Web Browsing System, and Method

JP2024022916A5Pending Publication Date: 2025-07-25CANON KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022126366
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-08-08
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Existing web browsing systems, such as those described in Patent Document 1, do not adequately address the use in special network environments, particularly under proxy management, leading to potential security risks and limitations in accessing restricted web pages and local network content.

Method used

A web browsing system that includes an image generation server and communication terminals, utilizing virtual proxies to establish separate communication paths for accessing web content through a cloud browser, allowing secure and appropriate browsing in various network environments.

Benefits of technology

Enables secure and effective browsing of web pages regardless of network configuration, ensuring access to both external and local content while maintaining security through virtual proxy management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a system and a communication terminal that can perform browsing conforming to a communication environment of the communication terminal in a configuration for browsing a web page by using an image creation server.SOLUTION: A cloud browser system 12-00 is a web browsing system having an image creation server 1-30, image forming apparatuses 21-01 to 21-03, and image forming apparatuses 31-01 to 31-03, and the image forming apparatuses construct respective tunnels between the image forming apparatuses and the image creation server so as to allow the image creation server to perform communication through respective virtual proxy units provided by the respective image forming apparatuses. The image creation server downloads web contents from a web page server 1-05 through the respective tunnels, and provides a result of rendering based on the web contents to the respective image forming apparatuses.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a communication terminal used in a Web browsing system. This communication terminal can be applied to image processing devices such as printers, scanners, FAX machines, and multifunction devices thereof, as well as general-purpose information processing devices such as personal computers and mobile terminals. [Background technology]

[0002] Conventionally, communication terminals such as image processing devices (information processing devices) equipped with a web browser (hereinafter referred to as a browser) and having a function for browsing web pages on the browser are known. A communication terminal that accesses a web page of an external service through the web browser can expand its functions by linking with the external service. In addition, when using such a web browser, in certain environments, methods such as restricting access or leaving an access history through a proxy are sometimes used to ensure security.

[0003] Recently, a mechanism called a cloud browser that uses an image generation server that generates rendering results of a web page on a cloud server is being considered. Patent Document 1 discloses a system that renders a web page on a virtual machine on a network different from that of a communication terminal and displays the rendering results on the communication terminal. With such a system, processes with high computational loads, such as analysis and execution of a web page, are executed on the server, so that the required specifications of the communication terminal can be reduced. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2022-41717 Summary of the Invention [Problem to be solved by the invention]

[0005] Patent Document 1 does not consider use in a special network environment, and there is room for improvement. It is desirable for a web browsing system to be able to be used appropriately even in a special network environment.

[0006] For example, in Patent Document 1, when a communication terminal is under proxy management, it is desirable to devise a way to make communication by a web browsing system conform to proxy management. This is because when a communication terminal under proxy management uses a cloud browser function, access permission to the image generation server is set. Then, when the communication terminal notifies the image generation server of the URL of a web page that should be access-restricted, this communication is permitted. Furthermore, the image generation server transmits the rendering result of the web page to the communication terminal, but this communication is permitted. Therefore, the communication terminal can access the web page that should be access-restricted, which may cause a security risk.

[0007] Furthermore, if a communications terminal wishes to render a web page on a web server within a local network, the web content cannot be obtained unless the image generation server has access to the local network.

[0008] The present invention has been made in consideration of the above problems, and has an object to provide a system that enables browsing of Web pages using an image generation server in a manner conforming to the communication environment of a communication terminal.

[0009] The present invention has been made in consideration of the above-mentioned problems, and another object of the present invention is to provide a system that enables browsing of Web pages using an image generation server in a manner that conforms to the communication environment of each of multiple communication terminals. [Means for solving the problem]

[0010] The present invention is a Web browsing system having an image generation server that renders Web content, and first and second communication terminals that communicate with the image generation server and display the Web content based on the results of the rendering, characterized in that the system has a means for establishing a first communication path between the first communication terminal and the image generation server so that the image generation server can communicate via a virtual proxy provided by the first communication terminal, a means for establishing a second communication path between the second communication terminal and the image generation server so that the image generation server can communicate via a virtual proxy provided by the second communication terminal, a means in the image generation server for downloading Web content from a Web server via the first communication path and providing a rendering result based on the Web content to the first communication terminal, and a means in the image generation server for downloading Web content from the Web server via the second communication path and providing a rendering result based on the Web content to the second communication terminal. Effect of the Invention

[0011] According to the present invention, it is possible to provide a system that allows browsing of Web pages using an image generation server in accordance with the communication environment of a communication terminal. [Brief description of the drawings]

[0012] [Figure 1] 1 is a block diagram showing an overall configuration of a cloud browser system. [Diagram 2] 2A and 2B are block diagrams showing the hardware and software configurations of a virtual machine. [Diagram 3] Fig. 3A is a block diagram showing a hardware configuration of the image forming apparatus, and Fig. 3B is a block diagram showing a software configuration of the image forming apparatus. [Figure 4] FIG. 4 illustrates an example of a home screen of the image forming apparatus. [Diagram 5] FIG. 2 is a diagram showing the configuration of a cloud browser screen. [Figure 6] FIG. 13 is a diagram showing a setting screen of a cloud browser. [Figure 7] Fig. 7A is a diagram showing an example of virtual proxy information managed by a virtual machine, and Fig. 7B is a diagram showing an example of session and browser association management information managed by a virtual machine. [Figure 8] FIG. 1 is a diagram showing a usage sequence of a cloud browser system. [Figure 9] FIG. 11 is a flowchart showing a Proxy process of the image forming apparatus. [Figure 10] FIG. 11 is a flowchart showing a process of establishing a tunnel between an image forming apparatus and a virtual machine. [Figure 11] Fig. 11(A) is a diagram showing a setting screen of a cloud browser in another embodiment, and Fig. 11(B) is a diagram showing a setting screen of a virtual machine in another embodiment. [Figure 12] FIG. 1 is a block diagram showing an example of the configuration of a cloud browser system in which image forming apparatuses in multiple networks can access one virtual machine. [Figure 13] Fig. 13A is a diagram showing an example of virtual proxy information managed by a virtual machine, and Fig. 13B is a diagram showing an example of session and browser association management information managed by a virtual machine. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0013] Hereinafter, the embodiment of the present invention will be described in detail with reference to the drawings. Note that the scope of the present invention is not limited to the configurations described in the embodiments. As long as the same effect is obtained, modifications such as replacing part of the configuration or part of the processing with an equivalent or omitting it may be made.

