Communication device, communication processing program, and communication processing system
The communication device's controller, with its object identifier and source verification processes, addresses the security gap in remote setting changes by ensuring only authorized devices can modify settings, thereby enhancing security.
Patent Information
- Application Number
- JP2023185502
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-14
AI Technical Summary
Existing communication systems lack adequate security measures when setting values are changed remotely, making them vulnerable to unauthorized access and changes.
A communication device equipped with a controller that includes an object identifier based on management information, which performs a first judgment process to determine if the object identifier is specific, and a second determination process to verify the source of the command, only allowing authorized devices to perform read/write operations.
This configuration enhances security by preventing unauthorized changes to setting values in communication devices, ensuring that only specific, authorized devices can modify settings remotely.
Smart Images

Figure 2025074586000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a communication device, a communication processing program, and a communication processing system capable of reading or writing setting values stored in a memory. [Background technology]
[0002] 2. Description of the Related Art Conventionally, as described in, for example, Patent Document 1, when a setting request for setting a setting value is received from a server via a network, a technique is known in which a setting value of a communication device is changed in response to the request. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2019-207481 A Summary of the Invention [Problem to be solved by the invention]
[0004] In the communication system described in Patent Document 1, no particular consideration is given to improving security when changing setting values remotely.
[0005] An object of the present invention is to provide a configuration that can improve security when settings in a communication device can be changed remotely. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, the communication device of the present invention is a communication device comprising a communication interface, a memory for storing setting values, and a controller, wherein the controller executes the following steps: a command reception process for receiving a command via the communication interface, the command including an object identifier of a management information base and requesting reading or writing of a value of the object identifier; a first determination process for determining whether the object identifier included in the command received in the command reception process is a specific identifier; a second determination process for determining whether the command was sent from a first device or from a second device different from the first device when it is determined in the first determination process that the object identifier is a specific identifier; and a first read / write process for not performing the processing requested by the command when it is determined in the second determination process that the command was sent from the second device, and performing a read or write process of the setting value corresponding to the value of the specific identifier in the management information base in accordance with the command.
[0007] In the present invention, a command receiving process executed by a controller receives a command requesting reading or writing a value of an object identifier in a management information base. If a first determination process determines that the object identifier included in the command is a specific identifier, a second determination process determines whether the command was sent from the first device or the second device. In the first read / write process, the command is handled differently depending on whether it was sent from the first device or the second device, based on the result of the second determination process.
[0008] If the command is sent from the first device, the controller performs a read or write process of the setting value corresponding to the value of the specific identifier of the management information base in accordance with the command. On the other hand, if the command is sent from the second device, the controller does not perform the process requested by the command and rejects the process. According to the present invention, the controller does not respond to remote setting requests from devices other than the specific device, so that changes to the settings of the communication devices can be suppressed and security can be improved.
[0009] In addition, in order to achieve the above-mentioned object, the communication processing program of the present invention causes a computer to execute the following steps: a command reception process for receiving, via a communication interface, a command including an object identifier of a management information base and requesting reading or writing a value of the object identifier; a first determination process for determining whether the object identifier included in the command received in the command reception process is a specific identifier; a second determination process for determining whether the command was sent from a first device or from a second device different from the first device when it is determined in the first determination process that the object identifier is a specific identifier; and a first read / write process for not performing the processing requested in the command when it is determined in the second determination process that the command was sent from the second device, and for performing a read or write process of a setting value corresponding to the value of the specific identifier in the management information base in accordance with the command when it is determined in the second determination process that the command was sent from the first device.
[0010] In addition, in order to achieve the above-mentioned object, the communication processing system of the present invention is a communication processing system having a communication device and an external device, wherein the communication device executes a command reception process that includes an object identifier of a management information base and receives a command from the external device requesting reading or writing of a value of the object identifier, a first determination process that determines whether the object identifier included in the command received in the command reception process is a specific identifier, a second determination process that determines whether the command was sent from a first external device or from a second external device different from the first external device when it is determined in the first determination process that the object identifier is a specific identifier, and a first read / write process that does not perform the processing requested by the command when it is determined in the second determination process that the command was sent from the second external device, and performs a read or write process of a setting value corresponding to the value of the specific identifier in the management information base in accordance with the command. Effect of the Invention
[0011] According to the present invention, security can be improved in a case where the setting values in a communication device can be changed remotely. [Brief description of the drawings]
[0012] [Figure 1] 1 is a diagram illustrating an example of a system configuration of an education service providing system according to an embodiment. [Diagram 2] FIG. 2 is a block diagram illustrating an example of a configuration of a server. [Diagram 3] FIG. 2 is a block diagram illustrating an example of a configuration of a multifunction peripheral. [Figure 4] FIG. 2 is a block diagram illustrating an example of a configuration of a mobile terminal. [Diagram 5] 2 is a diagram showing the configuration of software blocks processed in the multifunction peripheral and the flow of peripheral data. [Figure 6]10 is a sequence chart showing in detail a procedure when a service server transmits an instruction to change a setting value of a multifunction peripheral via a management server. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0013] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described with reference to the drawings.
