Information processing unit and control method and program thereof

The information processing device addresses the challenge of maintaining correct destination settings for electronic certificate issuance by using a display control mechanism to lock the setting screen during automatic issuance, thereby ensuring uninterrupted certificate issuance and acquisition.

JP2025085838APending Publication Date: 2025-06-05CANON KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2025049021
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing information processing devices face challenges in preventing the settings for electronic certificate issuance requests from being changed while automatic issuance is enabled, leading to potential failures in obtaining valid certificates.

Method used

An information processing device is equipped with a destination setting mechanism, a transmission mechanism, and an acquisition mechanism for electronic certificates, along with a display control mechanism that prevents the setting screen for changing the destination from being displayed when automatic issuance is enabled.

Benefits of technology

This solution effectively prevents changes to the destination settings for electronic certificate issuance requests while automatic issuance is enabled, ensuring that the information processing device can successfully send and obtain electronic certificates without interruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025085838000001_ABST
    Figure 2025085838000001_ABST
Patent Text Reader

Abstract

To prevent setting of transmission destination of issue request of an electronic certificate from being changed, while automatic issue of the electronic certificate is valid, in an information processing unit for transmitting the issue request of the electronic certificate automatically to a certificate management server.SOLUTION: An information processing unit having transmission destination setting means for setting a transmission destination where an issue request of the electronic certificate of public key is transmitted, transmission means for transmitting the issue request to the transmission destination at a timing set by a user, acquisition means for acquiring the electronic certificate, issued based on an issue request transmitted by the transmission means, from an external device, i.e., the transmission destination, is further provided with display control means for controlling the display means to display a setting image receiving the setting of the transmission destination, and the display control means controls not to display the setting screen while the setting for transmitting the issue request by the transmission means at the timing set by the user is effective.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing device, a control method thereof, and a program. [Background technology]

[0002] When devices such as a multifunction printer and a PC are connected to an in-house network, image data can be sent from the PC to the multifunction printer and stored in the multifunction printer, or the multifunction printer can be accessed from the PC and the image data stored in the multifunction printer can be retrieved.

[0003] When a multifunction device connects to a secure network such as an in-house network, it is necessary for the multifunction device to prove to the network server that the multifunction device is a client device that may connect to the in-house network. Therefore, the multifunction device obtains a public key certificate authenticated by a certification authority via a registration authority that functions as a certificate management server, and uses the public key certificate to indicate to the network server that the multifunction device is a device that may connect to the in-house network. If the network server determines that the certificate obtained from the multifunction device is a valid certificate, the multifunction device is permitted to connect to the in-house network.

[0004] The public key certificate obtained by the multifunction device has an expiration date, and if the expiration date passes, the multifunction device will no longer be able to prove that it is a device that may be connected to the company's internal network, and will no longer be able to connect to that network.

[0005] Patent Document 1 describes an electronic device that transmits a request for issuing an electronic certificate to a certificate management server a predetermined number of days before the expiration date of the electronic certificate, and automatically renews the electronic certificate. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] JP 2016-178458 A Summary of the Invention [Problem to be solved by the invention]

[0007] In order to automatically transmit a request for issuing a digital certificate to a registration authority, it is necessary for the user to set in advance server information, such as the address of the certificate management server to be used as the registration authority.

[0008] When an electronic certificate is automatically issued, if the registration authority information is changed to incorrect information, the information processing device may fail to send a request to issue the electronic certificate or fail to obtain the requested electronic certificate.

[0009] For example, if the address of the registration authority is changed to an incorrect address while the automatic issuance of electronic certificates is enabled, then when the information processing device sends the next issuance request for an electronic certificate, it will not receive a response from the registration authority, and the electronic certificate stored in the information processing device will not be able to be updated.

[0010] The present invention aims to prevent the settings of the destination of an electronic certificate issuance request from being changed while automatic issuance of electronic certificates is enabled in an information processing device that automatically sends an electronic certificate issuance request to a registration authority. [Means for solving the problem]

[0011] In order to solve the above problems, an information processing device described in this specification is an information processing device having a destination setting means for setting a destination to which a request for issuance of an electronic certificate of a public key is to be transmitted, a transmitting means for transmitting the issuance request to the destination set by the destination setting means at a timing set by a user, and an acquiring means for acquiring the electronic certificate issued based on the issuance request transmitted by the transmitting means from an external device which is the destination, The device further includes a display control means for displaying on a display means a setting screen for accepting settings of the destination, and the display control means is characterized in that the setting screen is not displayed while a setting for transmitting the issuance request by the transmitting means at a timing set by the user is valid. Effect of the Invention

[0012] According to the present invention, in an information processing device that automatically sends an electronic certificate issuance request to a certificate management server, it is possible to prevent the settings of the destination for the electronic certificate issuance request from being changed while the automatic issuance of electronic certificates is enabled. [Brief description of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram illustrating an example of a network configuration according to an embodiment of the present invention. [Diagram 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of an information processing device according to the present embodiment. [Diagram 3] FIG. 2 is a diagram illustrating an example of a software module of the information processing device according to the embodiment. [Figure 4] FIG. 4 is a diagram showing an example of a key pair and certificate database according to the embodiment. [Diagram 5] 11 is a diagram showing an example of a screen displayed on a PC 103 for making settings related to an electronic certificate of the information processing device according to the present embodiment. FIG. [Figure 6] FIG. 11 is a diagram showing an example of a screen for performing connection settings for transmitting a digital certificate issuance request, which is displayed on a PC 103 in the information processing apparatus according to the present embodiment. [Figure 7] 11 is a diagram showing an example of a screen showing details of an electronic certificate stored in the information processing device and displayed on a PC 103 in the information processing device according to the present embodiment. FIG. [Figure 8] 11 is a diagram showing an example of a screen for preventing input of connection settings from being accepted, the screen being displayed on a PC 103 in the information processing apparatus according to the present embodiment. FIG. [Figure 9]11 is a diagram showing an example of a screen for giving instructions relating to the transmission of a digital certificate issuance request in the information processing device according to the embodiment. FIG. [Figure 10] 11 is a diagram showing an example of a screen related to obtaining an electronic certificate in the information processing device according to the embodiment. FIG. [Figure 11] 11 is an example of a flowchart showing a process for issuing an electronic certificate scheduled for renewal in the information processing device according to the present embodiment. [Figure 12] 5 is an example of a flowchart showing a process related to issuing an electronic certificate in the information processing device according to the embodiment. [Figure 13] 6 is a flowchart showing a process relating to display of a connection setting screen in the information processing device according to the present embodiment. [Figure 14] 10 is a flowchart illustrating an example of a process for manually acquiring an electronic certificate in the information processing device according to the present embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0014] Hereinafter, an embodiment of the present invention will be described in detail with reference to the attached drawings. Note that the following embodiment does not limit the present invention according to the claims, and not all of the combinations of features described in the present embodiment are necessarily essential to the solution of the present invention. Note that a multifunction peripheral (digital multifunction peripheral / MFP / Multi Function Peripheral) will be described as an example of an information processing device that uses and manages electronic certificates according to the embodiment. However, the scope of application is not limited to multifunction peripherals, and any information processing device that can use electronic certificates will suffice, and the scope of application is not limited to multifunction peripherals.

[0015] FIG. 1 is a diagram illustrating a network configuration according to an embodiment of the present invention.