[0014] (Example) <Cloud Browser System> FIG. 1 is a diagram showing the overall configuration of a cloud browser system. The cloud browser system 1-00 is a web browsing system that renders web content on the cloud. The cloud browser system 1-00 includes multiple image forming devices 1-01 to 1-03 and an image generation server 1-30 to which these image forming devices are connected. The cloud browser system 1-00 also includes a web page server 1-05 and a local web page server 1-09 that provide web pages, and a proxy server 1-04. FIG. 1 shows an example in which there is one image generating server 1-30, while three image forming devices 1-01 to 1-03 are connected. However, the number of image forming devices connected to the image generating server 1-30 may be any number. The image generating server 1-30 is configured to provide services to multiple image forming devices in parallel or in a time-sharing manner. Therefore, in the cloud browser system 1-00, the number of image generating servers 1-30 is relatively small compared to the number of image forming devices. In addition, multiple image generation servers may be arranged in the cloud browser system 1-00 for the purpose of distributing the load, etc. In the following, the relationship with the image generation server 1-30 will be described using the image forming device 1-01 as an example representing multiple image forming devices.

[0015] The image generation server 1-30 is a system on the cloud that provides a service that substitutes for the rendering of web content. The image generation server 1-30 includes a gateway 1-06 and a virtual machine 1-07. Although details will be described later, a browser engine, which is a software module, runs on the virtual machine 1-07 of the image generation server 1-30. The browser engine receives a URL transmitted from the image forming device 1-01 via the gateway 1-06. The browser engine then accesses a web page corresponding to the received URL via the gateway 1-06 and receives web content such as HTML from the web page. After that, a rendering result (rendered image) of the received web content is generated by a software module that performs rendering, which is separately prepared. The rendering result is transmitted to the image forming device 1-01 via the gateway 1-06.

[0016] The image forming apparatus 1-01 is an image processing apparatus (information processing apparatus, communication terminal) having a function of forming (printing) an image on a sheet (paper) or a function of sending image data generated by scanning to an arbitrary destination. The image forming apparatus 1-01 may be a printer of either MFP or SFP type. The printing method of the image forming apparatus 1-01 may be either electrophotographic method or inkjet method. The image forming apparatus 1-01 of this embodiment is characterized in that it browses and displays web content on the Internet by using an image generation server 1-30. Details will be described later.

[0017] The image forming device 1-01 is also present in an intranet 1-20 and can communicate with other devices in the same intranet. For example, the image forming device 1-01 can access a web page provided by a local web page server. The image forming device 1-01 can also provide a web page to a user terminal 1-08 by functioning as a web server.

[0018] The proxy server 1-04 is a server that monitors and restricts communication going inside and outside the intranet 1-20. The proxy server 1-04 performs URL filtering (web filtering) to restrict access to websites. This access restriction is performed using a list of websites that are prohibited from being accessed or a list of websites that are permitted to be accessed. Each device in the intranet 1-20 connects to the Internet via or without the proxy server 1-04 according to the settings that each device holds. For example, in FIG. 1, assume that a user operates the image forming device 1-01 to input a request to view a web page server 1-05 that the user wants to view. Then, the image forming device 1-01 transmits the address (hereinafter referred to as URL) of the web page server 1-05 to the image generation server 1-30 via the proxy server 1-04. The proxy server 1-04 is set in the DMZ 1-10. The DMZ (Demilitarized Zone) 1-10 is a segment isolated from the intranet 1-20 for security enhancement.

[0019] <Virtual Machine> FIG. 2A is a block diagram showing the hardware configuration of a virtual machine.

[0020] The virtual machine 1-07 includes a CPU 2-01, a storage 2-02, a RAM 2-03, an interface 2-04, and a communication interface 2-05. Each component is communicatively connected via a bus 2-06.

[0021] A CPU (Central Processing Unit) 2-01 executes various processes using computer programs and data stored in the storage. As a result, the CPU 2-01 controls the operation of the entire virtual machine 1-07, and executes or controls each process to be described later as being performed by the virtual machine 1-07.

[0022] The storage 2-02 stores setting data for the virtual machine 1-07, computer programs and data related to the startup of the virtual machine 1-07, computer programs and data related to the basic operation of the virtual machine 1-07, etc. The RAM 2-03 has an area for storing computer programs and data loaded from the storage 2-02, and data received from an external device via the communication interface 2-05. The RAM 2-03 also has a work area used when the CPU 2-01 executes various processes. In this way, the RAM 2-03 can provide various areas (storage regions) as appropriate.

[0023] The interface 2-04 is an interface including a display unit for displaying the processing results by the CPU 2-01 as images and characters, an operation unit operated by the user to perform various operation inputs, etc. The display unit includes a liquid crystal screen and a touch panel screen, and the operation unit includes a user interface such as a keyboard, a mouse, and a touch panel screen.

[0024] The communication interface 2-05 is an interface for performing data communication with an external device.

