1-07 can be configured by a so-called virtualization technology, and various resources constituting a computer system can be organized into logical units independent of the physical configuration. That is, it is possible to integrate multiple resources to configure the virtual machine 1-07, or to divide one resource and configure one of the resources as the virtual machine 1-07. That is, the virtual machine 1-07 can be configured using at least a part of multiple resources (which can be configured by multiple devices) of an information processing system constituting a cloud.

[0025] FIG. 2B is a diagram showing the software configuration of a virtual machine that operates in the cloud browser system. The overall control unit 2-50 is a module that controls the entire virtual machine of the cloud browser system 1-00. The NW control unit 2-54 is a module that receives communication from the outside and transmits data through the communication interface 2-05. The NW control unit 2-54 receives a rendering request for Web content specified by a URL and notifies the overall control unit 2-50 of the request. Rendering refers to generating images and the like from abstract, high-level information described in a data description language or data structure. The overall control unit 2-50 receives the rendering request notification and notifies the browser engine 2-51 of the specified URL. The browser engine 2-51 passes the URL to the HTTP client 2-52 to obtain the Web content indicated by the URL. The HTTP client 2-52 obtains the proxy information set in the proxy setting unit 2-53 and requests the NW control unit 2-54 to obtain the Web content of the specified URL via the proxy. The NW control unit 2-54 accesses the URL via the specified proxy and acquires the Web content. The browser engine 2-51 requests the drawing control unit 2-55 to draw the acquired Web content information. The overall control unit 2-50 transmits the image data drawn by the drawing control unit 2-55 to an external device through the NW control unit 2-54. The virtual proxy unit 3-56 (virtual proxy unit) functions as a proxy that provides the virtual machine 1-07 with a communication environment via the image forming device 1-01. When the virtual proxy unit 3-56 functions, the virtual machine 1-07 accesses the Internet via the proxy server 1-04 and acquires Web content from the Web page server 1-05 or the like. Also, when the virtual proxy unit 3-56 functions, the virtual machine 1-07 accesses the intranet 1-20 and acquires Web content from the local Web page server 1-09 or the like.

[0026] <Image forming device> 3A is a diagram showing the hardware configuration of an image forming apparatus 1-01, which includes a controller unit 3-00, an operation unit 3-12, a USB storage 3-14, a scanner 3-70, and a printer 3-95.

[0027] The operation unit 3-12 is an operation unit that displays information to the user and accepts input from the user.

[0028] The operation unit 3-12 is composed of, for example, a display, a touch panel sensor, and hard keys.

[0029] The USB storage 3-14 is an external storage device that stores data and is detachable from the USB host I / F 3-13.

[0030] The scanner 3-70 is an image reading unit (image reading device, image input device) that reads an image from a document.

[0031] The printer 3-95 is an image forming unit (image forming device, image output device) that forms an image on a sheet (paper).

[0032] The controller unit 3-00 is a control unit having a configuration for performing various controls in the image forming apparatus 1-01. For example, the controller unit 3-00 performs control for implementing a copy function in which image data read by the scanner 37-0 is printed out by the printer 3-95.

[0033] The controller unit 3-00 includes a CPU 3-01, a RAM 3-02, a ROM 3-03, a storage 3-04, and an image path I / F 3-05. These components are connected to each other so as to be able to communicate with each other via a system bus 3-07.

[0034] The controller unit 3-00 also includes an operation unit I / F 3-06, a network I / F 3-10, a USB host I / F 3-13, an RTC 3-15, a device I / F 3-20, a scanner image processing unit 3-80, and a printer image processing unit 3-90. These components are communicatively connected via an image path I / F 3-05 and an image path.

[0035] The CPU 3-01 starts up an operating system (OS) using a boot program stored in the ROM 3-03. The CPU 3-01 executes programs stored in the storage 3-04 on this OS, thereby executing various processes. The RAM 3-02 is used as the working area for the CPU 3-01. The RAM 3-02 provides a working area as well as an image memory area for temporarily storing image data. The storage 3-04 is a storage unit that stores programs and image data. The storage 3-04 can be an HDD, SSD, or eMMC.

