Communication system, image acquisition device, computer program for image acquisition device, and control method for image acquisition device
The image acquisition device addresses the security concerns of protecting image information by encrypting the data and selectively transmitting the encryption key, ensuring robust security for sensitive image content.
Patent Information
- Application Number
- JP2023211812
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-26
AI Technical Summary
Existing image acquisition devices lack effective mechanisms for securely protecting the information contained in acquired images, particularly in scenarios where sensitive information is involved.
The image acquisition device employs encryption techniques by generating encrypted image data using a unique encryption key and transmitting this encrypted data to a terminal device. The encryption key is transmitted to the terminal device only in specific situations, ensuring enhanced security for sensitive information.
This approach effectively protects the information in acquired images by encrypting the data and controlling the transmission of the encryption key, thereby ensuring appropriate security measures are in place, especially for sensitive information.
Smart Images

Figure 2025095661000001_ABST
Abstract
Description
Technical Field
[0001] This specification relates to an image acquisition device.
Background Art
[0002] Patent Document 1 discloses an MFP that executes scanning in accordance with a scan instruction from a smartphone and transmits a file generated by the scanning to the smartphone.
Prior Art Document
Patent Document
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] The files acquired by the MFP contain various types of information. From the perspective of security, appropriate protection of the information is required. This specification provides a technique for appropriately protecting the information contained in an image.
Means for Solving the Problems
[0005] The image acquisition device disclosed in this specification includes a communication interface configured to communicate with a terminal device, an encryption key, image data acquired by the image acquisition device, and a generation unit that generates encrypted image data using the communication interface, the encryption key, and the image data, and a first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface, and a key transmission unit that transmits the encryption key to the terminal device via the communication interface in a first situation, wherein in a second situation different from the first situation, the encryption key is not transmitted to the terminal device.
[0006] According to the above configuration, the image data is protected by being encrypted with an encryption key. And the encryption key is transmitted to the terminal device in the first situation, but not in the second situation. In the second situation, the information included in the image can be protected more strongly than in the first situation. From the above, the information included in the image can be appropriately protected.
[0007] This specification also discloses a communication system. The communication system includes an image acquisition module and a control unit capable of communicating with the image acquisition module and a terminal device. The control unit is configured to execute an acquisition process for causing the image acquisition module to acquire image data, an encryption process for encrypting the image data using an encryption key when an instruction for acquiring the image data is received from the terminal device, a communication process for communicating with the terminal device either the encrypted image data or the unencrypted image data, and either a first process or a second process. The first process includes communicating the encryption key to the terminal device when the communication of the encrypted image data to the terminal device is started by the user on the terminal device and the user authenticates the communication of the encryption key, and communicating the unencrypted image data to the terminal device when the communication of the unencrypted image data to the terminal device is started by the user on the image acquisition module. The second process includes communicating the encryption key to the terminal device when the communication of the encrypted image data to the terminal device is started by the user on the image acquisition module.
[0008] According to the above configuration, the image data is protected by encryption. And the encryption key is transmitted when the communication of the encrypted image data to the terminal device is started by the user on the terminal device and the user authenticates the communication of the encryption key, or when the communication of the encrypted image data to the terminal device is started by the user on the image acquisition module. From the above, the information included in the image can be appropriately protected.
[0009] A computer program for realizing the above-described image acquisition device, and a computer-readable storage medium storing the computer program are also novel and useful. Further, a control method for the above-described image acquisition device is also novel and useful.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0011] (First Embodiment) (Configuration of Network System 2; FIG. 1) The network system 2 includes an image acquisition device 10 and a terminal device 100. The image acquisition device 10 can communicate with the terminal device 100 via the LAN 4. The LAN 4 is wireless or wired. The terminal device 100 is a desktop PC, a laptop PC, a smartphone, a tablet terminal, etc. A device name "td1" is assigned to the terminal device 100. A control program for controlling the image acquisition device 10 is installed in the terminal device 100. The control program is provided, for example, by the vendor of the image acquisition device 10.
[0012] (Configuration of Image Acquisition Device 10; Fig. 1) The image acquisition device 10 is a device having a function of acquiring an image. The image acquisition device is, for example, a peripheral device (e.g., a scanner) capable of executing a document reading function (i.e., a scanning function). Further, in addition to the scanning function, the image acquisition device 10 may be a multifunction device having multifunctions such as a printing function and a FAX function.
[0013] The image acquisition device 10 includes a scanning unit 12, an operation unit 14, a display unit 16, a LAN interface 20, and a control unit 30. Each of the units 14 to 30 is connected to the housing 11 of the image acquisition device 10. Hereinafter, "interface" is described as "I / F".
[0014] The scanning unit 12 is a unit for reading a document and includes, for example, an image sensor such as a Charge-Coupled Device (CCD) or a Contact Image Sensor (CIS). The operation unit 14 includes a plurality of buttons. The user can input various instructions to the image acquisition device 10 by operating the operation unit 14. The operation unit 14 includes, for example, buttons within a touch screen and structural buttons. The buttons within the touch screen are, for example, icons. The structural buttons are, for example, mechanical switches and keyboards. The display unit 16 is a display for displaying various information and is, for example, a liquid crystal display or an organic EL display. The LAN I / F 20 is an I / F for executing communication via the LAN 4 and is connected to the LAN 4.