[0016] The multifunction device 100 having a printing function can transmit and receive print data, scanned image data, device management information, and the like to and from other information processing devices via the network 110. The multifunction device 100 also has a function of performing encrypted communication such as TLS, IPSEC, IEEE802.1X, and holds a pair of a public key and a private key used in the encryption process, and an electronic certificate for the public key. Here, the multifunction device 100 is an example of an information processing device, and the information processing device is not limited to this, and may be a device having a single function of a facsimile machine, a printer, or a copy machine, or a device having a combination of these functions. The multifunction device 101 is also connected to the network 110, and this multifunction device 101 has the same functions as the multifunction device 100. The following mainly describes the multifunction device 100. The multifunction device 100 also has a Web server function. The multifunction device 100 provides a RUI (Remote UI) function that generates a screen for performing settings related to the multifunction device 100, such as a screen for performing settings related to the issuance request and acquisition process of an electronic certificate, in the form of a Web page, and provides the screen to the PC 103. The network 110 in this embodiment is not limited to the Internet, but may be a network used within a limited range, such as an in-house LAN. In other words, the multifunction device 100 and the registration station 102 may exist in the same domain.

[0017] The registration authority 102 has a function as a registration authority (RA) that receives requests for issuance of electronic certificates and performs registration processing. In other words, the registration authority 102 is a certificate management server that has a function of distributing CA certificates and issuing and registering electronic certificates via the network 110. In this embodiment, it is assumed that SCEP (Simple Certificate Enrollment Protocol) is used for issuing and obtaining electronic certificates. An information processing device such as the multifunction device 100 uses this SCEP to communicate with the registration authority 102 via the network 110 to request issuance of an electronic certificate and to obtain it.

[0018] The certificate authority 104 has a function of a certificate authority (CA) that issues digital certificates based on instructions from the registration authority 102 .

[0019] When the certification authority 104 and the registration authority 102 receive an issuance request for an electronic certificate from another information processing device via the network 110, they issue and register the electronic certificate based on the issuance request, and transmit the issued electronic certificate as a response to the issuance request. In this embodiment, the functions of the certification authority and the registration authority are realized by two server devices, but the certification authority and the registration authority may be realized by one server device. In this embodiment, SCEP is used as a protocol for requesting and acquiring an electronic certificate, but any protocol having equivalent functions may be used, and the protocol to be used is not limited. For example, CMP (Certificate Management Protocol) or EST (Enrollment over Secure Transport) protocol may be used.

[0020] The PC 103 is a personal computer that is equipped with a Web browser function and can analyze HTML data published by an information processing device connected to the network 110 and display a screen on the display unit. In this embodiment, the PC 103 accesses the multifunction device 100, acquires a Web page for setting the issuance of an electronic certificate and the settings of the certification authority, and displays it. A user performs settings for issuing an electronic certificate and obtaining an electronic certificate, and performs settings for the certification authority, via a screen displayed on the display unit of the PC 103. In this embodiment, a case will be described in which the registration authority 102 is set from the PC 103 using the RUI function of the multifunction device 100. A user may operate an operation panel of the multifunction device 100 to perform settings for issuing an electronic certificate and settings for the certification authority / registration authority 102.

[0021] FIG. 2 is a block diagram illustrating the hardware configuration of the multifunction peripheral 100 according to this embodiment.

[0022] The controller 213 is a controller to which the following modules are connected via a bus 209. The CPU 201 executes the software program of the multifunction peripheral 100 and controls the entire device. The ROM 202 is a read-only memory and stores the boot program and fixed parameters of the multifunction peripheral 100. The RAM 203 is a random access memory and is used to store programs and temporary data when the CPU 201 controls the multifunction peripheral 100. The HDD 204 is a hard disk drive and stores system software, applications, and various data. The CPU 201 executes the boot program stored in the ROM 202, and expands and executes the program stored in the HDD 204 in the RAM 203, thereby controlling the operation of the multifunction peripheral 100. The network I / F control unit 205 controls the transmission and reception of data to and from the network 110. The scanner I / F control unit 206 controls the reading of documents by the scanner 211. The printer I / F control unit 207 controls the printing process by the printer 210, etc. A panel control unit 208 controls a touch panel type operation panel 212, and controls the display of various information and input of instructions from the user. A bus 209 interconnects the CPU 201, ROM 202, RAM 203, HDD 204, network I / F control unit 205, scanner I / F control unit 206, printer I / F control unit 207, and panel control unit 208. Each piece of hardware transmits and receives control signals from the CPU 201 and data signals between each device via the bus 209.

[0023] 3 is a block diagram illustrating software modules included in the multifunction peripheral 100 according to this embodiment. The software modules shown in FIG. 3 are realized by the CPU 201 executing a program loaded in the RAM 203.

[0024] The network driver 301 controls the network I / F control unit 205 connected to the network 110 to transmit and receive data to and from the outside via the network 110. The network control unit 302 controls communication below the transport layer in a network communication protocol such as TCP / IP to transmit and receive data. The communication control unit 303 is a module for controlling a plurality of communication protocols supported by the multifunction device 100. In the process of acquiring and updating an electronic certificate according to this embodiment, the communication control unit 303 controls the generation and analysis of requests and response data for HTTP protocol communication, as well as data transmission and reception, and controls communication with the registration authority 102 and the PC 103. The communication control unit 303 also controls encrypted communication of TLS, IPSEC, and IEEE802.1X supported by the multifunction device 100.

[0025] Web page control unit 304 is a module that generates HTML data for displaying a Web page that can execute a request for issuing an electronic certificate and a process for acquiring the same, and controls the display of the data. Web page control unit 304 executes processes in response to a request for displaying a Web page sent from network driver 301 via communication control unit 303, and an instruction to issue and acquire an electronic certificate. Web page control unit 304 transmits HTML data of a default Web page stored in RAM 203 or HDD 204, or HTML data generated according to the contents of the display request, as a response to a request from a Web browser.

[0026] The key pair and certificate acquisition control unit 305 is a module for executing the process of acquiring an electronic certificate. The key pair and certificate acquisition control unit 305 is a module for controlling communications by SCEP, generating and analyzing encrypted data required for communications by SCEP such as PKCS#7 and PKCS#10, storing the acquired electronic certificate, setting its use, and so on.

[0027] The encryption processing unit 306 is a module for executing various encryption processes such as data encryption and decryption, generation and verification of electronic signatures, and generation of hash values. The encryption processing unit 306 executes each encryption process required for generation and analysis of SCEP request and response data in the acquisition and update process of an electronic certificate according to this embodiment. The encryption processing unit 306 also executes encryption processes in encrypted communication processes such as TLS, IPSEC, and IEEE802.1X by the communication control unit 303. During the encryption process, the encryption processing unit 306 acquires a key pair and electronic certificate data from the key pair and certificate management unit 307.

[0028] The key pair and certificate management unit 307 is a module that manages key pairs and electronic certificates held by the multifunction device 100. The key pair and certificate management unit 307 stores data on key pairs and electronic certificates together with various setting values ​​in the RAM 203 or HDD 204. Fig. 4(A) is a schematic diagram of a database showing detailed information on key pairs and electronic certificates managed by the key pair and certificate management unit 307. The database shown in Fig. 4(A) stores the names and uses of key pairs held by the multifunction device 100, as well as the start and end dates of their validity periods.

[0029] The UI control unit 308 controls the operation panel 212 and the panel control unit 208. The print / read processing unit 309 executes functions such as printing by the printer 210 and reading of a document by the scanner 211. In the following embodiment, the Web page control unit 304 generates HTML data for a screen, transmits it to the PC 103, and displays the screen on the operation unit of the PC 103. In the following description, when the screen to be displayed is displayed on the operation panel 212 of the multifunction device 100, the UI control unit 308 generates screen data and displays it on the operation panel 212. The device control unit 310 generates control commands and control data for the multifunction device 100 to comprehensively control the multifunction device 100. Note that the device control unit 310 according to this embodiment controls the power supply of the multifunction device 100, and executes a restart process of the multifunction device 100 according to an instruction from the Web page control unit 304. For example, if a user uses the RUI function to change the setting of the request to acquire an electronic certificate from the PC 103, the Web page control unit 304 instructs the device control unit 310 to restart as necessary. The device control unit 310 restarts the multifunction peripheral 100 in response to an instruction received from the Web page control unit 304 .