[0036] To the CPU 3-01, ROM 3-03, RAM 3-02, operation unit I / F (operation unit interface) 3-06, network I / F 3-10, USB host I / F 3-13, and image bus I / F (image bus interface) 3-05 are connected via a system bus 3-07. The operation unit I / F 3-06 is an interface with the operation unit 3-12, and outputs image data to be displayed on the operation unit 3-12 to the operation unit 3-12. The operation unit I / F 3-06 also sends information input by a user on the operation unit 3-12 to the CPU 3-01. The network I / F 3-10 is an interface for connecting the image forming apparatus to a LAN.

[0037] The USB host I / F 3-13 is an interface unit that communicates with the USB storage 3-14. The USB host I / F 3-13 is an output unit for storing data stored in the storage 3-04 in the USB storage 3-14. The USB host I / F 3-13 also inputs data stored in the USB storage 3-14 and transmits it to the CPU 3-01. A plurality of USB devices including the USB storage 3-14 can be connected to the USB host I / F 3-13.

[0038] The RTC3-15 controls the current time. The time information controlled by the RTC3-15 is used to record the time when a job is submitted, etc.

[0039] The image bus I / F 3-05 is a bus bridge that connects the system bus 3-07 and an image bus 3-08 that transfers image data at high speed and converts the data format. On the image bus 3-08, a device I / F 3-20, a scanner image processing unit 3-80, and a printer image processing unit 3-90 are provided. The device I / F 3-20 is connected to a scanner 3-70 and a printer 3-95, and performs synchronous / asynchronous conversion of image data. The scanner image processing unit 3-80 corrects, processes, and edits input image data. The printer image processing unit 3-90 performs correction, resolution conversion, etc. on print output image data according to the printer 3-95.

[0040] FIG. 3B is a diagram showing the software configuration of the image forming apparatus.

[0041] Each part indicated by a solid line in Fig. 3(B) is a software module realized by the CPU 3-01 executing a main program loaded into the RAM 3-02. The execution of each module of the main program, which will be described later, is managed and controlled by an OS (Operating System) 3-51.

[0042] The UI control unit 3-52 displays a screen on the operation unit 3-12 and accepts operations from the user via the operation unit 3-06. It also has a function of notifying other modules, receiving drawing instructions from other modules, and controlling screen updating.

[0043] The job execution control unit 3-53 is a module that receives a job execution instruction from the UI control unit 3-52 and controls job processing such as copying, scanning, and printing.

[0044] The NW control unit 3-54 receives a communication request from another module, controls the network IF 3-10, and controls communication with an external device. Also, upon receiving a notification from an external device, it notifies the other modules of the content of the notification.

[0045] The storage control unit 3-55 records and manages the setting information and job information recorded in the storage 3-04. Each module located in the OS hierarchy accesses the storage control unit 3-55 to refer to and set the setting values.

[0046] The virtual proxy unit 3-56 provides the virtual machine with a communication environment (a specified communication path) via a tunnel.

[0047] The browser control unit 3-60 is a submodule included in the OS 3-51, and performs control specific to the cloud browser, which will be described later. The number of submodules included in the OS is arbitrary.

[0048] The browser operation unit 3-62 has a function of notifying the command IF unit 3-64 or the proxy processing unit 3-65 of the contents of the user operation when the browser operation unit 3-62 receives a notification of the user operation from the UI control unit 3-52.

[0049] The proxy processing unit 3-65 receives a notification from the browser operation unit 3-62 and requests the storage control unit 3-55 to obtain proxy setting information. If the proxy setting is valid based on the obtained proxy setting information, it requests communication to the proxy server 1-04 via the NW control unit 3-54. It also has a function of receiving a response to the communication request from the NW control unit 3-54 and notifying the browser display unit 3-63 or command IF unit 3-64 of the result of processing the contents of the response.