[0015] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 stores a program 40. The CPU 32 executes various processes according to the program 40. The program 40 includes a plurality of programs and includes, for example, a scan execution program for causing the scanning unit 12 to execute a scan.
[0016] The memory 34 includes, for example, a non-volatile memory and a volatile memory. The non-volatile memory is, for example, a Hard Disk Drive (HDD), a Read Only Memory (ROM), a Solid State Drive (SSD), or a flash memory. The volatile memory is, for example, a Random Access Memory (RAM). The program 40 is stored in the non-volatile memory. The CPU 32 executes various processes according to the program loaded from the non-volatile memory to the volatile memory.
[0017] (Overview of pull scan and push scan; Figure 2) The image acquisition device 10 can execute a pull scan and a push scan as processes for causing the scan unit 12 to perform a scan. The pull scan is a process executed triggered by a predetermined operation on the operation unit (e.g., keyboard) of the terminal device 100. The push scan is a process executed triggered by a predetermined operation on the operation unit 14 of the image acquisition device 10.
[0018] Hereinafter, for ease of understanding, the operations executed by the CPU 32 of the image acquisition device 10 will be described with reference to the operations executed by the image acquisition device 10. Also, the communication between the image acquisition device 10 and the terminal device 100 is executed via the LAN 4 and the LANI / F 20 unless otherwise specified. Therefore, when describing the communication between the image acquisition device 10 and the terminal device 100, the descriptions "via the LAN 4" and "via the LANI / F 20" will be omitted.
[0019] The outline of the pull scan is as follows. At T2, the user inputs a pull execution instruction for instructing the execution of the pull scan to the operation unit of the terminal device 100. When receiving the pull execution instruction at T2, the terminal device 100 transmits a scan instruction to the image acquisition device 10 at T4. When receiving the scan instruction from the terminal device 100 at T4, the image acquisition device 10 calls a scan execution program. At T6, the image acquisition device 10 causes the scan unit 12 to execute a scan according to the scan instruction by using the scan execution program. Then, the image acquisition device 10 transmits the scan data generated by the scan at T6 to the terminal device 100. Here, the scan data is data obtained by converting the data generated by the scan unit 12 into a predetermined file format, for example, JPEG data. In a modification, the scan data may be the data generated by the scan unit 12 itself.
[0020] Also, the outline of the push scan is as follows. At T10, the user inputs a push execution instruction for instructing the execution of the push scan to the operation unit 14. When receiving the push execution instruction at T10, the image acquisition device 10 transmits an instruction request for requesting the transmission of a scan instruction to the terminal device 100 at T12. When receiving the instruction request from the image acquisition device 10 at T12, the terminal device 100 transmits a scan instruction to the image acquisition device 10 according to the instruction request at T14. T16 and T18 are the same as T6 and T8.
[0021] Here, the scan instruction at T4 in the pull scan and the scan instruction at T14 in the push scan are commands described in the same format. By using a common scan instruction for both the pull scan and the push scan, a common scan execution program can be used for both the pull scan and the push scan. In a modification, the processes at T12 and T14 may be omitted.
[0022] (Specific case of pull scan; Figure 3) Referring to FIG. 3, a specific case of the pull scan in this embodiment will be described. T102 and T104 are examples of T2 and T4 in FIG. 2, and the scan instruction for T104 includes the device name "td1" of the terminal device 100.
[0023] When the image acquisition device 10 receives a scan instruction from the terminal device 100 at T104, it generates a unique encryption key CK1 at T106. The encryption key CK1 is, for example, a common key according to the Advanced Encryption Standard (AES).
[0024] The subsequent T108 is an example of T6 in FIG. 2, and the image acquisition device 10 starts scanning the original document. In this embodiment, the original document is a paper document and consists of multiple pages. At T110A, the image acquisition device 10 generates scan data for the first page by scanning the first page, and encrypts the scan data for the first page using the encryption key CK1. At T112A, the image acquisition device 10 transmits the encrypted scan data for the first page, which is the encrypted scan data for the first page encrypted by the encryption key CK1, to the terminal device 100. As a result, at T114A, the terminal device 100 stores the encrypted scan data for the first page received from the image acquisition device 10. The image acquisition device 10 performs the same processing as T110A to T114A for all of the multiple pages. At T110B to T114B, scan data for the last page is generated, and the encrypted scan data for the last page, which is the scan data for the last page encrypted by the encryption key CK1, is transmitted to the terminal device 100. T112A and T112B are examples of T8 in FIG. 2. When the encrypted scan data for the last page is transmitted to the terminal device 100, the encrypted scan data for all pages is stored in the terminal device 100. Note that the original document may be an electronic document instead of a paper document. When the original document is an electronic document, the image acquisition device 10 may acquire the electronic document from the storage medium and encrypt the data corresponding to each page of the electronic document at T110A and the like.