[0030] First, a method for a user to check the list and details of public keys and certificates stored in the multifunction device 100 in the system according to this embodiment will be described. In this embodiment, the PC 103 accesses one multifunction device and obtains electronic certificate information related to that one multifunction device. The PC 103 may access multiple multifunction devices and obtain and display electronic certificate information related to the multiple multifunction devices.

[0031] 5A is an example of a screen displayed on the display unit of PC 103 when PC 103 accesses multifunction device 100 and performs an operation for setting up an electronic certificate. In this example, it is assumed that a key pair and certificate list screen is displayed when the user performs an operation for setting up an electronic certificate.

[0032] The key pair / certificate list screen shown in FIG. 5(A) includes a certificate name 1011, a purpose 1012, an issuer 1013, a validity period end date 1014, and a "details" button 1015. The name 1011 is a character string that the user arbitrarily sets when issuing the key pair / certificate. The purpose 1012 is a setting value indicating that the key pair / certificate is used for any of TLS, IPSEC, and IEEE802.1X. The issuer 1013 is the distinguished name (DN: Distinguished Name) of the certification authority that issued the electronic certificate. The validity period end date 1014 is information on the date on which the validity period of the electronic certificate ends. The "details" button 1015 is an icon for displaying detailed information about the electronic certificate. When the user selects the "details" button 1015, the PC 103 transmits a request to the multifunction device 100 to display detailed information about the selected electronic certificate. Upon receiving the request to display the detailed information of the electronic certificate, the multifunction device 100 obtains the detailed information of the selected electronic certificate from the HDD 204 and generates HTML data for a screen that displays the obtained information. The multifunction device 100 then transmits the generated data to the PC 103. As a result, the detailed information of the electronic certificate is displayed by the web browser of the PC 103, for example, as shown in FIG. 7. FIG. 7 is a diagram showing an example of the detailed information of the electronic certificate displayed on the PC 103.

[0033] Next, a method for setting information about the registration authority 102 to which a request for issuing a digital certificate is to be sent in this embodiment will be described. The user selects "Connection Settings" 1002 on the key pair and digital certificate list screen shown in Fig. 5(A). The Web page control unit 304 of the multifunction device 100 generates HTML data for displaying the connection settings screen and transmits it to the PC 103. The PC 103 displays a screen generated from the received HTML data.

[0034] FIG. 6(A) is a diagram showing an example of a connection setting screen of a SCEP server functioning as the registration authority 102 of an electronic certificate. The connection setting screen shown in FIG. 6(A) includes a field 1016 for inputting the URL of the SCEP server, a field 1017 for inputting a port number for inputting the number of the connection destination port of the SCEP server, and a "Set" button 1018 for instructing the setting of the input setting value. The user inputs information of the SCEP server functioning as the registration authority 102 in the above fields. Note that the connection setting screen shown in FIG. 6(A) has a field for inputting the address (URL) and port number of the server to which the certificate issuance request is to be sent. In addition to the above contents, a field for inputting information about the registration authority 102 may be displayed. For example, there may be a setting field for the timeout time of communication between the multifunction device 100 and the registration authority 102. Furthermore, an address indicating the same domain as the multifunction device 100 can be input in the field for inputting the URL of the SCEP server.

[0035] Whether the multifunction device 100 manually or automatically sends a request to obtain a certificate, the multifunction device 100 sends a request to issue a certificate to the URL and port number of the SCEP server that are set via the connection setting screen shown in Figure 6 (A).

[0036] When the user selects the "Set" button 1018 on the screen shown in Fig. 6(A), the key pair and certificate management unit 307 stores the server URL and port number entered in each field in the HDD 204. Then, if the settings have been correctly stored in the HDD 204, the screen shown in Fig. 6(B) is displayed on the display unit of the PC 103. Fig. 6(B) displays a message 1101 indicating that the displayed server URL 1016 and port number 1017 have been set in the multifunction device 100.

[0037] Next, a case where a user manually obtains a public key certificate will be described. On the certificate list screen shown in Fig. 5(A), the user selects "Certificate Issuance Request" 1004. Then, the certificate issuance request screen shown in Fig. 9(A) is displayed on the PC 103. Fig. 9(A) is an example of a screen for manually sending a request for issuance of a public key digital certificate.

[0038] The certificate issuance request screen in Fig. 9(A) includes a certificate name 1301, an algorithm that sets the key length of the key pair to be generated and a corresponding key length 1302, and an input field 1303 for issuing information. Furthermore, the certificate issuance request screen includes a signature verification 1304 for determining whether or not to verify the signature attached to the response to the certificate issuance request, a key use 1305 for setting the use of the issued certificate, and a password 1306 to be included in the certificate issuance request. An "Execute" button 1307 is a button for starting the process of requesting the issuance of a public key digital certificate. The use 1305 is a checkbox, indicating that multiple uses can be set for one key. Also, the user can uncheck a checked checkbox by selecting it again.

[0039] When the user inputs / sets 1301 to 1306 in Fig. 9(A) and clicks (selects) the "Execute" button 1307, the PC 103 sends a request for issuing an electronic certificate to the multifunction device 100. The multifunction device 100 stores the settings received from the PC 103 in the HDD 204, and sends a request for issuing an electronic certificate to the registration authority 102 using the information set in Fig. 9(A). At this time, the multifunction device 100 sends the request for issuing a certificate to the URL and port number of the SCEP server set via the connection setting screen in Fig. 6(A).

[0040] If the issuance and acquisition of the electronic certificate is successful, the screen shown in Fig. 9(B) is displayed on the display unit of the PC 103. A message 1308 indicating that the issuance and acquisition of the certificate is successful is displayed on the screen shown in Fig. 9(B). Furthermore, if a restart is required to store the acquired certificate in the HDD 204 and set it as a valid certificate, a "Restart" button 1309 for instructing the multifunction device 100 to restart is displayed. If the user selects the "Restart" button 1309, the screen shown in Fig. 10(B) is displayed on the PC 103. Then, the multifunction device 100 stores the acquired certificate in the HDD 204, executes the processing required to set the certificate as valid, and executes the restart processing.

[0041] Furthermore, if the "Execute" button 1307 is selected in Fig. 9(A) and a certificate issuance request is sent to the registration authority 102, but the issuance of the certificate does not end normally, the screen shown in Fig. 10(A) is displayed on the display unit of the PC 103. Cases in which the issuance of the certificate does not end normally include cases in which a connection with the registration authority 102 cannot be established, or cases in which the multifunction device 100 has not been able to obtain a certificate even after a predetermined time has elapsed since the sending of the certificate issuance request. A message 1401 is displayed on the screen shown in Fig. 10(A) indicating that the issuance / obtainment of the certificate has failed.

[0042] Next, a method for a user to set a reservation for certificate renewal will be described. When a user selects "reservation setting" 1005 on the screen of FIG. 5(A), a screen shown in FIG. 5(B) is displayed on the PC 103. FIG. 5(B) is an example of an electronic certificate renewal reservation setting screen. When a user selects one of the check boxes 1801, 1802, and 1803, a check mark is displayed in the check box. When a user selects a check box with a check mark again, the check mark is hidden. When the "renew" button 1806 is selected, the PC 103 transmits the set setting value to the multifunction device 100. The key pair and certificate management unit 307 of the multifunction device 100 stores the received information in the HDD 204. At this time, the key pair and certificate management unit 307 stores in the HDD 204 whether each check box is checked or not. When any of the check boxes 1801, 1802, and 1803 is checked, the multifunction device 100 determines that the reservation for certificate renewal is set to be valid. On the other hand, if none of the check boxes are checked, the multifunction device 100 determines that the certificate renewal reservation is set to invalid.

[0043] Check box 1801 is a check box for setting the renewal date and time of the electronic certificate. When check box 1801 is selected, the user can set the date and time to start requesting acquisition of the electronic certificate. At the specified time on the specified date, the multifunction device 100 will send an issuance request for the electronic certificate to the registration authority.

