Information processing device, information processing method, and program
Patent Information
- Application Number
- JP2024215132
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-10-17
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] Conventionally, identification and authentication of secure networks have been realized by using public key infrastructure (PKI) technology that uses digital certificates.
[0003] For example, an information processing device acting as a client can verify the authenticity of a server by acquiring a server public key certificate from the server and a certificate authority certificate of the certificate authority that issued the server public key certificate. Also, by providing the server with a client public key certificate of the information processing device, the server can verify the authenticity of the client.
[0004] Digital certificates have an expiration date, and when the expiration date is reached, communication using that digital certificate becomes impossible. Therefore, digital certificates must be renewed when they have expired or immediately before they expire.
[0005] Conventionally, there is known a technique for automatically updating an electronic certificate at a predetermined timing before the expiration date (for example, Patent Document 1). At a predetermined timing, an information processing device transmits an update request to a certificate management server via a network and receives an electronic certificate from the certificate management server. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] JP2016-178458 Public Relations Summary of the Invention [Problem to be solved by the invention]
[0007] However, when the automatic certificate update function of the information processing device is enabled, if the settings required for the automatic certificate update function are not configured in advance, the automatic certificate update function may not be executed normally. For example, if the automatic certificate update function is enabled in a state where the address of the certificate management server is not configured, the information processing device cannot connect to the certificate management server and therefore cannot obtain a certificate. [Means for solving the problem]
[0008] In order to solve the above problems, an information processing device according to one aspect of the present invention has the following configuration: That is, the information processing device is connectable to an external device via a network, and is characterized by having a setting means for enabling a function of transmitting an issuance request for a digital certificate to the external device at a pre-specified date and time or at a pre-specified cycle and obtaining a digital certificate from the external device in response to the issuance request, and a means for enabling the function in the setting means on the condition that information for connecting to the external device has been input.
[0009] An information processing device according to an aspect of the present invention has the following configuration: That is, the information processing device is connectable to an external device via a network, and is characterized by having a receiving means for receiving setting values used in the information processing device from the external device, a determining means for determining whether the setting values include information for connecting to the external device, and an importing means for importing the setting values based on the determining means determining that the setting values include information for connecting to the external device. Effect of the Invention
[0010] According to the present invention, it is possible to prevent a situation in which an electronic certificate cannot be obtained from an external device at a pre-specified date and time or at a pre-specified cycle. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram for explaining a network configuration according to a first embodiment of the present invention. [Diagram 2] FIG. 2 is a block diagram illustrating the hardware configuration of the multifunction peripheral according to the first embodiment. [Diagram 3] FIG. 2 is a block diagram for explaining software modules included in the multifunction peripheral according to the first embodiment. [Figure 4] FIG. 11 is a sequence diagram for explaining the overall processing flow, from initial settings related to an electronic certificate issuance request, display of electronic certificate information, issuance request and reception, reboot, and reflection of the electronic certificate, in the system of the first embodiment. [Diagram 5] 5A is a flowchart illustrating the process of obtaining a list of key pairs and electronic certificates and creating display data at S402 in FIG. 4 by a multifunction peripheral according to a first embodiment; and FIG. 5B is a flowchart illustrating the process when the multifunction peripheral according to the first embodiment receives a request to display detailed information from a PC. [Figure 6] 5 is a flowchart for explaining a process of setting a connection to a certification authority / registration authority in S407 of FIG. 4, performed by the multifunction peripheral according to the first embodiment. [Figure 7] 5 is a flowchart for explaining the CA certificate acquisition and registration process shown in S412 to S416 in FIG. 4 by the multifunction peripheral according to the first embodiment. [Figure 8] 5 is a flowchart for explaining the certificate issuance request / acquisition process from S419 to S424 in FIG. 4 by the multifunction peripheral according to the first embodiment. [Figure 9] 5 is a flowchart for explaining the process of restarting the multifunction peripheral 100 from S424 to S427 in FIG. 4, performed by the multifunction peripheral according to the first embodiment. [Figure 10] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 11] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 12] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 13] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 14] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 15] FIG. 4 is a diagram showing an example of a web page screen of an RUI displayed on a PC according to the first embodiment. [Figure 16] FIG. 13 is a diagram showing an example of detailed information of an electronic certificate displayed on a PC according to the first embodiment. [Figure 17] 4 is a conceptual diagram of a database of detailed information on key pairs and electronic certificates managed by a key pair and certificate management unit of the multifunction peripheral according to the first embodiment. FIG. [Figure 18] FIG. 4 is a diagram showing an example of an electronic certificate renewal reservation setting screen of the multifunction peripheral according to the first embodiment. [Figure 19] 6 is a flowchart for explaining a process performed when the multifunction peripheral according to the first embodiment executes an automatic update function and an automatic deletion function of an electronic certificate based on an update reservation setting of the electronic certificate. [Figure 20] 6 is a flowchart illustrating a process for generating an electronic certificate renewal reservation setting screen performed by the multifunction peripheral according to the first embodiment. [Figure 21] FIG. 4 is a diagram showing an example of an electronic certificate renewal reservation setting screen of the multifunction peripheral according to the first embodiment. [Figure 22] 10 is a flowchart illustrating a process in which the multifunction peripheral according to the second embodiment imports a setting value of an electronic certificate renewal reservation setting. [Figure 23] FIG. 13 is a diagram for explaining a network configuration according to a second embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, an embodiment of the present invention will be described in detail with reference to the attached drawings. Note that the following embodiment does not limit the present invention according to the claims, and not all of the combinations of features described in the present embodiment are necessarily essential to the solution of the present invention. Note that a multifunction peripheral (digital multifunction peripheral / MFP / Multi Function Peripheral) will be used as an example of an information processing device that uses and manages electronic certificates according to the embodiment. However, the scope of application is not limited to multifunction peripherals, and may be any information processing device that can use electronic certificates.
[0013] [Embodiment 1] FIG. 1 is a diagram for explaining a network configuration according to the first embodiment of the present invention. A multifunction device 100 having a printing function can be connected to other information processing devices via a network 110. The multifunction device 100 can transmit and receive print data, scanned image data, device management information, and the like to and from other information processing devices via the network 110. The multifunction device 100 also has a function for performing encrypted communication such as TLS, IPSEC, IEEE802.1X, and holds a public key pair and an electronic certificate used for the encryption processing. Here, the multifunction device 100 is an example of an image forming device, and the image forming device is not limited to this, and may be a device having a single function of a facsimile machine, a printer, or a copier, or a device having a combination of these functions. A multifunction device 101 is also connected to the network 100, and this multifunction device 101 has the same function as the multifunction device 100. Below, the multifunction device 100 will be mainly described, but the exchange of electronic certificates may also be for multiple multifunction devices.
