Image processing apparatus and control method
Patent Information
- Application Number
- JP2022160961
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-10-05
- Publication Date
- 2025-09-18
AI Technical Summary
Existing image processing devices face security risks during file encryption and transmission due to insecure network communication channels, which can lead to data leakage, especially when generating and transmitting encrypted files in response to scan requests.
Implementing encrypted communication protocols for both password transmission and file transfer between the image processing device and the client terminal, ensuring that communication paths are secure even when the network communication encryption setting is disabled on the device.
Enhances security by ensuring that encrypted files and passwords are transmitted securely, preventing data leaks and maintaining confidentiality during pull scans.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an image processing apparatus that executes a scan process in response to a request from an information processing apparatus, and to a process in an information processing apparatus that issues a scan request. [Background technology]
[0002] Conventionally, there has been a mechanism for scanning a paper document with an image processing device in response to a request from an information processing device via a network, and transmitting the image data obtained by the scan to a specific destination. The mode in which an image processing device transmits scanned image data to a destination specified by a request from an external device is also called "push scanning." On the other hand, the mode in which an image processing device transmits scanned image data to the requesting information processing device in response to a request from the information processing device via a network is called "pull scanning."
[0003] As a conventional technique, Patent Document 1 describes a technique for push scanning. Specifically, the technique is characterized in that when a communication terminal such as a smartphone requests an MFP to scan a document, the MFP is instructed to generate a file with a signature. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2020-65129 A Summary of the Invention [Problem to be solved by the invention]
[0005] Here, the image processing device has a function of encrypting a file including scan image data using a password or the like when generating the file. When instructing encryption of a file to be generated by a scan request, the information processing device must also transmit data such as a password for encryption to the image processing device. Note that a secure communication path is not necessarily ensured for communication on a network between the information processing device and the image processing device. Therefore, when transmitting a password for encryption from the information processing device or acquiring a file including scan data, the communication data may be leaked. Therefore, even if the image processing device encrypts the file itself in response to a scan request, it may not necessarily be said that the security expected by the request source is ensured. The above-mentioned Patent Document 1 does not describe a technology for generating and transmitting an encrypted file.
[0006] In consideration of the above problems, the present invention aims to propose a more secure method than the conventional techniques when encrypting a file containing scanned image data in response to an external scan request. [Means for solving the problem]
[0007] The image processing device of the present invention is an image processing device equipped with a scanner, and has an execution means for executing a process of generating a file including image data obtained using the scanner and sending the file to the client device based on multiple requests made from a client terminal via communication on a network, and is characterized in that when an encrypted file is specified for the file by the client terminal, at least one of the communication for sending a password used when generating the encrypted file from the client device to the image processing device and the communication for sending the file generated by the image processing device to the client device is encrypted communication. Effect of the Invention
[0008] According to the present invention, it is possible to propose a more secure method than the prior art when encrypting a file including scanned image data in response to an external scan request. [Brief description of the drawings]
[0009] [Figure 1] A diagram showing an example of the system configuration [Diagram 2] FIG. 1 is a diagram showing an example of a hardware configuration of an image processing apparatus; [Diagram 3] FIG. 1 is a diagram showing an example of a hardware configuration of an information processing device; [Figure 4] Figure showing the scan settings screen of the scanning application on the client terminal [Diagram 5] Figure showing the reception completion screen of the scan application [Figure 6] FIG. 1 is a diagram showing a sequence of an MFP and a client terminal according to a first embodiment; [Figure 7] A flowchart for explaining processing in a client terminal according to the first embodiment. [Figure 8] 1 is a flowchart for explaining processing in an image processing apparatus according to a first embodiment; [Figure 9] FIG. 13 is a diagram showing an example of communication contents of a pull scan according to the first embodiment; [Figure 10] FIG. 13 is a diagram showing communication contents for acquiring a scanner status according to the first embodiment; [Figure 11] A flowchart for explaining processing in a client terminal according to the second embodiment. [Figure 12] 11 is a flowchart for explaining a process in an image processing apparatus according to a second embodiment. [Figure 13] FIG. 13 is a diagram showing a sequence of an MFP and a client terminal according to a third embodiment. [Figure 14] A flowchart for explaining processing in a client terminal according to the third embodiment. [Figure 15] 11 is a flowchart for explaining processing in an image processing apparatus according to a third embodiment. [Figure 16]FIG. 13 is a diagram showing communication contents of a pull scan according to the third embodiment. [Figure 17] FIG. 13 is a diagram showing communication contents for setting an encryption password according to the third embodiment; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0011] <First embodiment> An example of a system configuration including a network in the first embodiment will be described with reference to Fig. 1. In the image processing system shown in Fig. 1, an MFP 101, which is an example of an image processing device, and a client terminal 102 are connected via a network 103. The network 103 is further connected to the Internet (not shown) and the like, and is connected to a storage service (not shown) on the network.