[0044] Check box 1802 is a check box for determining the renewal date and time based on the expiration date of the electronic certificate. When check box 1802 is selected, the user can set how many days before the expiration date of the electronic certificate held by multifunction device 100 to renew the electronic certificate.

[0045] A check box 1803 is a check box for setting the renewal cycle of the electronic certificate. When the check box 1803 is selected, the user can set the renewal cycle of the electronic certificate. The user can select how many days between renewals, whether to perform renewal on a date designated by the user every month, or whether to perform renewal on a date designated by the user every year. For example, in FIG. 5B, the multifunction device is set to transmit a request for issuing an electronic certificate to the certificate authority and obtain a new electronic certificate 14 days before the expiration date of the currently held electronic certificate. Note that if none of the check boxes 1801, 1802, and 1803 are selected, the multifunction device 100 determines that the renewal reservation function of the electronic certificate is disabled. In this embodiment, the check boxes 1801 to 1803 and the setting values ​​related to each are collectively referred to as "certificate renewal reservation settings."

[0046] Furthermore, the electronic certificate renewal reservation setting screen shown in Fig. 5(B) has an area 1804 for setting information on the public key and certificate for which renewal reservation setting is to be made. Area 1804 is an area for setting the name, length, purpose, algorithm, etc. of the key for automatically sending a certificate issuance request. When the user inputs the renewal reservation setting and the setting of the key and certificate for which the issuance request is to be made, and selects the "Update" button 1806, the certificate renewal reservation setting is stored in the HDD 204. Note that, in this embodiment, the user inputs the setting of the key and certificate for which the issuance request is to be made, but it is also possible to select the public key for which renewal reservation is to be made from the public keys stored in the key and certificate database.

[0047] An "Update" button 1806 on the electronic certificate update reservation setting screen in Fig. 5(B) is a button for instructing the process of sending the contents set on the update reservation setting screen to the multifunction device 100 and storing the setting values ​​in the HDD 204 of the multifunction device 100. A "Cancel" button 1807 is a button for interrupting the update reservation setting. When "Cancel" 1807 is selected, the update reservation setting screen is displayed on the display unit of the PC 103 with the current setting values ​​stored in the HDD 204 of the multifunction device 100 entered into each input form on the reservation update setting screen shown in Fig. 5(B).

[0048] In this embodiment, the automatic certificate deletion setting can be set only from the renewal reservation setting screen in Fig. 5(B). The automatic deletion setting may be set from the certificate issuance request screen in Fig. 9(A).

[0049] The above is an operation for displaying information on certificates stored in the HDD 204 of the multifunction device 100 and for setting certificate issuance in this embodiment. In the above description, transitions to each screen are made from the "Connection Settings" button 1002, "Certificate Issuance Request" button 1004, and "Reservation Settings" button 1005 displayed on the certificate list screen shown in FIG. 5(A). It is possible to transition to each screen from buttons 1001, 1002, 1004, and 1005 displayed in area 1020 of each screen, not limited to the certificate list screen shown in FIG. 5(A). When the user selects the "Certificate List" button 1001 on each screen, the certificate management list screen shown in FIG. 5(A) is displayed on the PC 103.

[0050] Here, in this embodiment, a screen that is displayed when a user attempts to execute connection settings with the certificate renewal reservation setting enabled will be described. In this embodiment, when a certificate renewal reservation is set, the connection settings cannot be changed. In this way, when a request to issue a reserved certificate is sent, a request to issue a certificate is prevented from being sent to an unintended server, and failure to issue the reserved certificate is prevented.

[0051] The connection setting screen shown in Fig. 8 is an example of a screen that is displayed when the user selects the "Connection Setting" button 1002 with the reservation update setting set to enabled. In Fig. 8, each input field is displayed in gray, and the user cannot input a character string into each input field. In addition, the "Settings" button 1018 is also set to disabled, and the user cannot select the "Settings" button 1018. In addition, since the certificate renewal reservation setting is set to enabled on the screen shown in Fig. 8, a message 1019 is displayed indicating that the connection setting cannot be changed. By displaying the message 1019, the user can know why the connection setting cannot be changed.

[0052] Additionally, the input fields on the connection setting screen shown in Fig. 8 display the currently set setting value for each setting item. The setting values ​​displayed here are the setting values ​​used when sending a digital certificate issuance request, whether manually or automatically. In other words, by checking this screen, the user can confirm to which server and which port the certificate issuance request is to be sent. In this way, the connection setting screen shown in Fig. 8 functions as a confirmation screen for confirming the connection destination.

[0053] Next, a process in which a user manually obtains a certificate will be described with reference to Fig. 14. The process shown in Fig. 14 is realized by the key pair / certificate acquisition control unit 305 executing a program stored in the ROM 202 or the HDD 204.

[0054] The process described in FIG. 14 is started when the user selects the “Certificate issuance request” button 1004 on the certificate list screen shown in FIG. 5(A) and the key pair / certificate acquisition control unit 305 receives an instruction to display the certificate issuance request screen via the communication control unit 303.

[0055] In S1701, the key pair / certificate acquisition control unit 305 controls the Web page control unit 304 to generate HTML data for a certificate issuance request screen shown in Fig. 9(A). Then, in S1702, the key pair / certificate acquisition control unit 305 transmits the generated HTML data to the PC 103. The PC 103 displays the certificate issuance request screen on the display unit based on the HTML data received from the multifunction device 100.

[0056] In S1703, the key pair / certificate acquisition control unit 305 judges whether or not an instruction to execute a certificate acquisition process has been received from the PC. In response to the user selecting the "Execute" button 1307 on the certificate issuance request screen, the PC 103 instructs the multifunction device 100 to execute a certificate acquisition process. The key pair / certificate acquisition control unit 305 of the multifunction device 100 receives an instruction to execute the certificate acquisition process received via the communication control unit 303. If the key pair / certificate acquisition control unit 305 receives an instruction to execute the certificate acquisition process, the process proceeds to S1704. If the key pair / certificate acquisition control unit 305 has not received an instruction to execute the certificate acquisition process, the process described in S1703 is performed. In this embodiment, the description of the process when the user inputs a character string in each field on the certificate issuance request screen or selects a radio button has been omitted. When the user inputs a character string on the certificate issuance request screen or selects a radio button, the PC 103 may notify the key pair / certificate acquisition control unit 305 of the multifunction device 100 of the input contents each time. In this case, the key pair / certificate acquisition control unit 305 that has received the input controls the Web page control unit 304 to generate HTML data for a screen to be displayed on the PC 103 and transmit it to the PC 103. Also, when the user inputs a character string or the like on the certificate issuance request screen, data for the screen after the input may be generated in the PC 103 and displayed on the display unit of the PC 103. In this case, the key pair / certificate acquisition control unit 305 of the multifunction peripheral 100 acquires the contents set by the user in S1704 (described later) after receiving a request to execute the certificate acquisition process.

[0057] In S1704, the key pair / certificate acquisition control unit 305 acquires the setting values ​​set via the certificate issuance request screen. Here, the key pair / certificate acquisition control unit 305 acquires from the PC 103 the character strings entered in each input field on the certificate issuance request screen and the setting values ​​indicating whether a radio button or a check box is enabled or disabled.

[0058] In S1705, key pair and certificate acquisition control unit 305 stores the setting values ​​acquired in S1704 in HDD 204. In S1705, key pair and certificate acquisition control unit 305 controls key pair and certificate management unit 307. Key pair and certificate management unit 307 registers the setting values ​​acquired by key pair and certificate acquisition control unit 305 in the certificate database shown in Fig. 5. At this time, data that will not be determined until the certificate is issued, such as the certificate validity start date and validity end date, is stored as no setting value. Setting values ​​that are undetermined until the certificate is issued may be set to predetermined values.