[0050] The command IF unit 3-64 receives notifications from the browser operation unit 3-62 and the proxy processing unit 3-65, and requests communication with the image generation server 1-30 through the NW control unit 3-54. The communication request at this time may include the notified information. The notified information includes user operations such as text input, link press, scrolling, and zooming. For example, text input includes a URL. When a link is pressed, the pressed coordinates on the operation unit 3-12 are included, and when scrolling and zooming, character strings associated with each are included. In addition, the command IF unit 3-64 accepts communication from the image generation server 1-30 through the NW control unit 3-54. It processes the accepted content and notifies the image data acquisition unit 3-61 or the browser display unit 3-63.

[0051] The image data acquisition unit 3-61 receives the URL of the storage 2-02 in which the rendering result is stored from the command IF unit 3-64, receives the image from the URL, and passes it to the browser display unit 3-63.

[0052] The browser display unit 3-63 receives an image from the image data acquisition unit 3-61 and instructs the UI control unit 3-52 to draw the image. Also, upon receiving a notification from the command IF unit 3-64 and the proxy processing unit 3-65, it instructs the UI control unit 3-52 to draw a screen that displays a message corresponding to the notification.

[0053] <System usage flow> The flow of using the cloud browser system 1-00 having the above-mentioned configuration will be described below. Fig. 8 is a diagram showing the usage sequence of the cloud browser system.

[0054] FIG. 8 shows interactions between a user, a browser control unit 3-60, a virtual proxy unit 3-56, a proxy server 1-04, a virtual machine 1-07, and web page servers 1-05 and 1-09 when using the cloud browser system 1-00.

[0055] When using the cloud browser system 1-00, a user operates the operation unit 3-12 of the image forming apparatus 1-01 to call up the cloud browser function. FIG. 4 is a diagram showing a menu screen displayed on the image forming apparatus. The screen is generated by the CPU 3-01 executing a program constituting the UI control unit 3-52, and is displayed on the operation unit 3-12. Button 4-01 is a button related to the copy function. Button 4-02 is a button related to the print function. Button 4-03 is a button related to the cloud browser. Button 4-04 is a button related to the scan function. When each button is selected, the corresponding function is called up. When button 4-03 is selected, the browser control unit 3-60 is started, and the browser screen 500 is displayed on the operation unit 3-12 (S8-010).

[0056] The browser screen 5-00 includes a back button 5-01, a forward button 5-02, an address bar 5-03, and a settings button 5-04. Below these, there is also a content area 5-05 that displays the rendering results of web content. The functions of these are the same as those of existing browsers.

[0057] The browser control unit 3-60 is configured so that nothing is displayed in the content area 5-05 from when it is started until a URL is input. Note that, like existing browsers, it is also possible to configure it so that a default URL can be registered in an item in the address bar 5-03, and the result of rendering the web content of that URL is displayed immediately after startup. Figure 5 shows an example in which the result of rendering some web content obtained from a web page pointed to by the URL "https: / / ***.***.***.*** / " is displayed.

[0058] The browser control unit 3-60 accesses the virtual machine 1-07 via the proxy server 1-04 and requests the construction of a tunnel between the image forming apparatus 1-01 and the virtual machine 1-07 (S8-020, S8-030). A tunnel, which will be described later, is constructed on this communication session. If a proxy is not set, the image forming apparatus 1-01 communicates with the virtual machine 1-07 without passing through the proxy server 1-04.

[0059] Next, the browser control unit 3-60 starts the virtual proxy function (S8-025). The virtual proxy function will be described in detail later.

[0060] The virtual machine 1-07 that receives the tunnel construction request S8-030 executes a server tunnel construction process S8-040 to construct a tunnel on that communication. Meanwhile, the virtual proxy unit 3-56 also executes a device tunnel construction process S8-045. Details of these tunnel construction processes will be described later with reference to FIG. 10.

[0061] The virtual proxy information is determined by these tunnel construction processes. An example of the virtual proxy information is shown in Figure 7(B). This virtual proxy information consists of a session ID 7-40, a proxy host 7-41, a proxy port 7-42, a proxy authentication ID 7-43, and a proxy authentication password 7-44 (password). The session ID 7-40 is an ID for identifying the client using the virtual machine 1-07. The proxy host 7-41 and the proxy port 7-42 indicate information on the virtual proxy accessed through the tunnel constructed by the tunnel construction process described above. The proxy authentication ID 7-43 and the proxy authentication password 7-44 indicate authentication information for the virtual proxy.