[0014] <Outline of network connection configuration for education service provision system> FIG. 1 shows an example of the configuration of an education service providing system 1 according to an embodiment. The education service providing system 1 is configured to be capable of providing a remote education service in which homework is printed on a sheet by a multifunction device at a student's home, and the homework sheet with the student's answers is read by the multifunction device and graded. In this embodiment, a case will be described in which a management server included in the education service providing system 1 can execute various setting processes for the multifunction device by remote control via a network. In FIG. 1, the education service providing system 1 has a management server 100A, a service server 100B, a multifunction device 200, a mobile terminal 300, and a user PC 400.
[0015] The management server 100A, the service server 100B, the multifunction device 200, and the mobile terminal 300 are connected to each other via a wide area network GAN such as a so-called GAN (Global Area Network) that covers a wide area so that they can transmit and receive data to each other. In addition, the multifunction device 200 and the user PC 400 are connected to each other via a local area network LAN such as a LAN (Local Area Network) provided on the premises of the home so that they can transmit and receive data to each other. The wide area network GAN includes, for example, the Internet and mobile phone communication lines. In particular, the multifunction device 200, the mobile terminal 300, and the user PC 400 that operate in close positions on the same premises may directly transmit and receive data via wireless communication such as Wi-fi (registered trademark) and Bluetooth (registered trademark) or wired communication. The education service providing system 1 is an example of a communication processing system, the management server 100A is an example of a first device and an external device, and the multifunction device 200 is an example of a communication device.
[0016] <Server> The management server 100A and the service server 100B have almost the same configuration as a server 100 equipped with a communication function for transmitting and receiving data and a data processing function for processing data, and the common configuration is shown in Fig. 2. As shown in Fig. 2, the server 100 has a processor 110, a storage device 115, and a communication interface 190. The processor 110, the storage device 115, and the communication interface 190 are connected to each other via a bus 105 so as to be able to transmit and receive data to and from each other.
[0017] The storage device 115 includes a volatile storage device 120 and a non-volatile storage device 130. The volatile storage device 120 is, for example, a DRAM, and stores various programs and data to be processed. The non-volatile storage device 130 is an example of a non-transient storage medium. The non-volatile storage device 130 is, for example, a hard disk drive or a solid state drive, and has a program storage area 131 and a data storage area 132. The program storage area 131 stores various programs that perform processes for managing the multifunction device 200 and processes for providing remote education services. The data storage area 132 stores various data generated by the above programs.
[0018] The processor 110 is a device for performing data processing, such as a CPU, and executes various programs stored in the program storage area 131. The processor 110 performs various processes including data communication with the multifunction peripheral 200 and the mobile terminal 300.
[0019] The communication interface 190 is a network interface for connecting to the wide area network GAN and transmitting and receiving data, and includes a hardware component used for connecting to a network, such as a NIC (Network Interface Card).
[0020] In addition, the storage device 115 is not limited to the above-mentioned configuration, and may be configured, for example, by a RAM, a ROM, an EEPROM, a HDD, a portable recording medium such as a USB memory that is detachably attached to the server 100, a buffer provided in the processor 110, or a combination thereof.
[0021] Furthermore, the storage device 115 may be a computer-readable storage medium. A computer-readable storage medium is a non-transitory medium. In addition to the above examples, non-transitory media also include recording media such as CD-ROMs and DVD-ROMs. A non-transitory medium is also a tangible medium. The same applies to the storage device 215 of the multifunction device 200 described later.
[0022] <Multifunction device> 3, the multifunction device 200 has a processor 210, a storage device 215, a touch panel 240, operation keys 250, a transport mechanism 260, a communication interface 270, a printing unit 280, and a reading unit 290. The processor 210, the storage device 215, the touch panel 240, the operation keys 250, the transport mechanism 260, the communication interface 270, the printing unit 280, and the reading unit 290 are connected via a bus 205 so as to be able to transmit and receive data to and from each other.
[0023] The storage device 215 includes a volatile storage device 220 and a non-volatile storage device 230. The volatile storage device 220 includes an image data storage area 222 that stores image data to be printed. The volatile storage device 220 is, for example, a DRAM. The non-volatile storage device 230 includes a program storage area 231 and a data storage area 232. The non-volatile storage device 230 is, for example, an NVRAM with a separate dedicated battery power source, a flash memory, or the like. Various programs are stored in the program storage area 231. The various programs include firmware such as a print processing program, and a remote processing program for remotely operating various setting values as shown in the sequence chart of FIG. 6 described later. The data storage area 232 stores various setting value data set by the remote processing program.
[0024] The processor 210 is a device that performs data processing. The processor 210 is, for example, a CPU. The processor 210 executes various programs stored in a program storage area 231. The multifunction device 200 may further include an ASIC (Application Specific Integrated Circuit), and the data processing of the multifunction device 200 may be performed by the ASIC together with the processor 210.