[0059] In S1905, the key pair / certificate acquisition control unit 305 executes a certificate issuance request process, which will be described later. In S1905, the key pair / certificate acquisition control unit 305 reads the setting values ​​stored in the certificate database in S1705 and executes the certificate issuance request process.

[0060] In S1706, the key pair / certificate acquisition control unit 305 determines whether the issuance of the certificate was successful. In S1706, the key pair / certificate acquisition control unit 305 obtains flag information indicating whether the acquisition of the certificate was successful or unsuccessful from the RAM 203, and determines whether the acquisition of the certificate was successful. If the acquisition of the certificate was successful, the key pair / certificate acquisition control unit 305 executes the processes from S1707 onwards.

[0061] In S1707, the key pair / certificate acquisition control unit 305 determines whether or not reboot is required to set the acquired certificate as a valid certificate. In this embodiment, it is assumed that whether or not reboot is required is determined for each setting value set as the use of the certificate. However, it is also possible to always reboot, or not reboot for any use. In S1707, the key pair / certificate acquisition control unit 305 determines whether or not the use of the acquired certificate is set to a use that requires reboot, and executes the process described in S1708 if it is determined that reboot is required. On the other hand, if the use of the certificate is not a certificate that requires reboot, the key pair / certificate acquisition control unit 305 completes the process described in FIG. 14.

[0062] In S1708, the key pair / certificate acquisition control unit 305 executes the restart process of the multifunction device 100. In S1708, the key pair / certificate acquisition control unit 305 controls the Web page control unit 304 to generate HTML data of the screen shown in FIG. 9B, and transmits the generated HTML data to the PC 103. The key pair / certificate acquisition control unit 305 receives an instruction to select the "Restart" button 1309 from the PC 103, and instructs the device control unit 310 to restart the multifunction device. When the "Restart" button 1309 is selected, the Web page control unit 304 generates HTML data of the screen shown in FIG. 10B, and transmits it to the PC 103. Then, the device control unit 310 executes the restart process of the multifunction device 100. In this embodiment, the restart process is started in response to an instruction from the user. However, when it is determined that the restart is necessary, the multifunction device 100 may automatically start the restart process.

[0063] If the certificate acquisition is not successful in S1706, key pair / certificate acquisition control unit 305 executes the process described in S1709. In S1709, key pair / certificate acquisition control unit 305 controls Web page control unit 304 to generate HTML data for a screen notifying that the certificate acquisition has failed, and transmits it to PC 103. Here, Web page control unit 304 generates HTML data for the screen shown in Fig. 10(A) and transmits it to PC 103. PC 103 displays the screen shown in Fig. 10(A) on the display unit.

[0064] Next, the process executed by the multifunction device 100 when the reserved renewal function of the electronic certificate is enabled will be described with reference to Fig. 11. A program for executing the process shown in Fig. 11 is stored in a storage device such as the HDD 204 or ROM 202 of the multifunction device 100. The key pair and certificate acquisition control unit 305 executes the above program to realize the process.

[0065] In S1901, the key pair and certificate acquisition control unit 305 acquires information on the certificate renewal reservation setting. The key pair and certificate acquisition control unit 305 controls the key pair and certificate management unit 307 to acquire the certificate renewal reservation setting from the HDD 204.

[0066] Next, in S1902, key pair and certificate acquisition control unit 305 acquires information on the electronic certificate currently being used from key pair and certificate management unit 307. Key pair and certificate acquisition control unit 305 accepts a request to acquire information on the electronic certificate currently being used from key pair and certificate management unit 307, and acquires the information on the electronic certificate currently being used from HDD 204. Key pair and certificate management unit 307 sends the electronic certificate information acquired from HDD 204 to key pair and certificate acquisition control unit 305. In S1902, the information on the electronic certificate being used is, for example, information stored in a database showing detailed information on the key pair and electronic certificate shown in FIG. 4(A), and is information on the validity period start date and validity period end date.

[0067] Next, the process proceeds to S1903, where the key pair and certificate acquisition control unit 305 acquires the current date and time managed by the multifunction device 100. The key pair and certificate acquisition control unit 305 acquires the date and time using a known method. For example, the key pair and certificate acquisition control unit 305 acquires the date and time from an RTC (Real Time Clock) on a controller board (not shown) provided in the multifunction device 100.

[0068] In S1904, the key pair and certificate acquisition control unit 305 uses the certificate renewal reservation setting, the electronic certificate information, and the current date and time information to determine whether or not the currently used electronic certificate needs to be renewed. If the key pair and certificate acquisition control unit 305 determines in S1904 that the electronic certificate does not need to be renewed, the key pair and certificate acquisition control unit 305 returns the process to S1901. Here, an example of a method in which the key pair and certificate acquisition control unit 305 determines in S1904 whether or not the electronic certificate needs to be renewed will be described. The determination in S1904 is not limited to the following method.

[0069] First, if a renewal date is specified in the certificate renewal reservation setting, the key pair and certificate acquisition control unit 305 judges whether or not the validity start date of the electronic certificate in use acquired in S1902 is a date earlier than the renewal date specified in the certificate renewal reservation setting. If the validity start date is a date later than the renewal date specified in the renewal reservation setting, the renewal of the electronic certificate instructed by the renewal reservation setting has been completed, so the electronic certificate is not renewed again. If the validity start date of the electronic certificate is earlier than the renewal date specified in the certificate renewal reservation setting, the renewal date specified in the certificate renewal reservation setting acquired in S1901 is compared with the current date and time acquired in S1903. It is judged whether or not the current date and time are later than the acquisition request start date and acquisition request start time specified in the certificate renewal reservation setting. If the current date and time are later than the acquisition request start date and acquisition request start time specified in the certificate renewal reservation setting, the key pair and certificate acquisition control unit 305 judges that the electronic certificate needs to be renewed.

[0070] Next, a case where the electronic certificate is set to be renewed a predetermined number of days before the expiration date of the validity period will be described. The key pair and certificate acquisition control unit 305 calculates the remaining validity period of the electronic certificate from the expiration date of the validity period of the electronic certificate currently in use acquired in S1902 and the current date and time acquired in S1903. The key pair and certificate acquisition control unit 305 compares the calculated remaining validity period of the electronic certificate with the number of days specified in the renewal reservation setting of the electronic certificate acquired in S1901. Then, the key pair and certificate acquisition control unit 305 determines that the electronic certificate needs to be renewed if the remaining validity period of the electronic certificate is less than the number of days specified in the renewal reservation setting.

[0071] Next, a case where the electronic certificate is set to be updated at a predetermined interval will be described. When an update interval is set, the key pair and certificate acquisition control unit 305 calculates the number of days that have passed since the validity start date of the electronic certificate in use, based on the validity start date of the electronic certificate in use and the current date. When the calculated number of days that have passed matches the specified update interval, the key pair and certificate acquisition control unit 305 determines that the electronic certificate needs to be updated. When an update is set to a specified date of each month or a specified date of each year, the key pair and certificate acquisition control unit 305 compares the date specified in the update reservation setting with the current date and time, and determines that the update is necessary if they match.

[0072] If it is determined that the digital certificate needs to be updated, the process proceeds to S1905, where the key pair / certificate acquisition control unit 305 executes the "certificate issuance request process" of Fig. 12. Then, when the process of Fig. 13 is completed, the process proceeds to S1906. Details of the certificate issuance request process will be described later with reference to Fig. 12.

[0073] In S1906, the key pair / certificate acquisition control unit 305 judges whether the certificate acquisition has been successful. In S1906, the key pair / certificate acquisition control unit 305 judges whether the certificate acquisition has been successful by referring to a flag stored in the RAM 203 for the certificate. If the certificate acquisition has been successful, the key pair / certificate acquisition control unit 305 executes the process described in S1907. On the other hand, if the certificate acquisition has failed, the key pair / certificate acquisition control unit 305 executes the process described in S1909. In S1909, the key pair / certificate acquisition control unit 305 controls the UI control unit 308 to display a screen on the operation panel 212 notifying the user that the certificate acquisition has failed. Note that the process performed in S1909 may be any process that notifies the user that the certificate acquisition has failed. For example, the multifunction device 100 may send an email notifying the user that the certificate acquisition has failed to an email address registered in advance in the multifunction device 100.