[0025] The configuration shown in FIG. 2(A) is merely an example of a configuration applicable to a virtual machine, and is not intended to be limited to the configuration shown in FIG. 2(A). For example, in the configuration shown in FIG. 2(A), a memory device may be further connected to the bus 2-06. The memory device includes, for example, a hard disk drive, a USB memory, a magnetic card, an optical card, an IC card, a memory card, and a drive device (a drive device for a storage medium such as an optical disk such as a flexible disk (FD) or a compact disk (CD)). The virtual machine 1-07 can be configured by a so-called virtualization technology, and various resources constituting a computer system can be organized into logical units independent of the physical configuration. That is, it is possible to integrate multiple resources to configure the virtual machine 1-07, or to divide one resource and configure one of the resources as the virtual machine 1-07. That is, the virtual machine 1-07 can be configured using at least a part of multiple resources (which can be configured by multiple devices) of an information processing system constituting a cloud.

[0026] FIG. 2B is a diagram showing the software configuration of a virtual machine that operates in the cloud browser system. The overall control unit 2-50 is a module that controls the entire virtual machine of the cloud browser system 1-00. The NW control unit 2-54 is a module that receives communication from the outside and transmits data through the communication interface 2-05. The NW control unit 2-54 receives a rendering request for Web content specified by a URL and notifies the overall control unit 2-50 of the request. Rendering refers to generating images and the like from abstract, high-level information described in a data description language or data structure. The overall control unit 2-50 receives the rendering request notification and notifies the browser engine 2-51 of the specified URL. The browser engine 2-51 passes the URL to the HTTP client 2-52 to obtain the Web content indicated by the URL. The HTTP client 2-52 obtains the proxy information set in the proxy setting unit 2-53 and requests the NW control unit 2-54 to obtain the Web content of the specified URL via the proxy. The NW control unit 2-54 accesses the URL via the specified proxy and acquires the Web content. The browser engine 2-51 requests the drawing control unit 2-55 to draw the acquired Web content information. The overall control unit 2-50 transmits the image data drawn by the drawing control unit 2-55 to an external device through the NW control unit 2-54. The virtual proxy unit 3-56 (virtual proxy unit) functions as a proxy that provides the virtual machine 1-07 with a communication environment via the image forming device 1-01. When the virtual proxy unit 3-56 functions, the virtual machine 1-07 accesses the Internet via the proxy server 1-04 and acquires Web content from the Web page server 1-05 or the like. Also, when the virtual proxy unit 3-56 functions, the virtual machine 1-07 accesses the intranet 1-20 and acquires Web content from the local Web page server 1-09 or the like.

[0027] <Image forming device> 3A is a diagram showing the hardware configuration of an image forming apparatus 1-01, which includes a controller unit 3-00, an operation unit 3-12, a USB storage 3-14, a scanner 3-70, and a printer 3-95.

[0028] The operation unit 3-12 is an operation unit that displays information to the user and accepts input from the user.

[0029] The operation unit 3-12 is composed of, for example, a display, a touch panel sensor, and hard keys.

[0030] The USB storage 3-14 is an external storage device that stores data and is detachable from the USB host I / F 3-13.

[0031] The scanner 3-70 is an image reading unit (image reading device, image input device) that reads an image from a document.

[0032] The printer 3-95 is an image forming unit (image forming device, image output device) that forms an image on a sheet (paper).

[0033] The controller unit 3-00 is a control unit having a configuration for performing various controls in the image forming apparatus 1-01. For example, the controller unit 3-00 performs control for implementing a copy function in which image data read by the scanner 37-0 is printed out by the printer 3-95.

[0034] The controller unit 3-00 includes a CPU 3-01, a RAM 3-02, a ROM 3-03, a storage 3-04, and an image path I / F 3-05. These components are connected to each other so as to be able to communicate with each other via a system bus 3-07.

[0035] The controller unit 3-00 also includes an operation unit I / F 3-06, a network I / F 3-10, a USB host I / F 3-13, an RTC 3-15, a device I / F 3-20, a scanner image processing unit 3-80, and a printer image processing unit 3-90. These components are communicatively connected via an image path I / F 3-05 and an image path.

[0036] The CPU 3-01 starts up an operating system (OS) using a boot program stored in the ROM 3-03. The CPU 3-01 executes programs stored in the storage 3-04 on this OS, thereby executing various processes. The RAM 3-02 is used as the working area for the CPU 3-01. The RAM 3-02 provides a working area as well as an image memory area for temporarily storing image data. The storage 3-04 is a storage unit that stores programs and image data. The storage 3-04 can be an HDD, SSD, or eMMC.

[0037] To the CPU 3-01, ROM 3-03, RAM 3-02, operation unit I / F (operation unit interface) 3-06, network I / F 3-10, USB host I / F 3-13, and image bus I / F (image bus interface) 3-05 are connected via a system bus 3-07. The operation unit I / F 3-06 is an interface with the operation unit 3-12, and outputs image data to be displayed on the operation unit 3-12 to the operation unit 3-12. The operation unit I / F 3-06 also sends information input by a user on the operation unit 3-12 to the CPU 3-01. The network I / F 3-10 is an interface for connecting the image forming apparatus to a LAN.

[0038] The USB host I / F 3-13 is an interface unit that communicates with the USB storage 3-14. The USB host I / F 3-13 is an output unit for storing data stored in the storage 3-04 in the USB storage 3-14. The USB host I / F 3-13 also inputs data stored in the USB storage 3-14 and transmits it to the CPU 3-01. A plurality of USB devices including the USB storage 3-14 can be connected to the USB host I / F 3-13.

[0039] The RTC3-15 controls the current time. The time information controlled by the RTC3-15 is used to record the time when a job is submitted, etc.