[0062] Next, the virtual machine 1-07 starts the browser engine 2-51 (S8-045).

[0063] Next, the virtual machine 1-07 sets the proxy information in the proxy setting unit 2-53 as the setting information to be used for the started browser engine 2-51. The above-mentioned virtual proxy information sets the proxy host, port, proxy authentication ID, and password as the settings of the browser engine 2-51.

[0064] A typical website includes link information for multiple web contents (such as CSS, JavaScript, and images) in HTML. The browser follows these links to perform HTTP access and obtains the web contents. HTTP access may also be performed dynamically by loaded JavaScript. All of these HTTP accesses are also performed by the browser engine 2-51. Therefore, all of these HTTP accesses pass through the tunnel between the image forming apparatus 1-01 and the virtual machine 1-07 due to the settings of S8-050.

[0065] In S8-058, the virtual machine 1-07 notifies the browser control unit 3-60 of the session ID 7-40 determined in S8-040. Next, in S8-060, the browser control unit 3-60 accesses the virtual machine 1-07 via the proxy server 1-04, notifies the virtual machine 1-07 of the URL of the Web content to be rendered, and requests rendering (S8-060, S8-070).

[0066] 9, this rendering request includes a session ID 9-01 and a URL 9-02 of the web content. This session ID 9-01 specifies the same ID as the session ID 7-40 notified in S8-058. The virtual machine 1-07 that has received the rendering request executes acquisition of the web content of the URL 9-02 included in the rendering request in the browser engine 2-51 (S8-075).

[0067] The proxy setting unit 2-53 issues a web content acquisition request S8-080 for URL 9-02 to the proxy set in S8-050. This web content acquisition request S8-080 is notified to the virtual proxy unit 3-56 through the tunnel built in the tunnel construction S8-040 and S8-045 described above. The virtual proxy unit 3-56 that receives the web content acquisition request S8-080 performs proxy processing S8-085, the details of which will be described later in FIG. 9. In this proxy processing S8-085, a content acquisition request (S8-090, S8-100) is made to the web page server 1-05 specified by the URL. Here too, the setting determines whether communication is made via the proxy server 1-04 or directly to the web page server 1-05. The Web page server 1-05, which receives this content acquisition request S8-100, returns the Web content of the specified URL (S8-110, S8-120).

[0068] The virtual proxy unit 3-56 sends the received web content back to the virtual machine 1-07 (S8-130). The virtual machine 1-07 renders the received web content in the proxy setting unit 2-53 and saves the rendered image (S8-140).

[0069] The virtual machine 1-07 returns a URL for accessing the saved rendering image (S8-150, S8-155).

[0070] The browser control unit 3-60 issues an image acquisition request for the rendering image URL received in S8-155 (S8-160, S8-165).

[0071] The virtual machine 1-07 returns an image corresponding to the URL of the image acquisition request (S8-170, S8-175). The browser control unit 3-60, which has acquired the rendering image, displays the image rendering on the operation unit 3-12 (S8-180). When the user has finished using the image, he or she issues an end request to the browser control unit 3-60 (S8-190).

[0072] When the browser control unit 3-60 receives the termination request, it requests the virtual machine 1-07 to discard the tunnel (S8-200, S8-210). In other words, the tunnel discard request is made when the browser function is terminated. Upon receiving the tunnel discard request, the virtual machine 1-07 discards the tunnel (S8-220) and terminates the proxy setting unit 2-53 (S8-230).

[0073] By operating as described above, even if the image forming device 1-01 and the image generation server 1-30 are in different networks, the image forming device 1-01 can behave as if it were directly accessing the target Web page server. This enables communication via the proxy server 1-04, ensuring security. In addition, even if the content is provided by a local Web page server 1-09 in a private network such as the intranet 1-20, the virtual machine can access it, render it, and provide it to the image forming device 1-01.