[0025] The touch panel 240 can display various information and accepts user operations at coordinates on the display screen. The touch panel 240 is, for example, a device that integrally combines a liquid crystal display and a transparent touch pad. The operation keys 250 are devices that mechanically accept user press operations. The communication interface 270 is a network interface for connecting to the wide area network GAN and the local area network LAN to transmit or receive data, and includes hardware components used for connecting to a network, such as a NIC (Network Interface Card).
[0026] The transport mechanism 260 transports a sheet supplied from a tray capable of holding multiple sheets. The printing unit 280 is provided on a path along which the sheet is transported by the transport mechanism 260, and forms an image corresponding to a print job on the sheet transported by the transport mechanism 260 in a predetermined manner. The reading unit 290 is provided below the platen or on a path along which the document is transported in the document transport device, and optically scans the document placed on the platen or the document transported by the document transport device to obtain image data. The processor 210 is an example of a controller and a computer, and the storage device 215 is an example of a memory.
[0027] <Mobile devices> The mobile terminal 300 is configured as a portable terminal such as a smartphone that has a function for displaying image data, a function for inputting operations, a communication function for sending and receiving data, and a data processing function for processing data. FIG. 4 shows the common configuration of the mobile terminal 300.
[0028] As shown in FIG. 4, the mobile terminal 300 includes a CPU 310, a memory 320, a communication control unit 330, a touch panel 340, and a large-capacity storage device 370.
[0029] The large-capacity storage device 370 includes a program storage area 371 and a data storage area 372. The large-capacity storage device 370 is, for example, a flash memory. Various programs are stored in the program storage area 371. The CPU 310 executes the various programs stored in the program storage area 371. The CPU 310 executes various processes including data communication with the service server 100B and the multifunction device 200 via the communication control unit 330 and wireless communication such as a mobile phone communication line or a wireless LAN.
[0030] The mobile terminal 300 displays various data and accepts various operations by the user on a touch panel 340 that is, for example, an integral combination of a liquid crystal display and a transparent touch pad. The user can input various instructions to the mobile terminal 300 by operating the touch panel 340.
[0031] Note that the mobile terminal 300 may be, instead of the above-mentioned portable terminal, another information terminal such as a general-purpose personal computer or a tablet computer.
[0032] <User PC> The user PC 400 is a commonly used general-purpose personal computer, and includes a CPU, a memory, a display, and a communication interface for connecting to an in-house network LAN (not shown).
[0033] <Distance learning services and remote control of settings on multifunction printers> The contents of the distance education service provided by the education service providing system 1 of this embodiment and the flow of various related data will be described with reference to Fig. 5. In Fig. 5, a student receiving the distance education service receives a sheet on which homework is printed without leaving his / her home, and sends the answers he / she has written on the sheet from his / her home to have them graded.
[0034] For this purpose, in the education service providing system 1 of the embodiment, the service server 100B owned and used by the operating company of the remote education service transmits image data of the homework to the multifunction device 200 at the student's home. The multifunction device 200 controls the printing unit 280 to print the image data of the homework received from the service server 100B on a sheet. The multifunction device 200 causes the reading unit 290 to read the sheet on which the student has written his / her homework answers, and uploads the image data of the sheet to the service server 100B. When the operating company inputs the homework grading results to the service server 100B based on the uploaded images, the service server B transmits the grading results to the mobile terminal 300 owned by the student's guardian.
[0035] In using and operating the above-mentioned distance education service, each of the operating companies and parents desires to arbitrarily set a large number of setting values for the multifunction device 200. Specific examples of such setting values include a setting value for a function that assigns one of the few operation keys 250 provided on a low-spec model of the multifunction device 200 to a scan button for inputting an instruction to start reading. There are also other setting values, such as a setting value for enabling / disabling a so-called memory stop function that stops reading by the reading unit 290 when the image data of a sheet read by the reading unit 290 exceeds the memory capacity of the multifunction device 200.
[0036] The setting value of the button allocation function, which is the former, is a setting value specific to each model of the multifunction device 200 because it needs to be associated with data such as the key ID of the operation key 250, the specifications of which differ depending on the model of the multifunction device 200. The setting value of the memory stop function, which is the latter, does not need to be associated with data whose specifications differ depending on the model of the multifunction device 200, and only has the values of enable and disable, so it is a setting value common to multiple models of the multifunction device 200. In this way, there are many and diverse settings in the multifunction device 200, from the viewpoint of whether they are data specific to the model specifications or data common to multiple models, and it is very cumbersome for the user to manually set all of them. For this reason, a function is required for the management server 100A to remotely obtain or change the setting values in the multifunction device 200 via network communication. It is also desired to reduce the storage capacity of the memory that stores these various setting values as much as possible, while also reducing the development and manufacturing costs for the product of the multifunction device 200 as much as possible.