[0012] The MFP (Multi Function Peripheral) 101 is an example of an image processing device that employs an electrophotographic method, and has scan, copy, and print functions. The MFP 101 has a function of transmitting an image read by a scanner to an external device such as a client terminal 102 via a network 103. The client terminal 102 is a general information processing device such as a personal computer (PC) or a smartphone. The network 103 is an example connected via a wired LAN (Local Area Network), but it may be a wireless LAN such as Wi-Fi.
[0013] With reference to FIG. 2, an example of the hardware configuration of MFP101, which is an example of an image processing apparatus, will be described. MFP101 includes CPU201, ROM202, RAM203, operation unit 204, scanner 205, printer 206, image processing circuit 207, hard disk 208, and network I / F 209. CPU201 is a control circuit that controls the entire system using a program stored in ROM202 and memory in RAM203. Operation unit 204 is a circuit that executes user operations. Scanner 205 reads an image on a document and outputs the read image page by page in order. Printer 206 prints an image based on the image on a recording medium. Image processing circuit 207 includes a large-capacity image memory, an image rotation circuit, a resolution magnification circuit, and an encoding / decoding circuit such as MH, MR, MMR, JBIG, and JPEG, and can also execute various image processes such as shading, trimming, and masking. Hard disk 208 is a large-capacity recording medium connected by an I / F such as SCSI or IDE. The hard disk 208 stores the program body relating to the pull scan of this embodiment, environmental settings referenced when the program runs, and the like. The network I / F 209 is a circuit for connecting to the network line 103. The scanner 205, printer 206, and image processing circuit 207 are connected by a high-speed video bus separate from the CPU 201 bus from the CPU 201, and are configured to be able to transmit images at high speed. The MFP 101 processes images read by the scanner 205 in the image processing circuit 207. Note that image processing devices to which the present invention can be applied also include network scanners that do not include the printer 206.
[0014] The image processing apparatus has a "network communication encryption" setting as a setting item that is referenced when processing a scan request from the client terminal 102. In the image processing apparatus, the setting value of this "network communication encryption" setting, enabled (ON) or disabled (OFF), is stored in the hard disk 208. When the "network communication encryption" setting is enabled, the network communication path executed in response to the scan request is encrypted (e.g., HTTPS communication) between the MFP 101 and the client terminal 102. Since encryption of the network communication path requires appropriate settings at both the communication source and the communication destination, the initial value of this "network communication encryption" setting is disabled (OFF) in the image processing apparatus.
[0015] An example of a hardware configuration of the client terminal 102, which is an example of an information processing device, will be described with reference to FIG.
[0016] The CPU 301 is connected to the DRAM 302 via a bus. The DRAM 302 is used by the CPU 301 as a working memory for temporarily arranging program data representing arithmetic instructions and data to be processed during the arithmetic process of the CPU 301. The CPU 301 is connected to the I / O controller 303 via a bus. The I / O controller 303 is connected to a network I / F 304. A wired LAN device, a wireless LAN device, or a data communication device is connected to the network I / F 304. The CPU 301 realizes communication on the network 103 by controlling the wired LAN device, the wireless LAN device, and the data communication device via the network I / F 304. The I / O controller 303 performs input / output to and from various devices according to instructions from the CPU 401. The 1 / 0 controller 303 is connected to a SATA (Serial Advanced Technology Attachment) I / F 305, to which a Flash ROM 310 is connected. Instead of a Flash ROM, a large-capacity storage device such as an HDD may be connected.