[0040] The image bus I / F 3-05 is a bus bridge that connects the system bus 3-07 and an image bus 3-08 that transfers image data at high speed and converts the data format. On the image bus 3-08, a device I / F 3-20, a scanner image processing unit 3-80, and a printer image processing unit 3-90 are provided. The device I / F 3-20 is connected to a scanner 3-70 and a printer 3-95, and performs synchronous / asynchronous conversion of image data. The scanner image processing unit 3-80 corrects, processes, and edits input image data. The printer image processing unit 3-90 performs correction, resolution conversion, etc. on print output image data according to the printer 3-95.

[0041] FIG. 3B is a diagram showing the software configuration of the image forming apparatus.

[0042] Each part indicated by a solid line in Fig. 3(B) is a software module realized by the CPU 3-01 executing a main program loaded into the RAM 3-02. The execution of each module of the main program, which will be described later, is managed and controlled by an OS (Operating System) 3-51.

[0043] The UI control unit 3-52 displays a screen on the operation unit 3-12 and accepts operations from the user via the operation unit 3-06. It also has a function of notifying other modules, receiving drawing instructions from other modules, and controlling screen updating.

[0044] The job execution control unit 3-53 is a module that receives a job execution instruction from the UI control unit 3-52 and controls job processing such as copying, scanning, and printing.

[0045] The NW control unit 3-54 receives a communication request from another module, controls the network IF 3-10, and controls communication with an external device. Also, upon receiving a notification from an external device, it notifies the other modules of the content of the notification.

[0046] The storage control unit 3-55 records and manages the setting information and job information recorded in the storage 3-04. Each module located in the OS hierarchy accesses the storage control unit 3-55 to refer to and set the setting values.

[0047] The virtual proxy unit 3-56 provides the virtual machine with a communication environment (a specified communication path) via a tunnel.

[0048] The browser control unit 3-60 is a submodule included in the OS 3-51, and performs control specific to the cloud browser, which will be described later. The number of submodules included in the OS is arbitrary.

[0049] The browser operation unit 3-62 has a function of notifying the command IF unit 3-64 or the proxy processing unit 3-65 of the contents of the user operation when the browser operation unit 3-62 receives a notification of the user operation from the UI control unit 3-52.

[0050] The proxy processing unit 3-65 receives a notification from the browser operation unit 3-62 and requests the storage control unit 3-55 to obtain proxy setting information. If the proxy setting is valid based on the obtained proxy setting information, it requests communication to the proxy server 1-04 via the NW control unit 3-54. It also has a function of receiving a response to the communication request from the NW control unit 3-54 and notifying the browser display unit 3-63 or command IF unit 3-64 of the result of processing the contents of the response.

[0051] The command IF unit 3-64 receives notifications from the browser operation unit 3-62 and the proxy processing unit 3-65, and requests communication with the image generation server 1-30 through the NW control unit 3-54. The communication request at this time may include the notified information. The notified information includes user operations such as text input, link press, scrolling, and zooming. For example, text input includes a URL. When a link is pressed, the pressed coordinates on the operation unit 3-12 are included, and when scrolling and zooming, character strings associated with each are included. In addition, the command IF unit 3-64 accepts communication from the image generation server 1-30 through the NW control unit 3-54. It processes the accepted content and notifies the image data acquisition unit 3-61 or the browser display unit 3-63.

[0052] The image data acquisition unit 3-61 receives the URL of the storage 2-02 in which the rendering result is stored from the command IF unit 3-64, receives the image from the URL, and passes it to the browser display unit 3-63.

[0053] The browser display unit 3-63 receives an image from the image data acquisition unit 3-61 and instructs the UI control unit 3-52 to draw the image. Also, upon receiving a notification from the command IF unit 3-64 and the proxy processing unit 3-65, it instructs the UI control unit 3-52 to draw a screen that displays a message corresponding to the notification.

[0054] <System usage flow> The flow of using the cloud browser system 1-00 having the above-mentioned configuration will be described below. Fig. 8 is a diagram showing the usage sequence of the cloud browser system.

[0055] FIG. 8 shows interactions between a user, a browser control unit 3-60, a virtual proxy unit 3-56, a proxy server 1-04, a virtual machine 1-07, and web page servers 1-05 and 1-09 when using the cloud browser system 1-00.

[0056] When using the cloud browser system 1-00, a user operates the operation unit 3-12 of the image forming apparatus 1-01 to call up the cloud browser function. FIG. 4 is a diagram showing a menu screen displayed on the image forming apparatus. The screen is generated by the CPU 3-01 executing a program constituting the UI control unit 3-52, and is displayed on the operation unit 3-12. Button 4-01 is a button related to the copy function. Button 4-02 is a button related to the print function. Button 4-03 is a button related to the cloud browser. Button 4-04 is a button related to the scan function. When each button is selected, the corresponding function is called up. When button 4-03 is selected, the browser control unit 3-60 is started, and the browser screen 500 is displayed on the operation unit 3-12 (S8-010).

[0057] The browser screen 5-00 includes a back button 5-01, a forward button 5-02, an address bar 5-03, and a settings button 5-04. Below these, there is also a content area 5-05 that displays the rendering results of web content. The functions of these are the same as those of existing browsers.

[0058] The browser control unit 3-60 is configured so that nothing is displayed in the content area 5-05 from when it is started until a URL is input. Note that, like existing browsers, it is also possible to configure it so that a default URL can be registered in an item in the address bar 5-03, and the result of rendering the web content of that URL is displayed immediately after startup. Figure 5 shows an example in which the result of rendering some web content obtained from a web page pointed to by the URL "https: / / ***.***.***.*** / " is displayed.