[0037] Depending on the type of setting value, it is desirable to not allow outsiders, even the operating company or end users (guardians), to obtain or change the setting value, and to keep the existence of the setting value secret as much as possible. For this reason, there has been a demand for a configuration that can improve security while enabling remote acquisition and change of the setting value of the multifunction device 200 using the public wide area network GAN. Note that the above-mentioned change of the setting value is an example of writing a setting value, and acquisition of the setting value is an example of reading a setting value.
[0038] <Use of MIB for remote control of settings and cooperation with control SW> In the education service providing system 1 of this embodiment, among all the setting values provided in the multifunction device 200, the setting values for remotely managing network communication devices are managed using the so-called MIB (Management Information Base), which is already widespread as a standard. In this embodiment, an example of the setting value provided in the multifunction device 200 is hereinafter referred to as a control SW (SWitch).
[0039] MIB is a database file that describes various setting values and status data in a tree-structured text format, specifically, it lists and describes pairs of individual identification data called OID (Object ID) and the corresponding setting values and status state contents (Value). Generally, this MIB is monitored by the software of both the managing SNMP manager and the managed SNMP agent via the network management protocol SNMP (Simple Network Management Protocol).
[0040] For example, the command to write "1" to the memory address of a setting value identified by the OID "1.2.3.4.5.6.7.8" and set it is written as "SET OID=1.2.3.4.5.6.7.8 Value=1". Similarly, the command to retrieve the memory address value of the setting value of the same OID is written as "GetRequest OID=1.2.3.4.5.6.7.8". Furthermore, there are two types of MIB standards that can be applied: standard MIB, which is defined in advance by each device manufacturer regarding common setting data, and extended MIB, which allows device manufacturers to define their own setting data.
[0041] On the other hand, a control SW is an example of setting data that can be changed by an end user (the parent in this example), and is a file in a data format described by specific bit units in a specific binary. For example, the command to set to "1" the first bit in the binary data of the memory address where the setting value of a control SW with identification number 10 is stored is described as "SW No.10 Bit1:1". This control SW is simply specified in advance by the device manufacturer as a description format for setting data, and in communications devices, the setting data is changed and obtained according to that format using an application developed independently by the device manufacturer.
[0042] The control SW requires a small amount of file data, so a large number of setting values can be managed with a small amount of memory. On the other hand, the MIB requires a large amount of file data, so if the entire control SW is remotely managed using the MIB, the multifunction device 200 needs to be equipped with a large amount of memory, which increases development and manufacturing costs. Therefore, by using the MIB as part of the control SW, the software configuration required for remote operation of the setting information in the multifunction device 200 can be functionally developed, and the development and manufacturing costs can be significantly reduced.
[0043] In this embodiment, the multifunction device 100 remotely manages the control SW, which is the device manufacturer's unique setting data, by using two types of extended MIBs including OIDs defined by the device manufacturer. The first extended MIB uses a command such as the above-mentioned "SET OID=1.2.3.4.5.6.7.8 Value=1" that indicates the control SW identification number "SW No. 10" with OID "1.2.3.4.5.6.7.8" and the subsequent "Value=1" that indicates the setting value of the identification number, and is hereinafter referred to as a normal MIB. The normal MIB does not correspond completely one-to-one with the setting value of the control SW, but is a MIB with a high level of abstraction that summarizes the setting values of multiple control SWs. The second extended MIB is an MIB (hereinafter referred to as a special MIB) that corresponds completely one-to-one with the setting value of the control SW of the multifunction device 200.
[0044] For example, in a special MIB, the string "1.2.3.4.5.6.7.9" indicating that it is a special OID is combined with the memory address where the setting value of the control SW identification number "No. 10" is stored and the value to be set in that memory address to create "OID=1.2.3.4.5.6.7.9".<SW No.10のメモリアドレス> Value=1”.
[0045] As described above, in this embodiment, the multifunction device 200 has an interface layer of a normal MIB and a special MIB in order to remotely obtain and change the setting data of the control SW from the management server 100A. Note that the above OID is an example of an object identifier, and the special OID is an example of a specific identifier.
[0046] <System configuration and peripheral data flow in a multifunction printer> In order to realize the remote control of the above-mentioned setting values, the software block configuration and the flow of peripheral data processed in the multifunction device 200 will be described with reference to Fig. 5. In Fig. 5, the multifunction device 200 has a server linkage function unit 233, a special MIB function unit 234, a normal MIB function unit 235, a print / read function unit 236, and an end user setting function unit 237 as software blocks executable by the processor 210 of the multifunction device 200. The special MIB function unit 234 has a data file F1 of the special MIB, and the normal MIB function unit 235 has a data file F2 of the normal MIB. A data file F3 of the control SW is recorded in the data storage area 232 of the nonvolatile storage device 230 (an example of the configuration in "NVRAM" is shown in the figure).