[0017] Programs such as a scan application according to the embodiments described below and setting values used therefor are stored in the Flash ROM 310. The CPU 301 executes programs such as a scan application to realize the processes in the client terminal 102 described in the embodiments. A panel I / F 307 is connected to the I / O controller 303, and the CPU 301 realizes input and output for a user to an operation unit 308 of the client terminal 102 connected via the panel I / F 307. An example of the operation unit 102 is a touch panel that also serves as a display device. The operation unit 308 may be realized by connecting a display or the like as a display device and an input device such as a keyboard for input to the panel I / F 406.
[0018] An example of a scan setting screen of a scan application provided on the display device of the client terminal 102 will be described with reference to FIG.
[0019] Buttons 401 to 407 are used to set the scan settings in the image processing device, and the current setting value is displayed on each button. The settings made here are sent as a scan request to the image processing device via the network, and are used for scanning an original in the image processing device, generating a file including scanned image data, and so on. In the case of a scan request for pull scanning, the destination of the generated file is the client terminal 102, so destination settings are omitted on this setting screen.
[0020] The "Reading target setting" button 401 is a button for setting the reading target (pressure plate or feeder). The "Paper size setting" button 402 is a button for setting the paper size to be read (A4 size, A3 size, etc.). The "Color mode setting" button 403 is a button for setting the color mode (color, black and white, etc.) during scanning. The "Resolution setting" button 404 is a button for setting the resolution during scanning (300 dpi, 600 dpi, etc.). The "Feed direction setting" button 405 is a button for setting the feeding direction of the document (vertical feed or horizontal feed).
[0021] The "File Format Setting" button 406 is a button for setting the file format of a file including scanned image data transmitted from an image processing device. A number of file formats can be selected, including JPEG, unencrypted PDF, and encrypted PDF. The "Encryption Password Setting" button 407 is a button that can be selected when "Encrypted PDF" is selected with the "File Format Setting" button 406, and is a button for setting an encryption password. When this button 407 is selected, a password input screen is additionally displayed, and the user can set a password of their choice. In FIG. 4, in order to conceal the characters entered as the encryption password, the entered characters are displayed replaced with "*".
[0022] A "Start Scan" button 408 is a button for starting the scanning process. A "Cancel" button 409 is a button for closing this application.
[0023] 5 shows an example of a reception completion screen provided by the scan application when a file including scanned image data is received from an image processing device. A reception completion area 501 displays a message indicating that reception is complete. Although not shown, if a reception error occurs, an error message or error code is displayed in this area. A "Done" button 502 is a button for closing the scan application.
[0024] A sequence of processes performed by the MFP 101 and the client terminal 102 in this embodiment will be described with reference to Fig. 6. Note that HTTP or HTTPS is used for each communication between the MFP 101 and the client terminal 102 described in Fig. 6 and subsequent figures. It is also assumed that the IP address of the MFP 101 is "192.168.1.100".
[0025] The client terminal 102 displays a scan setting screen as shown in Fig. 3 (S601). The client terminal 102 accepts an operation for read setting and performs the respective settings (S602).
[0026] Here, a case will be described in which the client terminal 102 selects encrypted PDF with the "file format setting" button 406 and sets an appropriate character string in the "encryption password setting" button 407. The client terminal 102 detects that the "start scanning" button 408 has been pressed (S603).
[0027] The client terminal 102 requests the MFP 101 to perform a pull scan, and the MFP 101 responds to the request (S604).
[0028] In S605, the MFP 101 executes the scan process.
[0029] The client terminal 102 requests the MFP 101 to obtain the scanner status, and the MFP 101 responds to the request (S606). At this time, the client terminal 102 switches processing depending on whether the scan processing is complete or not. In this sequence, the case where the scan processing is complete will be described.
[0030] If the scan process is complete, the client terminal 102 requests the MFP 101 to send a scanned image, and the MFP 101 responds to the request (S607). The client terminal 102 displays a transmission completion screen as shown in FIG.