[0059] The browser control unit 3-60 accesses the virtual machine 1-07 via the proxy server 1-04 and requests the construction of a tunnel between the image forming apparatus 1-01 and the virtual machine 1-07 (S8-020, S8-030). A tunnel, which will be described later, is constructed on this communication session. If a proxy is not set, the image forming apparatus 1-01 communicates with the virtual machine 1-07 without passing through the proxy server 1-04.

[0060] Next, the browser control unit 3-60 starts the virtual proxy function (S8-025). The virtual proxy function will be described in detail later.

[0061] The virtual machine 1-07 that receives the tunnel construction request S8-030 executes a server tunnel construction process S8-040 to construct a tunnel on that communication. Meanwhile, the virtual proxy unit 3-56 also executes a device tunnel construction process S8-045. Details of these tunnel construction processes will be described later with reference to FIG. 10.

[0062] The virtual proxy information is determined by these tunnel construction processes. An example of the virtual proxy information is shown in Figure 7(B). This virtual proxy information consists of a session ID 7-40, a proxy host 7-41, a proxy port 7-42, a proxy authentication ID 7-43, and a proxy authentication password 7-44 (password). The session ID 7-40 is an ID for identifying the client using the virtual machine 1-07. The proxy host 7-41 and the proxy port 7-42 indicate information on the virtual proxy accessed through the tunnel constructed by the tunnel construction process described above. The proxy authentication ID 7-43 and the proxy authentication password 7-44 indicate authentication information for the virtual proxy.

[0063] Next, the virtual machine 1-07 starts the browser engine 2-51 (S8-048).

[0064] Next, the virtual machine 1-07 sets the proxy information in the proxy setting unit 2-53 as the setting information to be used for the started browser engine 2-51. The above-mentioned virtual proxy information sets the proxy host, port, proxy authentication ID, and password as the settings of the browser engine 2-51.

[0065] A typical website includes link information for multiple web contents (such as CSS, JavaScript, and images) in HTML. The browser follows these links to perform HTTP access and obtains the web contents. HTTP access may also be performed dynamically by loaded JavaScript. All of these HTTP accesses are also performed by the browser engine 2-51. Therefore, all of these HTTP accesses pass through the tunnel between the image forming apparatus 1-01 and the virtual machine 1-07 due to the settings of S8-050.

[0066] In S8-058, the virtual machine 1-07 notifies the browser control unit 3-60 of the session ID 7-40 determined in S8-040. Next, in S8-060, the browser control unit 3-60 accesses the virtual machine 1-07 via the proxy server 1-04, notifies the virtual machine 1-07 of the URL of the Web content to be rendered, and requests rendering (S8-060, S8-070).

[0067] 9, this rendering request includes a session ID 9-01 and a URL 9-02 of the web content. This session ID 9-01 specifies the same ID as the session ID 7-40 notified in S8-058. The virtual machine 1-07 that has received the rendering request executes acquisition of the web content of the URL 9-02 included in the rendering request in the browser engine 2-51 (S8-075).

[0068] The proxy setting unit 2-53 issues a web content acquisition request S8-080 for URL 9-02 to the proxy set in S8-050. This web content acquisition request S8-080 is notified to the virtual proxy unit 3-56 through the tunnel built in the tunnel construction S8-040 and S8-045 described above. The virtual proxy unit 3-56 that receives the web content acquisition request S8-080 performs proxy processing S8-085, the details of which will be described later in FIG. 9. In this proxy processing S8-085, a content acquisition request (S8-090, S8-100) is made to the web page server 1-05 specified by the URL. Here too, the setting determines whether communication is made via the proxy server 1-04 or directly to the web page server 1-05. The Web page server 1-05, which receives this content acquisition request S8-100, returns the Web content of the specified URL (S8-110, S8-120).

[0069] The virtual proxy unit 3-56 sends the received web content back to the virtual machine 1-07 (S8-130). The virtual machine 1-07 renders the received web content in the proxy setting unit 2-53 and saves the rendered image (S8-140).

[0070] The virtual machine 1-07 returns a URL for accessing the saved rendering image (S8-150, S8-155).

[0071] The browser control unit 3-60 issues an image acquisition request for the rendering image URL received in S8-155 (S8-160, S8-165).

[0072] The virtual machine 1-07 returns an image corresponding to the URL of the image acquisition request (S8-170, S8-175). The browser control unit 3-60, which has acquired the rendering image, displays the image rendering on the operation unit 3-12 (S8-180). When the user has finished using the image, he or she issues an end request to the browser control unit 3-60 (S8-190).

[0073] When the browser control unit 3-60 receives the termination request, it requests the virtual machine 1-07 to discard the tunnel (S8-200, S8-210). In other words, the tunnel discard request is made when the browser function is terminated. Upon receiving the tunnel discard request, the virtual machine 1-07 discards the tunnel (S8-220) and terminates the proxy setting unit 2-53 (S8-230).

[0074] By operating as described above, even if the image forming device 1-01 and the image generation server 1-30 are in different networks, the image forming device 1-01 can behave as if it were directly accessing the target Web page server. This enables communication via the proxy server 1-04, ensuring security. In addition, even if the content is provided by a local Web page server 1-09 in a private network such as the intranet 1-20, the virtual machine can access it, render it, and provide it to the image forming device 1-01.

[0075] <Proxy settings> FIG. 6 is a diagram showing a setting screen of the cloud browser system. This setting screen can be viewed from an external device by providing it as a web page using the server function of the image forming apparatus 1-01. For example, a user terminal 1-08 connected to the same network line can display a setting screen 4-00 by inputting a specific URL into a web browser. The process of S10-01 is performed using this setting screen. Note that the setting screen 6-00 may be displayed directly on the operation unit 3-12 without being converted into web page information.

[0076] The setting screen 6-00 includes items 6-01, 6-02, 6-03, 6-04, and 6-05.

[0077] Item 6-01 is a setting item for turning the use of the cloud browser function ON / OFF. Checking the checkbox for item 6-01 turns the use of the cloud browser function ON, and the cloud browser button 4-03 appears on screen 6-00. Unchecking the checkbox for item 6-01 turns the use of the cloud browser function OFF, and the cloud browser button 4-03 is removed from screen 6-00. Also, item 6-01 is the first item operated on the settings screen 6-00, and checking the checkbox for item 6-01 makes it possible to operate the other items.

[0078] Item 6-02 is a setting item for setting whether or not to use a proxy. In an environment where a proxy is used for Internet access, check the check box of setting item 6-02 and set the proxy host and port information.

[0079] Item 6-03 is a setting item for setting authentication information for proxy authentication. In an environment where authentication is required to use the proxy, check the check box for item 6-03 and specify the proxy authentication information (ID, Password).

[0080] Item 6-04 is a setting item for setting the startup URL. Checking the checkbox for item 6-04 and entering a URL in the input field will automatically access the specified URL when the cloud browser app is started. The information set here is notified via the network I / F 3-10 and recorded in the storage 3-04.

[0081] The HTTP header specification item 6-06 is an item for specifying the HTTP header to be used when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30. If this setting is enabled, the specified HTTP header (HTTP header for proxy) is additionally set in the HTTP header when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30, and communication is performed. This makes it possible to determine which of the HTTP accesses that pass through the proxy server 1-04 are accesses to the image generation server 1-30. If the proxy server is restricting Web access, this can be used to identify which accesses to restrict, and the effect of appropriately restricting access can be expected.

[0082] <Control> FIG. 10 is a flowchart showing the tunnel construction process between the image forming apparatus and the virtual machine. FIG. 10 explains the details of the ServerTunnel construction S8-040 and the DeviceTunnel construction S8-045. Among the processes shown in FIG. 10, the process on the image forming apparatus 1-01 side is realized by the controller unit 3-00. In detail, the process is realized by loading a program stored in the ROM 3-03 or the storage 3-04 into the RAM 302 and executing it by the CPU 3-01. Among the processes shown in FIG. 8, the process on the virtual machine 1-07 side is realized by loading a program stored in the storage 2-02 into the RAM 2-03 and executing it by the CPU 2-01.

[0083] In the ServerTunnel construction S8-040, the CPU 2-01 determines the session ID that manages the Tunnel (S10-010). The session ID determined here is managed in item 7-40 as shown in Fig. 7(A). This session ID may be in any format as long as it is unique information.

[0084] Next, in order to confirm the authentication information (ID, password) to be used in the virtual Proxy unit 3-56, the CPU 2-01 executes a virtual Proxy authentication confirmation process (S10-020).

[0085] This authentication information (ID, Password) is generated using a random character string, a hash function, etc. The generated authentication information is associated with a session ID and managed in items 7-43 and 7-44. Next, the CPU 2-01 notifies the image forming apparatus 1-01 of the determined authentication information (S10-030).

[0086] Next, the CPU 2-01 determines a port number for communicating with the virtual Proxy unit 3-56 (S10-040). This port number is associated with the session ID and managed in item 7-42.

[0087] Next, the CPU 2-01 listens to the TCP port of the determined port number (S10-050). When this port is accessed, settings are made to communicate with the virtual Proxy unit 3-56. The details of the Server Tunnel construction process S8-040 have been described above.

[0088] Meanwhile, in the DeviceTunnel construction S8-045, the CPU 3-01 receives the virtual Proxy authentication information (ID, Password) (S10-060).

[0089] Next, the CPU 3-01 sets this authentication information as the authentication information of the virtual proxy (S10-070), and then creates a tunnel so that the virtual proxy unit 3-56 can receive the proxy access from the virtual machine 1-07 (S10-080).

[0090] In this manner, a tunnel is established between the virtual machine 1-07 and the image forming apparatus 1-01. In this embodiment, the virtual Proxy authentication confirmation process S10-020 is executed on the virtual machine 1-07 side, and the virtual Proxy information reception process S10-070 is executed on the image forming apparatus 1-01. However, the roles of the virtual machine 1-07 and the image forming apparatus 1-01 may be reversed.

[0091] Next, the details of S8-085 will be described. Fig. 9 is a flowchart showing the Proxy processing of the image forming apparatus. Each process shown in this flowchart is realized by the controller unit 3-00. In detail, the program stored in the ROM 3-03 or storage 3-04 is loaded into the RAM 302, and the CPU 3-01 executes it, thereby realizing the process.

[0092] The proxy process S8-085 is executed by the virtual proxy unit 3-56 when a Web content acquisition request is received from the virtual machine 1-07.

[0093] The CPU 3-01 verifies whether the proxy authentication information added to the Web content acquisition request and the proxy authentication information set in S10-070 are correct (S9-010). If the verification is successful, the CPU 3-01 advances the process to S9-020, and if the verification is unsuccessful, the CPU 3-01 advances the process to S9-070.

[0094] In S9-020, the CPU 3-01 checks whether the URL of the Web content acquisition request is a URL (loopback address) indicating the Web content of the image forming device 1-01. If the URL is the image forming device 1-01, the process proceeds to S9-060, and if not, the process proceeds to S9-030.

[0095] In S9-030, the CPU 3-01 checks whether or not a proxy usage setting has been made. If a proxy usage setting has been made, the process proceeds to S9-050, and if a proxy usage setting has been made, the process proceeds to S9-040.

[0096] In S9-040, the CPU 3-01 performs a process of acquiring the content of the requested URL without going through the proxy, and ends the process.

[0097] In S9-050, the CPU 3-01 transfers the Web content acquisition request to the set Proxy and ends the process.

[0098] In S9-060, the CPU 3-01 acquires (downloads) the Web content provided by the image forming apparatus 1-01, and ends the process.

[0099] In S9-070, the CPU 3-01 returns an authentication error and ends the process.

[0100] As a result, the Web content acquisition request from the virtual machine 1-07 can be processed appropriately.

[0101] <Notes> As described above, in this embodiment, even if the image forming device 1-01 and the image generation server 1-30 are in different networks, the image forming device 1-01 can behave as if it were directly accessing the target Web page server. Therefore, communication via the proxy server 1-04 is possible, and security can be guaranteed. In addition, even if the content is provided by a local Web page server 1-09 in a private network such as the intranet 1-20, the virtual machine 1-07 can access it, render it, and provide it to the image forming device 1-01.

[0102] Example 2 In the first embodiment, an example in which one image forming device connects to one virtual machine via Tunnel has been described. However, due to the nature of web browsing, it is unlikely that one image forming device will always make rendering requests to one virtual machine, fully utilizing the resources of the virtual machine. Therefore, in the second embodiment, an example in which multiple image forming devices connect to one virtual machine via Tunnel will be described.

[0103] <Cloud Browser System> FIG. 12 is a block diagram showing an example of the configuration of a cloud browser system in which image forming apparatuses in multiple networks can access one virtual machine.

[0104] In the cloud browser system 12-00, a Web page server 1-05 and an image generation server 1-30 are accessed from a plurality of intranets (intranet A 12-01, intranet B 12-02).

[0105] In the intranet A12-01, a proxy server 21-04, image forming devices 21-01 to 21-03, a user terminal 21-08, and a local Web page server 21-09 are arranged. The proxy server 21-04 corresponds to the proxy server 1-04. However, it is assumed that the proxy server 21-04 of the second embodiment is arranged in the intranet A12-01. The image forming devices 21-01 to 21-03 correspond to the image forming devices 1-01 to 1-03. The user terminal 21-08 corresponds to the user terminal 1-08. The local Web page server 21-09 corresponds to the local Web page server 1-09.

[0106] Intranet B 12-02, a proxy server 31-04, image forming devices 31-01 to 31-03, a user terminal 31-08, and a local Web page server 31-09 are arranged. Proxy server 31-04 corresponds to Proxy server 1-04. However, it is assumed that the proxy server 31-04 of the second embodiment is arranged in intranet A 12-02. Image forming devices 31-01 to 31-03 correspond to image forming devices 1-01 to 1-03. User terminal 31-08 corresponds to user terminal 1-08. Local Web page server 31-09 corresponds to local Web page server 1-09.

[0107] In addition, in a normal case, devices in the intranet A 12-01 can access the local Web page server 21-09, but devices outside the intranet A 12-01 cannot access it. For example, the image forming device 21-01 can access the local Web page server 21-09, but the image forming device 31-01 and the virtual machine 1-07 cannot access it.

[0108] Similarly, in normal cases, devices within the intranet B12-02 can access the local Web page server 31-09, but devices outside the intranet B12-02 cannot access it. For example, the image forming device 31-01 can access the local Web page server 31-09, but the image forming device 21-01 and the virtual machine 1-07 cannot access it.

[0109] The virtual machine 1-07 in the second embodiment is configured to be able to hold a proxy setting A12-03 and a proxy setting B12-04 simultaneously. The proxy setting A12-03 is setting information for establishing a tunnel connection with, for example, the image forming device 21-01, and the proxy setting B12-04 is setting information for establishing a tunnel connection with, for example, the image forming device 31-01. In this way, the virtual machine 1-07 establishes a tunnel connection in parallel with each device on a different network. Therefore, the virtual machine 1-07 can sequentially accept rendering requests at the same time.

[0110] <Difference> The flow of using the system in the second embodiment is substantially the same as that described in the first embodiment with reference to FIG. 8. However, since it is necessary to start a different browser for each image forming apparatus to be connected, control for each browser is performed in S8-048. Control for each browser is managed using a session ID. FIG. 13(B) is a diagram showing an example of session and browser association management information managed by a virtual machine. As shown in FIG. 13(B), association between a session ID and a browser is managed by a session ID field 13-70 and a browser field 13-71. "Session 2" is a session ID corresponding to a browser for the image forming apparatus 21-01, for example, and "Session 3" is a session ID corresponding to the image forming apparatus 31-01, for example. In this way, a session ID is determined in S10-010 so that a unique session ID can be used for each connection destination.

[0111] Since each browser for each session ID is a browser that connects to a different device, the virtual proxy information used is also different. FIG. 13(A) is a diagram showing an example of virtual proxy information managed by a virtual machine. In the second embodiment, the image forming device to which the tunnel connection is made is distinguished by making the port different for each virtual proxy. Therefore, as shown in the Proxy port column 13-42, a different port number is used for each session ID. For example, "Proxy port 10001" is a port for making a tunnel connection with the image forming device 21-01, and "Proxy port 10002" is a port for making a tunnel connection with the image forming device 31-01. In this way, the processes in S10-020, S10-030, and S10-040 are performed so that the virtual proxy information and port for each connection destination can be used.

[0112] <Notes> As described above, in this embodiment, even if the image generation server 1-30 is in a network different from the image forming apparatus 21-01 and the image forming apparatus 31-01, it is possible for the image forming apparatus 21-01 and the image forming apparatus 31-01 to behave as if they were directly accessing the target Web page server. Therefore, communication via the Proxy server 21-04 and the Proxy server 31-04, which are the respective Proxy servers, is possible, and security can be ensured individually. In addition, it is possible to build a usage environment in which Web contents provided by the local Web page server 21-09 in the intranet 12-01 are provided to the image forming apparatus 21-01 but not to the image forming apparatus 31-01.