[0047] The server linkage function unit 233 accesses either the special MIB function unit 234 or the normal MIB function unit 235, which will be described later, in response to a command received from the management server 100A. At this time, the server linkage function unit 233 can determine whether the OID designated in the received command is a normal OID or a special OID by comparing the text string in each OID. For this comparison, the server linkage function unit 233 refers to the normal MIB file F2, which includes all normal OIDs as a list, and the special MIB file F1, which includes all special OIDs as a list, and determines which OID matches the OID designated in the received command. In addition, if the OID includes a predetermined specific value "1.2.3.4.5.6.7.9" indicating a special OID, it may be determined that the OID is a special OID. If the result of this determination is a special OID, the server linkage function unit 233 passes the command to the special MIB function unit 234. On the other hand, if the discrimination result is a normal OID, the server linkage function unit 233 passes a command to the normal MIB function unit 235. Furthermore, when the server linkage function unit 233 acquires a setting value from the special MIB function unit 234 or the normal MIB function unit 235, it returns the setting value to the management server 100A.
[0048] The special MIB function unit 234 accesses the control SW file F3 stored in the NVRAM 232 based on the special OID in the command passed from the server linkage function unit 233, and changes or acquires the setting value. Specifically, the special MIB function unit 234 changes the value of the memory address where the setting value of the control SW indicated by the special OID is stored to the value specified by the command. Furthermore, when the special MIB function unit 234 acquires the setting value, it returns the setting value to the server linkage function unit 233.
[0049] The normal MIB function unit 235 accesses the control SW file F3 stored in the NVRAM 232 based on the normal OID in the command passed from the server linkage function unit 233, and changes or acquires the setting value. Specifically, the normal MIB function unit 235 first refers to the correspondence between the normal OID and the memory address stored in advance in the NVRAM 232, and identifies the memory address in which the setting value of the control SW corresponding to the character string of the normal OID is stored. Next, the normal MIB function unit 235 changes the value of the identified memory address to the value specified by the command. Furthermore, when the normal MIB function unit 235 acquires the setting value, it returns the setting value to the server linkage function unit 233.
[0050] The end user setting function unit 237 is a software processing unit that functions as the above-mentioned SNMP agent. The end user setting function unit 237 passes a command sent from the SNMP manager on the user PC used by the guardian to the above-mentioned normal MIB function unit 235, and the normal MIB function unit 235 changes or acquires the setting value. When the end user setting function unit 237 acquires the setting value from the normal MIB function unit 235, it returns the setting value to the user PC 400.
[0051] The print / read function unit 236 downloads image data of the homework between the service server 100B and controls the print unit 280 to print the image data of the homework on a sheet. It also controls the read unit 290 to read the sheet on which the homework answers are written, and uploads the read image data. At this time, the print / read function unit 236 accesses the control SW file F3 to refer to or change setting data related to the execution of various control processes. For these accesses, existing control SW access methods and software can be applied.
[0052] <Security measures in this embodiment> As mentioned above, the special OIDs and the types of setting data that correspond to them are specified independently by the device manufacturer, and are basically confidential data that should not be known to anyone outside, including service operators and end users. Therefore, unless there is a particular need, it is desirable for device manufacturers to keep the existence of special OIDs themselves, their contents, and the types and contents of the corresponding setting data secret and not disclose them from a security standpoint.
[0053] However, in the case of MIB monitoring by cooperation between an SNMP agent and an SNMP manager via the above-mentioned SNMP protocol, when data is sent to and received from the multifunction device 200 via a private local area network LAN, as in the above-mentioned user PC 400, there is no problem in terms of security even if communication is performed using the SNMP protocol. On the other hand, when data is sent to and received from the multifunction device 200 via a public wide area network GAN, as in the above-mentioned management server 100A and service server 100B, it is desirable to communicate using a protocol with higher security strength than the SNMP protocol.
[0054] The server link function unit 233 in the multifunction device 200 of this embodiment determines whether the sender of the command including the OID determined to be a special OID by the above-mentioned method is the management server 100A. Specifically, when the server link function unit 233 receives a command including the OID determined to be a special OID via a communication protocol capable of identifying the individual device of the communication partner, such as XMPP (see FIG. 5), it determines that the sender of the command is the management server 100A. Note that, other than XMPP in the example shown in FIG. 5, any communication protocol capable of identifying the individual device of the communication partner, such as MQTT, can be similarly applied. In addition, when a service ID for identifying the individual device of the sender is included in the command to be transmitted and received, the sender of the command may be identified based on the service ID.
[0055] When the server cooperation function unit 233 determines that a special OID has been received from an external device unrelated to the management server 100A, it notifies the external device that sent the command that the OID does not exist, and does not process the setting data. This improves security by preventing the existence or contents of the special OID applied to the multifunction device 200 from being identified, even if a command including a special OID is received from the unrelated external device. The unrelated external device is an example of a second device, the communication protocols of XMPP and MQTT are an example of a first protocol, and the SNMP is an example of a second protocol.