[0014] The certificate authority / registration authority 102 has a function of a certificate authority (CA) that issues digital certificates, and a function of a registration authority (RA) that accepts requests for issuing digital certificates and performs registration processing. That is, the certificate authority / registration authority 102 is a server device that has a function of distributing CA certificates and issuing and registering digital certificates via a network 110. In the first embodiment, the network 110 uses the Simple Certificate Enrollment Protocol (SCEP) as a protocol for this network 110. An information processing device such as the multifunction peripheral 100 uses this SCEP to communicate with the certificate authority / registration authority 102 via the network 110 to request and obtain an electronic certificate. The multifunction peripheral 100 according to the first embodiment has a web server function and exposes a web page type RUI (Remote UI) function on the network 110 that can execute processes for requesting and obtaining an electronic certificate.
[0015] When the certification authority / registration authority 102 receives an issuance request for an electronic certificate from another information processing device via the network 110, it issues and registers the electronic certificate based on the issuance request, and transmits the issued electronic certificate as a response to the issuance request. In the first embodiment, the functions of the certification authority and the registration authority are realized by the same server device, but the certification authority and the registration authority may be realized by different server devices, and there is no particular limitation. In the first embodiment, SCEP is used as a protocol for requesting issuance of an electronic certificate and for acquiring it, but any protocol having equivalent functions may be used, and there is no particular limitation in this embodiment. For example, CMP (Certificate Management Protocol) or EST (Enrollment over Secure Transport) protocol may be used.
[0016] The PC 103 is a personal computer that is equipped with a Web browser function, and is capable of viewing and using HTML documents and Web sites published by information processing devices connected to the network 110 .
[0017] Next, an overview of the process of obtaining and updating a digital certificate according to the first embodiment will be described.
[0018] The administrator of the multifunction device 100 uses a web browser installed in the PC 103 to connect to a web page published by the multifunction device 100 to request and acquire an electronic certificate, and makes settings and gives instructions for requesting and executing the process to acquire the electronic certificate. The multifunction device 100 requests the certification authority / registration authority 102 to acquire a CA certificate by SCEP and issue an electronic certificate, according to the settings and instructions given by the administrator. The multifunction device 100 also acquires the electronic certificate issued by the certification authority / registration authority 102 and included in the response to the request to issue the electronic certificate, and makes settings for using the acquired electronic certificate in the multifunction device 100.
[0019] Next, the hardware configuration of the multifunction peripheral 100 according to the first embodiment will be described.
[0020] FIG. 2 is a block diagram illustrating the hardware configuration of the multifunction peripheral 100 according to the first embodiment.
[0021] The CPU 201 executes the software program of the multifunction device 100 and controls the entire device. The ROM 202 is a read-only memory that stores the boot program and fixed parameters of the multifunction device 100. The RAM 203 is a random access memory that is used to store programs and temporary data when the CPU 201 controls the multifunction device 100. The HDD 204 is a hard disk drive that stores system software, applications, and various data. The CPU 201 executes the boot program stored in the ROM 202, expands the program stored in the HDD 204 into the RAM 203, and controls the operation of the multifunction device 100 by executing the expanded program. The network I / F control unit 205 controls the transmission and reception of data to and from the network 110. The scanner I / F control unit 206 controls the reading of documents by the scanner 211. The printer I / F control unit 207 controls the printing process by the printer 210. The panel control unit 208 controls a touch panel type operation panel 212, and controls the display of various information and the input of instructions from the user. A bus 209 interconnects the CPU 201, ROM 202, RAM 203, HDD 204, network I / F control unit 205, scanner I / F control unit 206, printer I / F control unit 207, and panel control unit 208. Control signals from the CPU 201 and data signals between the various devices are transmitted and received via the bus 209.
[0022] Fig. 3 is a block diagram for explaining software modules included in the multifunction peripheral 100 according to the embodiment 1. The software modules shown in Fig. 3 are realized by the CPU 201 executing a program loaded in the RAM 203.
[0023] The network driver 301 controls the network I / F control device 205 connected to the network 110 to transmit and receive data to and from the outside via the network 110. The network control unit 302 controls communication below the transport layer in a network communication protocol such as TCP / IP to transmit and receive data. The communication control unit 303 is a module for controlling a plurality of communication protocols supported by the multifunction peripheral 100. In the process of acquiring and updating an electronic certificate according to the first embodiment, the communication control unit 303 generates and analyzes requests and response data for HTTP protocol communication, and controls data transmission and reception, and executes communication with the certification authority / registration authority 102 and the PC 103. The communication control unit 303 also executes encrypted communication of TLS, IPSEC, and IEEE802.1X supported by the multifunction peripheral 100.
[0024] Web page control unit 304 is a module that generates HTML data for displaying a Web page that can execute a request for issuing an electronic certificate and a process for acquiring the same, and controls communication. Web page control unit 304 executes processing in response to a request for displaying a Web page sent from network driver 301 via communication control unit 304, and an instruction to issue and acquire an electronic certificate. Web page control unit 304 transmits HTML data of a default Web page stored in RAM 203 or HDD 204, or HTML data generated according to the contents of the display request, as a response to a request from a Web browser.
[0025] The key pair and certificate acquisition control unit 305 is a module for executing the process of acquiring an electronic certificate based on an instruction from the Web page control unit 304. The key pair and certificate acquisition control unit 305 is a module for performing communication control by SCEP, generation and analysis of encrypted data required for communication by SCEP such as PKCS#7 and PKCS#10, storage of acquired electronic certificates, and processing such as setting of usage. The encryption processing unit 306 is a module for performing various encryption processes such as data encryption and decryption, generation and verification of electronic signatures, and generation of hash values. The encryption processing unit 306 performs each encryption process required for generation and analysis of SCEP request and response data in the acquisition and update processing of electronic certificates according to the first embodiment. The key pair and certificate management unit 307 is a module for managing the public key pair and electronic certificates held by the multifunction peripheral 100. The key pair and certificate management unit 307 stores the data of the public key pair and electronic certificate together with various setting values in the RAM 203 or the HDD 204. Although not shown in the first embodiment, processes such as displaying details of a public key pair and an electronic certificate, generating, deleting, etc., can also be executed by a user's instruction via the operation panel 212. The operation panel 212 and the panel control unit 208 are controlled by a UI control unit 308. In encrypted communication processes such as TLS, IPSEC, and IEEE802.1X executed by the communication control unit 303, encryption processing is also performed by an encryption processing unit 306, and public key pair and electronic certificate data to be used are obtained from a key pair and certificate management unit 307.
[0026] The print / read processing unit 309 is a module for executing functions such as printing by the printer 210 and reading of documents by the scanner 211. The device control unit 310 is a module for generating control commands and control data for the multifunction device 100 and for overall control of the multifunction device 100. The device control unit 306 according to the first embodiment controls the power supply of the multifunction device 100 and executes restart processing of the multifunction device 100 in response to an instruction from the Web page control unit 304.
[0027] FIG. 4 is a sequence diagram explaining the overall processing flow in the system of embodiment 1, from initial settings regarding an electronic certificate issuance request, display of electronic certificate information, issuance request and reception, reboot, and reflection of the electronic certificate.