[0025] When the transmission of the encrypted scan data of the last page is completed in T112B, the image acquisition device 10 causes the confirmation screen SC1 to be displayed on the display unit 16 in T120. The confirmation screen SC1 is a screen for confirming the transmission of the encryption key CK1 generated in T106 to the terminal device 100, and includes an OK button and a Cancel button. Also, the confirmation screen SC1 displays the device name "td1" received from the terminal device 100 in T104. The user can know the terminal device 100 that is the source of the scan instruction by looking at the device name "td1" displayed on the confirmation screen SC1.
[0026] In T122, the image acquisition device 10 determines whether an operation of selecting the OK button of the confirmation screen SC1 has been performed on the operation unit 14. For example, when the user determines that the device name "td1" displayed on the confirmation screen SC1 matches the user's intention, the user selects the OK button. When the image acquisition device 10 determines that an operation of selecting the OK button has been performed (YES in T122), in T130, it transmits the encryption key CK1 to the terminal device 100.
[0027] In T130, the terminal device 100 receives the encryption key CK1 from the image acquisition device 10. In T132, the terminal device 100 uses the encryption key CK1 received from the image acquisition device 10 in T130 to decrypt the encrypted scan data of all pages stored in T114A and T114B. As a result, the scan data showing all pages of the original document is stored in the terminal device 100, and an image showing the original document is displayed on the terminal device 100.
[0028] Also, for example, when the user determines that the device name "td1" displayed on the confirmation screen SC1 does not match the user's intention, the user selects the Cancel button. When the image acquisition device 10 determines that an operation of selecting the Cancel button has been performed (NO at T122), it does not execute the process of T130 and ends the process of FIG. 3. That is, the encryption key CK1 is not transmitted to the terminal device 100. In this case, the encrypted scan data of all pages stored in the terminal device 100 is not decrypted, and the image showing the original document is not displayed on the terminal device 100.
[0029] According to the configuration of this embodiment, the scan data is protected by being encrypted with the encryption key CK1. For example, the image acquisition device 10 is placed in an office. An employee in the office can operate the image acquisition device 10. The employee operates the terminal device 100 to perform a pull scan. The employee knows the device name "td1" displayed on the confirmation screen SC1, determines that the device name "td1" displayed on the confirmation screen SC1 matches the employee's intention, and selects the OK button on the confirmation screen SC1. In this case, the encryption key CK1 is transmitted to the terminal device 100 (YES at T122), and the employee can view the image of the original document displayed on the terminal device 100.
[0030] Also, for example, a situation is assumed where an unauthenticated third party other than an employee in the office illegally performs a pull scan. In this situation, it is difficult for the third party to enter the office. Therefore, the OK button on the confirmation screen SC1 is not selected by the third party. Furthermore, the employee in the office does not know the device name "td1" displayed on the confirmation screen SC1 and may feel suspicious. In this case, the employee in the office determines that the device name "td1" displayed on the confirmation screen SC1 does not match the employee's intention and selects the Cancel button on the confirmation screen SC1. In this case, the encryption key CK1 is not transmitted to the terminal device 100 (NO at T122). The unauthenticated third party cannot view the information described in the original document. In this situation, the information described in the original document can be protected from the third party.
[0031] (Specific Case of Push Scan; Figure 4) Referring to Figure 4, a specific case of the push scan of this embodiment will be described. T140 to T144 are examples of T10 to T14 in Figure 2. The instruction request of T142 includes the IP address of the terminal device 100, and the scan instruction of T144 includes the device name "td1" of the terminal device 100. For example, the image acquisition device 10 stores a list of terminal devices (for example, a list of IP addresses) that can communicate with the image acquisition device 10. The push execution instruction of T140 includes an operation in which the user selects the terminal device 100 from the list.
[0032] T148 is the same as T108 in Figure 3. On the other hand, in this case, the encryption key CK1 is not generated, and the scan data of each page of the original document is not encrypted by the encryption key CK1. In T152 of this case, the image acquisition device 10 transmits the scan data of each page of the original document to the terminal device 100. Thereby, the terminal device 100 stores the scan data of each page of the original document at T154 and displays an image indicating the original document.
[0033] As described above, it is difficult for a third party to enter the office. The push scan is a scan executed by triggering an operation of the operation unit 14 of the image acquisition device 10, and it is difficult for a third party to execute. In the pull scan that can be illegally executed by a third party, the information described in the original document can be strongly protected by the encryption key CK1. On the other hand, in the push scan that is difficult for a third party to execute, the encryption and decryption by the encryption key CK1 can be omitted to reduce the processing load of the image acquisition device 10 and the terminal device 100.
[0034] Also, as shown in this embodiment, the image acquisition device 10 generates a unique encryption key CK1 every time scan data is generated according to a scan instruction (T106 in Figure 3). That is, the encryption key used this time is different from the encryption key used last time. By generating a unique encryption key, the security is improved.