[0031] Fig. 7 is a flowchart for explaining the processing in the client terminal 102 in this embodiment. The processing shown in Fig. 7 is realized by the CPU 301 of the client terminal 102 executing a scan application.
[0032] The client terminal 102 displays a scan setting screen as shown in FIG. 3 (S701). The client terminal 102 accepts an operation from a user (S702). The client terminal 102 determines whether the accepted operation is a read setting (S703). If any of the read setting buttons 401 to 407 is pressed, it is determined that it is a read setting. If it is a read setting, the client terminal 102 updates the corresponding read setting (S704). Thereafter, the process proceeds to S702. If it is not a read setting, the client terminal 102 determines whether the accepted operation is a scan start (S705). If the "scan start" button 408 is pressed, it is determined that it is a scan start. If the client terminal 102 accepts a scan start operation, the process proceeds to S706, and if the application is terminated without accepting the scan start due to a cancel process or the like, the process also ends.
[0033] In step S706 , the client terminal 102 transmits a pull scan request to the MFP 101 .
[0034] Figure 9(a) shows an example of the contents of a pull scan request. The request is made by using the POST method to the URI (Uniform Resource Identifier) "http: / / 192.168.1.100 / ScanJob". The settings are written under the ScanJob element in XML (eXtensible Markup Language) format in the message body.
[0035] The Source element represents the object to be read, and "Platen" indicates that the object to be read is a platen. The Direction element represents the feed direction, and "ShortEdgeFeed" indicates that the feed direction is short edge feed. The Size element represents the paper size to be read, and "A4" indicates that the paper size to be read is A4. The Format element represents file transmission, and "EncryptedPDF" indicates that the file format is encrypted PDF. The EncryptionPassword element represents the encryption password, and "0101" indicates that the encryption password is 0101. The ColorMode element represents the color mode, and "Color" indicates that the color mode is color. The Resolution element represents the resolution at the time of scanning.
[0036] In step S707, the client terminal 102 receives the pull scan response from the MFP 101.
[0037] Figure 9(b) is an example of a successful response to an HTTP POST request. "Location: https: / / 192.168.1.100 / ScanJob / 1" indicates the URI for obtaining the scanned image of the requested pull scan.
[0038] Here, by setting the protocol for acquiring images to https, an encrypted communication path can be used. If encrypted communication is not used, use http instead of https.
[0039] In S708, the client terminal 102 checks the contents of the pull scan response and determines whether it was successful. If it was successful, the process proceeds to S709, and if it was not successful, the reception completion screen of Fig. 5 is displayed on the operation unit 308 (S717), and then the process ends. At this time, a message notifying that an error has occurred is displayed in the reception completion area 501.
[0040] The client terminal 102 makes a scanner status acquisition request to the MFP 101 (S709). The request is made by using a GET method to the URI "http: / / 192.168.1.100 / ScannerStatus." In response to this request, the MFP 101 makes a response as shown in Fig. 10(a) or 10(b), and the MFP 101 receives this response (S710).
[0041] Detailed scanner status is described below the ScannerStatus element in XML format in the message body. The State element indicates the status of the scan job, with "Scanning" indicating scanning is in progress and "Idle" indicating waiting. The ScanPage element indicates the number of pages that have been scanned. The JobStatus element indicates the status of the scan job, with "Processing" indicating processing is in progress and "Completed" indicating completion. The JobResult element indicates the result of the scan job, with "Success" indicating successful completion.
[0042] The client terminal 102 determines whether the scan status response reception was successful (S711). If successful, the process proceeds to S712, and if not successful, the reception completion screen of Fig. 5 is displayed on the operation unit 308 (S718) and the process ends. At this time, a message notifying that an error has occurred is displayed in the reception completion area 501.
[0043] The client terminal 102 determines whether the scan job requested in S706 is complete (S712). If the JobStatus element is "Completed", it is determined that the scan job is complete. If the scan job is not complete, the process proceeds to S709.
[0044] If it is determined that the scan job is completed, the client terminal 102 requests the MFP 101 for the scanned image (S713). The request is made by using a GET method to the URI responded to in S707, and the MFP 101 responds to this request with binary data of the scanned image, which the MFP 101 receives (S714).