[0113] (Other Examples) The present invention is not limited to the above-described embodiments, and various modifications (including organic combinations of the embodiments) are possible based on the spirit of the present invention, and these are not excluded from the scope of the present invention.

[0114] In the embodiment, the description has been given on the assumption that the Tunnel function is used when using the cloud browser system. However, the use of the Tunnel function may be switched ON / OFF by a setting. FIG. 11A is a diagram showing a setting screen of the cloud browser in another embodiment. The setting screen includes an item 11-01. The item 11-01 is an item for setting whether or not to build a Tunnel between the image forming apparatus 1-01 and the virtual machine 1-07. When the item 11-01 is set to be enabled, the operation is performed according to the sequence in FIG. 8. Therefore, when the virtual machine 1-07 attempts to access the Web page server 1-05, the Tunnel can be used to communicate via the Proxy server 1-04, which is normally inaccessible. In addition, the Tunnel can be used to access the local Web page server 1-09, which is normally inaccessible. When the item 11-01 is set to be disabled, the processes of S8-020 and S8-25 are not executed. Therefore, a tunnel is not established between the image forming apparatus 1-01 and the virtual machine 1-07, and the virtual machine 1-07 goes directly to the web page server 1-05 to obtain the web contents.

[0115] In the embodiment, an example has been described in which Proxy authentication for the Tunnel function is performed automatically without the intervention of a user operation. However, a manual setting method involving the intervention of a user operation may be adopted for Proxy authentication for the Tunnel function. For example, an ID and a password are generated on the image forming apparatus 1-01 side and displayed on a setting screen 11-00. The user makes a note of this information and inputs it into a setting screen 11-50 of the virtual machine 1-07. Proxy authentication information required for constructing a Tunnel may be exchanged in this manner.

[0116] The present invention can also be realized by a process in which a program for implementing one or more of the functions of the above-mentioned embodiments is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that implements one or more of the functions.

[0117] The present invention may be applied to a system consisting of multiple devices, or to an apparatus consisting of a single device. For example, a part of a software module may be configured to be executed on an external server, and the function may be realized by obtaining the results of processing on the external server.

[0118] The abbreviations appearing in the examples have the following meanings: ASIC stands for Application Specific Integrated Circuit. CPU stands for Central Processing Unit. EMMC stands for embedded MultiMediaCard. FAX stands for Facsimile. HDD stands for Hard Disk Drive. HTML stands for HyperText Markup Language. HTTP stands for HyperText Transfer Protocol. LAN stands for Local Area Network. MFP stands for Multi Function Peripheral. OS stands for Operating System. RAM stands for Random-Access Memory. ROM stands for Read Only Memory. SFP stands for Single Function Peripheral. SSD stands for Solid State Drive. UI stands for User Interface. URL stands for Uniform Resource Locator. USB stands for Universal Serial Bus. [Explanation of symbols]

[0119] 1-00 Cloud Browser System 1-01 Image forming device 1-04 Proxy Server 1-30 Image generation server

Claims

A Web browsing system comprising a communication terminal having a proxy function and an image generation server that provides a rendering result based on Web content to the communication terminal, a construction means for constructing a predetermined communication path between the communication terminal and the image generation server, a management means for managing proxy information of a proxy used during communication via the predetermined communication path in the image generation server, a download means in the image generation server for downloading Web content from a Web server corresponding to a request received from the communication terminal via the proxy corresponding to the proxy information via the predetermined communication path, and having, when the construction means constructs a first communication path as the predetermined communication path between the first communication terminal and the image generation server, the management means manages information on the proxy function of the first communication terminal used during communication via the first communication path as the proxy information, a Web browsing system characterized in that when the construction means constructs a second communication path as the predetermined communication path between the second communication terminal and the image generation server, the management means additionally manages information on the proxy function of the second communication terminal used during communication via the second communication path as the proxy information. The Web browsing system according to claim 1, wherein the management means manages information on the proxy function of the first communication terminal and information on the proxy function of the second communication terminal in association with respective session IDs for identifying respective connections of the first communication path and the second communication path as the predetermined communication path. The Web browsing system according to claim 1, wherein the management means further manages port numbers used when connecting to each of the first communication terminal and the second communication terminal in association with respective session IDs. The Web browsing system according to claim 1, wherein the communication terminal has display means for displaying a rendering result of the Web content provided from the image generation server. The Web browsing system according to claim 1, wherein the communication terminal includes an image forming unit for forming an image on a sheet.

6. The Web browsing system according to claim 1, wherein the communication terminal includes an image reading unit that reads an image from a document.

7. A method in a Web browsing system having a communication terminal with a proxy function and an image generation server that provides a rendering result based on Web content to the communication terminal, comprising: a construction step of constructing a predetermined communication path between the communication terminal and the image generation server; a management step of managing proxy information of a proxy used during communication via the predetermined communication path in the image generation server; a download step of downloading Web content from a Web server corresponding to a request received from the communication terminal in the image generation server via the proxy corresponding to the proxy information via the predetermined communication path; and when a first communication path is constructed as the predetermined communication path between the first communication terminal and the image generation server, in the management step, information on the proxy function of the first communication terminal used during communication via the first communication path is managed as the proxy information; when a second communication path is constructed as the predetermined communication path between the second communication terminal and the image generation server, in the management step, information on the proxy function of the second communication terminal used during communication via the second communication path is additionally managed as the proxy information.