[0035] (Corresponding Relationship) The image acquisition device 10 is an example of an "image acquisition device" and a "communication system". The combination of at least one of the scan unit 12, the operation unit 14, and the display unit 16 is an example of an "image acquisition module". The operation unit 14 and the LANI / F 20 are examples of an "operation unit" and a "communication interface", respectively. The scan data and the encrypted scan data are examples of "image data" and "encrypted image data", respectively. The terminal device 100 is an example of a "terminal device". The encryption key CK1 is an example of an "encryption key". The situation determined as YES at T122 in FIG. 3 and the situation determined as NO at T122 are examples of a "first situation" and a "second situation", respectively. The operation of selecting the OK button on the confirmation screen SC1 is an example of a "predetermined operation". The scan instruction at T104 and the push execution instruction at T140 in FIG. 4 are examples of a "first acquisition instruction" and a "second acquisition instruction", respectively. The processes in FIGS. 3 and 4 are examples of a "first process". Any one of the push scans in any of FIGS. 5 to 7 is an example of a "second process". T400 and T402 in FIG. 7 are examples of a "judgment process".
[0036] T110A and T112A in FIG. 3 are examples of processes realized by a "generation unit" and a "first data transmission unit", respectively. T130 is an example of a process realized by a "key transmission unit".
[0037] (Second Embodiment) This embodiment is the same as the first embodiment except that the determination of whether to transmit the encryption key CK1 and the subsequent processes are different from those in the first embodiment.
[0038] (Specific Case of Pull Scan; FIG. 5) Referring to FIG. 5, a specific case of the pull scan in this embodiment will be described. T202 to T208 are the same as T102 to T108 in FIG. 3. At T210, the image acquisition device 10 analyzes whether the manuscript contains information marked as confidential. For example, if the manuscript contains information marked as confidential, the manuscript includes a confidential image, which is an image indicating confidentiality. The confidential image is, for example, a character string "Confidential" indicating confidentiality or a predetermined symbol indicating confidentiality. For the analysis at T210, for example, character recognition for recognizing a character string indicating confidentiality from each page is used. In a modification, well-known techniques other than character recognition may be used for the analysis at T210. Such techniques are, for example, pattern matching for extracting an image that matches a predetermined symbol indicating confidentiality from the image of each page, and machine learning for determining whether an image similar to the predetermined symbol is included in each page using a learning model.
[0039] At T212, the image acquisition device 10 determines whether the analysis result at T210 indicates that at least one page of the entire manuscript contains a confidential image. When the image acquisition device 10 determines that the analysis result at T210 indicates that none of the pages of the entire manuscript contain a confidential image (NO in S212), the process proceeds to the processing of T220 to T232. T220 to T232 are the same as T110A to T114B, T130, and T132 in FIG. 3. That is, the encrypted scan data of all pages and the encryption key CK1 are transmitted to the terminal device 100. Here, after the transmission of the encrypted scan data of all pages is completed, the image acquisition device 10 transmits the encryption key CK1 to the terminal device 100 (T230).
[0040] Also, when the image acquisition device 10 determines that the analysis result of T210 indicates that at least one page contains a confidential image outside the company (YES in S212), the image acquisition device 10 skips the processes of T220 to T232 and proceeds to T240. In T240, the image acquisition device 10 causes the warning screen SC2 to be displayed on the display unit 16. The warning screen SC2 includes, for example, a message indicating that scanning of the document is not permitted. The user can see the warning screen SC2 and know that scanning of the document is not permitted. Also, since the processes of T220 to T232 are skipped, the encryption key CK1 is not transmitted to the terminal device 100. Note that in a modified example, the warning screen SC2 may not be displayed.
[0041] As described above, the document is composed of a plurality of pages, and the scan data is generated for each page. The analysis of T210 is executed in parallel with the scanning of the document, and the warning screen SC2 can be displayed even during the scanning. For example, in the analysis from the first page to the fifth page, if it is determined that none of the pages contain a confidential image outside the company, the image acquisition device 10 transmits the encrypted scan data from the first page to the fifth page to the terminal device 100 (T220). Then, when it is determined that the sixth page contains a confidential image outside the company, the image acquisition device 10 displays the warning screen SC2 (T240). In this case, the scanning from the seventh page to the last page may be stopped. That is, although the encrypted scan data from the first page to the fifth page is transmitted to the terminal device 100, the encryption key CK1 is not transmitted to the terminal device 100. As a result, the encrypted scan data from the first page to the fifth page cannot be decrypted. Note that in a modified example, the analysis of T210 may be executed after the scanning of all pages of the document is completed. In this case, the warning screen SC2 may be displayed after the transmission of the encrypted scan data of the last page is completed.
[0042] According to the configuration of this embodiment, the scan data of a manuscript without information marked as confidential is protected by being encrypted with the encryption key CK1 (NO at T212). On the other hand, the scan data of a manuscript with information marked as confidential is strongly protected by not transmitting the encryption key CK1 to the terminal device 100. As a result, even an employee in the office where the image acquisition device 10 is installed cannot obtain the scan data of a manuscript with information marked as confidential, and it is possible to prevent the information marked as confidential from leaking outside the office.
[0043] (Specific case of push scan; FIG. 5) In this embodiment, the scan data can also be encrypted in push scan. T250 to T254 in FIG. 5 are the same as T140 to T144 in FIG. 4. Then, the image acquisition device 10 executes the same processing as T208 to T240. As a result, in push scan as well, when there is no information marked as confidential on the manuscript, the encryption key CK1 is transmitted to the terminal device 100, while when there is information marked as confidential on the manuscript, the encryption key CK1 is not transmitted to the terminal device 100. In push scan as well, it is possible to prevent the information marked as confidential from leaking outside the office.
