Printer, control method for printer and program
Patent Information
- Application Number
- JP2023208658
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-12-08
- Filing Date
- 2023-12-11
- Publication Date
- 2025-05-22
- Estimated Expiration
- 2042-05-18
AI Technical Summary
Existing systems fail to consider the specific usage environment when setting security-related functions for image forming apparatuses, leading to uncertainty in selecting appropriate security levels.
A printing device that allows users to select a usage environment and automatically sets security-related functions based on predefined settings suitable for that environment, using a storage means to associate setting values with different environments and a reception means to receive environment selection information, and a setting changing means to adjust settings accordingly.
Enables users to set security functions appropriately for their environment, improving convenience and ensuring security measures are tailored to the specific context of use.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a printing device that performs settings for security-related functions in a single operation. [Background technology]
[0002] Generally, information processing devices connected to a network have a setting function that allows users to set security-related functions. In recent years, information processing devices have been installed in a variety of environments, such as telecommuting and public spaces shared by an unspecified number of people, and the required security settings have become more complex.
[0003] Therefore, Patent Document 1 discloses a technique in which a user specifies a security level from a range of stages, and the security-related functions of an image forming apparatus are all set in accordance with the security level. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-185814 Summary of the Invention [Problem to be solved by the invention]
[0005] However, Patent Document 1 does not take into consideration the setting of security-related functions suitable for the usage environment of the image forming device, which may result in the user not knowing which security level to specify for the usage environment of the image forming device.
[0006] One object of the present invention is to provide an information processing device that accepts a user operation to select a usage environment for a printing device and sets security-related functions appropriate for the selected usage environment. Another object of the present invention is to improve the convenience of setting security-related functions. [Means for solving the problem]
[0007] In order to achieve at least one of the above-mentioned objects, a printing device as one aspect of the present invention comprises a storage means for storing a set of setting values including a plurality of setting values corresponding to a plurality of setting items including security setting items specific to the printing device, which is associated with a first usage environment, and a set of setting values including a plurality of setting values corresponding to a plurality of setting items not including security setting items specific to the printing device, which is associated with a second usage environment; a receiving means for receiving information indicating a selection result for identifying the usage environment of the printing device; and a setting change means for changing the setting values of the printing device based on the set of setting values corresponding to the first usage environment or the second usage environment identified by the information indicating the selection result, which is stored in the storage means. [Effects of the Invention]
[0008] According to one aspect of the present invention, it is possible to provide a printing device that allows a user to select a usage environment for the printing device, and then configures security-related functions to suit the selected usage environment. Another aspect of the present invention is to improve the convenience of configuring security-related functions. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of a usage environment of an information processing device. [Figure 2] 10 is a flowchart showing an example of conditions for classifying the usage environment of an information processing device. [Figure 3] FIG. 2 illustrates an example of a hardware configuration of an image forming apparatus 101. [Figure 4]FIG. 2 illustrates an example of a software configuration of the image forming apparatus 101. [Figure 5] FIG. 3 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the first embodiment. [Figure 6] 10 is a flowchart showing an example of security setting processing executed by the image forming apparatus 101. [Figure 7] 10 is a flowchart showing an example of a security setting cancellation process executed by the image forming apparatus 101. [Figure 8] FIG. 10 is a diagram showing an example of a screen displayed on an operation unit 320 of the image forming apparatus 101 in the second embodiment. [Figure 9] 10 is a flowchart showing an example of a screen display and security setting process executed by the image forming apparatus 101 in the second embodiment. [Figure 10] 10 is a flowchart showing an example of a screen display and security setting process executed by the image forming apparatus 101 in the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] The following describes embodiments of the present invention with reference to the drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0011] First Embodiment FIG. 1 is a configuration diagram illustrating an example of a usage environment of an information processing device according to this embodiment.
[0012] Image forming apparatuses 101 to 104, which are examples of information processing apparatuses in this embodiment, are installed in different usage environments 111 to 114. The usage environments 111 to 114 illustrated in Fig. 1 are an in-house intranet environment 111, a direct internet connection environment 112, an internet-prohibited environment 113, and a home environment 114, respectively.
[0013] The company intranet environment 111 is an environment in which an image forming apparatus 101 and a PC 121 are connected via a company's in-house local area network (LAN) 131. A firewall 141 is installed at the boundary between the LAN 131 and the Internet 100. That is, communication between each information processing device in the company intra environment 111 and the Internet 100 is monitored and protected by the firewall 141. Therefore, in the company intra environment 111, threats such as access to each information processing device by an attacker from the Internet 100 are greatly reduced.
[0014] On the other hand, no firewall is installed in the direct internet connection environment 112. The direct internet connection environment 112 is an environment in which the image forming apparatus 102 and the PC 122 are directly connected to the Internet 100 and communicate with each other. Therefore, information processing apparatuses such as the image forming apparatus 102 and the PC 122 need to take measures against threats such as access by attackers from the Internet 100, for example, by using a personal firewall function within each information processing apparatus.
[0015] The internet prohibited environment 113 is a closed network environment isolated from other networks such as the internet 100. Information processing devices such as the image forming device 103 and the PC 123 are connected via a LAN 133. In the internet prohibited environment 113, network communication is possible only between the information processing devices installed on the LAN 133. The information processing devices cannot be accessed by unspecified users on the internet 100.
[0016] The home environment 114 is an environment in which the image forming device 104 and the PC 124 are connected via a home LAN 134. The LAN 134 is a private network configured with a home router 144, but does not have security measures such as a strong firewall like the company intranet environment 111. Therefore, like the direct internet connection environment 112, the information processing devices installed in the home environment 114 need to take measures against threats such as access by attackers from the Internet 100, such as by using a personal firewall function within each information processing device.
[0017] In this embodiment, a public space environment and a highly confidential environment (not shown) are assumed in addition to the usage environments 111 to 114. The above six classifications of usage environments will be described in detail with reference to FIG.