[0056] <Control procedure> In this embodiment, to realize remote control of the above setting values, an example of a control procedure executed by the processor 110 of the service server 100B, the processor 110 of the management server 100A, and the processor 210 of the multifunction device 200 will be described with reference to the sequence chart of Fig. 6. Fig. 6 shows a sequence in which the service server 100B transmits an instruction to the management server 100A to change a predetermined control SW setting value in the multifunction device 200. In particular, the procedure executed by the multifunction device 200 in this sequence chart is executed mainly by the server linkage function unit 233.
[0057] First, in step ST5, the service server 100B instructs the management server 100A to change a predetermined control SW setting value in the multifunction device 200 to a specific setting value. At this time, the service server 100B transmits to the management server 100A a control SW change command including the control SW identification number, a bit number used to identify the position of a specific bit in a memory address that stores the control SW setting value, and the setting value to be changed. In step ST10, the management server 100A transmits to the multifunction device 200 a MIB / control SW change command including a special OID and setting value generated based on the received control SW change command.
[0058] The multifunction device 200 receives the MIB / control SW change command in step ST13, and determines in step ST15 whether the OID included in the received MIB / control SW change command is a special OID, in other words, whether it is an OID other than a normal OID. If it is a special OID, the determination is affirmative (ST15: YES), and the process proceeds to step ST20. In step ST20, the multifunction device 200 determines whether the sender of the MIB / control SW command is the management server 100A based on the communication protocol of the received command. If the sender is the management server 100A, the determination is affirmative (ST20: YES), and the process proceeds to step ST25.
[0059] In step ST25, the multifunction device 200 returns a permission notification to the management server 100A, indicating that the change operation requested by the received MIB / control SW change command is permitted. In step ST30, the management server 100A, which has received this, similarly returns a permission notification to the service server 100B, which is the sender of the corresponding MIB / control SW change command. In step ST35, the service server 100B, which has received this, displays the permission notification from the management server 100A on a display or the like to notify that the MIB / control SW change command has been permitted.
[0060] Next, in step S40, the multifunction device 200 judges whether the OID included in the received MIB / control SW change command is a special OID, as in ST15. If it is a special OID, the judgment is affirmative (ST40: YES), and in step S45, the command is passed to the special MIB function unit 234 to change the control SW setting value corresponding to the special OID included in the command to the setting value also included in the command.
[0061] On the other hand, if the OID included in the received command is a normal OID in the judgment of step ST15, the judgment is denied (ST15: NO), and the process proceeds to step ST25. Also, if the OID included in the received MIB / control SW change command is a normal OID in the judgment of step ST40, the judgment is denied (ST40: NO), and the process proceeds to step ST50. In step ST50, the multifunction device 200 passes the command to the normal MIB function unit 235, and changes the control SW setting value corresponding to the normal OID included in the command to the setting value also included in the command.
[0062] After steps ST45 and ST50, when the multifunction device 200 receives a notification from the special MIB function unit 234 or the normal MIB function unit 235 that the change of the setting value of the control SW has been successful, in step ST55 the multifunction device 200 replies to the management server 100A with a success notification that the change operation requested by the received MIB / control SW change command has been successful. In step ST60, the management server 100A that has received this similarly replies with a success notification to the service server 100B that is the sender of the corresponding MIB / control SW change command. In step ST65, the service server 100B that has received this displays the success notification from the management server 100A on a display or the like to notify the user that the change operation of the MIB / control SW change command has been successful.
[0063] On the other hand, if the determination in step ST20 above is that the sender of the received command is not the management server 100A, the determination is denied (ST20: NO), and the process proceeds to step ST70. In step ST70, the multifunction device 200 returns a refusal notice to the sender (not shown) to the effect that the change operation requested by the received MIB / control SW change command has been rejected. In this case, even if the OID specified in the received command is an actually specified special OID, the refusal notice notifies the sender that a non-existent OID was included.
[0064] In the illustrated example, a command to change the setting value is transmitted, but the same processing can be performed when a command to obtain the setting value is transmitted. That is, in the procedures of steps ST45 and ST50, a command is passed to the special MIB function unit 234 or the normal MIB function unit 235, respectively, to obtain the setting value instead of changing it. After steps ST45 and ST50, when the multifunction device 200 receives a notification from the special MIB function unit 234 or the normal MIB function unit 235 that the acquisition of the setting value of the control SW has been successful and the acquired setting value, the multifunction device 200 also returns the acquired setting value when returning a success notification of step ST55. Although not shown in particular, immediately after step ST15, a procedure is provided to determine whether the received command is a command to change or obtain the setting value, and if it is determined that the received command is a command to request a change of the setting value, the process proceeds to step ST20. If it is determined that the received command is a command to request an acquisition of the setting value, the process proceeds to step ST25, and the acquisition of the setting value requested by the command is executed regardless of the device that transmitted the received command. Conversely, if it is determined that the received command is a request to obtain a set value, the process proceeds to step ST20, and if it is determined that the received command is a request to change a set value, the process proceeds to step ST25, where the change of the set value requested by the command may be executed regardless of the device that transmitted the received command. Note that the processing of the command content of this command is an example of a specific process, and the process of determining whether the processing of the command content of this command is a change or acquisition of a set value is an example of a fifth determination process.