[0044] (Corresponding relationship) The situation determined as NO at T212 in FIG. 5 and the situation determined as YES at T212 are examples of the "first situation" and the "second situation" respectively. The confidential image is an example of the "predetermined image". The warning screen SC2 and the display unit 16 are examples of the "warning screen" and the "display unit" respectively.
[0045] (Third embodiment) This embodiment is the same as the second embodiment except that the analysis of the scan data is executed by the analysis server 200 capable of communicating with the image acquisition device 10 and the processing when there is information marked as confidential on the manuscript is different.
[0046] (Specific case of pull scan; FIG. 6) Referring to FIG. 6, a specific case of the pull scan of this embodiment will be described. T302 to T308 are the same as T202 to T208 in FIG. 5. At T310, the image acquisition device 10 encrypts the scan data of each page, and at T312, transmits the encrypted scan data of each page to the terminal device 100. The terminal device 100 stores the encrypted scan data of each page received from the image acquisition device 10 at T314. In this embodiment, when the transmission of the encrypted scan data of all pages is completed, the image acquisition device 10 proceeds to the processing after T320.
[0047] At T320, the image acquisition device 10 transmits the scan data of all pages of the document to the analysis server 200. The analysis server 200 may be installed within the LAN 4 or on the Internet.
[0048] At T320, when the analysis server 200 receives the scan data of all pages of the document from the image acquisition device 10, it performs the same analysis as T210 in FIG. 5. Then, at T322, the analysis server 200 transmits the analysis result to the image acquisition device 10.
[0049] When the image acquisition device 10 receives the analysis result from the analysis server 200 at T322, it proceeds to T324. T324 is the same as T212 in FIG. 5. When the image acquisition device 10 determines that the analysis result received at T322 indicates that none of the pages of the document contain off-site confidential images (NO at S324), it proceeds to T330. T330 and T332 are the same as T230 and T232 in FIG. 5.
[0050] Also, when the image acquisition device 10 determines that the analysis result received at T322 indicates that at least one page of the entire manuscript contains a confidential image outside the company (NO at S324), it proceeds to T340. At T340, the image acquisition device 10 causes the confirmation screen SC3 to be displayed on the display unit 16. The confirmation screen SC3 includes, for example, a message for confirming whether confidential information outside the company is described in the manuscript and whether to permit the transmission of the encryption key CK1. The confirmation screen SC3 includes a YES button and a NO button.
[0051] At T342, the image acquisition device 10 determines whether an operation of selecting the YES button of the confirmation screen SC3 has been performed on the operation unit 14. When the image acquisition device 10 determines that an operation of selecting the YES button of the confirmation screen SC3 has been performed (YES at T342), at T344, it transmits the encryption key CK1 to the terminal device 100. T346 is the same as T332. On the other hand, when the image acquisition device 10 determines that an operation of selecting the NO button of the confirmation screen SC3 has been performed (NO at T342), it skips the process of T344 and ends the push scan process in FIG. 6. That is, the encryption key CK1 is not transmitted to the terminal device 100.
[0052] For example, although most employees are not permitted to scan manuscripts with confidential information outside the company, an operation is assumed in which some employees are permitted to scan manuscripts with confidential information outside the company. According to the configuration of this embodiment, some employees can obtain scan data with confidential information outside the company by selecting the YES button of the confirmation screen SC3. The convenience of some employees is improved.
[0053] (Specific cases of push scan; FIG. 6) This embodiment, similar to the second embodiment, enables the scan data to be encrypted even in push scan. In the push scan of this embodiment, after the processes of T250 to T254 in FIG. 5 are executed, the processes of T306 to T346 in FIG. 6 are executed. In this embodiment, when there is no information marked as company confidential on the document, and when there is information marked as company confidential on the document and the YES button on the confirmation screen SC3 is selected, the encryption key CK1 is transmitted to the terminal device 100. On the other hand, when there is information marked as company confidential on the document and the NO button on the confirmation screen SC3 is selected, the encryption key CK1 is not transmitted to the terminal device 100. In this embodiment, in push scan, the leakage of company confidential information outside the office is prevented, and the convenience of some employees is improved.
[0054] (Corresponding relationship) The situation where it is determined as NO in T324 of FIG. 6 and the situation where it is determined as YES in T324 and NO in T342 are examples of the "first situation" and the "second situation", respectively. The confirmation screen SC3 and the display unit 16 are examples of the "confirmation screen" and the "display unit", respectively. An instruction to select the YES button on the confirmation screen SC3 is an example of the "specific instruction".
[0055] (Fourth Embodiment) This embodiment is the same as the second embodiment except that the memory 34 of the image acquisition device 10 stores the user table 42 and the content of the processing of the image acquisition device 10 is different.