[0018] In this embodiment, the usage environment of an information processing device is classified into six categories, and appropriate security settings are provided for each category. FIG. 2 is a flowchart illustrating the concept of classification when classifying and defining usage environments. Note that the following definitions of usage environments do not limit the present invention, and some or other usage environments exemplified in this embodiment may be defined. For example, assuming installation within a company, usage environments may be classified by industry, such as finance or government agencies.
[0019] S201 is a classification of whether the environment handles highly confidential information. An environment that handles highly confidential information can be said to be an environment in which security measures must be given the highest priority. Hereinafter, in this embodiment, an environment in which security measures must be given the highest priority is defined as a highly confidential information management environment 116.
[0020] If the environment does not handle highly confidential information, the classification of the usage environment is further subdivided. S202 classifies the environment as being entry-controlled or not. This is an example of classification based on whether or not unspecified users can physically access the information processing device, i.e., whether or not users who enter the location where the information processing device is installed are restricted. Therefore, the classification condition of whether or not physical access is possible is not limited to this embodiment, and conditions other than entry control may also be used as the classification condition. Furthermore, entry control in this embodiment is not limited to a card-based access / exit system. For example, an entry-controlled environment also includes an environment in which only people belonging to an organization work during business hours, limiting the number of people who can actually enter, and the door is locked outside of business hours.
[0021] When entry control is not performed, i.e., when unspecified users can physically access the information processing device, the usage environment is subdivided according to the classification conditions shown in S205. S205 classifies the environment based on whether unspecified users share and use the network within the environment. In this embodiment, an environment in which unspecified users share and use the network within the environment is defined as a public space environment 115. Furthermore, an environment in which unspecified users do not share the network within the environment is defined as a home environment 114. In this embodiment, an environment in which unspecified users do not share the network within the environment, such as the home environment 114, i.e., an environment in which the user can be identified, is defined as a private network environment.
[0022] The usage environment classified as entry-controlled in S202 is further subdivided according to the classification conditions shown in S203. S203 classifies the environment based on whether or not the information processing device in the environment is connected to an external network such as the Internet. An environment that is not connected to an external network such as the Internet is defined as an Internet-prohibited environment 113. Note that the Internet-prohibited environment 113, which is entry-controlled and is based on a closed network, is a private network environment.
[0023] If the information processing device in the environment is connected to an external network such as the Internet, the usage environment is further subdivided according to the classification conditions shown in S204. S204 classifies the environment based on whether or not a firewall is installed. An environment in which a firewall is installed is defined as an in-house intra environment 111. An environment in which no firewall is installed is defined as a direct Internet connection environment 112. The in-house intra environment 111, in which users who use the network within the environment can be restricted by a firewall, is a private network environment.
[0024] Next, we will explain the six usage environments mentioned above and the security measures that should be taken for each usage environment using Table 1. Here, we will give seven examples of security measures.
[0025] [Table 1]
[0026] Communication path encryption is a security measure that prevents information leakage by encrypting communication content on a network. Transport Layer Security (TLS) is an example of a function that realizes communication path encryption. In an environment connected to the Internet, it is desirable to encrypt the communication path because there is a possibility that a third party may eavesdrop on the communication content. In other words, it is recommended to encrypt the communication path except in an Internet-prohibited environment 113.
[0027] Disabling legacy protocols is a security measure to prevent spoofing and information leakage by disabling functions that use insecure legacy communication protocols. An example of a legacy protocol is WINS (Windows Internet Name Service). As with encryption of communication paths, disabling legacy protocols is also desirable in environments connected to external networks such as the Internet. In other words, disabling legacy protocols is recommended except for Internet-prohibited environments 113.
[0028] A personal firewall is a firewall installed and used on an information processing device. Like a typical firewall, it monitors communication between the information processing device and external networks such as the Internet. Examples of firewalls include IP filters and port number filters. IP filters are a security measure that reads the destination and source information of communication packets and allows only pre-defined communication packets. This prevents unauthorized access and information leakage. Port number filters are a security measure that closes unused ports to prevent intrusion through those ports. This prevents DoS (Denial of Service), a cyber attack that creates vulnerabilities by imposing a large load. In environments connected to external networks but without a firewall, it is desirable to enable a personal firewall due to the possibility of information leakage and DoS. In other words, enabling a personal firewall is recommended except for Internet-prohibited environments 113 not connected to external networks and intranet environments 111 where a firewall is installed.
[0029] Strengthening the security of authentication means strengthening measures against spoofing, for example, by prohibiting password caching, specifying the minimum number of characters for passwords, etc. Except for the Internet-prohibited environment 113 connected within an isolated network, it is desirable to strengthen the security of authentication because there is a possibility of spoofing.
[0030] Countermeasures against physical attacks are security measures to physically prevent information from being leaked. The image forming apparatuses 101 to 104 generate temporary data, such as print jobs, on their hard disks. Each image forming apparatus is equipped with a complete erasure function that automatically and completely erases the generated temporary data upon job completion. The complete erasure function described above is an example of a countermeasure against physical attacks for the image forming apparatuses 101 to 104. With this function enabled, even if the hard disk is physically removed, the temporary data cannot be read. It is desirable to implement countermeasures against physical attacks in the home environment 114 and the public space environment 115, which are environments where entry management is not performed and physical access to information processing devices cannot be restricted. It is also desirable to implement countermeasures against physical attacks in the highly confidential information management environment 116, where reducing the risk of information leakage is given top priority.
[0031] The file sharing function is a function for sharing files over a network within an environment. In an environment where unspecified users share the network within the environment, it is desirable to disable the file sharing function to prevent information leakage. That is, it is recommended to disable the file sharing function except for private network environments where specific users share the network within the environment. As described above, the private network environments in this embodiment are the company intranet environment 111, the internet-prohibited environment 113, and the home environment 114. Therefore, it is recommended to disable the file sharing function in the other environments, namely the direct internet connection environment 112, the public space environment 115, and the highly confidential information management environment 116. Note that an example of settings related to the file sharing function is SMB (Server Message Block) server settings.