[0028] This sequence is started in response to a display instruction for the key pair and the book selection certificate list being input by the user. In the first embodiment, an example of processing for one multifunction device 100 will be described, but multiple multifunction devices 100 and 101 may be executed in response to one start instruction. For example, the PC 103 may issue a request to the multifunction devices 100 and 101, and each of the multifunction devices may execute the processing shown in the flowchart described below. In this case, the process of acquiring the certificates from the multifunction devices 100 and 101 and displaying them for confirmation may be skipped. Then, the multifunction device may automatically detect an expired certificate, transmit its bibliographic information (certificate ID and expiration date) to the PC 103, and the PC 103 may automatically update the certificates that are about to expire or have expired on the multiple multifunction devices. This is so-called silent installation.
[0029] First, in S401, when the multifunction device 100 accepts a connection from the PC 103, it receives a request sent from the PC 103 to display a list of key pairs and electronic certificates held by the multifunction device 100. In the first embodiment, the administrator of the multifunction device 100 uses a web browser installed in the PC 103 to connect to a web page format RUI for requesting and acquiring issuance of electronic certificates made public by the multifunction device 100, and performs operations such as issuing instructions. This RUI stands for remote user interface, and is a technology that allows the operation screen data of the multifunction device 100 or 101 to be remotely requested and displayed on the PC 103 using the web browser of the PC 103. At this time, the screen can be implemented using HTML, a servlet, or the like.
[0030] Next, in S402, the multifunction device 100 acquires data for displaying a list of key pairs and digital certificates held by the multifunction device 100, and generates a Web page screen for displaying the data.
[0031] Fig. 5A is a flowchart for explaining the process of obtaining a list of key pairs and digital certificates and creating display data in S402 in Fig. 4. This process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0032] FIG. 17 is a conceptual diagram of a database of detailed information on key pairs and electronic certificates managed by the key pair and certificate management unit 307 . This database is stored in the HDD 204 of the multifunction device 100 .
[0033] The flowchart in Fig. 5(A) will be described. This process starts by receiving a request to acquire a list of key pairs and electronic certificates. First, in S501, the CPU 201 receives the request to acquire a list of key pairs and electronic certificates. Next, the process proceeds to S502, where the CPU 201 acquires detailed information on the key pair and electronic certificate managed by the key pair and certificate management unit 307, for example, as shown in Fig. 17(A). Next, the process proceeds to S503, where the CPU 201 uses the detailed information on the key pair and electronic certificate acquired in S502 to generate HTML data for a Web page screen to be provided as an RUI.
[0034] 10 to 15 are diagrams showing examples of a web page screen of the RUI displayed on the PC 103 according to the first embodiment. In S503 in Fig. 5 according to the first embodiment, HTML data of the web page screen shown in Fig. 10(A) is generated, and this is displayed by the web browser of the PC 103. This makes it possible for the PC 103 to check the key pair and electronic certificate list held by the multifunction device 100.
[0035] The information of the electronic certificate displayed in the list of FIG. 10A includes the certificate name 1011, the purpose 1012, the issuer 1013, the validity end date 1014, and the certificate details 1015. The name 1011 is a character string arbitrarily given by an operator such as an administrator of the multifunction device 100 when the key pair and the electronic certificate are issued. The purpose 1012 is a setting value indicating that the key pair and the electronic certificate are used for any of TLS, IPSEC, and IEEE802.1X. The issuer 1013 is the distinguished name (DN: Distinguished Name) of the certificate authority that issued the electronic certificate. The validity end date 1014 is information on the date on which the validity of the electronic certificate ends. The details 1015 are an icon for displaying the detailed information of the electronic certificate. Then, the process proceeds to S504, where the CPU 201 transmits the HTML data generated in S503 to the PC 103 as a response to S501, and ends this process. In this manner, S403 in FIG. 4 is executed.
[0036] Although not shown in the sequence diagram of Fig. 4, when the administrator of multifunction device 100 clicks on the icon of details 1015 in Fig. 10(A) displayed on PC 103, a display request for detailed information on the corresponding electronic certificate is sent from PC 103 to multifunction device 100. Receiving the display request, multifunction device 100 acquires the detailed information on the electronic certificate, generates HTML data for the detailed information on the certificate based on the acquired information, and transmits the generated data to PC 103 as a response.
[0037] As a result, detailed information on the electronic certificate is displayed by the web browser of the PC 103, for example, as shown in Fig. 16. Fig. 16 is a diagram showing an example of detailed information on the electronic certificate displayed on the PC 103.
[0038] 5B is a flowchart for explaining the process when the multifunction peripheral 100 according to the first embodiment receives a request to display this detailed information from the PC 103. This process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0039] First, in S511, the CPU 201 receives a request to obtain detailed information about the electronic certificate from the PC 103. Next, the process proceeds to S512, where the CPU 201 obtains detailed information about the key pair and electronic certificate shown in Fig. 17A, which are managed by the key pair and certificate management unit 307. Next, the process proceeds to S513, where the CPU 201 uses the detailed information about the key pair and electronic certificate obtained in S512 to generate HTML data for a Web page screen, and transmits this to the PC 103 in S514.
[0040] FIG. 16 is a diagram showing an example of a display screen for detailed information on an electronic certificate according to the first embodiment. This screen is displayed on the PC 103 in a Web page format as an RUI.
[0041] Returning to the explanation of FIG. 4, in S403, the multifunction peripheral 100 transmits HTML data of the Web page screen shown in FIG. 10A, which was generated in S402, to the PC 103 as a response.
[0042] The processes shown in S401 to S403 in FIG. 4 and S501 to S504 and S511 to S514 in FIG. 5 indicate control processes related to display processing of electronic certificate information in the multifunction device 100 that has received a display request for the key pair / electronic certificate list.
[0043] Then, in S404, the multifunction peripheral 100 receives a display request for a connection setting screen of the SCEP server from the PC 103. In the first embodiment, the administrator of the multifunction peripheral 100 transmits a display request for the connection setting screen to the multifunction peripheral 100 by clicking on connection setting 1002 in Fig. 10(A) in order to perform connection settings with the certification authority / registration authority 102.
[0044] Next, in S405, the multifunction peripheral 100 transmits HTML data of the default SCEP server connection setting screen shown in FIG. 10B to the PC 103 as a response to S404.
[0045] The connection setting screen shown in Figure 10 (B) includes input fields for server name 1016 and port number 1017 for inputting the host name and destination port number of the SCEP server, and a set button 1018 for instructing the setting of the input setting values.
[0046] Next, in S406, the multifunction device 100 receives a setting instruction request for connection settings from the PC 103. The administrator of the multifunction device 100 in the first embodiment inputs server name 1016 and port number 1017 in Fig. 10(B) from the PC 103, and transmits this setting instruction request to the multifunction device 100 by clicking a setting button 1018.
[0047] Next, in S407, the multifunction device 100 executes a process for setting the connection settings and a process for generating a Web page screen showing the setting results, and in S408, transmits the HTML data of the Web page screen shown in FIG. 11(A) generated in S407 to the PC 103 as a response.