[0045] The client terminal 102 judges whether the binary data of the scanned image has been successfully received as a response (S715). If successful, the process proceeds to S716, and if not, the process proceeds to S719.
[0046] In S716, the client terminal 102 displays the reception completion screen of Fig. 5 and ends the process. At this time, a message notifying that reception is complete is displayed in the reception completion area 501.
[0047] In S719, a reception completion screen is displayed on the operation unit 308, and the process ends. At this time, a message notifying that an error has occurred is displayed on the reception completion screen.
[0048] Fig. 8 is a flowchart for explaining the processing in the MFP 101 in this embodiment. The CPU 201 of the MFP 101 executes a program related to this processing, thereby realizing the processing shown in Fig. 8.
[0049] The MFP 101 accepts a request (S801). The MFP 101 determines whether the request is for a pull scan (S802). It determines that the request is for a pull scan if the request is a POST method to "http: / / 192.168.1.100 / ScanJob" or "https: / / 192.168.1.100 / ScanJob" and if the request does not contain a Destination element under the ScanJob element in XML format in the message body. If it is not for a pull scan, the process proceeds to S808.
[0050] In step S803, if the request is a pull scan, the MFP 101 checks the value of the Format element in the pull scan request to determine whether the file is encrypted. If the value is EncryptedPDF, the MFP 101 determines that the file is encrypted. If the file is encrypted, the process proceeds to step S805, and if not, the process proceeds to step S804.
[0051] In S804, the MFP 101 issues a URI for acquiring a scanned image, and the MFP 101 generates a pull scan response as shown in Fig. 9(c), where the protocol of the Location is http.
[0052] In S805, the MFP 101 issues a URI for acquiring the scanned image, and generates a pull scan response as shown in Fig. 9(b). Here, the Location protocol is https. Note that the MFP 101 may be designed to set the Location protocol to "https" even if the "encryption of network communication" setting is OFF.
[0053] If the pull scan request cannot be processed normally in the process of S804 or S805, the MFP 101 generates a response indicating an error in response to the pull scan request in either step.
[0054] In S806, the MFP 101 transmits the pull scan response generated in S804 or S805 to the client terminal 102. The MFP 101 executes scanning with the scan settings included in the scan request (S807). After that, the MFP 101 waits for other requests, and returns to S801 when a request is accepted.
[0055] In S808, the MFP 101 determines whether the request received in S801 is for scanner status acquisition. If the request is a GET method to "http: / / 192.168.1.100 / ScannerStatus" or "https: / / 192.168.1.100 / ScannerStatus", it determines that the request is for scanner status acquisition. If the request is for scanner status acquisition, the process proceeds to S810, and if the request is not for scanner status acquisition, the process proceeds to S810.
[0056] In step S809, the MFP 101 responds to the request source as shown in Fig. 10(a) or Fig. 10(b) depending on the scanner status. If a scan job is being processed, the MFP 101 responds as shown in Fig. 10(a). If the scan job is completed, the MFP 101 responds as shown in Fig. 10(b). If the scanner status acquisition request cannot be processed normally, the MFP 101 responds with an error (not shown).
[0057] In S810, the MFP 101 determines whether the request received in S801 is for scan image acquisition. If the request is a GET method to the URI specified in the Location of the pull scan response sent in S806, it is determined that the request is for scan image acquisition. If the request is for scan image acquisition, the process proceeds to S811, and if the request is not for scan image acquisition, the process proceeds to S812.
[0058] In S811, the MFP 101 responds with the scanned image to the request source. If the scanned image acquisition request cannot be processed normally, an error response is returned. In S812, the MFP 101 determines that an incompatible request has been received, and responds with an error to the request source. Thereafter, the MFP 101 waits for other requests, and if a request is received, the process returns to S801.
[0059] According to the first embodiment, when a client terminal 102 instructs an image processing device to perform a pull scan, if the file format specified by the user is an encrypted file, the client terminal 102 can process the acquisition of the image file using encrypted communication.
[0060] <Second embodiment> In the second embodiment, an example will be described in which a pull scan request from a client terminal 102 to an MFP 101 is sent via HTTPS communication depending on a condition.