[0065] In the above, step ST13 is an example of a command reception process, step ST15 is an example of a first determination process, step ST20 is an example of a second determination process, step ST45 and the process of obtaining a setting value instead of it are an example of a first read / write process, step ST50 and the process of obtaining a setting value instead of it are an example of a second read / write process, and the program of steps ST15, 20, 25, 40, 45, 50, 55, and 70 executed by the server linkage function unit 233, including each of these processes, is an example of a communication processing program.
[0066] <Effects of the embodiment> As described above, in the education service providing system 1 of this embodiment, the processor 210 of the multifunction device 200 receives a command requesting change or acquisition of a setting value corresponding to an OID of an MIB (Management Information Base) via the wide area network GAN in step ST13. If it is determined in step ST15 that the OID included in the command is a special OID, it is determined in step ST20 whether the command was sent from the management server 100A or an unrelated external device. In step ST45 and the process of acquiring a setting value instead, the handling differs depending on whether the command was sent from the management server 100A or an unrelated external device, based on the determination result in step ST20.
[0067] When the command is sent from the management server 100A, the processor 210 of the multifunction device 200 performs processing to change or acquire the setting value corresponding to the special OID of the MIB according to the command. On the other hand, when the command is sent from an unrelated external device, the multifunction device 200 does not perform the processing requested by the command and rejects the processing.
[0068] According to this embodiment, the processor 210 of the multifunction device 200 does not respond to remote setting requests from devices other than a specific device (the management server 100A in this example), thereby suppressing setting changes to the multifunction device 200 and improving security.
[0069] In particular, in this embodiment, the processor 210 of the multifunction device 200 does not respond to remote setting requests using a communication protocol other than the specific communication protocol. For example, only commands received using the XMPP protocol, which ensures security as described above, can be regarded as being sent from the expected management server 100A and the setting request can be responded to. For example, commands received using a communication protocol that does not ensure security can be regarded as being sent from an unrelated external device or terminal other than the management server 100A and the setting request cannot be responded to. As a result, the processor 210 of the multifunction device 200 can suppress setting changes from unrelated devices other than the specific device, thereby improving security.
[0070] Furthermore, particularly in this embodiment, if the processor 210 of the multifunction device 200 determines in step ST15 that the OID is not a special OID, the process proceeds to step ST25, where it permits the change or acquisition of the setting value corresponding to the OID requested by the command, regardless of the device that sent the command. This allows the change or acquisition of setting values that do not require strict security, regardless of the sender, ensuring smooth processing.
[0071] In particular, in this embodiment, when the processor 210 of the multifunction device 200 determines in step ST20 that the command was sent from an external device unrelated to the management server 100A, the process proceeds to step ST70, and notifies the unrelated external device that is the sender that the special OID contained in the command does not exist. That is, when a command is sent from an unrelated external device, the unrelated external device is notified that the special OID specified by the command does not exist. This allows the unrelated external device to recognize that the special OID is invalid.
[0072] In particular, in this embodiment, the special OID is a text string containing a specific value and is an identifier that uniquely identifies a setting value, while the normal OID is an OID that does not contain the specific value. This makes it possible to realize a special OID that can uniquely identify a setting value, unlike conventional normal OIDs.
[0073] In particular, in this embodiment, when the received command is a command that requests a process of changing or acquiring a setting value corresponding to a normal OID, the change or acquisition requested by the command is executed regardless of whether the command is sent from the management server 100A or an external device unrelated thereto. This allows the change or acquisition of the setting value to be permitted regardless of the sender for processes that do not require strict security, ensuring smooth processing.
[0074] In the MIB standard, there is a command that queries a specific communication device for all OIDs that it applies to itself. When this query command is received, it is determined whether a special OID is included in the OIDs returned in response to the query command. If it is determined that a special OID is included, it is also determined whether the query command was received from the management server 100A or from an external device unrelated to the management server 100A. If it is determined that the query command was received from the unrelated external device, the special OID is not returned in response to the query, but if it is determined that the query command was received from the management server 100A, the special OID is returned. As described above, the determination of whether a special OID is included in the OIDs returned is an example of a third determination process, and the determination of whether the query command was received from the management server 100A or from an external device unrelated to the management server 100A is an example of a fourth determination process. This makes it possible to notify that the setting value of the special OID cannot be handled by an unrelated external device.
[0075] In addition, in the above, the sequence chart shown in FIG. 6 does not limit the present invention to the procedures shown in the sequence chart, and procedures may be added or deleted or the order of procedures may be changed without departing from the spirit and technical concept of the invention.