[0056] (Configuration of User Table 42; FIG. 1) The user table 42 stores, for each of a plurality of users who can use the image acquisition device 10, the user name of the user, the password used by the user, and the attribute of the user, in association with each other. The image acquisition device 10 permits the user to operate the image acquisition device 10 when the authentication using the user name and password is successful. Note that the authentication method is not limited to the method using the user name and password, and may be, for example, biometric authentication or authentication using an IC card.
[0057] In addition, the attribute in the user table 42 indicates either "high", which indicates a user who is permitted to handle confidential information outside the company, or "low", which indicates a user who is not permitted to handle confidential information outside the company. Note that the values "high" and "low" are merely examples.
[0058] (Specific case of push scan; Figure 7) Referring to Figure 7, a specific case of the push scan of this embodiment will be described. In T400, the user executes an authentication request operation for requesting authentication using a user name and a password on the image acquisition device 10. The authentication request operation includes an operation of inputting a user name and a password.
[0059] In T402, the image acquisition device 10 authenticates the user name and password input in T400. In this case, the user name and password input in T400 match the information in the user table 42, and the authentication is successful. When the authentication is successful, the image acquisition device 10 changes the state of the image acquisition device 10 from a state where input of a push execution instruction is prohibited to a state where input of a push execution instruction is permitted. The state where input of a push execution instruction is permitted is, for example, a state where a button for inputting a push execution instruction is displayed on the display unit 16. Note that if the authentication fails in T402, the state of the image acquisition device 10 is maintained in a state where input of a push execution instruction is prohibited.
[0060] When the authentication is successful, the image acquisition device 10 executes the processes of T410 to T414. T410 to T414 are the same as T140 to T144 in Figure 4. T416 to T422 are the same as T206 to T212 in Figure 5. When the image acquisition device 10 determines that the analysis result in T420 indicates that none of the entire pages of the document contain a confidential image outside the company (NO in T422), it executes the same processes as T220 to T232 in Figure 5 (i.e., transmission of the encryption key CK1).
[0061] Also, when the image acquisition device 10 determines that the analysis result of T420 indicates that at least one page of the document contains off-site confidential images (YES in T422), it proceeds to T430. At T430, the image acquisition device 10 determines whether the attribute stored in association with the user name input at T400 in the user table 42 indicates the value "high".
[0062] When the image acquisition device 10 determines that the attribute stored in association with the user name input at T400 indicates the value "low" (NO in T430), it proceeds to T440. T440 is the same as T240 in FIG. 5, and the encryption key CK1 is not transmitted to the terminal device 100. In a modification, the warning screen SC2 of T440 may not be displayed.
[0063] Also, when the image acquisition device 10 determines that the attribute stored in association with the user name input at T400 indicates the value "high" (YES in T430), it proceeds to T450. For example, when the off-site confidential image is included on the 6th page, the encrypted scan data up to the 5th page is transmitted to the terminal device 100, and the determination of T430 is executed before transmitting the encrypted scan data of the 6th page to the terminal device 100. At T450, the image acquisition device 10 encrypts the scan data of the remaining pages (for example, from the 6th page to the last page). At T452, the image acquisition device 10 transmits the encrypted scan data of the remaining pages to the terminal device 100. Thereby, the terminal device 100 stores the encrypted scan data of all pages at T454.
[0064] When the transmission of the encrypted scan data of the last page is completed, the image acquisition device 10 transmits the encryption key CK1 to the terminal device 100 at T460. Thereby, the terminal device 100 decrypts the encrypted scan data of all pages at T462.
[0065] For example, although employees with the attribute "low" are not permitted to scan manuscripts containing confidential information outside the company, an operation is assumed in which employees with the attribute "high" are permitted to scan manuscripts containing confidential information outside the company. According to the configuration of this embodiment, when authentication by an employee with the attribute "high" is successful in the image acquisition device 10, even if the manuscript contains confidential information outside the company, the encryption key CK1 is transmitted to the terminal device 100, and the encrypted scan data is decrypted. By performing an authentication request operation, an employee with the attribute "high" can obtain scan data of a manuscript containing confidential information outside the company. The convenience of employees with the attribute "high" is improved.
[0066] Note that the technology of this embodiment can also be applied to pull scanning. For example, in pull scanning, an authentication request operation for T400 may be executed by the terminal device 100, and the information (i.e., the username and password) input by the authentication request operation may be transmitted from the terminal device 100 to the image acquisition device 10.
[0067] (Corresponding relationship) The situation determined as NO by T422 and the situation determined as YES by T422 and NO by T430 in FIG. 6 are examples of the "first situation" and the "second situation", respectively. The attribute "high" and the attribute "high" are examples of the "first attribute" and the "second attribute", respectively.
[0068] As described above, the examples of the present invention have been described in detail, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the examples shown above. Modification examples of the above embodiments are listed below.
[0069] (Modification example 1) The confirmation screen SC1 in FIG. 3 may not include an OK button. In this case, for example, after transmitting the encrypted scan data, when a predetermined structural button in the operation unit 14 is selected, the process of T130 may be executed. In this modification example, the operation of selecting a predetermined structural button is an example of the "predetermined operation".