[0048] 6 is a flowchart for explaining the process of setting the connection settings to the certification authority / registration authority 102 in S407 of FIG. 4 by the multifunction peripheral 100 according to the first embodiment. This process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0049] First, in S601, the CPU 201 receives a connection setting request from the PC 103. Next, the process proceeds to S602, where the CPU 201 acquires the host name and port number settings included in the connection setting request, and stores the acquired settings in the RAM 203 or HDD 204. Next, the process proceeds to S603, where the CPU 201 generates HTML data for a Web page screen, for example, as shown in FIG. 11A. Then, the process proceeds to S604, where the CPU 201 transmits the HTML data generated in S603 as a response to S601, and ends this process. Then, the process proceeds to S408. As a result, the PC 103 displays a character string 1101 indicating that the settings have been reflected, as shown in FIG. 11A.
[0050] The above-mentioned processes shown in S406 to S408 and S600 to 604 are the control related to the connection setting process in the multifunction device 100.
[0051] 4, the multifunction device 100 receives a display request for a CA certificate acquisition screen sent from the browser of the PC 103. In the first embodiment, the administrator of the multifunction device 100 transmits a display request for a CA certificate acquisition screen to the multifunction device 100 by clicking CA certificate acquisition 1003 in FIG.
[0052] As a result, in S410, the multifunction peripheral 100 transmits HTML data of the default CA certificate acquisition screen shown in FIG. 11B as a response to S409.
[0053] The connection setting screen in FIG. 11(B) includes an execute button 1102 for instructing acquisition of a CA certificate.
[0054] Next, in S411, the multifunction device 100 receives a request to acquire a CA certificate sent from the browser of the PC 103 when the execute button 1102 in Fig. 11(B) is clicked. In the first embodiment, it is assumed that the administrator of the multifunction device 100 clicks the execute button 1102 in Fig. 11(B) to send a request to acquire a CA certificate to the multifunction device 100.
[0055] Next, in S412, the multifunction device 100 executes a process of generating data for requesting acquisition of a CA certificate. Then, the process proceeds to S413, where the multifunction device 100 transmits the data for requesting acquisition of a CA certificate generated in S412 to the certification authority / registration authority 102, which is a SCEP server, based on the information set in S407. Then, the process proceeds to S414, where the multifunction device 100 receives a response to the request for acquiring a CA certificate transmitted from the certification authority / registration authority 102. As a result, the process proceeds to S415, where the multifunction device 100 analyzes the received response for acquiring the CA certificate, acquires the CA certificate contained in the response, and registers the acquired CA certificate as a CA certificate trusted by the multifunction device 100. Then, the process proceeds to S416, where the multifunction device 100 transmits HTML data of the Web page screen shown in FIG. 12(A) or FIG. 12(B), generated in S415, to the PC 103. FIG. 12(A) shows an example of a screen that is displayed when the CA certificate is successfully acquired and registered as a CA certificate. On the other hand, FIG. 12(B) shows an example of a screen that is displayed when acquisition of a CA certificate fails.
[0056] 7 is a flowchart for explaining the CA certificate acquisition and registration process shown in S412 to S416 in Fig. 4 by the multifunction peripheral 100 according to the first embodiment. Note that this process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0057] First, in S701, the CPU 201 receives a request to acquire a CA certificate from the PC 103. Next, the process proceeds to S702, where the CPU 201 generates a message for requesting to acquire a CA certificate based on the information on the connection settings to the certification authority / registration authority 102 acquired in S407. The following is an example of an acquisition request message generated in the first embodiment. In the first embodiment, SCEP is used as the communication protocol, and the message is a request message for using this protocol. xxxxxxx / yyyyy?operation=GetCAXyz&message=CAIdentifier
[0058] Next, the process proceeds to S703, where the CPU 201 connects to the certification authority / registration authority 102, which is the SCEP server, using the TCP / IP protocol based on the connection settings to the certification authority / registration authority 102 acquired in S407 of Fig. 4. Next, the process proceeds to S704, where the CPU 201 determines whether the connection in S703 was successful, and if successful, the process proceeds to S705, and if unsuccessful, the process proceeds to S714.
[0059] In S705, the CPU 201 transmits the CA certificate acquisition message generated in S702 to the certification authority / registration authority 102 by the GET or POST method of the HTTP protocol. Next, the process proceeds to S706, where the CPU 201 determines whether the connection in S704 was successful, and if successful, the process proceeds to S707, and if unsuccessful, the process proceeds to S714. In S707, the CPU 201 receives response data from the certification authority / registration authority 102 in response to the CA certificate acquisition request. Then, the process proceeds to S708, where the CPU 201 determines whether the response data reception in S707 was successful, and if successful, the process proceeds to S709, and if unsuccessful, the process proceeds to S714. In S709, the CPU 201 analyzes the response data received in S708, and acquires the data of the CA certificate included in the response data. The analysis process of the response data and the acquisition process of the CA certificate are performed by the encryption processing unit 306.
[0060] The response data in the first embodiment is binary data in X.509 (RFC5280) format. However, for example, data in PKCS#7 (RFC5652: Cryptographic Message Syntax) format may be sent as a response, and the data format is not limited.
[0061] Next, the process proceeds to S710, where the CPU 201 determines whether the CA certificate was successfully acquired in S709. If the CA certificate was successfully acquired, the process proceeds to S711. If the CA certificate was not successfully acquired, the process proceeds to S714. In S711, the CPU 201 registers the CA certificate acquired in S709 as a CA certificate trusted by the multifunction device 100. At this time, the CPU 201 holds the acquired CA certificate in the RAM 203, and also stores the acquired CA certificate in a predetermined directory in the HDD 204 for storing CA certificates trusted by the multifunction device 100 by the key pair and certificate management unit 307. Then, the process proceeds to S712, where the CPU 201 determines whether the CA certificate registration process in S710 was successful. If the CA certificate was successfully acquired, the process proceeds to S713. If the CA certificate was not successfully acquired, the process proceeds to S714. In S713, the CPU 201 generates a thumbprint (a hash value based on the SHA1 algorithm) of the CA certificate to be displayed in 1201 in FIG. 12A when the CA certificate was successfully acquired. The generation of the thumbprint is executed by the encryption processing unit 306. Then, the process proceeds to S715, where the CPU 201 generates HTML data for display data of the CA certificate acquisition result in FIG. 12(A) and FIG. 12(A) from the processing results from S703 to S714. Then, the process proceeds to S716, where the CPU 201 transmits the HTML data generated in S715 to the PC 103 as a response to S701, and ends this process. Then, the process proceeds to S417 in FIG. 4. In the first embodiment, the character string 1201 in FIG. 12(A) is displayed according to the CA certificate acquisition result. Alternatively, if error processing is executed in S714, the character string 1202 in FIG. 12(B) is displayed. Next, the description of FIG. 4 is returned to.