[0032] Disabling an external storage device means, for example, setting a USB (Universal Serial Base) storage device so that it cannot be used as an external storage device by an information processing device. This prevents information from being written to the external storage device, preventing information leakage. It also prevents computer virus infection via the USB storage device and the resulting information leakage. The threat of information leakage from external storage devices such as USBs is common to all usage environments. Therefore, it is desirable to disable them in all usage environments.
[0033] Table 2 shows the recommended setting items and values for each usage environment, based on the security measures described above. For items with recommended settings, the recommended setting value is indicated as "on," "off," "deny," etc. When the user selects a usage environment on the screen shown in Figure 5 (described later), the recommended setting value for the selected usage environment is applied by the process shown in Figure 6 (described later).
[0034] Image forming apparatuses 101 to 104, which are examples of information processing apparatuses, have a wide variety of setting items, such as setting items related to security functions and other setting items, and perform various controls according to the setting values corresponding to the setting items. In this embodiment, the target items for collective setting of security functions are the 22 items shown in Table 2.
[0035] [Table 2]
[0036] LPD, RAW, WSD, and IPP are printing protocols used for communication between client devices and printers. Unlike other protocols, IPP itself provides user authentication, access control, and communication data encryption functions, making it a more secure printing protocol than other protocols. For this reason, it is recommended that "Use IPP Printing" be set to "On" in environments requiring high security and high confidential information management. Furthermore, it is recommended that LPD, RAW, and WSD, which have weaker security than IPP, be set to "Off" except in trusted environments such as corporate intranet environments and environments where internet access is prohibited.
[0037] SNMP is a protocol for monitoring and controlling communication devices on a network, and allows you to check the number of pages printed by a printer and error information using a PC. SNMPv1 determines the communication range using information called a community name, but because the community name is sent over the network in plain text, there is a risk of information leakage. For this reason, it is recommended that you set this option to "Off" except in trusted environments such as company intranet environments and environments that do not connect to the Internet and where Internet access is prohibited.
[0038] A dedicated port is a port used to set and view printer information from the printer driver, etc. If the "Use dedicated port" option is set to "Off," printer information will not be available when using the printer driver, etc. over a network connection. In environments directly connected to the Internet or in public spaces, there is a risk of information leakage, so it is recommended that this option be set to "Off." It is also recommended that this option be set to "Off" in environments requiring high security and where highly confidential information is managed.
[0039] Automatic deletion of interrupted jobs is a function that automatically deletes print jobs that are interrupted due to an error or other reason. This prevents an interrupted print job from being resumed after a period of time, leaving printed documents unattended, reducing the risk of information leakage. It is recommended that this setting be set to "On" in home environments and public space environments without access control, as well as in highly confidential information management environments that require high security.
[0040] A transmission result report is a report used to confirm whether a transmission to the intended recipient was successful. This setting determines whether or not to automatically print transmission result reports for fax, e-mail, and I-fax transmissions, as well as for saving to a file server or user box. By turning off the transmission result report, reports containing information such as the content of the transmission and the transmission history will not be left on the printer, reducing the risk of information leaks. It is recommended to turn off the report in home environments or public space environments without access control, or in highly confidential information management environments requiring high security.
[0041] Simple login is a method of logging in by pressing the user name displayed on the operation panel, which eliminates the need to enter the user name. Simple login allows you to set a PIN. This item allows you to set whether or not this PIN must be used. If a PIN is not used, users can simply log in by selecting the user name displayed on the operation panel, but this poses a risk of identity theft. Setting this item to "On" reduces the risk of identity theft. It is recommended that this setting be set to "On" in home environments and public space environments where entry is not controlled, and in highly confidential information management environments that require high security.
[0042] "Display job status before authentication" is an item that allows you to set whether or not to display a screen that allows you to check the job status before authentication, assuming that you are using a login service. By setting this item to "Off," you can prevent the job status from being viewed by an unspecified number of people, reducing the risk of information leakage. It is recommended that you set this to "Off" in home environments or public space environments that do not have access control, or in highly confidential information management environments that require high security.
[0043] Job history is the history of print jobs and includes information such as the username of the user who instructed printing and the document name of the printed document. Turning off the display of job history prevents information such as the document name and the name of the user who printed it from being seen by an unspecified number of people, reducing the risk of information leaks. It is recommended that this setting be set to "off" in home environments and public space environments without access control, and in highly confidential information management environments that require high security.
[0044] The audit log function makes it possible to audit security events. For example, the user authentication log can be used to check for unauthorized access to the device or attempts to do so, and the logs of device usage such as printing, document transmission, and setting changes can be used to audit for unauthorized use of the device. The key operation log is a log of key operations performed by the user, and includes, for example, the key operation log for login operations. By saving and analyzing these logs, it is possible to investigate how the printer was operated. By acquiring or saving the audit log and key operation log, it is possible to prevent users from denial of access or use in the event of unauthorized access or use. Because the risk of denial exists in all environments, these settings are recommended for all six environments.
[0045] Although not listed in Table 2, in a highly confidential information management environment requiring high security, it is possible to add the following setting items: For example, "Use Mopria," "Use AirPrint," "Use Remote UI," etc.
[0046] In addition, the following items can be added in a home environment. Examples include PJL (Printer Job Language) and Admin (Embedded Web Server) passwords, and SNMPv1 / v2 and SNMPv3-related settings. For example, you can prevent PJL and EWS administrator passwords from being changed from devices to which centralized settings for the home environment have been applied. SNMP is a device management protocol that allows administrators to retrieve and set settings for image forming devices such as printers over the network. Using SNMP allows administrators to freely change settings for image forming device functions, allowing them to manage the permissions required for each setting. To prevent general users working from home from changing settings after the settings set in accordance with company policy have been applied, you can also prevent changes to settings related to device management protocols in a home environment. It is also possible to add settings related to checking firmware versions and updates. It is also possible to add settings for selecting whether to restrict access to PJL commands and settings related to HTTPS redirection.
[0047] Note that the setting values are not limited to those in Table 2, as long as they are appropriate for each usage environment. For example, in Table 2, a firewall is installed in a company intranet environment, so personal firewall settings are not necessary. However, there may be cases where a firewall installed in the office is used in conjunction with a personal firewall. Given this, it is possible to perform centralized settings, including personal firewall settings, even in a company intranet environment or an environment where Internet access is prohibited. The same applies to other setting items.