[0076] In addition to the above, the methods according to the above embodiments and their modifications may be used in appropriate combination.
[0077] Although not specifically illustrated, the present invention can be implemented with various modifications without departing from the spirit and scope of the present invention. [Explanation of symbols]
[0078] 1. Educational service provision system (an example of a communication processing system) 100A Management server (first device, an example of an external device) 100B Service Server 200 Multifunction printer (an example of a communication device) 210 Processor (an example of a controller or computer) 215 Storage device (an example of memory) 233 Server linkage function unit (an example of a communication processing program) 234 Special MIB function section 235 Normal MIB Linkage Section 236 Printing and reading function unit 237 End User Settings Function 270 Communication Interface 300 mobile devices 400 user PCs F1 Special MIB file F2 Normal MIB file F3 Control SW file GAN Wide Area Network LAN (Local Area Network)
Claims
1. A communication interface; A memory for storing a set value; A controller; A communication device comprising: The controller: a command receiving process for receiving, via the communication interface, a command including an object identifier of a management information base and requesting reading or writing of a value of the object identifier; a first determination process for determining whether or not the object identifier included in the command received in the command receiving process is a specific identifier; a second determination process for determining whether the command was sent from a first device or a second device different from the first device when the first determination process determines that the object identifier is a specific identifier; a first read / write process for not performing a process requested by the command when it is determined in the second determination process that the command has been sent from the second device, and for performing a read or write process of the setting value corresponding to the value of the specific identifier of the management information base in accordance with the command when it is determined in the second determination process that the command has been sent from the first device; A communication device that executes the above.
2. The controller, in the second determination process, When the command is received in a first protocol in which security is ensured, the command is determined to have been sent from the first device, and when the command is received in a second protocol different from the first protocol, the command is determined to have been sent from the second device. The communication device according to claim 1.
3. The controller further comprises: A communication device as described in claim 1, wherein if the first determination process determines that the object identifier is not the specific identifier, a second read / write process is executed to read or write the setting value requested in the command according to the value of the object identifier, regardless of the device that sent the command.
4. The controller, in the first read / write process, The communication device according to claim 1 , further comprising: a notification to the second device that the specific identifier contained in the command is not present when the second determination process determines that the command was sent from the second device.
5. The controller further comprises: a query receiving process for receiving a query for the object identifier via the communication interface; a third determination process for determining whether or not the specific identifier is included in object identifiers to be returned in response to the inquiry received in the inquiry receiving process; a fourth determination process for determining whether the inquiry received in the inquiry receiving process was transmitted from the first device or the second device when it is determined in the third determination process that the specific identifier is included; an inquiry reply process that does not reply with the specific identifier in response to the inquiry when it is determined in the fourth determination process that the inquiry has been transmitted from the second device, and that replies with the specific identifier in response to the inquiry to the first device via the communication interface when it is determined in the fourth determination process that the inquiry has been transmitted from the first device; The communication device of claim 1 , further comprising:
6. the specific identifier is an identifier that uniquely identifies the setting value, the identifier including a predetermined specific value; The object identifier that is not the specific identifier is an identifier that does not include the specific value. A communication device according to any one of claims 1 to 5.
7. The controller further comprises: executing a fifth determination process for determining whether or not the command requests a specific process for the setting value of the specific identifier when the first determination process determines that the object identifier is the specific identifier; If it is determined in the fifth determination process that the command requests the specific process, the read or write requested by the command is executed regardless of the device that transmitted the command. A communication device according to any one of claims 1 to 5.
8. For computers, a command receiving process for receiving, via a communication interface, a command including an object identifier of a management information base and requesting reading or writing of a value of the object identifier; a first determination process for determining whether or not the object identifier included in the command received in the command receiving process is a specific identifier; a second determination process for determining whether the command was sent from a first device or a second device different from the first device when the first determination process determines that the object identifier is a specific identifier; a first read / write process for not performing a process requested by the command when it is determined in the second determination process that the command has been sent from the second device, and for performing a read or write process of a setting value corresponding to a value of the specific identifier of the management information base in accordance with the command when it is determined in the second determination process that the command has been sent from the first device; A communication processing program for executing the above.
9. A communication processing system having a communication device and an external device, The communication device includes: a command receiving process for receiving a command from the external device, the command including an object identifier of a management information base and requesting reading or writing of a value of the object identifier; a first determination process for determining whether or not the object identifier included in the command received in the command receiving process is a specific identifier; a second determination process for determining whether the command was transmitted from a first external device or a second external device different from the first external device when the first determination process determines that the object identifier is a specific identifier; a first read / write process for not performing a process requested by the command when it is determined in the second determination process that the command has been sent from the second external device, and for performing a read or write process of a setting value corresponding to a value of the specific identifier of the management information base in accordance with the command when it is determined in the second determination process that the command has been sent from the first external device; A communication processing system that executes the above.
Citation Information
Patent Citations
Computer program for server and server
JP2019207481A