[0070] (Modification Example 2) When the delete button for deleting the confirmation screen SC1 is selected, the image acquisition device 10 may determine NO at T122 in FIG. 3. Further, when a predetermined time elapses without any operation being performed after the display of the confirmation screen SC1, the image acquisition device 10 may determine NO at T122 in FIG. 3. In this modification example, the situation where the delete button is selected or the situation where a predetermined time elapses after the display of the confirmation screen SC1 is an example of the "second situation".
[0071] (Modification Example 3) In the first embodiment, instead of the process of FIG. 4, push scanning may also be performed, and the transmission of encrypted scan data and the transmission of the encryption key may also be executed. In this modification example, the "second data transmission unit" can be omitted.
[0072] (Modification Example 4) The object analyzed at T210 in FIG. 5 may be, for example, personal information indicating an individual's address, a public certificate, a bill, an image that conflicts with the copyright of others (for example, an image of a character), a mark indicating copyright, or an image indicating prohibition of copying. Each of the images listed above is an example of the "predetermined image".
[0073] (Modification Example 5) The confirmation screen SC3 in FIG. 6 may not include an OK button. In this case, for example, when a predetermined structural button in the operation unit 14 is selected after the display of the confirmation screen SC3, the process of T344 may be executed. In this modification example, the selection of the predetermined structural button is an example of the "specific instruction".
[0074] (Modification Example 6) When the delete button for deleting the confirmation screen SC3 is selected, the image acquisition device 10 may determine NO at T342 in FIG. 3. Further, when a predetermined time elapses without any operation being performed after the display of the confirmation screen SC3, the image acquisition device 10 may determine NO at T342 in FIG. 3. In this modification example, the situation where the delete button is selected and the situation where a predetermined time elapses after the display of the confirmation screen SC1 are each an example of the "second situation".
[0075] (Modification Example 7) The process of T106 in FIG. 3 may be omitted. In this case, the image acquisition device 10 may store a list of encryption keys in advance. Then, the image acquisition device 10 may encrypt the scan data using one encryption key selected from the list. In this modification example, the "key generation unit" can be omitted.
[0076] (Modification Example 8) Any one of the warning screen SC2 in FIG. 5, the confirmation screen SC3 in FIG. 6, and the warning screen SC2 in FIG. 7 may be displayed on the terminal device 100. In this modification example, the terminal device 100 is an example of a "display unit".
[0077] (Modification Example 9) In the above-described embodiment, each process from FIG. 2 to FIG. 7 is realized by the CPU 32 executing the program 40. Instead of this, any process may be realized by hardware such as a logic circuit.
[0078] Also, the technical elements described in this specification or the drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Further, the technology exemplified in this specification or the drawings achieves a plurality of purposes simultaneously, and has technical utility by achieving one of those purposes itself.
[0079] In the claims of this patent application at the time of filing, even if each claim depends only on some of the claims, each claim is not limited to depending only on some of the claims. Within a technically non - conflicting range, each claim can also depend on other claims that it did not depend on at the time of filing. That is, the technologies of each claim can be combined in various ways as follows. Hereinafter, the features of the technology disclosed in this specification are listed. (Item 1) An image acquisition device, A communication interface configured to communicate with a terminal device, A generation unit that generates encrypted image data using an encryption key and the image data acquired by the image acquisition device. A first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface; A key transmission unit that transmits the encryption key to the terminal device via the communication interface in a first situation, and in a second situation different from the first situation, the encryption key is not transmitted to the terminal device; An image acquisition device comprising the above. (Item 2) The image acquisition device further comprises: A first determination unit that determines whether the situation of the image acquisition device is the first situation or the second situation; The key transmission unit transmits the encryption key to the terminal device when it is determined that the situation of the image acquisition device is the first situation; The key transmission unit does not transmit the encryption key to the terminal device when it is determined that the situation of the image acquisition device is the second situation. The image acquisition device according to Item 1. (Item 3) The image acquisition device further comprises an operation unit; The first situation is a situation where a predetermined operation is performed on the operation unit after the encrypted image data is transmitted to the terminal device; The second situation is a situation where the predetermined operation is not performed on the operation unit after the encrypted image data is transmitted to the terminal device. The image acquisition device according to Item 1 or 2. (Item 4) The image acquisition device further comprises an operation unit; The image acquisition device acquires the image data according to either a first acquisition instruction received from the terminal device via the communication interface or a second acquisition instruction input to the operation unit; When the first acquisition instruction is received from the terminal device, the first data transmission unit transmits the encrypted image data to the terminal device via the communication interface; The image acquisition device further comprises: The image acquisition device according to item 2 or 3, comprising a second data transmission unit that transmits the image data to the terminal device via the communication interface when the second acquisition instruction is input to the operation unit. (Item 5) The first situation is a situation where the document corresponding to the image data does not include a predetermined image, The second situation is a situation where the document includes the predetermined image, for the image acquisition device according to item 1. (Item 6) The predetermined image includes an out-of-company confidential image, for the image acquisition device according to item 5. (Item 7) The image acquisition device further comprises a first display control unit that causes a warning screen to be displayed on the display unit in the second situation, for the image acquisition device according to item 5 or 6. (Item 8) The image acquisition device further comprises a second display control unit that causes a confirmation screen to be displayed on the display unit when the document corresponding to the image data includes a predetermined image, The first situation is a situation where the document