[0048] Among the setting items shown in Table 2, TLS settings and personal firewall settings are general network settings, while printing protocol settings and device management settings such as displaying print job history are printing device-specific settings.
[0049] In this embodiment, an information processing apparatus is provided that performs settings suitable for a selected usage environment based on the definitions of the above-described environment classifications and the recommended setting values of security functions. Specific explanations will be given below.
[0050] <Hardware Configuration of Image Forming Apparatus 101> The hardware configuration of an image forming apparatus 101, which is an example of an information processing apparatus in this embodiment, will be described with reference to Fig. 3. Note that while Fig. 3 only describes the image forming apparatus 101, the image forming apparatuses 102 to 104, and image forming apparatuses installed in public space environments and highly confidential information management environments (not shown) are also assumed to have the same configuration as the image forming apparatus 101.
[0051] The image forming apparatus 101 includes a printer 330 that outputs electronic data onto a paper medium, and a scanner 340 that reads the paper medium and converts it into electronic data. In this embodiment, the image forming apparatus 101 has multiple functions as an example of an information processing apparatus, but is not limited to this. For example, it may be a single-function printer, scanner, or other device. It may also be a 3D printer, 3D scanner, or other device.
[0052] A control unit 310 including a CPU (Central Processing Unit) 311 controls the overall operation of the image forming apparatus 101. A ROM (Read Only Memory) 312 is used to store programs executed by the CPU 311. The CPU 311 reads out control programs stored in the ROM 312 and performs various controls of the image forming apparatus 101, such as reading control and transmission control. A RAM (Random Access Memory) 313 is used as a temporary storage area such as the main memory and work area of the CPU 311. A HDD (Hard Disk Drive) 314 is a storage device that stores image data, various programs, and various setting information. Note that other storage devices such as an SSD (Solid State Drive) may also be included. In this way, the hardware such as the CPU 311, ROM 312, RAM 313, and HDD 314 constitute a so-called computer.
[0053] An operation unit I / F (interface) 315 connects the operation unit 320 and the control unit 310 . The operation unit 320 is provided with a liquid crystal display unit with a touch panel function, various hard keys, etc. The operation unit 320 functions as a display unit that displays information to the user and a reception unit that receives instructions from the user.
[0054] The printer I / F 316 connects the printer 330 and the control unit 310. Image data to be printed by the printer 330 is transferred from the control unit 310 via the printer I / F 316. The input image data is output onto a recording medium in the printer 330. The scanner I / F 317 connects the scanner 340 and the control unit 310. The scanner 340 reads an original placed on an original platen (not shown) and generates image data. The generated image data is input to the control unit 310 via the scanner I / F 317.
[0055] A network cable is connected to the network I / F 318, and it is possible to communicate with an external device on the LAN 131. In this embodiment, it is assumed that the network I / F 318 is a communication interface that performs wired communication, but this is not limited to this. For example, it may be a wireless communication interface. Note that the network I / F 318 of the image forming apparatus 101 is connected to the LAN 131, but the network to which it is connected varies depending on the usage environment. For example, the image forming apparatus 102 is directly connected to the Internet 100. The image forming apparatuses 103 and 104 are connected to LANs 133 and 134, respectively.
[0056] <Software Configuration of Image Forming Apparatus 101> Next, the software configuration of the image forming apparatus 101, which is an example of an information processing apparatus in this embodiment, will be described with reference to Fig. 4. Each unit shown in Fig. 4 is realized by the CPU 311 executing a program corresponding to each unit stored in the ROM 312.
[0057] The operation control unit 410 displays a screen for the user on the operation unit 320. It also detects user operations, and switches the screen or updates the display based on the detection result.
[0058] The data storage unit 420 stores data in the HDD 314 and reads data from the HDD 314 in response to requests from other control units. The data storage unit 420 stores information related to security function settings in addition to setting information for determining the operation of the image forming apparatus 101. Specifically, the data storage unit 420 stores a recommended setting value database 421, pre-change setting data 422, and current operation setting data 423.
[0059] The recommended setting value database 421 is a database such as that shown in Table 2 above. In other words, it is a database that associates combinations of setting items and setting values of security functions suitable for the usage environment of the image forming apparatus 101 with a plurality of classified usage environments. Here, setting items refer to items such as TLS settings and WINS settings. Setting values are indicated as "on," "off," "reject," etc. in Table 2. Setting items in Table 2 that have blank setting values and are indicated by diagonal lines indicate that they do not have recommended setting values. That is, the setting value for the setting item is not changed, and the setting value before the setting change is carried over. In this embodiment, the recommended setting value database 421 is defined in advance by the vendor of the image forming apparatus 101 and stored in the data storage unit 420 .
[0060] The pre-change setting data 422 is data of a combination of setting items and setting values that was applied before the user selected an environment type on a screen 500 in FIG. 5 (described later). When the security setting control unit 430 (described later) performs batch setting, the pre-change setting data 422 is used to restore the setting values if a problem occurs, such as the end user being unable to use a desired function in the operation settings after batch setting. In this embodiment, the pre-change setting data 422 is stored when an environment type is selected for the first time on the image forming apparatus 101, or when an environment type is selected for the first time after a cancel button 502 (described later) is pressed. In other words, if the user selects environment types consecutively, the pre-change setting data 422 is not updated.
[0061] The current operation setting data 423 is data of a combination of setting items and setting values currently applied to the image forming apparatus 101. When a setting is changed, the current operation setting data 423 is rewritten. When the image forming apparatus 101 is then restarted, the rewritten current operation setting data 423 is read by a program, and the image forming apparatus operates with the applied settings.