[0061] 1 to 6 are the same as those in the first embodiment. However, in this embodiment, the MFP 101 waits for HTTP communication and HTTPS communication from the client terminal 102 even if the "encryption of network communication" setting is OFF.
[0062] Fig. 11 is a flowchart for explaining the processing in the client terminal 102 in the second embodiment. Processing different from the processing explained in Fig. 7 will be specifically explained using Fig. 11.
[0063] Note that the processes in S701 to S704 and S706 to S719 are the same as those in FIG. 7, and therefore the description thereof will be omitted.
[0064] In S1101, if a scan start operation is accepted, the process proceeds to S1102, and if the application is terminated without accepting the scan start command due to a cancellation process or the like, the process also ends.
[0065] In S1102, the client terminal 102 determines whether the file format is an encrypted file. If the file format 406 is selected as encrypted PDF, it is determined that the file is encrypted. If it is an encrypted file, the process proceeds to S1103, and if not, the process proceeds to S706.
[0066] In step S1103 , the client terminal 102 transmits a pull scan request to the MFP 101 .
[0067] Fig. 9(a) shows an example of the contents of a pull scan request. The request is made to the URI (Uniform Resource Identifier) "https: / / 192.168.1.100 / ScanJob" by using the POST method of HTTPS communication. Fig. 9(a) includes an encryption password used when a file including scanned image data is converted to an encrypted PDF by an image processing device, which means that in the second embodiment, the communication path for transmitting the encryption password is also encrypted.
[0068] Fig. 12 is a flowchart for explaining the processing in the MFP 101 in the second embodiment. Processing different from the processing explained in Fig. 8 will be specifically explained using Fig. 12.
[0069] Note that the processes in S801 and S805 to S812 are the same as those in FIG. 8, and therefore the description thereof will be omitted.
[0070] In step S1201, the process of the MFP 101 proceeds to step S1202 if the request is for pull scanning, and proceeds to step S808 if the request is not for pull scanning.
[0071] In step S1202, the MFP 101 determines whether the protocol used when the pull scan is requested is HTTPS. If the protocol is HTTPS, the process proceeds to step S805. If the protocol is HTTP, the process proceeds to step S803.
[0072] According to the second embodiment, when the file format specified by the user is an encrypted file, encrypted communication can be used from the client terminal 102 to the image processing apparatus via a pull scan request including an encryption password.
[0073] <Third embodiment> In the third embodiment, an embodiment different from the second embodiment will be described for transmitting an encryption password via HTTPS communication when an encrypted file is specified as the file format in a pull scan request from a client terminal.
[0074] In this embodiment, the internal configurations and processes shown in FIGS. 1 to 5 are common to the first and second embodiments.
[0075] The sequence of processing performed by the MFP and client terminal in this embodiment is different from that in the first embodiment and is shown in the sequence of Fig. 13. The differences from Fig. 6 will be specifically described with reference to Fig. 13. S601 to S603 and S606 to S607 are the same as in Fig. 6.
[0076] In S1301, the client terminal 102 makes a pull scan request to the MFP 101, and the MFP 101 responds to the request. In S1302, the client terminal 102 makes an encryption password setting request to the MFP 101, and the MFP 101 responds to the request. Then, the MFP 101 executes a scan process (S1303).
[0077] In the first and second embodiments, the encryption password is specified in the pull scan request, but in this embodiment, the encryption password is not specified in the pull scan request, but is specified in the encryption password setting request.
[0078] Fig. 14 is a flowchart for explaining the processing of the client terminal 102 in the third embodiment. Processing different from the processing explained in Fig. 7 will be specifically explained using Fig. 14.
[0079] Note that the processes in S701 to S704 and S708 to S719 are the same as those in FIG. 7, and therefore the description thereof will be omitted.
[0080] In step S1401, the process of the client terminal 102 proceeds to step S1402 if scanning is to be started.
[0081] In S1402, the client terminal 102 transmits a pull scan request.