[0062] In S417, the multifunction device 100 receives a display request for a certificate issuance request screen transmitted from the browser of the PC 103. In the first embodiment, the administrator of the multifunction device 100 clicks on the certificate issuance request 1004 in Fig. 10(A) to request and obtain a certificate from the certification authority / registration authority 102.
[0063] Next, in S418, the multifunction device 100 transmits HTML data of a default certificate issuance request screen shown in Fig. 13A as a response to S417 to the PC 103. In response to this, the PC 103 performs display control to display the screen shown in Fig. 13A.
[0064] The certificate issuance request screen in Fig. 13(A) includes a certificate name 1301, key length 1302 for setting the key length of the key pair to be generated, and an input field 1303 for issuing destination information. The certificate issuance request screen in Fig. 13(A) also includes signature verification 1304 for setting whether to verify a signature attached to a response to the certificate issuance request sent from the certification authority / registration authority 102. The certificate issuance request screen in Fig. 13(A) also includes key usage 1305 for setting the usage of the issued certificate, a password 1306 to be included in the certificate issuance request, and an execute button 1307 for executing the certificate issuance request. Usage 1305 is a checkbox, indicating that multiple usages can be set for one key.
[0065] Next, in S419, the multifunction device 100 receives a certificate issuance request including the input / setting information 1301 to 1306 transmitted from the browser of the PC 103 when the execute button 1307 on the screen in Fig. 13(A) is clicked. In the first embodiment, the administrator of the multifunction device 100 performs the input / settings 1301 to 1306 in Fig. 13(A) and clicks the execute button 1307 to transmit the certificate issuance request from the PC 103.
[0066] Next, in S420, the multifunction device 100 executes a process for generating certificate issuance request data. Then, in S421, the multifunction device 100 transmits the certificate issuance request data generated in S420 to the CA / registration authority 102, which is the SCEP server, based on the information set in S407. Then, in S422, the multifunction device 100 receives a response to the certificate issuance request transmitted from the CA / registration authority 102. Next, in S423, the multifunction device 100 performs processing for analyzing the response to the certificate issuance request received in S422 (performing signature verification according to settings, acquiring the certificate included in the response, and setting the acquired certificate for a specified purpose). Then, processing for generating a Web page screen showing the result of the certificate issuance request is executed.
[0067] If the certificate is successfully issued and acquired, the electronic certificate data is saved and its purpose is set by the process of S423. The purpose setting here refers to a communication function that uses the electronic certificate, and in the first embodiment, encrypted communication such as TLS, IPSEC, and IEEE802.1X can be set. The multifunction peripheral 100 according to the first embodiment can have multiple electronic certificates, and the purpose is set for each electronic certificate. For example, when the electronic certificate used when the multifunction peripheral 100 provides a server service that performs TLS communication as a Web server and the electronic certificate used by the multifunction peripheral 100 to perform client communication using IEEE802.1X are different, each can be set. However, one electronic certificate may be automatically applied to all communication purposes.
[0068] Then, in S424, the multifunction device 100 transmits HTML data of the Web page screen shown in Fig. 13(B) or Fig. 14(A) generated in S423 to the PC 103. Note that depending on the result of the certificate issuance request, a character string of the setting result is displayed as shown in 1308 in Fig. 13(B) or 1401 in Fig. 14(A). Fig. 13(B) shows an example of a screen when the issuance and acquisition of the certificate are successful, and Fig. 14(A) shows an example of a screen when the issuance and acquisition of the certificate are unsuccessful.
[0069] If the certificate is issued and obtained successfully, the electronic certificate data is saved and its purpose is set by the process of S423. Since the communication control unit 303 according to the first embodiment obtains the data of the electronic certificate used in encrypted communication of TLS, IPSEC, and IEEE802.1X when the multifunction device 100 is started, if the purpose is changed, the multifunction device 100 must be restarted.
[0070] 8 is a flowchart for explaining the certificate issuance request / acquisition process from S419 to S424 in Fig. 4 by the multifunction peripheral 100 according to the first embodiment. Note that this process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0071] First, in S801, the CPU 201 receives a certificate issuance request from the PC 103. Next, the process proceeds to S802, where the CPU 201 acquires information on the certificate name 1301, key length 1302, issuer information input 1303, signature verification 1304, and key usage 1305 included in the certificate issuance request received in S801. Next, the process proceeds to S803, where the CPU 201 acquires the CA certificate acquired in S412 to S415 of FIG. 4. Then, the process proceeds to S804, where the CPU 201 performs a key pair generation process based on the information on the name 1301 and key length 1302 acquired in S802. The CPU 201 also generates Certificate Signing Request (CSR) data in the PKSC#10 (RFC2986) format using the cryptographic processing unit 306, based on the information on the issuer information input 1303 and password 1306. Next, the process proceeds to S805, where the CPU 201 determines whether the generation of the key pair and certificate signing request in S804 was successful, and proceeds to S806 if it is determined to be successful, and proceeds to S823 if it is unsuccessful. In S806, the CPU 201 generates certificate issuance request data. The acquisition request data generated in S806 is data in the PKCS#7 format defined by SCEP, based on the connection settings to the certification authority / registration authority 102 acquired in S407 of FIG.
[0072] Next, the process proceeds to S808, and the CPU 201 connects to the CA / registration authority 102, which is the SCEP server, using the TCP / IP protocol based on the connection setting to the CA / registration authority 102 acquired in S407 of FIG. 4. Next, the process proceeds to S809, and the CPU 201 determines whether the connection in S808 was successful, and if successful, the process proceeds to S810, and if unsuccessful, the process proceeds to S823. In S810, the CPU 201 transmits the certificate issuance request data generated in S806 by the GET or POST method of the HTTP protocol. Then, in S811, the CPU 201 determines whether the transmission in S810 was successful, and if successful, the process proceeds to S812, and if unsuccessful, the process proceeds to S823. In S812, the CPU 201 receives response data to the certificate issuance request from the CA / registration authority 102. The response data defined in SCEP is data in PKCS#7 format that is transmitted as a response.
[0073] Next, the process proceeds to S813, where the CPU 201 determines whether the response data was successfully received in S812, and if successful, the process proceeds to S814, and if unsuccessful, the process proceeds to S823. In S814, the CPU 201 determines whether the signature verification is set to be performed based on the setting of the signature verification 1304 acquired in S802, and if so, the process proceeds to S815, and if not, the process proceeds to S817. In S815, the CPU 201 verifies the signature data attached to the data received in S812 using the public key included in the CA certificate acquired in S803. Then, the process proceeds to S816, where the CPU 201 determines whether the signature verification in S815 was successful, and if successful, the process proceeds to S817, and if unsuccessful, the process proceeds to S823.