[0074] In S1907, the key pair and certificate acquisition control unit 305 determines whether or not rebooting is necessary to reflect the settings of the newly acquired electronic certificate after updating the electronic certificate. In this embodiment, it is assumed that whether or not rebooting is necessary is determined for each purpose for which the certificate is used. If it is determined that rebooting is necessary, in S1907, the key pair and certificate acquisition control unit 305 instructs the device control unit 310 to execute rebooting via the communication control unit 303. The device control unit 310 accepts the instruction from the key pair and certificate acquisition control unit 305 and reboots the multifunction device 100. Thereafter, the automatic electronic certificate update process described in this flowchart is terminated. If it is determined in S1906 that rebooting is not necessary, the key pair and certificate acquisition control unit 305 terminates the process described in this flowchart.

[0075] Next, the process when the multifunction device 100 acquires a digital certificate of a public key will be described with reference to Fig. 12. Fig. 12 shows the process executed in S1905 in Figs.

[0076] 12 is stored in the HDD 204 or the ROM 202. The key pair and certificate acquisition control unit 305 executes the program to realize the processing.

[0077] In S801, the key pair and certificate acquisition control unit 305 acquires information about the electronic certificate to be issued by the certificate authority from the key pair and certificate management unit 307. The information acquired by the key pair and certificate acquisition control unit 305 in S801 includes, for example, a name 1301, a key length 1302, an input field 1303 for issuer information, a signature verification 1304, and a key usage 1305. The key pair and certificate management unit 307 acquires the above information from the HDD 204 and transmits it to the key pair and certificate acquisition control unit 305.

[0078] Next, the key pair and certificate acquisition control unit 305 acquires the certificate of the registration authority to be used from the key pair and certificate management unit 307. In S802, the key pair and certificate acquisition control unit 305 requests the key pair and certificate management unit 307 to acquire the registration authority certificate. The key pair and certificate management unit 307 acquires the registration authority certificate from the HDD 204, and transmits the acquired registration authority certificate to the key pair and certificate acquisition control unit 305. In this embodiment, the method of acquiring the certificate of the server that serves as the registration authority may be any known method.

[0079] Then, the process proceeds to S803, where the key pair and certificate acquisition control unit 305 executes generation of a key pair based on the information of the name 1301 and the key length 1302 acquired in S801. A publicly known method is used as a method for generating a private key and a public key corresponding to the private key. Furthermore, the key pair and certificate acquisition control unit 305 generates Certificate Signing Request (CSR) data based on the issuer information entered in the issuer information input field 1303 and the password 1306 information. The Certificate Signing Request is data in the PKSC#10 (RFC2986: PKCS #10: Certification Request Syntax Specification) format.

[0080] Next, the process proceeds to S804, where the key pair and certificate acquisition control unit 305 determines whether or not the generation of the key pair and certificate signing request in S803 was successful. If it is determined that the generation of the key pair and the generation of the certificate signing request data were successful, the key pair and certificate acquisition control unit 305 proceeds to S805. If it is determined that the generation of the key pair or the generation of the digital certificate signing request data failed, the key pair and certificate acquisition control unit 305 proceeds to S822.

[0081] In S805, the key pair and certificate acquisition control unit 305 generates issuance request data for an electronic certificate. This acquisition request data generated in S805 is data in the PKCS#7 format defined by SCEP. In S806, the key pair and certificate acquisition control unit 305 determines whether or not the generation of the certificate issuance request data was successful. If the generation of the certificate issuance request data failed, the key pair and certificate acquisition control unit 305 advances the process to S822. If the generation of the certificate issuance request data was successful in S806, the key pair and certificate acquisition control unit 305 advances the process to S807.

[0082] In S807, the key pair / certificate acquisition control unit 305 connects to the SCEP server set as the registration authority 102 via the connection setting screen of FIG. 6(A) using the TCP / IP protocol.

[0083] Next, in S808, the key pair and certificate acquisition control unit 305 judges whether or not the connection in S807 was successful. If the connection to the registration authority 102 was successful, the key pair and certificate acquisition control unit 305 advances the process to S809, and if it was unsuccessful, the process advances to S822. In S809, the key pair and certificate acquisition control unit 305 transmits the certificate issuance request data generated in S805 by the GET or POST method of the HTTP protocol. Then, in S810, the key pair and certificate acquisition control unit 305 judges whether or not the transmission of the certificate issuance request data in S809 was successful. If the transmission of the certificate issuance request data was successful, the key pair and certificate acquisition control unit 305 advances the process to S811, and if the transmission of the certificate issuance request data was unsuccessful, the key pair and certificate acquisition control unit 305 advances the process to S822.

[0084] In S811, the key pair / certificate acquisition control unit 305 receives response data to the certificate issuance request from the registration authority 102. Next, in S812, the key pair / certificate acquisition control unit 305 determines whether or not the response data was successfully received in S811. If the response data was successfully received, the key pair / certificate acquisition control unit 305 proceeds to S814, and if not, proceeds to S822.

[0085] In S812, the key pair and certificate acquisition control unit 305 determines whether or not the setting is to perform signature verification based on the setting of the signature verification 1304 acquired in S801. If the setting is to perform signature verification, the key pair and certificate acquisition control unit 305 advances the process to S814, and if the setting is not to perform signature verification, the process advances to S816.

[0086] In S814, the key pair and certificate acquisition control unit 305 controls the encryption processing unit 306 to verify the signature data added to the data received in S811, using the public key included in the registration authority certificate acquired in S802. Then, the process proceeds to S815, where the key pair and certificate acquisition control unit 305 determines whether the signature verification in S815 was successful. If the signature verification was successful, the key pair and certificate acquisition control unit 305 advances the process to S816. If the signature verification was unsuccessful, the key pair and certificate acquisition control unit 305 advances the process to S822.

[0087] In S816, the key pair and certificate acquisition control unit 305 analyzes the data received in S811 and acquires the certificate data included in the response data. At this time, the encryption processing unit 306 performs the analysis of the response data and the certificate acquisition process. Next, the process proceeds to S817, where the key pair and certificate acquisition control unit 305 judges whether or not the certificate acquisition in S816 was successful. If the certificate acquisition was successful, the key pair and certificate acquisition control unit 305 advances the process to S819, and if it was unsuccessful, the key pair and certificate acquisition control unit 305 advances the process to S822. In S818, the key pair and certificate acquisition control unit 305 registers the certificate acquired in S816 as the electronic certificate corresponding to the key pair generated in S803. At this time, the key pair and certificate acquisition control unit 305 controls the key pair and certificate management unit 307 to store the key pair generated in S803 and the acquired electronic certificate in a predetermined directory of the HDD 204 for storing the key pair and electronic certificate. At this time, the key pair and certificate management unit 307 adds information about the generated public key pair and the acquired electronic certificate to the key pair and certificate database S804 shown in Fig. 4(A). In Fig. 4(B), a new key pair and certificate Xyz4 has been added.

[0088] Next, the process proceeds to S819, where the key pair and certificate acquisition control unit 305 judges whether or not the registration process of the electronic certificate in S818 has been successful. If the registration process of the electronic certificate has been successful, the key pair and certificate acquisition control unit 305 advances the process to S820, and if it has failed, the process proceeds to S822. In S820, the key pair and certificate acquisition control unit 305 controls the key pair and certificate management unit to set the purpose of the certificate based on the information of the key purpose 1305 acquired in S801. At this time, the key pair and certificate management unit 307 updates the information of the purpose in the list of the detailed information of the key pair and certificate, for example, as shown in FIG. 4(C). In FIG. 4(C), the key pair and certificate used in TLS have been changed from Xyz1 to Xyz4. In S821, the key pair and certificate acquisition control unit 305 judges whether or not the purpose of the certificate has been set successfully. If the purpose setting is successful, the key pair / certificate acquisition control unit 305 advances the process to S823, and if it is unsuccessful, the key pair / certificate acquisition control unit 305 advances the process to S822.

[0089] In S822, the key pair / certificate acquisition control unit 305 stores a flag indicating that the acquisition of the certificate has failed in the RAM 203, and ends the process described in this flow.

[0090] In S923, the key pair / certificate acquisition control unit 305 stores a flag indicating that the certificate has been successfully acquired in the RAM 203, and then the process described in this flow is completed.

[0091] The above-mentioned processing constitutes the control related to the issuance request, reception processing, and communication usage setting of the electronic certificate in the multifunction device 100. In this embodiment, the processing of the issuance request, reception processing, and communication usage setting is collectively referred to as the "automatic update function of the electronic certificate."

[0092] If the address or port number of the registration authority 102 is changed to an incorrect address or port number when the renewal reservation of the electronic certificate is enabled, the registration authority 102 cannot be accessed when executing the process of S807 to S811 in Fig. 12. Also, if the user changes the settings related to the registration authority 102 while the multifunction device 100 is executing the process of S807 to S811 in Fig. 13, the certificate renewal process cannot be completed. Therefore, in this embodiment, by executing the process shown in Fig. 13(A) and (B) below, when the renewal reservation of the certificate is enabled, display control is performed so that the information of the device to which the certificate issuance request is to be sent cannot be changed. In this way, when the renewal reservation of the certificate is enabled, the information of the device to which the certificate issuance request is to be sent cannot be changed, and failure of the reserved certificate issuance process is suppressed.

[0093] Fig. 13(A) is a flowchart showing the process when the multifunction device 100 generates the connection setting screen shown in Fig. 6(A). A program for executing the process shown in Fig. 13(A) is stored in the HDD 204 or the ROM 202. The following process is realized by the Web page control unit 304 executing the program.

[0094] The process shown in FIG. 13A is started when the user operates the PC 103, clicks on “Connection Settings” 1002 in FIG. 5A, and the Web page control unit 304 of the multifunction device 100 receives a request to display the connection settings screen.

[0095] Proceeding to S611, the Web page control unit 304 acquires the certificate renewal reservation settings from the HDD 204. The certificate renewal reservation settings stored in the HDD 204 are the setting values ​​set via the certificate renewal reservation screen shown in Fig. 5(B). In S611, the Web page control unit 304 acquires from the HDD 204 the setting values ​​indicating whether each of the check boxes 1801, 1802, and 1803 is valid or invalid, from among the certificate renewal reservation settings.

[0096] In S612, the Web page control unit 304 determines whether the certificate renewal reservation setting is valid. The Web page control unit 304 refers to the setting value acquired in S611, and if any of the check boxes 1801, 1802, and 1803 is set to valid, it determines that the certificate renewal reservation setting is valid. If none of the check boxes 1801, 1802, and 1803 is set to valid, the Web page control unit 304 determines that the certificate renewal reservation setting is invalid.

[0097] If it is determined in S612 that the certificate renewal reservation setting is not valid, in S613, the Web page control unit 304 generates HTML data for displaying a Web page screen for accepting the connection setting shown in Fig. 6(A) on the PC 103. In S612, the Web page control unit 304 acquires a UI part for inputting the URL and port number of the SCEP server from the HDD 204. Furthermore, the Web page control unit 304 acquires information on the URL and port number of the currently set SCEP server from the HDD 204. The Web page control unit 304 combines the acquired UI part data with the information on the URL and port number of the SCEP server to generate HTML data for displaying a connection setting screen. In this way, it is possible to generate HTML data for displaying Fig. 6(A) in which a character string can be input into each input field.

[0098] If it is determined in S612 that the certificate renewal reservation setting is set to be valid, the Web page control unit 304 advances the process to S614. In S614, the Web page control unit 304 generates HTML data of a Web page screen that cannot accept the input of the connection setting shown in FIG. 8. The Web page control unit 304 acquires data of UI parts required to configure the connection setting screen from the HDD 204. In S615, the Web page control unit 304 acquires UI parts for masking input from the user in addition to UI parts for displaying the input form and the "Setting" button 1018. Furthermore, the Web page control unit 304 acquires information on the URL and port number of the currently set SCEP server from the HDD 204. Then, the Web page control unit 304 generates HTML data of the screen shown in FIG. 8 by combining the acquired data of the UI parts with the information on the URL and port number of the SCEP server. At this time, the Web page control unit 304 arranges UI parts for masking input from the user over each input form and the "Setting" button. The Web page control unit 304 masks the input when a user at the location where the UI part is placed attempts to enter a character string into each input form or select the "Settings" button 1018. This makes it possible to prevent information about the device to which the digital certificate issuance request is to be sent from being changed while the reservation update setting is enabled.

[0099] The process proceeds to S615, and the Web page control unit 304 transmits the HTML data generated in S613 or S614 to the PC 103, and causes a connection setting screen to be displayed on the display unit of the PC 103. Thereafter, the Web page control unit 304 ends the process shown in FIG.

[0100] 13(A) is performed, it is possible to prevent the destination setting of the certificate acquisition request from being changed while the certificate renewal reservation setting is enabled. In this way, it is possible to prevent the destination of the certificate acquisition request from being changed to an incorrect destination while the certificate renewal reservation setting is enabled, which would result in the reserved certificate renewal failing.

[0101] Fig. 13(B) is a flowchart showing the processing performed by the multifunction peripheral 100 according to this embodiment when the setting values ​​for the connection settings to the registration authority 102 are stored in the HDD 204. A program for executing the processing shown in Fig. 13(B) is stored in the HDD 204 or the ROM 202. The key pair and certificate management unit 307 reads out and executes the program to realize the processing.

[0102] First, in S621, the key pair and certificate management unit 307 receives a connection setting request from the PC 103. The connection setting request is transmitted to the key pair and certificate management unit 307 via the network driver 301, the network control unit 302, and the communication control unit 303.

[0103] Next, in S622, the key pair and certificate management unit 307 acquires the address of the registration authority 102 specified in the received connection setting, the setting value of the port number, and the setting value of the certificate renewal reservation setting.

[0104] In S623, the key pair and certificate management unit 307 judges whether the certificate renewal reservation setting is valid. The method for judging whether the certificate renewal reservation setting is valid or not is the same as that of S613 in Fig. 13(A). If the certificate renewal reservation setting is set to valid in S623, the key pair and certificate management unit 307 advances the process to S626. On the other hand, if the certificate renewal reservation function is set to invalid, the key pair and certificate management unit 307 advances the process to S624.

[0105] In S624, the key pair and certificate management unit 307 stores the setting values ​​of the address and port number of the registration authority 102 acquired in S622 in the HDD 204. In S625, the key pair and certificate management unit 307 controls the Web page control unit 304 to generate HTML data for displaying the Web page screen shown in FIG.

[0106] If it is determined in S623 that the certificate renewal reservation setting is valid, then in S626 the key pair and certificate management unit 307 generates HTML data for a Web page screen that does not accept connection setting input, as shown in Fig. 9. At this time, the content input via the connection setting screen shown in Fig. 6(A) is not stored in the HDD 204. The method by which the Web page control unit 304 generates HTML data is the same as that shown in Fig. 13(A), and therefore a description thereof will be omitted.

[0107] Then, the process proceeds to S616, and the key pair and certificate management unit 307 transmits the HTML data generated in S625 or S626 to the PC 103, completing the processing described in this flowchart.

[0108] By executing the processes of S622 to S626, when the certificate renewal reservation setting is enabled, the multifunction device 100 does not reflect the change in the destination of the certificate acquisition request instructed by the user. In this way, while the automatic digital certificate renewal function is enabled, it is possible to prevent the destination setting of the certificate issuance request from being changed to an incorrect destination, which would result in the reserved certificate renewal failing.

[0109] In this embodiment, in addition to the process shown in FIG. 13A, the process shown in FIG. 13B is also executed. This is because of the following cases. When a user uses the RUI function to set up the issuance of an electronic certificate, multiple users can access the multifunction device 100 from different PCs at the same time and set up the settings. Therefore, one user can set up a connection, another user can set up a certificate renewal reservation, and another user can set up a connection using the connection setting screen. Therefore, before one user completes the connection setting, another user may set up a renewal reservation. In this case, if the connection setting is accepted after the renewal reservation setting is set to be valid, the user who set up the renewal reservation will reserve the issuance of an electronic certificate for an address or port number that is not intended by the user who set up the renewal reservation. Therefore, at the timing when the connection setting is reflected, it is determined again whether the renewal reservation setting is valid, and if the renewal reservation setting is valid, the connection setting is not accepted.

[0110] As described above, in this embodiment, both the process shown in FIG. 13(A) and the process shown in FIG. 13(B) are performed, but it is also possible to execute only one of them.

[0111] In this embodiment, the address of the registration authority 102 and the port number to which the certificate issuance request is to be sent are input on the connection setting screen shown in FIG. 6(A).

[0112] As described above, in this embodiment, when the setting for automatically obtaining a public key digital certificate is enabled, control is performed so that the information of the device to which the certificate issuance request is to be sent cannot be changed. This prevents the destination of the certificate issuance request from being set to an incorrect or unintended destination while the certificate is being reserved, and prevents failure in issuing the reserved certificate.

[0113] (Other embodiments) In this embodiment, when the electronic certificate renewal reservation setting is set to valid, the setting for automatically renewing the electronic certificate is determined to be valid, and the setting of the transmission destination of the certificate issuance request is controlled so that it cannot be changed. After the multifunction device 100 transmits a request for issuing an electronic certificate of a public key to the registration authority 102, the period during which a polling process is performed on the registration authority 102 to acquire the issued certificate may be automatically set as the period during which the automatic renewal of the electronic certificate is valid. The polling process is a process in which, if it is determined in S817 of FIG. 12 that the certificate acquisition has failed, the multifunction device returns the process to S816, transmits a request for acquiring certificate data to the registration authority 102 at predetermined time intervals, and acquires the issued certificate. If the setting related to the registration authority 102 is changed during the polling process to receive the issued certificate after the multifunction device 100 transmits a request for issuing an electronic certificate, the multifunction device 100 cannot receive the issued certificate. Therefore, it may be possible to prevent the settings related to the registration authority 102 from being changed only during the polling process, thereby preventing the multifunction device 100 from being unable to receive the certificate issued in response to a request for issuance of an electronic certificate that has already been sent.

[0114] The present invention can also be realized by executing the following process. That is, software (programs) that realize the functions of the above-mentioned embodiments are supplied to a system or device via a network or various storage media, and the computer (or CPU, MPU, etc.) of the system or device reads and executes the program code. In this case, the computer program and the storage medium on which the computer program is stored constitute the present invention.

Claims

1. a destination setting means for setting a destination to which a request for issuing a public key digital certificate is to be sent; a transmission means for transmitting the issuance request to the destination set by the destination setting means at a timing set by a user; an acquisition means for acquiring the electronic certificate issued based on the issuance request transmitted by the transmission means from an external device that is the transmission destination, a display control means for displaying a setting screen for receiving the setting of the transmission destination on a display means; The information processing apparatus according to claim 1, wherein the display control means does not display the setting screen while a setting for transmitting the issuance request at a timing set by a user by the transmitting means is valid.

2. The setting screen may be displayed on the display device. The information processing device according to claim 1, characterized in that the display control means, while a setting for sending the issuance request at a timing set by the user is valid, does not display the setting screen based on an instruction from the user accepted by the acceptance means, and causes the display means to display a confirmation screen that shows the destination and does not allow the destination to be set.

3. 3. The information processing apparatus according to claim 2, wherein the display control means controls the display means so as not to execute a process corresponding to the input of the transmission destination on the confirmation screen.

4. 4. The information processing apparatus according to claim 3, wherein the confirmation screen is a screen in which an area for inputting the destination is grayed out on the setting screen.

5. The information processing device according to any one of claims 2 to 4, characterized in that the confirmation screen is a screen indicating that the destination to which the certificate issuance request is sent cannot be changed because a setting to cause the sending means to send the issuance request at a timing set by a user is enabled.

6. The method further includes a storage unit for storing information indicating that a setting for transmitting the issuance request at a timing set by a user is enabled, The information processing apparatus according to claim 1 , wherein the display control means controls the display so as not to display the setting screen based on the information stored in the storage means.

7. 7. The information processing apparatus according to claim 1, wherein the display control means generates HTML data for a screen to be displayed on the display means.

8. 8. The information processing device according to claim 1, further comprising a control means for controlling so as not to reflect the information of the external device set by the destination setting means while a setting for causing the transmission means to transmit the issuance request at a timing set by a user is valid.

9. 9. The information processing apparatus according to claim 1, wherein the setting screen is a screen for setting the destination and a port number to which the issuance request is to be sent.

10. 10. The information processing apparatus according to claim 1, wherein the timing is specified based on at least one of an update date, a number of days based on a validity period of the electronic certificate, and an update cycle.

11. The display control means can cause the display means to display a screen for inputting settings related to a certificate, 11. The information processing apparatus according to claim 1, wherein the display control means is capable of displaying a screen for inputting settings related to the certificate even while the settings made by the control means are valid.

12. 12. The information processing apparatus according to claim 11, wherein the settings related to the certificate include information on an algorithm and a key length used to generate the certificate.

13. 13. The information processing apparatus according to claim 1, wherein the external device is an SCEP server.

14. 14. The information processing apparatus according to claim 1, wherein the transmitting means transmits the request for issuing the certificate to the destination in accordance with an instruction of a user to request the issuance of the certificate.

15. 15. The information processing apparatus according to claim 1, further comprising a storage unit for storing the certificate acquired by the acquisition unit.

16. a destination setting means for setting a destination to which a request for issuing a public key digital certificate is to be sent; a transmitting means for transmitting the issuance request to the destination at a timing set by a user while a setting for transmitting the issuance request to the destination at the timing set by the user is valid; an acquisition means for acquiring the electronic certificate issued based on the issuance request transmitted by the transmission means from an external device, an information processing device comprising: a control means for controlling so that the destination set by the destination setting means is not changed while a setting for sending the electronic certificate issuance request at a timing set by a user is valid.

17. a destination setting step of setting a destination to which a request for issuing a public key digital certificate is to be sent; a transmission step of transmitting a request for issuing a digital certificate for the public key to the destination set in the destination setting step; an acquisition step of acquiring the electronic certificate issued based on the issuance request transmitted in the transmission step from the external device which is the transmission destination; a setting step of enabling a function of transmitting the issuance request at a timing set by a user, a display control step of displaying a setting screen for receiving input of the destination on a display means, The control method for an information processing apparatus, wherein the display control step does not display the setting screen while a setting for transmitting the issuance request at a timing set by a user is valid.

18. A computer program for causing a computer to execute the method for controlling an information processing device according to claim 17.

Citation Information

Patent Citations

  • Device, method for managing function, program, and recording medium

    JP2006059141A

  • POS terminal device

    JP2010039546A

  • Information processing apparatus and control method thereof

    JP2012050139A

  • Electronic apparatus and automatic update method of electronic certificate

    JP2016178458A

  • Image forming apparatus

    JP2017092991A