[0082] Fig. 16(a) shows an example of the contents of a pull scan request. The request is made to the URI (Uniform Resource Identifier) "http: / / 192.168.1.100 / ScanJob" by using the POST method of HTTP communication. Here, the file format is specified as encrypted PDF, but the EncryptionPassword element is not included. This makes it possible in this embodiment to prevent the encryption password from flowing in plain text over the communication path.
[0083] In S1403, the client terminal 102 receives a pull scan response from the MFP 102. Fig. 16B shows an example of the contents of the pull scan response, which is the same as Fig. 9B.
[0084] In S1404, the client terminal 102 checks the contents of the pull scan response and determines whether or not the response was successful. If the response was successful, the process of the client terminal 102 proceeds to S1405, and if the response was not successful, the process proceeds to S717. In S717, the client terminal 102 displays a message notifying the user that an error has occurred.
[0085] In S1405, the client terminal 102 determines whether the file format is an encrypted file. If the file format 406 is selected as encrypted PDF, it is determined that the file is encrypted. If the file is encrypted, the process of the client terminal 102 proceeds to S1404, and if not, the process proceeds to S1408.
[0086] In S1406, the client terminal 102 transmits an encryption password setting request to the MFP 101. Fig. 17A shows an example of the contents of the encryption password setting request.
[0087] The request is made to the Uniform Resource Identifier (URI) "https: / / 192.168.1.100 / ScanJob / 1" by using the POST method of HTTPS communication. This URI is the URI set in the Location field of the pull scan response received in S1403 with the protocol part replaced with https.
[0088] The encryption password setting request is composed of only the EncryptionPassword element of the ScnaJob element of the pull scan request.
[0089] By using HTTPS communication here, the encrypted password is transmitted over an encrypted communication channel, thereby preventing the encrypted password from being leaked.
[0090] In step S1407 , the client terminal 102 receives the encrypted password setting response from the MFP 101 .
[0091] FIG. 17(b) is an example of an encrypted password setting response when the response is successful.
[0092] In S1408, the client terminal 102 checks the contents of the encrypted password setting response and determines whether or not the setting was successful. If the setting was successful, the process of the client terminal 102 proceeds to S709, and if not, the process proceeds to S717.
[0093] Fig. 15 is a flowchart for explaining the processing of the MFP 101 in the third embodiment. Processing different from the processing explained in Fig. 8 will be specifically explained using Fig. 15.
[0094] Note that the processes in S801 to S805, S807 to S809, and S811 to S812 are similar to those in FIG. 8, and therefore the description thereof will be omitted.
[0095] In S1501, the MFP 101 checks the value of the Format element of the pull scan request to determine whether it is an encrypted file. If the value is EncryptedPDF, it is determined to be an encrypted file. If it is an encrypted file, the process proceeds to S801, and if not, the process proceeds to S807.
[0096] In S1502, the MFP 101 determines whether the request received in S801 is for scan image acquisition. If the request is a GET method to the URI specified in the Location of the pull scan response sent in S806, it is determined that the request is for scan image acquisition. If the request is for scan image acquisition, the MFP 101 processes by returning the scan image to the request source (S811). If the request is not for scan image acquisition, the MFP 101 process proceeds to S1503.
[0097] In S1503, the MFP 101 determines whether the request received in S801 is for encryption password setting. If the request is a POST method to the URI specified in Location of the pull scan response sent in S806 and contains only the EncryptionPassword element in the ScanJob element in XML format, it is determined that the request is for encryption password setting. If the request is for encryption password setting, the MFP 101 proceeds to S1504, and if the request is not for encryption password setting, the MFP 101 proceeds to S812.
[0098] In step S1504, the MFP 101 transmits an encryption password setting response to the client terminal 102. If the encryption password setting request cannot be processed normally, an error response is transmitted.
[0099] According to the third embodiment, when an instruction is given to the image processing device to generate an encrypted file, encrypted communication can be used as communication for transmitting an encryption password for this purpose from the client terminal.
[0100] Furthermore, according to the first to third embodiments, even if the value of the setting item "encryption of network communication" is OFF, the encrypted file, the encrypted file and the password are transmitted from the MFP to the client in encrypted communication.