[0074] In S817, the CPU 201 analyzes the data received in S812 and obtains the certificate data included in the response data. At this time, the encryption processing unit 306 performs the analysis of the response data and the process of obtaining the certificate. Next, the process proceeds to S818, where the CPU 201 determines whether the acquisition of the certificate in S817 was successful. If it was successful, the process proceeds to S819, and if it was unsuccessful, the process proceeds to S823. In S819, the CPU 201 registers the certificate obtained in S818 as the electronic certificate corresponding to the key pair generated in S804. At this time, the CPU 201 stores the public key pair generated in S804 and the obtained electronic certificate in a predetermined directory of the HDD 204 that stores the key pair and electronic certificate by the key pair and certificate management unit 307. At this time, the key pair and certificate management unit 307 adds the information of the public key pair generated in S804 and the obtained electronic certificate to the list of the detailed information of the key pair and certificate, as shown in FIG. 17B. In FIG. 17B, a new key pair and certificate Xyz4 are added.
[0075] Next, the process proceeds to S820, where the CPU 201 determines whether the registration process of the CA certificate in S819 was successful, and if successful, the process proceeds to S821, and if unsuccessful, the process proceeds to S823. In S821, the CPU 201 sets the purpose of the certificate based on the information of key purpose 1305 acquired in S802. At this time, the key pair and certificate management unit 307 updates the information of purpose in the list of detailed information on the key pair and certificate, for example, as shown in Fig. 17(C). In Fig. 17(C), the key pair and certificate used in TLS have been changed from Xyz1 to Xyz4.
[0076] Next, the process proceeds to S824, and the CPU 201 generates HTML data of the result of the certificate issuance request shown in Fig. 13B according to the process results from S801 to S823. In S825, the HTML data generated in S824 is sent to the PC 103 as a response to the certificate issuance request in S801, and this process ends. Then, the process proceeds to S425 in Fig. 4.
[0077] The above-mentioned processes of S419 to S424 and S801 to S825 constitute the control related to the issuance request, reception process, and communication purpose setting of the electronic certificate in the multifunction device 100. In this embodiment 1, the processes of the issuance request, reception process, and communication purpose setting are collectively referred to as the "automatic update function of the electronic certificate."
[0078] This automatic digital certificate update function allows the multifunction device 100 to automatically perform issuance requests and reception processes for digital certificates via the network, and further allows the user to set the usage of the received digital certificate, reducing the amount of work required by the user. Returning to the explanation of FIG. 4.
[0079] In S425, the multifunction peripheral 100 receives the request to restart the multifunction peripheral 100. In the first embodiment, it is assumed that the administrator of the multifunction peripheral 100 clicks the restart button 1309 in FIG.
[0080] Next, the process proceeds to S426, and the multifunction peripheral 100 transmits HTML data of the default restart execution screen shown in Fig. 14B as a response to S425. Next, the process proceeds to S427, and the multifunction peripheral 100 executes the multifunction peripheral 100 restart process.
[0081] The MFP 100 according to the first embodiment assumes that when a communication purpose such as IEEE802.1X is set for a received electronic certificate, the setting cannot be reflected unless the MFP 100 is restarted. This is because, for example, an electronic certificate such as IEEE802.1X is expanded in the RAM 203 when the MFP 100 is started and continues to be used, and may not be replaced with the received electronic certificate stored in the HDD 204. However, if the MFP 100 can switch the electronic certificate used for the communication purpose without restarting, restart may not be necessary. For example, when the purpose is set to TLS, restart may not be necessary. For example, the necessity of restarting may be set in advance for each of a plurality of purposes, and the MFP 100 may automatically determine whether or not to restart according to the information on necessity of restart.
[0082] 9 is a flowchart for explaining the process of restarting the multifunction peripheral 100 from S424 to S427 in FIG. 4, which is performed by the multifunction peripheral 100 according to the first embodiment. This process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0083] First, in S901, the CPU 201 receives a request to restart the MFP 100 from the PC 103. Next, the process proceeds to S902, where the CPU 201 transmits HTML data of the default request to restart the MFP 100 shown in Fig. 14B to the PC 103 as a response to S501. Next, the process proceeds to S903, where the CPU 201 instructs the device control unit 310 to start a restart process, and ends this process.
[0084] Through the above series of operations, the multifunction device 100 after rebooting uses the electronic certificate obtained from the certification authority / registration authority 102 .
[0085] FIG. 15 shows an example of a screen that appears when the key pair and electronic certificate list is displayed again by processing S401 if the certificate is successfully issued and obtained, and information 1501 about the certificate (Xyz4) issued by the certification authority / registration authority 102 has been added.
[0086] Fig. 20 is a flowchart for explaining the process of generating the certificate renewal reservation setting screen of Fig. 18 by the multifunction peripheral 100 according to the first embodiment. Note that this process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0087] First, in step S2001, the CPU 201 receives a request from the PC 103 to display a certificate renewal reservation setting screen.
[0088] Next, the process proceeds to step S2002, and the CPU 201 acquires from the HDD 204 setting values required for executing the automatic update function of the digital certificate.
[0089] In this embodiment, the "setting value required to execute the automatic update function of the electronic certificate" refers to the connection setting having information such as the server name 1016 and the port number 1017 shown in Fig. 10(B). However, there may be other setting values required for the automatic update function of the electronic certificate, such as a communication timeout time, and there is no particular limitation.
[0090] Next, in step S2003, the CPU 201 determines whether the setting values required to execute the automatic update function of the electronic certificate have been set.
[0091] If CPU 201 determines in S2003 that the setting value acquired in S2002 has already been set, the process proceeds to S2005 where CPU 201 generates HTML data for a Web page screen that accepts the certificate renewal reservation setting shown in Fig. 18. Then, the process proceeds to S2007 where CPU 201 transmits the HTML data generated in S2005 to PC 103 as a response to S2001, and this process ends.
[0092] 18 is a diagram showing an example of a certificate renewal reservation setting screen of the multifunction peripheral 100 according to the first embodiment, and is displayed by a web page type RUI like other screens. The certificate renewal date can be set via this certificate renewal reservation setting screen.
[0093] In the first embodiment, three settings, namely, update date 1801, expiration date 1802, and cycle 1803, can be set to specify the update date and update interval. In this embodiment, these settings are collectively referred to as certificate update reservation settings. The update date 1801 can specify the year, month, day, and time of update, and when the current date and time stored in the multifunction device 100 becomes the date and time of this update date 1801, the automatic certificate update function is executed. The expiration date 1802 specifies the number of days until the expiration date of the certificate being used. When the current date and time stored in the multifunction device 100 becomes shorter than the specified number of days from the expiration date, the automatic certificate update function is executed. The cycle 1803 executes the automatic certificate update function at this cycle. In the first embodiment, this cycle can be set to the number of days, a specified date every month, or a specified date every year. In the second embodiment, the settings of the certificate update date and update cycle are referred to as "certificate update reservation settings". When these certificate update reservation settings are updated, the CPU 201 stores them in the HDD 204.
[0094] 18 shows an example of a screen in which the automatic certificate renewal function is set to be executed 14 days before the expiration date in the expiration date 1802. In the second embodiment, the automatic certificate renewal function is reserved using the above-mentioned certificate renewal reservation setting type, but a different date and time or timing may be specified, and there are no particular limitations.