[0074] <Proxy settings> FIG. 6 is a diagram showing a setting screen of the cloud browser system. This setting screen can be viewed from an external device by providing it as a web page using the server function of the image forming apparatus 1-01. For example, a user terminal 1-08 connected to the same network line can display a setting screen 4-00 by inputting a specific URL into a web browser. The process of S10-01 is performed using this setting screen. Note that the setting screen 6-00 may be displayed directly on the operation unit 3-12 without being converted into web page information.

[0075] The setting screen 6-00 includes items 6-01, 6-02, 6-03, 6-04, and 6-05.

[0076] Item 6-01 is a setting item for turning the use of the cloud browser function ON / OFF. Checking the checkbox for item 6-01 turns the use of the cloud browser function ON, and the cloud browser button 4-03 appears on screen 6-00. Unchecking the checkbox for item 6-01 turns the use of the cloud browser function OFF, and the cloud browser button 4-03 is removed from screen 6-00. Also, item 6-01 is the first item operated on the settings screen 6-00, and checking the checkbox for item 6-01 makes it possible to operate the other items.

[0077] Item 6-02 is a setting item for setting whether or not to use a proxy. In an environment where a proxy is used for Internet access, check the check box of setting item 6-02 and set the proxy host and port information.

[0078] Item 6-03 is a setting item for setting authentication information for proxy authentication. In an environment where authentication is required to use the proxy, check the check box for item 6-03 and specify the proxy authentication information (ID, Password).

[0079] Item 6-04 is a setting item for setting the startup URL. Checking the checkbox for item 6-04 and entering a URL in the input field will automatically access the specified URL when the cloud browser app is started. The information set here is notified via the network I / F 3-10 and recorded in the storage 3-04.

[0080] The HTTP header specification item 6-06 is an item for specifying the HTTP header to be used when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30. If this setting is enabled, the specified HTTP header (HTTP header for proxy) is additionally set in the HTTP header when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30, and communication is performed. This makes it possible to determine which of the HTTP accesses that pass through the proxy server 1-04 are accesses to the image generation server 1-30. If the proxy server is restricting Web access, this can be used to identify which accesses to restrict, and the effect of appropriately restricting access can be expected.

[0081] <Control> FIG. 10 is a flowchart showing the tunnel construction process between the image forming apparatus and the virtual machine. FIG. 10 explains the details of the ServerTunnel construction S8-040 and the DeviceTunnel construction S8-045. Among the processes shown in FIG. 10, the process on the image forming apparatus 1-01 side is realized by the controller unit 3-00. In detail, the process is realized by loading a program stored in the ROM 3-03 or the storage 3-04 into the RAM 302 and executing it by the CPU 3-01. Among the processes shown in FIG. 8, the process on the virtual machine 1-07 side is realized by loading a program stored in the storage 2-02 into the RAM 2-03 and executing it by the CPU 2-01.

[0082] In the ServerTunnel construction S8-040, the CPU 2-01 determines the session ID that manages the Tunnel (S10-010). The session ID determined here is managed in item 7-40 as shown in Fig. 7(A). This session ID may be in any format as long as it is unique information.

[0083] Next, in order to confirm the authentication information (ID, password) to be used in the virtual Proxy unit 3-56, the CPU 2-01 executes a virtual Proxy authentication confirmation process (S10-020).

[0084] This authentication information (ID, Password) is generated using a random character string, a hash function, etc. The generated authentication information is associated with a session ID and managed in items 7-43 and 7-44. Next, the CPU 2-01 notifies the image forming apparatus 1-01 of the determined authentication information (S10-030).

[0085] Next, the CPU 2-01 determines a port number for communicating with the virtual Proxy unit 3-56 (S10-040). This port number is associated with the session ID and managed in item 7-42.

[0086] Next, the CPU 2-01 listens to the TCP port of the determined port number (S10-050). When this port is accessed, settings are made to communicate with the virtual Proxy unit 3-56. The details of the Server Tunnel construction process S8-040 have been described above.

[0087] Meanwhile, in the DeviceTunnel construction S8-045, the CPU 3-01 receives the virtual Proxy authentication information (ID, Password) (S10-060).