[0101] <Fourth embodiment> Although not described in the first to third embodiments, when the value of the setting item "Encryption of network communication" of MFP101 is OFF and an encrypted PDF, the encrypted PDF, and a password are communicated via HTTPS, the setting may be changed to ON.
[0102] This improves the security of network communications during pull scanning.
[0103] <Fifth embodiment> Assuming that generation of an encrypted PDF is specified in a scan request from client terminal 102, a password to be used for the encryption may be pre-registered in MFP 101. In this case, a user such as an administrator can register in MFP 101 in advance at least any one of user information, a specific protocol, and a specific application information and a password in association with each other.
[0104] When the MFP 101 receives a scan request specifying the generation of an encrypted PDF file, if a password associated with at least one of the user information corresponding to the request source, a specific protocol, and a specific application has been registered, the MFP 101 generates an encrypted PDF file using that password. This eliminates the need for the client terminal 102 to transmit a password to the MFP 101 when making a scan request.
[0105] When a scan request specifying the generation of an encrypted PDF is received, if a password associated with at least any of the user information corresponding to the request source, a specific protocol, and a specific application is not registered in the MFP 101, a method according to the first to fourth embodiments described above can be appropriately adopted. This ensures a more secure password transmission method than the conventional technology.
[0106] Sixth embodiment In the second and third embodiments, the encrypted password is transmitted from the client terminal 102 to the MFP 101 over an encrypted communication path (HTTPS communication). In these embodiments, an encrypted PDF file is transmitted from the MFP 101 to the client terminal 102. Some users may consider that an encrypted communication path (HTTPS communication) is not necessary for transmitting this encrypted PDF file.
[0107] Therefore, in the second and third embodiments, when transmitting an encrypted PDF file from the MFP 101, HTTP or HTTPS communication may be performed in accordance with the value of the setting item "encryption of network communication" of the MFP 101.
[0108] (Other Examples) The present invention also includes an apparatus or system configured by appropriately combining the above-described embodiments, and a method thereof.
[0109] Here, the present invention is a device or system that executes one or more pieces of software (programs) that realize the functions of the above-mentioned embodiments. Also, a method for realizing the above-mentioned embodiments executed by the device or system is also one aspect of the present invention. Also, the program is supplied to the system or device via a network or various storage media, and the program is read into one or more memories by one or more computers (CPU, MPU, etc.) of the system or device and executed. In other words, as one aspect of the present invention, the program itself, or various storage media that store the program and can be read by a computer, are also included. Also, the present invention can be realized by a circuit (e.g., ASIC) that realizes the functions of the above-mentioned embodiments. [Explanation of symbols]
[0110] 101 MultiFunction Peripheral (MFP) 102 Client terminals
Claims
1. An image processing device equipped with a scanner, a receiving means for receiving a scan request from a client terminal via a network; an execution means for executing a process of causing the client terminal to transmit a password used for encrypting the file using encrypted communication with the client terminal when the scan request includes a specification regarding an encrypted file; a processing means for encrypting a file containing image data obtained by the scanner based on the scan request using a password received from the client terminal through encrypted communication; a transmitting means for transmitting the file encrypted by the encryption process to a client terminal; 1. An image processing device comprising:
2. An image processing device as described in Claim 1, characterized in that it further has an instruction means for sending an instruction to a client terminal to make the communication for sending the file generated by the image processing device to the client device an encrypted communication.
3. The image processing device as described in claim 1, further comprising a setting means for setting encryption of communications on the network.
4. The image processing device described in Claim 1, characterized in that the sending means sends the encrypted file to the client terminal in response to a request from the client terminal.
5. The image processing device described in Claim 1, characterized in that the execution means receives the password from the client terminal after encrypting the communication for sending the password from the client terminal to the image processing device.
6. A control method for an image processing device equipped with a scanner, comprising: a receiving step of receiving a scan request from a client terminal via a network; an execution step of executing a process of transmitting a password used for encrypting the file to the client terminal using encrypted communication with the client terminal when the scan request includes a specification regarding an encrypted file; a processing step of encrypting a file including image data obtained by the scanner based on the scan request using a password received from the client terminal through encrypted communication; a transmitting step of transmitting the file encrypted by the encryption process to a client terminal; A control method comprising: