Image acquisition device, computer program for image acquisition device, and control method for image acquisition device
The image acquisition device addresses the security gap in protecting image data by encrypting the data with a key stored in an external device accessible by the terminal device, ensuring that only authorized devices can decrypt the data, thus enhancing security.
Patent Information
- Application Number
- JP2023211809
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-26
AI Technical Summary
Existing image acquisition devices, such as Multi-Function Peripherals (MFPs), do not adequately protect the information contained in acquired image data from security threats.
The image acquisition device includes a communication interface, an encryption key, a generation unit for encrypting image data, a storage control unit for storing the encryption key in an external device accessible by a terminal device, and a data transmission unit for sending encrypted data to the terminal device, which decrypts the data using the received encryption key.
This configuration effectively protects the information in the image data by ensuring that only authorized terminal devices can decrypt the encrypted data, thus preventing unauthorized access and ensuring appropriate security measures are in place.
Smart Images

Figure 2025095658000001_ABST
Abstract
Description
Technical Field
[0001] This specification relates to an image acquisition device that acquires image data.
Background Art
[0002] Patent Document 1 discloses a Multi-Function Peripheral (MFP) that executes scanning according to a scan command from a smartphone and transmits a file generated by the scanning to the smartphone.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] The image data acquired by the MFP contains various information. From the perspective of security, appropriate protection of the information is required. This specification provides a technique for appropriately protecting the information contained in the image.
Means for Solving the Problems
[0005] The image acquisition device disclosed in this specification includes a communication interface configured to communicate with a terminal device, an encryption key, image data acquired by the image acquisition device, and a generation unit that generates encrypted image data using the above, a storage control unit that stores the encryption key in an external device different from the image acquisition device and accessible by the terminal device, and a first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, wherein the terminal device decrypts the encrypted image data using the encryption key received from the external device.
[0006] According to the above configuration, the image data is encrypted with an encryption key. The encryption key is stored in an external device accessible by the terminal device. Even if the encrypted image data leaks from the terminal device to another device, the other device cannot access the external device, and the encrypted image data cannot be decrypted by the other device. Information included in the image corresponding to the image data can be appropriately protected.
[0007] A computer program for realizing the above image acquisition device, and a computer-readable storage medium storing the computer program are also novel and useful. Further, a control method for the above image acquisition device is also novel and useful.
Brief Description of Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0009] (First Embodiment) (Configuration of Communication System 2; FIG. 1) The communication system 2 includes an image acquisition device 10, a terminal device 100, a terminal device 200, and a server 300. The image acquisition device 10 can communicate with the terminal devices 100 and 200 via the LAN 4. The LAN 4 can be wireless or wired. The terminal devices 100 and 200 are desktop PCs, laptop PCs, smartphones, tablet terminals, etc. The device name "td1" is assigned to the terminal device 100, and the device name "td2" is assigned to the terminal device 200. A control program for controlling the image acquisition device 10 is installed in the terminal devices 100 and 200. The control program is provided by, for example, the vendor of the image acquisition device 10.
[0010] The LAN 4 is connected to the Internet 6. The server 300 is connected to the Internet 6. The image acquisition device 10, the terminal devices 100 and 200 can communicate with the server 300 via the LAN 4 and the Internet 6. The server 300 is provided by, for example, the vendor of the image acquisition device 10. In a modification, the server 300 may be provided by a business operator different from the vendor of the image acquisition device 10. In another modification, the server 300 may be directly connected to the LAN 4.
[0011] (Configuration of the image acquisition device 10; FIG. 1) The image acquisition device 10 is a device having a function of acquiring an image. The image acquisition device is, for example, a peripheral device (e.g., a scanner) capable of executing a document reading function (i.e., a scanning function). Further, in addition to the scanning function, the image acquisition device 10 may be a multifunction device having multiple functions such as a printing function and a FAX function.
[0012] The image acquisition device 10 includes a scan execution unit 12, an operation unit 14, a display unit 16, a LAN interface 20, and a control unit 30. Hereinafter, "interface" will be described as "I / F".
[0013] The scanning execution unit 12 is a unit for reading a document, and includes, for example, image sensors such as a Charge-Coupled Device (CCD) and a Contact Image Sensor (CIS). The operation unit 14 includes a plurality of buttons. The user can input various instructions to the image acquisition device 10 by operating the operation unit 14. The operation unit 14 includes, for example, buttons within a touch screen and structural buttons. The buttons within the touch screen are, for example, icons. The structural buttons are, for example, mechanical switches and keyboards. The display unit 16 is a display for displaying various information, and is, for example, a liquid crystal display or an organic EL display. The LANI / F20 is an I / F for executing communication via the LAN4 and is connected to the LAN4.
[0014] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 stores a program 40. The CPU 32 executes various processes according to the program 40. The program 40 includes a plurality of programs and includes, for example, a scan execution program for causing the scanning execution unit 12 to execute a scan.
[0015] The memory 34 includes, for example, a non-volatile memory and a volatile memory. The non-volatile memory is, for example, a Hard Disk Drive (HDD), a Read Only Memory (ROM), a Solid State Drive (SSD), or a flash memory. The volatile memory is, for example, a Random Access Memory (RAM). The program 40 is stored in the non-volatile memory. The CPU 32 executes various processes according to the program loaded from the non-volatile memory to the volatile memory.
[0016] (Overview of Pull Scan and Push Scan; Figure 2) The image acquisition device 10 can execute a pull scan and a push scan as processes for causing the scan execution unit 12 to perform a scan. The pull scan is a process that is executed triggered by a predetermined operation on the operation unit (e.g., keyboard) of the terminal device 100. The push scan is a process that is executed triggered by a predetermined operation on the operation unit 14 of the image acquisition device 10.
[0017] Hereinafter, for the sake of easier understanding, the operations executed by the CPU 32 of the image acquisition device 10 will be described with reference to the operations performed by the image acquisition device 10. Also, the communication between the image acquisition device 10 and the terminal device 100 is executed via the LAN 4 and the LANI / F 20 unless otherwise specified. Therefore, when explaining the communication between the image acquisition device 10 and the terminal device 100, the descriptions "via the LAN 4" and "via the LANI / F 20" are omitted.
[0018] The outline of the pull scan is as follows. At T2, the user inputs a pull execution instruction for instructing the execution of the pull scan to the operation unit of the terminal device 100. At T2, when the terminal device 100 receives the pull execution instruction, at T4, it transmits a scan instruction to the image acquisition device 10. When the image acquisition device 10 receives the scan instruction from the terminal device 100 at T4, it calls a scan execution program. At T6, the image acquisition device 10 uses the scan execution program to cause the scan execution unit 12 to perform a scan according to the scan instruction. Then, the image acquisition device 10 transmits the scan data generated by the scan at T6 to the terminal device 100. Here, the scan data is data obtained by converting the data generated by the scan execution unit 12 into a predetermined file format, for example, JPEG data. In a modification, the scan data may be the data generated by the scan execution unit 12 itself.
[0019] Also, the outline of push scan is as follows. At T10, the user inputs a push execution instruction to the operation unit 14 to instruct the execution of push scan. When receiving the push execution instruction at T10, the image acquisition device 10 transmits an instruction request for requesting the transmission of a scan instruction to the terminal device 100 at T12. When receiving the instruction request from the image acquisition device 10 at T12, the terminal device 100 transmits a scan instruction to the image acquisition device 10 according to the instruction request at T14. T16 and T18 are the same as T6 and T8.
[0020] Here, the scan instruction at T4 in pull scan and the scan instruction at T14 in push scan are commands described in the same format. By using a common scan instruction for both pull scan and push scan, a common scan execution program can be used for both pull scan and push scan. In a modification, the processes at T12 and T14 may be omitted.
[0021] In this embodiment, the image acquisition device 10 operates in either a non-permitted state or a permitted state. The non-permitted state is a state where the execution of scan is not permitted, and the permitted state is a state where the execution of scan is permitted. For example, when the image acquisition device 10 is operating in the non-permitted state, even if a scan instruction is received from the terminal device 100, the image acquisition device 10 does not execute the scan. On the other hand, when the image acquisition device 10 is operating in the permitted state, when a scan instruction is received from the terminal device 100, the image acquisition device 10 executes the scan.
[0022] (Specific case of pull scan; FIG. 3) Referring to FIG. 3, a specific case of the pull scan of this embodiment will be described. In the initial state of this case, the state of the image acquisition device 10 is the non-permitted state.
[0023] In T100, the image acquisition device 10 causes the display unit 16 to display a login screen in accordance with a predetermined operation by the user. The login screen is a screen for inputting login information for logging in to the server 300. The login information is, for example, an account name and a password. In a modification, the login information may be biometric information for performing biometric authentication such as face authentication, or authentication information stored in an IC card.
[0024] In T102, the image acquisition device 10 generates a unique encryption key CK1 and stores it in the memory 34. The encryption key CK1 is, for example, a common key conforming to the Advanced Encryption Standard (AES).
[0025] When the image acquisition device 10 receives the input of the login information in T104, it transmits the login information to the server 300 via the Internet 6 in T106. In the following, when explaining the communication with the server 300, the description "via the Internet 6" will be omitted.
[0026] When the server 300 receives the login information from the image acquisition device 10 in T106, it authenticates the login information received in T106. The server 300 determines that the authentication of the login information received in T106 is successful when the login information received in T106 matches the login information stored in the server 300. In this case, the server 300 determines in T108 that the authentication of the login information received in T106 is successful, and establishes a session with the image acquisition device 10 in T110. The session is, for example, a session conforming to the Hypertext Transfer Protocol Secure (HTTPS). If the authentication in T108 fails, the processing after T110 is not executed, and the processing in FIG. 3 ends.
[0027] When the image acquisition device 10 establishes a session with the server 300 at T110, at T112, it uses the session established at T110 to transmit the encryption key CK1 generated at T102 and the file path to the server 300. Here, the file path includes the directory path indicating the position where the encryption key CK1 should be stored in the server 300 and the file name of the encryption key CK1. The file path is specified by the image acquisition device 10.
[0028] When the server 300 receives the encryption key CK1 and the file path from the image acquisition device 10 at T112, at T114, it stores the encryption key CK1 according to the file path received from the image acquisition device 10. Here, the encryption key CK1 is stored in association with the login information for which the session was established at T110. The server 300 transmits a completion notification indicating that the storage of the encryption key CK1 is complete to the image acquisition device 10 at T116.
[0029] When the image acquisition device 10 receives the completion notification from the server 300 at T116, at T118, it changes the state of the image acquisition device 10 from an impossible state to a possible state.
[0030] T132 and T134 are examples of T2 and T4 in FIG. 2. T136 is an example of T6 in FIG. 2, and the image acquisition device 10 starts scanning the document. In this embodiment, the document is a paper document and consists of multiple pages. In T138A, the image acquisition device 10 generates scan data for the first page by scanning the first page, and encrypts the scan data for the first page using the encryption key CK1. In T140A, the image acquisition device 10 transmits the encrypted scan data for the first page, which is the encrypted scan data for the first page encrypted by the encryption key CK1, to the terminal device 100. As a result, in T142A, the terminal device 100 stores the encrypted scan data for the first page received from the image acquisition device 10. The image acquisition device 10 executes the same processing as T138A to T142A for all of the multiple pages. In T138B to T142B, scan data for the last page is generated, and the encrypted scan data for the last page, which is the scan data for the last page encrypted by the encryption key CK1, is transmitted to the terminal device 100. T140A and T140B are examples of T8 in FIG. 2. By transmitting the encrypted scan data for the last page to the terminal device 100, the encrypted scan data for all pages is stored in the terminal device 100. Note that the document may be an electronic document instead of a paper document. When the document is an electronic document, in T140A etc., the image acquisition device 10 may acquire the electronic document from the storage medium and encrypt the data corresponding to each page of the electronic document.
[0031] When the image acquisition device 10 transmits the encrypted scan data for the last page to the terminal device 100 in T140B, in T150, it transmits a scan completion notification indicating that the scanning of all pages of the document has been completed to the terminal device 100. The scan completion notification includes the file path transmitted to the server 300 in T112.
[0032] When the terminal device 100 receives a scan completion notification from the image acquisition device 10 at T150, it displays a login screen at T160. When the terminal device 100 receives input of login information from the user on the login screen, it transmits the login information to the server 300 at T162. In this case, the user inputs the same login information into the terminal device 100 as the login information input at T104. In this case, the server 300 determines at T164 that the authentication of the login information received at T162 is successful, and establishes a session with the terminal device 100 at T166. Note that if the authentication at T164 fails, the processing after T166 is not executed, and the processing in FIG. 3 ends.
[0033] When the terminal device 100 establishes a session with the server 300 at T166, it transmits a key request for requesting an encryption key to the server 300 using the session established at T166 at T168. The key request includes the folder path received from the image acquisition device 10 at T150.
[0034] When the server 300 receives the key request from the terminal device 100 at T168, it acquires the encryption key CK1 from the position indicated by the folder path included in the key request, and transmits the encryption key CK1 to the terminal device 100 at T170.
[0035] When the terminal device 100 receives the encryption key CK1 from the server 300 at T170, it decrypts the encrypted scan data of all pages using the encryption key CK1 received from the server 300 at T172. As a result, the scan data indicating all pages of the original document is stored in the terminal device 100, and the image indicating the original document is displayed on the terminal device 100.
[0036] Also, in this case, after the scan completion notice is sent to the terminal device 100 at T150, the user performs an operation to log out from the server 300 on the image acquisition device 10 at T152. As a result, the session between the image acquisition device 10 and the server 300 is disconnected. In a modified example, when the image acquisition device 10 sends the completion notice to the terminal device 100, it may automatically disconnect the session with the server 300 and log out.
[0037] When the session between the image acquisition device 10 and the server 300 is disconnected, at T154, the image acquisition device 10 changes the state of the image acquisition device 10 from a permitted state to a non-permitted state. Then, at T156, the encryption key CK1 generated at T102 is discarded (i.e., the encryption key CK1 is deleted from the memory 34). By discarding the encryption key CK1, the leakage of the encryption key CK1 can be suppressed.
[0038] Also, the image acquisition device 10 may sequentially scan the originals until the session with the server 300 is disconnected. The image acquisition device 10 may encrypt each scan data corresponding to each original using the encryption key CK1 and send the encrypted scan data corresponding to each original to the terminal device 100. That is, one encryption key CK1 may be used for each of the plurality of originals.
[0039] (Effect of this embodiment) According to the configuration of this embodiment, the scan data is encrypted with the encryption key CK1 and transmitted to the terminal device 100 (T140A in FIG. 3). When the authentication of the login information input to the image acquisition device 10 is successful, that is, when the server 300 authenticates the image acquisition device 10, the encryption key CK1 is stored in the server 300 (T114). Also, when the authentication of the login information input to the terminal device 100 is successful, the encryption key CK1 is transmitted to the terminal device 100 (T170). Even if the encrypted scan data leaks from the terminal device 100 to another device, if the user of the other device does not know the login information, the other device cannot access the server 300. That is, the encrypted scan data is not decrypted by other devices. The information included in the original document corresponding to the scan data can be appropriately protected.
[0040] Also, in this embodiment, the image acquisition device 10 causes the server 300 to store the encryption key CK1 in a situation where the state of the image acquisition device 10 is in a non-permitted state (T112). Thereby, until the preparation of the encryption key CK1 is completed, scanning is prohibited, and it is possible to suppress the scan data from leaking without being encrypted.
[0041] Also, in push scanning as well, similar to pull scanning, the scan data may be encrypted with the encryption key CK1, and the encryption key CK1 may be stored in the server 300. Furthermore, in push scanning as well, the encryption key CK1 may be stored in the server 300 in a situation where the state of the image acquisition device 10 is in a non-permitted state. In a modified example, in push scanning, the encryption key CK1 may not be used, and unencrypted scan data may be transmitted to the terminal device 100.
[0042] (Corresponding relationship) The image acquisition device 10, the terminal device 100, and the server 300 are each an example of an "image acquisition device", a "terminal device", and an "external device". LANI / F20 is an example of a "communication interface". The encryption key CK1, the scan data, and the file path are each an example of an "encryption key", "image data", and "location information".
[0043] In FIG. 3, T138A, T112, and T140A are examples of processes realized by a "generation unit", a "memory control unit", and a "first data transmission unit", respectively.
[0044] (Second Embodiment) This embodiment is the same as the first embodiment except that the method of storing the encryption key CK1 is different. In this embodiment, the encryption key CK1 is stored in a storage medium 400 (see FIG. 4). The storage medium 400 is, for example, a USB memory or a memory card.
[0045] (Configuration of Image Acquisition Device 10; FIG. 1) In this embodiment, the image acquisition device 10 includes a media I / F 22. The media I / F 22 is an I / F for connecting the storage medium 400.
[0046] (Specific Case of Pull Scan; FIG. 4) Referring to FIG. 4, a specific case of the pull scan in this embodiment will be described. In the initial state of this case, the state of the image acquisition device 10 is a non-permitted state.
[0047] When the image acquisition device 10 detects at T200 that the storage medium 400 is connected to the media I / F 22, it generates the encryption key CK1 at T202 and stores it in the memory 34. T212 to T218 are the same as T112 to T118 in FIG. 3 except that the storage medium 400 is used.
[0048] T232 to T256 are the same as T132 to T156 in FIG. 3, except that when the image acquisition device 10 detects the removal of the storage medium at T252, the processing after T254 is executed. When the terminal device 100 receives a scan completion notification from the image acquisition device 10 at T250, it monitors the connection of the storage medium. Then, when the terminal device 100 detects the connection of the storage medium 400 at T260, it executes the processing after T268. T268 to T272 are the same as T168 to T172 in FIG. 3, except that the terminal device 100 receives the encryption key CK1 from the storage medium 400.
[0049] (Effect of this embodiment) According to the configuration of this embodiment, the encryption key CK1 is stored in the storage medium 400 (T214 in FIG. 4). The storage medium 400 is held by the user of the image acquisition device 10, and a third party other than the user cannot use the storage medium 400. That is, the storage medium 400 can be accessed by the terminal device 100 used by the user of the image acquisition device 10, while it cannot be accessed by other devices of a third party. Since other devices cannot access the storage medium 400, the encrypted scan data is not decrypted by other devices. The information included in the image corresponding to the scan data can be appropriately protected. The storage medium 400 is an example of an "external device".
[0050] (Third embodiment) This embodiment is the same as the first embodiment, except that the storage method of the encryption key CK1 is different. In this embodiment, the encryption key CK1 is stored in the server 300 in association with the key ID.
[0051] (Specific case of pull scan; FIG. 5) Referring to FIG. 5, a specific case of the pull scan in this embodiment will be described. T300 and T301 are the same as T132 and T134 in FIG. 3, except that the scan instruction includes the device name "td1" of the terminal device 100. T302 is the same as T102 in FIG. 3, except that in addition to the encryption key CK1, a key ID "k01" is generated. At T312, the image acquisition device 10 transmits the encryption key CK1 and the key ID "k01" generated at T302 to the server 300.
[0052] When the server 300 receives the encryption key CK1 and the key ID "k01" from the image acquisition device 10 at T312, at T314, it stores the encryption key CK1 in association with the key ID "k01". T316 is the same as T116 in FIG. 3.
[0053] T336 to T342 are the same as T136 to T142B in FIG. 3. When the transmission of the encrypted scan data for all pages is completed, the image acquisition device 10 causes the display unit 16 to display a confirmation screen at T350 for the user to confirm the transmission source of the scan instruction of T301. The confirmation screen includes the device name "td1" received at T301, an OK button, and a Cancel button. In this case, the user determines that the device name "td1" included in the confirmation screen indicates a known terminal device and selects the OK button on the confirmation screen. If, by chance, the user determines that the device name "td1" indicates an unknown terminal device, the user selects the Cancel button on the confirmation screen. When the Cancel button on the confirmation screen is selected, the processing after T354 described below is not executed, and the processing in FIG. 5 ends.
[0054] When the image acquisition device 10 receives the selection of the OK button on the confirmation screen at T352, at T354, it transmits the key ID "k01" and the device name "td1" to the server 300.
[0055] When the server 300 receives the key ID "k01" and the device name "td1" from the image acquisition device 10 at T354, it stores the device name "td1" in association with the key ID "k01" at T356. Thereby, the server 300 stores the device name "td1" and the encryption key CK1 in association with the key ID "k01".
[0056] Also, at T360, the image acquisition device 10 transmits a scan completion notification including the key ID "k01" to the terminal device 100. T362 is the same as T156 in FIG. 3.
[0057] When the terminal device 100 receives the scan completion notification from the image acquisition device 10 at T360, it transmits a key request including the device name "td1" and the key ID "k01" received from the image acquisition device 10 at T360 to the server 300 at T370.
[0058] When the server 300 receives the key request from the terminal device 100 at T370, it determines at T372 whether the device name "td1" included in the key request matches the device name stored in association with the key ID "k01" included in the key request. In this case, the server 300 determines that the two device names match, and transmits the encryption key CK1 stored in association with the key ID "k01" to the terminal device 100 at T374. Thereby, the terminal device 100 decrypts the encrypted scan data for all pages using the encryption key CK1 received from the server 300 at T376. If the server 300 determines that the two device names do not match, the processing after T374 is not executed, and the processing of FIG. 5 ends.
[0059] In this case, the encryption key CK1 is stored in the server 300 in association with the device name "td1" specified by the user using the OK button (T356 in FIG. 5). And the encryption key CK1 is not transmitted to the terminal device that is the source of the key request unless the device name indicating the terminal device that is the source of the key request matches the device name stored in the server 300. That is, the encryption key CK1 is not transmitted to a terminal device different from the terminal device specified by the user. It is possible to suppress the acquisition of the encryption key CK1 by a third party.
[0060] In T380 of FIG. 6, the user changes the original document set in the image acquisition device 10 to another original document. T400 to T476 are the same as T300 to T376 in FIG. 5 except that another key ID "k02" and another encryption key CK2 are used.
[0061] As shown in FIG. 6, in this embodiment, the scan data corresponding to the other original document scanned in FIG. 6 is encrypted with another encryption key CK1 different from the encryption key CK1. In this embodiment, compared with a configuration in which the same encryption key is used for all of a plurality of original documents, the information in the original document can be strongly protected. Also, by using the key ID, the terminal device 100 can receive an appropriate encryption key among a plurality of encryption keys.
[0062] (Specific case of push scan; FIG. 7) Referring to FIG. 7, a specific case of the push scan of this embodiment will be described. T610 to T616 are examples of T10 to T16 in FIG. 2. The instruction request of T162 includes the IP address of the terminal device 100, and the scan instruction of T164 includes the device name "td1" of the terminal device 100. For example, in the image acquisition device 10, a list of terminal devices (for example, a list of IP addresses) that can communicate with the image acquisition device 10 is stored. The push execution instruction of T160 includes an operation in which the user selects the terminal device 100 from among the list.
[0063] In this case, the encryption key CK1 is not generated, and the scan data of each page of the manuscript is not encrypted by the encryption key CK1. In T618, the image acquisition device 10 transmits the scan data of each page of the manuscript to the terminal device 100. Thereby, the terminal device 100 stores the scan data of each page of the manuscript and displays an image indicating the manuscript at T154.
[0064] For example, the image acquisition device 10 is placed in an office. It is difficult for an unauthenticated third party other than the employees in the office to enter the office. Push scan is a scan executed by triggering the operation of the operation unit 14 of the image acquisition device 10, and it is difficult for an unauthenticated third party to execute. In the push scan that is difficult for a third party to execute, encryption and decryption by the encryption key CK1 can be omitted to reduce the processing load on the image acquisition device 10 and the terminal device 100.
[0065] (Corresponding relationship) The key ID "k01" in FIG. 5 and the key ID "k02" in FIG. 6 are examples of the "first key identifier" and the "second key identifier", respectively. The device name "td1" and the terminal device 100 are examples of the "terminal identifier" and the "specific device", respectively. The operation unit 14 is an example of the "operation unit". The pull execution instruction of T300 in FIG. 5 and the push execution instruction of T610 in FIG. 7 are examples of the "first acquisition instruction" and the "second acquisition instruction", respectively.
[0066] As described above, specific examples of the present invention have been described in detail, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples exemplified above. Modifications of the above embodiments are listed below.
[0067] (Modification 1) In the first embodiment, the login information used in the session of T162 may be different from the login information used in the session of T110. That is, it is sufficient that both the image acquisition device 10 and the terminal device 100 are authenticated by the server 300, and the two pieces of login information do not have to be the same.
[0068] (Modification Example 2) In the second embodiment, instead of the storage medium, an IC chip capable of communicating by wireless communication (for example, Near Field Communication (NFC)) may be used. The IC chip is included in, for example, a card, a mobile terminal, or the like. In this modification example, when a wireless connection with the IC chip is established at T200 in FIG. 4, the image acquisition device 10 executes the processes after T202, and may transmit the encryption key CK1 to the IC chip at T212. Further, when a wireless connection with the IC chip is established at T260, the terminal device 100 executes the processes after T268, and may receive the encryption key CK1 from the IC chip at T270. In this modification example, the IC chip is an example of an "external device".
[0069] (Modification Example 3) In the first and third embodiments, the encryption key CK1 may be generated by the server 300. In this modification example, for example, at T212 in FIG. 3, the image acquisition device 10 may transmit a generation request for requesting generation of an encryption key to the server 300, and receive the encryption key from the server 300 at T116. In this modification example, the control unit 30 that transmits the above generation request is an example of a "storage control unit".
[0070] (Modification Example 4) In the third embodiment, the processes of T350 to T356 and T372 in FIG. 5 may not be executed. That is, in the third embodiment, the device name may not be used. In this modification example, the "terminal identifier" and the "second identifier transmission unit" can be omitted.
[0071] (Modification Example 5) In the third embodiment, the key ID may not be used. In this modification example, the encryption key is stored in association with the device name, and the key request may include only the device name. Then, when the device name included in the key request matches the device name stored in the server 300, the server 300 may transmit the encryption key to the terminal device 100. In this modification example, the "first key identifier (and the second key identifier)" can be omitted.
[0072] (Modification Example 6) The process of FIG. 7 may be omitted. In this case, for example, the scan data generated by push scanning may be encrypted by the encryption key CK1. In this modification example, the "second data transmission unit" can be omitted.
[0073] (Modification Example 7) In the first and second implementations, the processes of T118, T154, T218, and T254 may be omitted. In this modification example, the "non-permitted state" and the "permitted state" can be omitted.
[0074] (Modification Example 8) The process of any one of T156 in FIG. 3, T256 in FIG. 4, and T362 in FIG. 5 may be omitted. In this modification example, the "discarding unit" can be omitted.
[0075] (Modification Example 9) In the first and second embodiments, the file path may not be used. In this modification example, the "location information" can be omitted.
[0076] (Modification Example 10) The determination using the device name of T372 in FIG. 5 may be executed in the first and second embodiments.
[0077] (Modification Example 11) In the above embodiments, each process from FIG. 2 to FIG. 7 is realized by the CPU 32 executing the program 40. Instead of this, any process may be realized by hardware such as a logic circuit.
[0078] Also, the technical elements described in this specification or the drawings exhibit technical utility alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Further, the technology illustrated in this specification or the drawings achieves a plurality of purposes simultaneously, and has technical utility by achieving one of those purposes itself.
[0079] In the claims at the time of filing this patent application, even if each claim depends only on some of the claims, each claim is not limited to being able to depend only on some of the claims. Within a technically non - contradictory range, each claim can also depend on other claims that it did not depend on at the time of filing. That is, the technologies of each claim can be combined in various ways as follows. Hereinafter, the features of the technology disclosed in this specification are listed. (Item 1) An image acquisition device, A communication interface configured to communicate with a terminal device, A generation unit that generates encrypted image data by using an encryption key and the image data acquired by the image acquisition device, A storage control unit that is an external device different from the image acquisition device and stores the encryption key in the external device accessible by the terminal device, A first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, and the terminal device decrypts the encrypted image data by using the encryption key received from the external device, the first data transmission unit, An image acquisition device comprising the above. (Item 2) When the external device authenticates the image acquisition device, the storage control unit transmits the encryption key to the external device and stores the encryption key in the external device, The terminal device acquires the encryption key from the external device when the external device authenticates the terminal device. The image acquisition device according to Item 1. (Item 3) When the external device is connected to the image acquisition device, the storage control unit transmits the encryption key to the external device and stores the encryption key in the external device, The terminal device receives the encryption key from the external device when the external device is connected to the terminal device. The image acquisition device according to Item 1. (Item 4) The external device stores the encryption key in association with a first key identifier, The image acquisition device further includes a first identifier transmission unit that transmits the first key identifier to the terminal device, and the terminal device receives the encryption key from the external device by using the first key identifier received from the image acquisition device. The image acquisition device according to item 1. (Item 5) When other image data different from the image data is acquired by the image acquisition device, the generation unit generates encrypted other image data by using another encryption key different from the encryption key and the other image data, the storage control unit stores the other encryption key in the external device in association with a second key identifier different from the first key identifier, the first data transmission unit transmits the encrypted other image data to the terminal device via the communication interface, the first identifier transmission unit transmits the second key identifier to the terminal device, and the terminal device receives the other encryption key from the external device by using the second key identifier received from the image acquisition device. The image acquisition device according to item 4. (Item 6) The image acquisition device further includes a second identifier transmission unit that transmits a terminal identifier for identifying the terminal device designated by the user of the image acquisition device to the external device, the external device stores the terminal identifier and the encryption key in association with each other, and when the external device is requested for the encryption key from a specific device and an identifier for identifying the specific device matches the terminal identifier, the external device transmits the encryption key to the specific device that is the terminal device, and when the external device is requested for the encryption key from the specific device and the identifier does not match the terminal identifier, the external device does not transmit the encryption key to the specific device. The image acquisition device according to any one of items 1 to 5. (Item 7) The image acquisition device further includes an operation unit, The image acquisition device acquires the image data according to either a first acquisition instruction received from the terminal device via the communication interface or a second acquisition instruction input to the operation unit. When the first acquisition instruction is received from the terminal device, the first data transmission unit transmits the encrypted image data to the terminal device via the communication interface. The image acquisition device further When the second acquisition instruction is input to the operation unit, the image acquisition device according to any one of items 1 to 6 includes a second data transmission unit that transmits the image data not encrypted with the encryption key to the terminal device via the communication interface. (Item 8) The image acquisition device further The image acquisition device according to any one of items 1 to 7 includes a deletion unit that deletes the encryption key stored in the image acquisition device after transmitting the encrypted image data to the terminal device. (Item 9) In a situation where the state of the image acquisition device is a non-permission state in which acquisition of the image data is not permitted, the storage control unit stores the encryption key in the external device. The image acquisition device further The image acquisition device according to item 2 or 3 includes a change unit that changes the state of the image acquisition device from the non-permission state to a permission state in which acquisition of the image data is permitted after storing the encryption key in the external device. (Item 10) The image acquisition device further The image acquisition device according to item 2 or 3 includes an information transmission unit that transmits, to the terminal device, position information indicating a position where the encryption key is stored in the external device after transmitting the encrypted image data to the terminal device. (Item 11) A computer program for an image acquisition device, The image acquisition device A communication interface configured to communicate with a terminal device, a computer, comprising wherein the computer program causes the computer to perform the following steps, namely, a generation unit that generates encrypted image data by using an encryption key and the image data acquired by the image acquisition device; a storage control unit that stores the encryption key in an external device different from the image acquisition device and accessible by the terminal device; a first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, wherein the terminal device decrypts the encrypted image data by using the encryption key received from the external device; and functions as an image acquisition device. (Item 12) A control method for an image acquisition device, wherein the image acquisition device is configured to be communicable with a terminal device, the control method comprising a generation step of generating encrypted image data by using an encryption key and the image data acquired by the image acquisition device; a storage control step of storing the encryption key in an external device different from the image acquisition device and accessible by the terminal device; a first data transmission step of transmitting the encrypted image data to the terminal device, wherein the terminal device decrypts the encrypted image data by using the encryption key received from the external device; and comprising a control method.
Description of Signs
[0080] 2: Communication system, 4: LAN, 6: Internet, 10: Image acquisition device, 12: Scanning execution unit, 14: Operation unit, 16: Display unit, 20: LAN I / F, 22: Media I / F, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 100, 200: Terminal device, 300: Server, 400: Storage media, CK1, CK2: Encryption key
Claims
1. An image acquisition device, comprising: a communication interface configured to communicate with a terminal device; a generation unit that generates encrypted image data by using an encryption key and the image data acquired by the image acquisition device; a storage control unit that is an external device different from the image acquisition device and causes the external device accessible by the terminal device to store the encryption key; a first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, wherein the terminal device decrypts the encrypted image data by using the encryption key received from the external device; An image acquisition device comprising the above components.
2. When the external device authenticates the image acquisition device, the storage control unit transmits the encryption key to the external device and causes the external device to store the encryption key. When the external device authenticates the terminal device, the terminal device acquires the encryption key from the external device. The image acquisition device according to Claim 1.
3. When the external device is connected to the image acquisition device, the storage control unit transmits the encryption key to the external device and causes the external device to store the encryption key. When the external device is connected to the terminal device, the terminal device receives the encryption key from the external device. The image acquisition device according to Claim 1.
4. The external device stores the encryption key in association with a first key identifier. The image acquisition device further comprises: a first identifier transmission unit that transmits the first key identifier to the terminal device; The terminal device receives the encryption key from the external device by using the first key identifier received from the image acquisition device. The image acquisition device according to Claim 1.
5. When other image data different from the image data is acquired by the image acquisition device, the generation unit generates encrypted other image data by using another encryption key different from the encryption key and the other image data. The storage control unit stores the other encryption key in the external device in association with a second key identifier different from the first key identifier. The first data transmission unit transmits the encrypted other image data to the terminal device via the communication interface. The first identifier transmission unit transmits the second key identifier to the terminal device. The terminal device receives the other encryption key from the external device by using the second key identifier received from the image acquisition device, according to the image acquisition device of claim 4.
6. The image acquisition device further includes a second identifier transmission unit that transmits a terminal identifier for identifying the terminal device specified by the user of the image acquisition device to the external device, the external device stores the terminal identifier and the encryption key in association with each other, when the external device is requested for the encryption key from a specific device and an identifier for identifying the specific device matches the terminal identifier, the external device transmits the encryption key to the specific device which is the terminal device, when the external device is requested for the encryption key from the specific device and the identifier does not match the terminal identifier, the external device does not transmit the encryption key to the specific device, according to the image acquisition device of claim 1.
7. The image acquisition device further includes an operation unit, the image acquisition device acquires the image data according to either a first acquisition instruction received from the terminal device via the communication interface or a second acquisition instruction input to the operation unit, when the first acquisition instruction is received from the terminal device, the first data transmission unit transmits the encrypted image data to the terminal device via the communication interface, The image acquisition device further includes a second data transmission unit that transmits the image data not encrypted with the encryption key to the terminal device via the communication interface when the second acquisition instruction is input to the operation unit, according to the image acquisition device of any one of claims 1 to 6.
8. The image acquisition device further includes a discard unit that discards the encryption key stored in the image acquisition device after transmitting the encrypted image data to the terminal device, according to the image acquisition device of any one of claims 1 to 6.
9. In a situation where the state of the image acquisition device is a non-permission state in which acquisition of the image data is not permitted, the storage control unit causes the external device to store the encryption key, The image acquisition device further includes a change unit that changes the state of the image acquisition device from the non-permission state to a permission state in which acquisition of the image data is permitted after causing the external device to store the encryption key, according to the image acquisition device of claim 2 or 3.
10. The image acquisition device further The image acquisition device according to claim 2 or 3, further comprising an information transmission unit that transmits position information indicating a position where the encryption key is stored in the external device to the terminal device after transmitting the encrypted image data to the terminal device.
11. A computer program for an image acquisition device, The image acquisition device A communication interface configured to communicate with a terminal device, A computer, Comprising The computer program causes the computer to perform the following units, namely, A generation unit that generates encrypted image data using an encryption key and image data acquired by the image acquisition device, A storage control unit that stores the encryption key in an external device different from the image acquisition device and accessible by the terminal device, A first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, wherein the terminal device decrypts the encrypted image data using the encryption key received from the external device, Functioning as an image acquisition device.
12. A control method for an image acquisition device, The image acquisition device is configured to be communicable with a terminal device, The control method A generation step of generating encrypted image data using an encryption key and image data acquired by the image acquisition device, A storage control step of storing the encryption key in an external device different from the image acquisition device and accessible by the terminal device, A first data transmission step of transmitting the encrypted image data to the terminal device, wherein the terminal device decrypts the encrypted image data using the encryption key received from the external device, Comprising a control method.
Citation Information
Patent Citations
Information processing unit, control method and program of information processing unit
JP2020065129A