[0088] Next, the CPU 3-01 sets this authentication information as the authentication information of the virtual proxy (S10-070), and then creates a tunnel so that the virtual proxy unit 3-56 can receive the proxy access from the virtual machine 1-07 (S10-080).

[0089] In this manner, a tunnel is established between the virtual machine 1-07 and the image forming apparatus 1-01. In this embodiment, the virtual Proxy authentication confirmation process S10-020 is executed on the virtual machine 1-07 side, and the virtual Proxy information reception process S10-070 is executed on the image forming apparatus 1-01. However, the roles of the virtual machine 1-07 and the image forming apparatus 1-01 may be reversed.

[0090] Next, the details of S9-085 will be described. Fig. 9 is a flowchart showing the Proxy processing of the image forming apparatus. Each process shown in this flowchart is realized by the controller unit 3-00. In detail, the program stored in the ROM 3-03 or storage 3-04 is loaded into the RAM 302, and the CPU 3-01 executes it, thereby realizing the process.

[0091] The proxy process S9-085 is executed by the virtual proxy unit 3-56 when a Web content acquisition request is received from the virtual machine 1-07.

[0092] The CPU 3-01 verifies whether the proxy authentication information added to the Web content acquisition request and the proxy authentication information set in S10-070 are correct (S9-010). If the verification is successful, the CPU 3-01 advances the process to S9-020, and if the verification is unsuccessful, the CPU 3-01 advances the process to S9-070.

[0093] In S9-020, the CPU 3-01 checks whether the URL of the Web content acquisition request is a URL (loopback address) indicating the Web content of the image forming device 1-01. If the URL is the image forming device 1-01, the process proceeds to S9-060, and if not, the process proceeds to S9-030.

[0094] In S9-030, the CPU 3-01 checks whether or not a proxy usage setting has been made. If a proxy usage setting has been made, the process proceeds to S9-050, and if a proxy usage setting has been made, the process proceeds to S9-040.

[0095] In S9-040, the CPU 3-01 performs a process of acquiring the content of the requested URL without going through the proxy, and ends the process.

[0096] In S9-050, the CPU 3-01 transfers the Web content acquisition request to the set Proxy and ends the process.

[0097] In S9-060, the CPU 3-01 acquires (downloads) the Web content provided by the image forming apparatus 1-01, and ends the process.

[0098] In S9-070, the CPU 3-01 returns an authentication error and ends the process.

[0099] As a result, the Web content acquisition request from the virtual machine 1-07 can be processed appropriately.

[0100] <Notes> As described above, in this embodiment, even if the image forming device 1-01 and the image generation server 1-30 are in different networks, the image forming device 1-01 can behave as if it were directly accessing the target Web page server. Therefore, communication via the proxy server 1-04 is possible, and security can be guaranteed. In addition, even if the content is provided by a local Web page server 1-09 in a private network such as the intranet 1-20, the virtual machine 1-07 can access it, render it, and provide it to the image forming device 1-01.

[0101] (Other Examples) The present invention is not limited to the above-described embodiments, and various modifications (including organic combinations of the embodiments) are possible based on the spirit of the present invention, and these are not excluded from the scope of the present invention.

[0102] In the embodiment, the description has been given on the assumption that the Tunnel function is used when using the cloud browser system. However, the use of the Tunnel function may be switched ON / OFF by a setting. FIG. 11A is a diagram showing a setting screen of the cloud browser in another embodiment. The setting screen includes an item 11-01. The item 11-01 is an item for setting whether or not to build a Tunnel between the image forming apparatus 1-01 and the virtual machine 1-07. When the item 11-01 is set to be enabled, the operation is performed according to the sequence in FIG. 8. Therefore, when the virtual machine 1-07 attempts to access the Web page server 1-05, the Tunnel can be used to communicate via the Proxy server 1-04, which is normally inaccessible. In addition, the Tunnel can be used to access the local Web page server 1-09, which is normally inaccessible. When the item 11-01 is set to be disabled, the processes of S8-020 and S8-25 are not executed. Therefore, a tunnel is not established between the image forming apparatus 1-01 and the virtual machine 1-07, and the virtual machine 1-07 goes directly to the web page server 1-05 to obtain the web contents.