[0095] 18 also has automatic certificate deletion setting 1804 as a specification for automatically deleting unnecessary certificates after updating. This has automatic deletion options "Perform 18041" and "Do not perform 18042". When "Perform 18041" is enabled, "Delete only if there is no free certificate storage area" setting 18043 and "Automatic deletion advanced settings" 1805 can be set. When "Delete only if there is no free certificate storage area" setting 18043 is enabled, this setting deletes the certificate if the certificate storage area reaches its upper limit when a new certificate is obtained. When this setting is disabled, the certificate is deleted when the conditions specified in automatic deletion advanced settings 1805 are met, regardless of the upper limit of the storage area.
[0096] The automatic deletion detailed settings have settings from 18051 to 18055.
[0097] When the setting 18051 "Delete previous certificates with the same usage settings" is enabled, the previous certificate with the same usage settings as TLS, etc., specified in 1305 in FIG. 13(A) is automatically deleted.
[0098] When the "Delete certificates with no use set" setting 18052 is enabled, certificates held by the multifunction device 100 before the update that have no use set are determined to be unused and are automatically deleted.
[0099] If the "Delete only self-signed certificates" setting 18053 is enabled, the self-signed certificate held by the multifunction device 100 is deleted before updating. The reason why the condition of not deleting anything other than self-signed certificates is that the multifunction device 100 may have purchased a certificate from an external source and it is assumed that the device 100 will be used in cases where it is not possible to determine whether to automatically delete the certificate.
[0100] When the "Delete factory default certificate" setting 18054 is enabled, the factory default certificate held by the multifunction device 100 is deleted before updating. The reason why the condition of not deleting any certificates other than the factory default certificate is that it is assumed to be used in cases where it is unclear whether to automatically delete a certificate that was added to the multifunction device 100 later.
[0101] When the "Delete expired certificates" setting 18055 is enabled, if a certificate held by the multifunction device 100 before updating has expired, it is automatically deleted because it can still be used. The CPU 201 stores these setting values in the HDD 204.
[0102] In this embodiment, the automatic certificate deletion setting can be set only from the renewal reservation setting screen in FIG. 18, but the same setting value may be held on the certificate issuance request screen in FIG. 13 as well, and there is no particular limitation.
[0103] Returning to the description of Fig. 20, if CPU 201 determines in S2003 that the setting value acquired in S2002 has not been set, the process proceeds to S2006 where CPU 201 generates HTML data for a Web page screen displaying that the certificate renewal reservation setting is prohibited, as shown in Fig. 21. Then, the process proceeds to S2007 where CPU 201 transmits the HTML data generated in S2006 to PC 103 as a response to S2001, and this process ends.
[0104] By performing the above-mentioned processes from S2003 to S2007, if the setting values required to execute the automatic update function of the electronic certificate have been set, the multifunction device 100 enables the certificate update reservation setting. If the setting values required to execute the automatic update function of the electronic certificate have not been set, it is possible to prevent failure in sending a certificate issuance request when certificate acquisition is executed by the automatic update function of the electronic certificate by not enabling the certificate update reservation setting.
[0105] Fig. 19 is a flowchart explaining the process when multifunction device 100 executes the automatic update function of the electronic certificate based on the update reservation setting of the electronic certificate. By first specifying multiple multifunction devices (different time settings can be made for each multifunction device), it is also possible to cause multiple multifunction devices to execute the process of Fig. 19. In this case, the process of Fig. 19 is executed in parallel in the multiple multifunction devices. This process is achieved by CPU 201 executing a program loaded in RAM 203.
[0106] First, in S1901, the CPU 201 obtains the update reservation setting for the electronic certificate from the HDD 204. Next, the process proceeds to S1902, where the CPU 201 obtains information on the electronic certificate currently being used. This information is, for example, the information held in FIG. 17. Next, the process proceeds to S1903, where the CPU 201 obtains the current date and time managed by the multifunction device 100. Then, the process proceeds to S1904, where the CPU 201 compares the update reservation setting for the electronic certificate with the information on the electronic certificate to determine whether the currently used electronic certificate needs to be updated. If it is determined here that the electronic certificate does not need to be updated, the process returns to S1901.
[0107] On the other hand, if it is determined that the digital certificate needs to be updated, the process proceeds to S1905, where control shifts to "certificate issuance request processing" in Fig. 8. Then, when the processing in Fig. 8 is completed, the process shifts to S1906.
[0108] In step S1906, the CPU 201 acquires the automatic certificate deletion setting in FIG.
[0109] Next, in S1907, CPU 201 determines whether the automatic certificate deletion setting is enabled, and if it is determined that it is not enabled, the process proceeds to S1910. If CPU 201 determines in S1907 that the automatic certificate deletion setting is enabled, CPU 201 determines in S1908 whether a certificate that meets the conditions for deletion exists. This is done by CPU 201 determining whether the certificates held by multifunction device 100 meet the settings of 18043, 18051 to 18055 in FIG. 18. If it is determined in S1908 that a certificate that meets the conditions for deletion exists, the process proceeds to S1909, where CPU 201 deletes the applicable certificate from HDD 204. Then the process proceeds to S1910. If it is determined in S1908 that a certificate that meets the conditions for deletion does not exist, the process proceeds to S1910.
[0110] The above process checks whether the necessary settings have been made beforehand when enabling the automatic certificate update function, and if the necessary settings have not been made, the automatic certificate update function is not enabled, thereby making it possible to prevent communication errors. However, the settings are not limited to communication settings, as long as they are settings that prevent the automatic certificate update function from normally executing a certificate issuance request and certificate acquisition. For example, information such as an encryption algorithm compatible with the certificate management server or an issuer name required for certificate issuance may also be used.
[0111] [Embodiment 2] Next, a second embodiment of the present invention will be described.
[0112] In the first embodiment, a web page type RUI is provided to the user of the multifunction device 100 using the web server function of the multifunction device 100, and the user enables the automatic certificate update function in the multifunction device 100 via the RUI. At that time, if the settings required for the automatic certificate update function have not been configured, enabling the automatic certificate update function from the RUI is prohibited, thereby making it possible to prevent communication errors from occurring when the automatic certificate update function is used.
[0113] The settings of the automatic certificate update function may be set not only by the RUI of embodiment 1, but also by instructions via a network or a setting value distribution function that imports setting values from a USB memory medium. Even when the settings for enabling the automatic certificate update function are imported by the setting value distribution function, it is necessary to prevent operational inconsistencies of the automatic certificate update function by prohibiting the automatic certificate update function from being enabled if the necessary settings have not been configured.
[0114] In the second embodiment, a control of enabling the automatic update function of an electronic certificate will be described when a setting value is imported by a setting value distribution function instead of an RUI setting from a user in an information processing device having the automatic update function of an electronic certificate as in the first embodiment. Here, the setting value refers to the values 1801 to 1803 in Fig. 18, values indicating copy settings such as density adjustment values used when copying using the multifunction device 100, values indicating scan settings used when scanning, and the like.