[0062] The security setting control unit 430 performs collective setting of security functions of the image forming apparatus 101 in accordance with instructions from the user detected by the operation control unit 410. Specific setting control will be described later with reference to FIGS. 6 and 7. Note that the collective setting in this embodiment is a function that allows recommended setting values of typical security functions defined by a vendor to be set in a collective manner. Hereinafter, this function will also be referred to as a collective setting function. Its nature is different from that of a function that applies a security policy edited by a user and prohibits changing settings for specific security setting items to settings that do not conform to the policy. In other words, even if a user such as an administrator performs collective setting using the collective setting function, the user can change the setting values of individual setting items to different setting values again via an individual setting change screen (not shown) depending on the actual usage situation.
[0063] A web UI (User Interface) control unit 440 controls a setting screen displayed on an external information processing device such as the PC 121 via the network I / F 318. A user can refer to and change settings of the image forming apparatus 101 using a setting screen on a web browser provided by the web UI control unit 440. The web UI control unit 440 may also have a function for importing and exporting the recommended setting value database 421. This function allows the user to create and edit a data file related to the recommended setting value database 421 on the PC 121. The edited recommended setting value database 421 can also be sent to the image forming apparatus 101 and stored in the data storage unit 420. The web UI control unit 440 may be omitted in this embodiment.
[0064] Next, the setting screen 500 displayed on the operation unit 320 of the image forming apparatus 101 will be described with reference to Fig. 5. Note that, although the setting screen 500 displayed on the operation unit 320 of the image forming apparatus 101 will be described in this embodiment, the present invention is not limited to this. For example, it is also possible to use the web UI control unit 440 to provide a web page similar to the setting screen 500 to a web browser of an external information processing apparatus, and to perform setting operations via this web page.
[0065] The setting screen 500 is a screen that the operation control unit 410 displays on the operation unit 320. The usage environment list button 501 is a button that the user uses to select a usage environment. The user selects the usage environment of the image forming apparatus 101 from the usage environment list button 501 on the setting screen 500 and presses the execute button 503. In this embodiment, the user selects from the six usage environment options shown in FIG. 2. The operation control unit 410 of the image forming apparatus 101 detects the user's operation and transmits information indicating the user's selection to the security setting control unit 430. The security setting control unit 430 collectively sets the security functions that are appropriate for the usage environment selected by the user and that are received from the operation control unit 410.
[0066] The cancel setting button 502 is a button that the user can use to cancel the bulk setting of security functions after the bulk setting has been performed. The user performs an operation of pressing the execute button 503 while the cancel setting button 502 is selected. The operation control unit 410 detects the user's operation and transmits information indicating the user's instruction to cancel the settings to the security setting control unit 430. When the security setting control unit 430 receives information indicating a setting cancellation instruction, it cancels the collective setting of the security functions and returns them to their original settings. After the user selects the usage environment and performs collective setting of the security functions, it is possible that a problem may occur in the use of the image forming apparatus 101. In such a case, by providing the setting cancellation button 502, it is possible to return to the state before the collective setting, and the problem can be dealt with immediately.
[0067] Next, the process from when the user selects the usage environment on the screen 500 to when the security functions are all set at once will be described with reference to FIG.
[0068] Each operation (step) shown in the flowchart of FIG. 6 is realized by the CPU 311 calling up a program for implementing each control unit stored in the ROM 312 or HDD 314 into the RAM 313 and executing the program.
[0069] When the operation control unit 410 detects that the user has selected the usage environment on the operation unit 320 and pressed the execute button 503, the process shown in FIG. 6 starts.
[0070] In S601, the security setting control unit 430 determines whether another usage environment has already been selected and whether collective setting of security functions suitable for that usage environment has been applied. This determination is made using the pre-change setting data 422 stored in the data storage unit 420. If the pre-change setting data 422 is stored in the data storage unit 420, the security setting control unit 430 determines that another usage environment has already been selected. If the pre-change setting data 422 is not stored in the data storage unit 420, the security setting control unit 430 determines that another usage environment has not been selected. Therefore, if the pre-change setting data 422 is stored, the process proceeds to S605, and if it is not stored, the process proceeds to S602.
[0071] First, we will explain the process when the pre-change setting data 422 is not saved. In S602, the security setting control unit 430 saves the combination of the setting items and setting values of the currently applied security functions in the data storage unit 420 as the pre-change setting data 422.
[0072] Next, in S603, the security setting control unit 430 reads recommended setting data from the data storage unit 420. The recommended setting data is a combination of security setting items and setting values suitable for the usage environment selected by the user. The usage environment selected by the user is detected by the operation control unit 410 on the operation unit 320, and the security setting control unit 430 receives this information from the operation control unit 410. The security setting control unit 430 performs the processing of S603 by extracting recommended setting data suitable for the selected usage environment from the recommended setting value database 421 stored in the data storage unit 420.
[0073] Proceeding to S604, the security settings control unit 430 applies the read recommended setting data to the settings of the security functions of the image forming apparatus 101. Specifically, the security settings control unit 430 reads the current operational setting data 423 stored in the data storage unit 420 and overwrites the current operational setting data 423 with the recommended setting data. That is, if the recommended setting data has a value for a setting item of a security function, the setting value is changed to the recommended setting value. If the recommended setting data does not have a value (items indicated by diagonal lines in Table 2), the setting value remains unchanged as the value of the current operational setting data 423. Through the above processing, the security settings control unit 430 determines a combination of a setting item and a setting value for a security function to be newly set. Then, the current operational setting data 423 is rewritten with the newly determined data.
[0074] Finally, the process proceeds to step S609, where the security setting control unit 430 restarts the image forming apparatus 101. When the image forming apparatus 101 restarts, the rewritten current operation setting data 423 is read by the program, and the program operates with the new rewritten settings. In this way, the applied settings are reflected in the operation of the image forming apparatus 101.
[0075] Next, a description will be given of the processing to be performed when it is determined in S601 that the pre-change setting data 422 is stored in the data storage unit 420. In S605, the security setting control unit 430 reads out the pre-change setting data 422 stored in the data storage unit 420.
[0076] Next, in S606, the security setting control unit 430 reads out recommended setting data suited to the usage environment selected by the user. The process of S606 is the same as S603.