[0103] In the embodiment, an example has been described in which Proxy authentication for the Tunnel function is performed automatically without the intervention of a user operation. However, a manual setting method involving the intervention of a user operation may be adopted for Proxy authentication for the Tunnel function. For example, an ID and a password are generated on the image forming apparatus 1-01 side and displayed on a setting screen 11-00. The user makes a note of this information and inputs it into a setting screen 11-50 of the virtual machine 1-07. Proxy authentication information required for constructing a Tunnel may be exchanged in this manner.

[0104] The present invention can also be realized by a process in which a program for implementing one or more of the functions of the above-mentioned embodiments is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that implements one or more of the functions.

[0105] The present invention may be applied to a system consisting of multiple devices, or to an apparatus consisting of a single device. For example, a part of a software module may be configured to be executed on an external server, and the function may be realized by obtaining the results of processing on the external server.

[0106] The abbreviations appearing in the examples have the following meanings: ASIC stands for Application Specific Integrated Circuit. CPU stands for Central Processing Unit. EMMC stands for embedded MultiMediaCard. FAX stands for Facsimile. HDD stands for Hard Disk Drive. HTML stands for HyperText Markup Language. HTTP stands for HyperText Transfer Protocol. LAN stands for Local Area Network. MFP stands for Multi Function Peripheral. OS stands for Operating System. RAM stands for Random-Access Memory. ROM stands for Read Only Memory. SFP stands for Single Function Peripheral SSD stands for Solid State Drive. UI stands for User Interface. URL stands for Uniform Resource Locator. USB stands for Universal Serial Bus. [Explanation of symbols]

[0107] 1-00 Cloud Browser System 1-01 Image forming device 1-04 Proxy Server 1-30 Image generation server

Claims

1. A Web browsing system having an image generation server for rendering Web content and a communication terminal having a proxy function, means for constructing a predetermined communication path between the communication terminal and the image generation server; request means in the communication terminal for sending a request for Web content to the image generation server; download means in the image generation server for downloading Web content from a Web server corresponding to the request via the proxy function of the communication terminal through the predetermined communication path; providing means in the image generation server for providing a rendering result based on the downloaded Web content to the communication terminal; display means in the communication terminal for displaying the rendering result; A Web browsing system characterized by comprising the above.

2. The Web browsing system further includes a proxy server for monitoring communication from the communication terminal to an external network, The download of the Web content by the download means is realized by the proxy function of the communication terminal that has received a content acquisition request from the image generation server transferring the Web content obtained from the Web server via the proxy server to the image generation server. The Web browsing system according to Claim 1, characterized in that.

3. The Web browsing system according to Claim 1, further comprising setting means for setting proxy information of the proxy function of the communication terminal as a proxy setting when performing communication through the predetermined communication path in the image generation server.

4. The predetermined communication path is constructed when the function as the display means for displaying the rendering result of the communication terminal is activated, and is discarded when the function ends. The Web browsing system according to Claim 1, characterized in that.

5. The communication terminal is provided with an image forming unit for forming an image on a sheet. The Web browsing system according to Claim 1, characterized in that.

6. The communication terminal is provided with an image reading unit for reading an image from a document. The Web browsing system according to Claim 1, characterized in that.

7. A communication terminal having a proxy function, means for constructing a predetermined communication path between the communication terminal and the image generation server; request means for sending a request for Web content to the image generation server; receiving means for receiving, from the image generation server, a rendering result based on Web content downloaded by the image generation server from a Web server via the proxy function of the communication terminal through the predetermined communication path; display means for displaying the rendering result; A communication terminal, characterized by comprising the above. **Claim 8**: A method in a communication terminal having a proxy function, comprising: a step of constructing a predetermined communication path between the communication terminal and the image generation server; a request step of sending a request for Web content to the image generation server; a receiving step of receiving, from the image generation server, a rendering result based on Web content downloaded by the image generation server from a Web server via the proxy function of the communication terminal through the predetermined communication path; a display step of displaying the rendering result; A method, characterized by comprising the above.