[0115] In this embodiment, the parts that are not explained, such as the network configuration diagram, the hardware configuration of the multifunction device 100 which is an information processing device, the software configuration, the list display process of the key pair and the electronic certificate, and the process of setting the connection settings, are the same as those in the first embodiment.
[0116] 22 is a flowchart for explaining a process in which the multifunction peripheral 100 according to the second embodiment imports setting values using the setting value distribution function. This process is achieved by the CPU 201 executing a program loaded in the RAM 203.
[0117] The setting value distribution function in this embodiment is a function for importing setting values from a setting value distribution server to the multifunction device 100 via the network 110, or importing setting values from a USB memory medium connected to the multifunction device 100. An instruction to import a setting value can come from either the setting value distribution server or the operation panel 210 of the multifunction device 100, but FIG. 22 of this embodiment 2 explains an example in which a setting value is imported in response to an instruction from the setting value distribution server. FIG. 23 is a diagram for explaining a network configuration according to this embodiment 2. The multifunction device 100 is connected to a setting value distribution server 104 via the network 110. The other configuration is the same as FIG. 1 of the first embodiment.
[0118] The flowchart in FIG. 22 will be described.
[0119] First, in S2201, the CPU 201 receives a setting value import request from the certificate distribution server 104 via the network 110. Next, the process proceeds to S2202, where the CPU 201 receives import data including the setting values and stores the data in the RAM 203. Next, the process proceeds to S2203, where the CPU 201 analyzes the contents of the setting values in the import data received in S2202.
[0120] Next, the process proceeds to S2204, where the CPU 201 checks whether the setting values of the received import data include a setting for enabling the automatic certificate update function. In S2204, it checks, for example, whether any of 1801 to 1803 in FIG. 18 is enabled. In S2204, if the CPU 201 determines that the setting values of the received import data do not include a setting for enabling the automatic certificate update function (none of 1801 to 1803 in FIG. 18 are enabled), the process proceeds to S2206. In S2206, the CPU 201 saves the setting values of the received import data in the HDD 204. Then, this process ends.
[0121] In S2204, if the CPU 201 determines that the setting values of the received import data include a setting for enabling the automatic certificate update function (if any of 1801 to 1803 in FIG. 18 is enabled), the process proceeds to S2205.
[0122] In S2205, the CPU 201 checks whether the setting values of the received import data include settings required for the automatic certificate update function. The settings required for the automatic certificate update function are settings required to execute the automatic certificate update function, such as communication settings (e.g., connection settings having information on the server name 1016 and port number 1017 shown in FIG. 10(B)) as in the first embodiment.
[0123] If the CPU 201 determines in S2205 that the setting values of the received import data include settings required for the automatic certificate update function, the process proceeds to S2206, where the CPU 201 saves the setting values of the received import data in the HDD 204. Then, this process ends.
[0124] If the CPU 201 determines in step S2205 that the setting values of the received import data do not include settings necessary for the automatic certificate update function, the CPU 201 does not import the setting values and ends this process.
[0125] When the settings for enabling the automatic certificate update function are imported by the setting value distribution function through the above-mentioned processing in S2203 to S2206, if the necessary settings are not imported at the same time, the setting values including the setting values for enabling the automatic certificate update function are not imported. As a result, the automatic certificate update function is not enabled. This ensures that the automatic certificate update function is enabled only when the correct settings have been made in the multifunction device 100, and it is necessary to prevent operational inconsistencies such as communication errors when the automatic certificate update function is executed due to incorrect settings.
[0126] (Other embodiments) The present invention can also be realized by a process in which a program for implementing one or more of the functions of the above-described embodiments is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that implements one or more of the functions.
Claims
1. An information processing device that can be connected to an external device via a network, a transmitting means for transmitting a request for issuing a digital certificate to the external device; a receiving means for receiving the digital certificate issued by the external device in accordance with the transmitted issuance request; an updating means for updating the electronic certificate stored in the information processing device to the received electronic certificate; a display means for displaying a setting item for when the electronic certificate is to be automatically renewed; a setting unit for setting the timing at which the electronic certificate is automatically updated and information for connecting to the external device; The display means displays the setting items even if the information for connecting to the external device is not set.
1. An information processing device comprising:
2. a generating unit that generates a public key pair in response to the request for issuing the digital certificate and generates a signature request for the digital certificate based on the public key pair; The request for issuing the digital certificate includes a request for signing the generated digital certificate.
2. The information processing apparatus according to claim 1, wherein:
3. the transmitting means, when the information for connecting to the external device is set, transmits the issuance request to the external device at the set timing; The receiving means receives the digital certificate issued by the external device in accordance with the issuance request.
3. The information processing apparatus according to claim 1, wherein the information processing apparatus is a computer.
4. 4. The information processing apparatus according to claim 3, wherein said receiving means receives a result of said request for issuance of said digital certificate.
5. 5. The information processing apparatus according to claim 3, further comprising a storage means for storing the received digital certificate.
6. 6. The information processing apparatus according to claim 1, wherein the information for connecting to the external device is a server name of the external device or a port number of the external device.
7. 6. The information processing apparatus according to claim 1, wherein the information for connecting to the external device is a communication setting for communicating with the external device.
8. When the timing and information for connecting to the external device are set, The transmitting means transmits the issuance request, the receiving means receives the digital certificate, and the updating means updates the stored digital certificate to the received digital certificate.
2. The information processing apparatus according to claim 1, wherein:
9. An information processing device as described in Claim 1, characterized in that if information for connecting to the external device is not set, the issuance request is not sent to the external device by the transmitting means at the set timing.
10. The information processing device according to claim 1, further comprising a receiving means for receiving the information for connecting to the external device from a user.
11. The information processing device according to claim 10, characterized in that the receiving means further receives the timing specification by the user inputting a numerical value into the displayed setting item.
12. An information processing device as described in Claim 1, characterized in that the timing is an interval independent of the expiration date of the electronic certificate stored in the information processing device.
13. The information processing device according to claim 12, wherein the interval is an interval in days.
14. The information processing device according to claim 1, characterized in that the information processing device is a multifunction device.
15. A program for causing a computer to function as each of the means of the information processing device according to any one of claims 1 to 14.
16. An information processing method in a device connectable to an external device via a network, comprising: a transmitting step of transmitting a request for issuing a digital certificate to the external device; a receiving step of receiving a digital certificate issued by the external device in accordance with the transmitted issuance request; an updating step of updating the digital certificate stored in the device with the received digital certificate; a display step of displaying a setting item for when the digital certificate is automatically renewed; a setting step of setting the timing at which the digital certificate is automatically updated and information for connecting to the external device, In the display step, the setting items are displayed even if the information for connecting to the external device is not set.
1. An information processing method comprising:
17. A computer program characterized by causing a computer to execute the information processing method described in claim 16.