[0077] Proceeding to S607, the security settings control unit 430 uses the pre-change configuration data 422 read in S605 and the recommended configuration data read in S606 to determine a combination of setting items and setting values for the security functions to be newly set. The security settings control unit 430 determines the new data to be set by overwriting the pre-change configuration data 422 with the recommended configuration data. If the recommended configuration data has a value for a setting item of a security function, the setting value is changed to the recommended setting value. If the recommended configuration data does not have a value (items indicated by diagonal lines in Table 2), the setting value remains unchanged as the value in the pre-change configuration data. Through the above processing, the security settings control unit 430 determines a combination of setting items and setting values for the security functions to be newly set.
[0078] Proceeding to S608, the security setting control unit 430 applies the setting values determined in S607 to the settings of the security functions of the image forming apparatus 101. Specifically, the current operation setting data 423 is rewritten with the data newly determined in S607.
[0079] Finally, the process proceeds to step S609, where the security setting control unit 430 restarts the image forming apparatus 101, and causes the applied settings to be reflected in the operation of the image forming apparatus 101.
[0080] Through the above process, the user can select the usage environment of the image forming apparatus 101, thereby realizing processing for collectively setting security functions suited to the usage environment.
[0081] The overwriting process shown in S607 may be omitted. In that case, the processes of S605 to S608 are not performed, and only the processes of S603 to S604 are performed.
[0082] Next, the process of canceling settings using the cancel settings button 502 will be described with reference to Fig. 7. As with Fig. 6, each operation (step) shown in the flowchart of Fig. 7 is also realized by the CPU 311 calling into the RAM 313 a program for realizing each control unit stored in the ROM 312 or the HDD 314 and executing the program.
[0083] When the operation control unit 410 detects that the user has selected the setting cancel button 502 and pressed the execute button 503 on the operation unit 320, the processing shown in FIG. 7 starts.
[0084] In S701, the security setting control unit 430 reads the pre-change setting data 422 stored in the data storage unit 420.
[0085] In S702 , the security setting control unit 430 applies the read pre-change setting data 422 to the settings of the security functions of the image forming apparatus 101 .
[0086] In S703, the security setting control unit 430 deletes the pre-change setting data 422 stored in the data storage unit 420.
[0087] Finally, in step S704, the security setting control unit 430 restarts the image forming apparatus 101, and causes the applied settings to be reflected in the operation of the image forming apparatus 101.
[0088] By the above process, when the user selects to cancel the collective settings, it is possible to realize the process of canceling the settings to return to the state before the collective settings of the security functions suited to the usage environment were made.
[0089] By performing the above-described series of processes, the user can select the operating environment of the information processing device, and the security-related function settings can be collectively set to settings suitable for the selected operating environment. Furthermore, even if a problem occurs due to the setting change, such as the user being unable to use a desired function, the settings can be immediately restored to the state before the setting change. In this way, the convenience of setting the security functions can be improved.
[0090] <Second embodiment> In the first embodiment, a configuration in which a user selects an environment type is illustrated, as shown in the usage environment list button 501 in Fig. 5. In the second embodiment, a configuration in which questions for determining the usage environment are displayed to the user, and security functions are collectively set based on the usage environment determined from the user's answers to those questions, is described. Note that the hardware configuration and software configuration of the image forming apparatus 101 according to this embodiment are the same as those in the first embodiment, and therefore description thereof will be omitted.
[0091] The screen configuration in this embodiment will be described with reference to Fig. 8. Fig. 8 illustrates an example of a setting screen displayed on the operation unit 320 of the image forming apparatus 101. Note that, although the setting screen displayed on the operation unit 320 of the image forming apparatus 101 is described in this embodiment, the present invention is not limited to this. For example, it is also possible to use the web UI control unit 440 to provide a web page similar to the setting screen 500 to a web browser of an external information processing apparatus, and to perform setting operations via this web page.
[0092] Due to space limitations, Fig. 8 shows an example of a screen that may be displayed on the operation unit 320. Fig. 8(a) shows a setting screen 800 that presents the user with a question for determining whether the type is an internet prohibited type, an in-house intranet type, or a direct internet connection type. FIG. 8(b) shows a setting screen 801 that is displayed when the user selects "Yes" on the setting screen 800. The setting screen 801 presents the user with a question for determining whether the device is an in-house intranet type or a direct internet connection type. FIG. 8(c) shows a setting screen 802 that is displayed when the user selects "No" on the setting screen 801. The setting screen 802 presents the user with the result of determining the usage environment as a direct internet connection type. The setting screen 802 also presents the user with a question as to whether or not to apply security function settings suitable for the direct internet connection type. When the user selects "Yes" on the setting screen 802, security function settings suitable for the direct internet connection type are applied.
[0093] The display of the screen shown in FIG. 8 and the processing related to the collective setting of security functions will be explained using FIGS.
[0094] Each operation (step) shown in FIGS. 9 and 10 is realized by the CPU 311 calling up a program for implementing each control unit stored in the ROM 312 or HDD 314 into the RAM 313 and executing the program.
[0095] When the operation control unit 410 detects that the user has opened a security function setting screen on the operation unit 320, the process shown in FIG. 9 starts.
[0096] 9 and 10 ask the user a number of questions to classify the usage environment the user is using into which of the definitions shown in Fig. 2 it fits. Therefore, the following explanation will be given in association with the environment classification steps in Fig. 2.
[0097] First, in S901, the operation control unit 410 displays a question on the operation unit 320 asking the user whether or not the usage environment of the image forming apparatus 101 is an environment in which highly confidential information is handled. The question in S901 corresponds to the classification of S201 in FIG. 2. After the question is displayed, the process proceeds to S902. If the operation control unit 410 detects that the user's answer to the question in S901 is "Yes," the process proceeds to processing A, which will be described later. If the operation control unit 410 detects that the user's answer is "No," the process proceeds to S903.
[0098] In S903, the operation control unit 410 displays a question on the operation unit 320 asking the user whether the usage environment of the image forming apparatus 101 is an entry-controlled environment. The question in S903 corresponds to the classification of S202 in Fig. 2. After the question is displayed, the process proceeds to S904. If the operation control unit 410 detects that the user's answer to the question in S903 is "No," the process proceeds to S905. If the operation control unit 410 detects that the user's answer is "Yes," the process proceeds to S907.
[0099] In S905, the operation control unit 410 displays a question asking the user whether the usage environment of the image forming apparatus 101 is an environment in which unspecified users share a network, on the operation unit 320. The question in S905 corresponds to the classification of S205 in FIG. Once the question is displayed, the process proceeds to S906. If the operation control unit 410 detects that the user's answer to the question in S905 is "yes," the process proceeds to processing B, which will be described later. If the operation control unit 410 detects that the user's answer is "no," the process proceeds to processing C, which will be described later.
[0100] In S907, the operation control unit 410 displays a question on the operation unit 320 asking the user whether the usage environment of the image forming apparatus 101 is an internet connection environment. The question in S907 corresponds to the classification of S203 in FIG. 2. After the question is displayed, the process proceeds to S908. If the operation control unit 410 detects that the user's answer to the question in S907 is "No," the process proceeds to processing D, which will be described later. If the operation control unit 410 detects that the user's answer is "Yes," the process proceeds to S909.
[0101] In S909, the operation control unit 410 displays on the operation unit 320 a question asking the user whether or not a firewall is installed in the usage environment of the image forming apparatus 101. The question in S909 corresponds to the classification of S204 in FIG. 2. Once the question is displayed, the process proceeds to S910. If the operation control unit 410 detects that the user's answer to the question in S909 is "No," the process proceeds to processing E, which will be described later. If the operation control unit 410 detects that the answer is "Yes," the process proceeds to S911.
[0102] In S911, the operation control unit 410 displays on the operation unit 320 a question asking the user whether or not to apply recommended settings suited to the company's intranet environment to the security function settings of the image forming apparatus 101. Once the question is displayed, the process proceeds to S912. If the operation control unit 410 detects that the user's answer to the question in S911 is "Yes," the process proceeds to S913. If the operation control unit 410 detects that the user's answer is "Cancel," the process proceeds to processing F and returns to S901. At this time, instead of returning to S901, the process may be configured to display FIG. 5. Alternatively, a message or a QR code (registered trademark) that prompts the user to display a detailed manual may be displayed.
[0103] In S913, the security setting control unit 430 applies recommended settings suited to the company's intranet environment to the security function settings of the image forming apparatus 101. Note that the application of the recommended settings is performed in the same manner as in the first embodiment, which was described with reference to FIG. 6. Finally, in S914, the security setting control unit 430 restarts the image forming apparatus 101, and reflects the applied settings in the operation of the image forming apparatus 101.
[0104] Next, the above-mentioned processes A to E will be described with reference to FIG.
[0105] First, processing A will be described with reference to FIG. 10(a). In S1001, the operation control unit 410 displays a question on the operation unit 320 asking the user whether or not to apply recommended settings suitable for a highly confidential information management environment to the security function settings of the image forming apparatus 101. After the question is displayed, the process proceeds to S1002. If the operation control unit 410 detects that the user's answer to the question in S1001 is "Yes," the process proceeds to S1003. If the operation control unit 410 detects that the user's answer is "Cancel," the process proceeds to processing F and returns to S901. In S1003, the security setting control unit 430 performs the same processing as in FIG. 6 to apply recommended settings suitable for a highly confidential information management environment to the security function settings of the image forming apparatus 101. Finally, the process proceeds to processing G, where in S914 the security setting control unit 430 restarts the image forming apparatus 101.
[0106] Processes B to E are similar to process A. Process A displays and configures the highly confidential information management environment, but process B replaces it with a public space environment, process C with a home environment, process D with an internet-prohibited environment, and process E with a direct internet connection environment.
[0107] Through the above process, the user answers questions to determine the usage environment of the image forming apparatus 101, thereby realizing processing for performing batch setting of security functions suited to the usage environment.
[0108] <Modification> In the above-described embodiment, the display of the setting screen and the generation of the current operation setting data are described as being performed on the image forming device 101 or on a web page provided to the web browser of an external information processing device using the web UI control unit 440 of the image forming device 101. However, the present invention is not limited to this. Specifically, the display of the setting screen and the generation of the current operation setting data may be performed on an application in an external information processing device.
[0109] The external application includes an operation control unit that displays the setting screen shown in Fig. 5 or 8 and accepts user operations. It also includes a data storage unit that stores data similar to the recommended setting value database 421, pre-change setting data 422, and current operation setting data 423. The external application acquires data similar to the current operation setting data 423 from the image forming apparatus 101 via the network.
[0110] First, the external application displays the setting screen shown in Fig. 5 or 8 on the external information processing device. The user selects the usage environment of the image forming device 101 on the external application. The external application receives information indicating the usage environment selected by the user.
[0111] The external application extracts recommended setting data suitable for the operating environment selected by the user from a recommended setting value database stored within the external application, and performs processing similar to steps S601 to S608 in Figure 6 within the external application to generate new current operational setting data.
[0112] The external application transmits an instruction to change the operation settings to the image forming apparatus 101 based on the generated new current operation setting data. For example, the instruction to change the operation settings is transmitted using a SetRequest operation of the Simple Network Management Protocol (SNMP). Note that the communication protocol used for the setting change and the method for issuing the instruction for the setting change are not limited to SNMP. For example, a configuration is possible in which a data file for importing setting values that lists setting items and setting values is generated and transmitted to the image forming apparatus 101. Upon receiving this data file, the image forming apparatus 101 changes its own settings based on the data file.
[0113] The image forming apparatus 101 receives new current operation setting data from the external application and applies it to the settings of the image forming apparatus 101. The image forming apparatus 101 is restarted, and the applied settings are reflected in the operation of the image forming apparatus 101.
[0114] Through the above processing, the user can set the security functions of the image forming apparatus 101 on an application of an external information processing apparatus.
[0115] In this modification, the external application acquires current operation setting data from the image forming apparatus 101 via a network. At this time, the acquired current operation setting data may be given a name and saved in the external application. The name may be given based on the usage environment selected by the user. As described above, after collective settings are made based on the usage environment selected by the user, the user can change the setting values of individual setting items to different setting values again. When the current operation setting data acquired by the external application is data in which individual setting values have been changed in this way, the data may be saved with a new name. The saved setting data can be distributed to image forming apparatuses other than the image forming apparatus 101. The distributed setting data is applied to each image forming apparatus.
[0116] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of each of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC or FPGA) that realizes one or more functions. [Explanation of symbols]
[0117] 101 Image forming device 410 Operation control section 420 Data storage unit 430 Security setting control section
Claims
1. A printing device, comprising: a receiving means for receiving a selection of a usage environment of the printing device from a plurality of usage environments including a first usage environment and a second usage environment; A setting means for performing setting based on a plurality of setting values corresponding to the selected use environment; having When the second usage environment is selected while the first usage environment is selected, a setting value that was set before the first usage environment was selected is set to a predetermined item corresponding to the second usage environment and to which a setting value included in a first plurality of setting values corresponding to the first usage environment was set. A printing device comprising:
2. A storage means for storing the setting value that was set before the first usage environment was selected; an acquisition means for acquiring the setting value stored by the storage means when the second usage environment is selected while the first usage environment is selected; and The setting means sets the setting value acquired by the acquisition means to the predetermined item.
2. The printing device according to claim 1.
3. The predetermined item corresponding to the second usage environment is a setting item identified based on a second plurality of setting values corresponding to the second usage environment.
2. The printing device according to claim 1.
4. The predetermined item corresponding to the second usage environment is a setting item that is not included in a plurality of setting items corresponding to a second plurality of setting values corresponding to the second usage environment.
2. The printing device according to claim 1.
5. The plurality of setting values corresponding to the selected usage environment include a setting value corresponding to a security setting item.
2. The printing device according to claim 1.
6. The plurality of setting values corresponding to the selected usage environment include setting values corresponding to security setting items related to printing.
6. The printing apparatus according to claim 5.
7. The plurality of setting values corresponding to the selected usage environment include setting values corresponding to security setting items specific to the printing device.
7. The printing apparatus according to claim 6.
8. The first plurality of setting values corresponding to the first usage environment are at least partially different from the second plurality of setting values corresponding to the second usage environment.
2. The printing device according to claim 1.
9. A storage means for storing the setting value that was set before the first usage environment was selected; a second receiving means for receiving an instruction to cancel the setting based on the plurality of setting values corresponding to the selected usage environment; a second setting means for setting the setting value stored by the storage means in response to receiving the instruction to cancel; The printing device of claim 1 further comprising:
10. A third receiving means for receiving an instruction to set individual setting items of the printing device after receiving the selection of the usage environment; a third setting means for setting a setting value designated by a user to the individual setting item; The printing device of claim 1 further comprising:
11. The multiple usage environments include at least one of an environment in which the printing device is connected to an intranet within a company, an environment in which the printing device is directly connected to the Internet, an environment in which the printing device is prohibited from being connected to the Internet, an environment in which the printing device is used at home, an environment in which the printing device is used in a public space, and an environment in which the printing device handles highly confidential information.
2. The printing device according to claim 1.
12. The selection is accepted via a panel of the printing device.
2. The printing device according to claim 1.
13. The method further comprises providing means for providing a user interface to an external information processing device, The selection is accepted via the user interface screen.
2. The printing device according to claim 1.
14. The plurality of setting values corresponding to the selected usage environment include at least one of a setting value corresponding to a setting item related to displaying a print job history and a setting value corresponding to a setting item related to automatically deleting an interrupted print job.
2. The printing device according to claim 1.
15. The plurality of setting values corresponding to the selected usage environment include setting values corresponding to security setting items related to a device management protocol used by an administrator of the printing device.
2. The printing device according to claim 1.
16. The plurality of setting values corresponding to the selected usage environment include a setting value corresponding to a security setting item related to a password used in the printing device.
2. The printing device according to claim 1.
17. A printing device comprising: a reception unit for receiving a selection of a usage environment indicating that the printing device is to be used at home; a setting means for setting a plurality of values corresponding to the selected usage environment indicating that the printing device is to be used at home; A printing device having the above configuration.
18. The plurality of values corresponding to the selected usage environment include a value corresponding to a security setting item related to a print protocol for communication between the printing device and a client terminal.
20. The printing device according to claim 17,
19. The plurality of values corresponding to the selected usage environment include a value corresponding to a security setting item related to a device management protocol used by an administrator of the printing device.
20. The printing device according to claim 17, 20. A method for controlling a printing device, comprising: a receiving step of receiving a selection of a usage environment of the printing device from a plurality of usage environments including a first usage environment and a second usage environment; A setting step of performing setting based on a plurality of setting values corresponding to the selected usage environment; having When the second usage environment is selected while the first usage environment is selected, a setting value that was set before the first usage environment was selected is set to a predetermined item corresponding to the second usage environment and to which a setting value included in a first plurality of setting values corresponding to the first usage environment was set. A control method comprising:
21. A method for controlling a printing device, comprising: a receiving step of receiving a selection of a usage environment indicating that the printing device is to be used at home; a setting step of setting a plurality of values corresponding to the selected usage environment indicating that the printing device is to be used at home; The control method includes:
22. A printing device comprising: a receiving means for receiving a selection of a usage environment of the printing device from a plurality of usage environments including a first usage environment and a second usage environment; A setting means for performing setting based on a plurality of setting values corresponding to the selected usage environment; A program for causing the device to function as a When the second usage environment is selected while the first usage environment is selected, a setting value that was set before the first usage environment was selected is set to a predetermined item corresponding to the second usage environment and to which a setting value included in a first plurality of setting values corresponding to the first usage environment was set. A program characterized by:
23. A printing device comprising: a reception unit for receiving a selection of a usage environment indicating that the printing device is to be used at home; a setting means for setting a plurality of values corresponding to the selected usage environment indicating that the printing device will be used at home; A program to function as a