does not include a predetermined image, The second situation is a situation where the document includes the predetermined image and the image acquisition device does not receive a specific instruction from the user after the confirmation screen is displayed, The key transmission unit further transmits the encryption key to the terminal device via the communication interface in a situation where the document includes the predetermined image and the image acquisition device receives the specific instruction after the confirmation screen is displayed, for the image acquisition device according to item 1. (Item 9) The image acquisition device further comprises a second determination unit that determines whether the attribute of the user of the image acquisition device is a first attribute or a second attribute, The first situation is a situation where the document corresponding to the image data does not include a predetermined image, The second situation is a situation where it is determined that the document includes the predetermined image and the attribute of the user is the first attribute. The key transmission unit further transmits the encryption key to the terminal device via the communication interface in a situation where it is determined that the document includes the predetermined image and the attribute of the user is the second attribute, the image acquisition device according to item 1. (Item 10) The key transmission unit transmits the encryption key to the terminal device after the transmission of the encrypted image data is completed, the image acquisition device according to any one of items 1 to 9. (Item 11) The image acquisition device further includes a key generation unit that generates a unique encryption key every time the image data is generated, the image acquisition device according to any one of items 1 to 10. (Item 12) A computer program for an image acquisition device, wherein the image acquisition device includes a communication interface configured to communicate with a terminal device, a computer, and the computer program causes the computer to generate encrypted image data using an encryption key and the image data acquired by the image acquisition device, a generation unit; a first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface; a key transmission unit that transmits the encryption key to the terminal device via the communication interface in a first situation, wherein in a second situation different from the first situation, the encryption key is not transmitted to the terminal device; function as, a computer program. (Item 13) A control method for an image acquisition device, The image acquisition device includes a communication interface configured to communicate with a terminal device. The control method includes: a generation step of generating encrypted image data by using an encryption key and the image data acquired by the image acquisition device; a first data transmission step of transmitting the encrypted image data to the terminal device via the communication interface; a key transmission step of transmitting the encryption key to the terminal device via the communication interface in a first situation, wherein in a second situation different from the first situation, the encryption key is not transmitted to the terminal device; A control method comprising the above. (Item 14) A communication system comprising: an image acquisition module; a control unit capable of communicating with the image acquisition module and a terminal device; The control unit is configured to execute: an acquisition process of causing the image acquisition module to acquire image data; an encryption process of encrypting the image data by using an encryption key when an instruction for acquiring the image data from the terminal device is received; a communication process of communicating with the terminal device either the encrypted image data or the unencrypted image data; either a first process or a second process; The first process includes: communicating the encryption key to the terminal device when communication of the encrypted image data to the terminal device is started by the user on the terminal device and the user authenticates communication of the encryption key; communicating the unencrypted image data to the terminal device when communication of the unencrypted image data to the terminal device is started by the user on the image acquisition module. When communication of the encrypted image data to the terminal device is started by the user on the terminal device and the user authenticates communication of the encryption key, transmitting the encryption key to the terminal device; When communication of the unencrypted image data to the terminal device is started by the user on the image acquisition module, transmitting the unencrypted image data to the terminal device. The second process includes communicating the encryption key to the terminal device when communication of the encrypted image data to the terminal device is started by the user using the image acquisition module. Communication system. (Item 15) The communication system according to item 14, wherein the image acquisition module includes at least one of a scanning unit, a display unit, and an operation unit. (Item 16) The communication system according to item 14, wherein the image acquisition module is connected to a housing. (Item 17) The control unit further is configured to be able to execute a determination process for determining whether the user is an authenticated user, in the communication system according to item 14. (Item 18) The communication system according to any one of items 14 to 17, wherein the communication system is configured as a scanner.
Explanation of Signs
[0080] 2: Communication system 4: LAN 10: Image acquisition device 11: Housing 12: Scanning unit 14: Operation unit 16: Display unit 20: LAN I / F 30: Control unit 32: CPU 34: Memory 40: Program 42: User table 100: Terminal device 200: Analysis server CK1: Encryption key SC1: Confirmation screen SC2: Warning screen SC3: Confirmation screen
Claims
1. An image acquisition device, comprising: A communication interface configured to communicate with a terminal device; A generation unit that generates encrypted image data by using an encryption key and the image data acquired by the image acquisition device; A first data transmission unit that transmits the encrypted image data to the terminal device via the communication interface; A key transmission unit that transmits the encryption key to the terminal device via the communication interface in a first situation, wherein the encryption key is not transmitted to the terminal device in a second situation different from the first situation; An image acquisition device comprising the above.
2. The image acquisition device further comprises: A first determination unit that determines whether the situation of the image acquisition device is the first situation or the second situation; The key transmission unit transmits the encryption key to the terminal device when it is determined that the situation of the image acquisition device is the first situation; The key transmission unit does not transmit the encryption key to the terminal device when it is determined that the situation of the image acquisition device is the second situation. The image acquisition device according to Claim 1.
3. The image acquisition device further comprises an operation unit, The first situation is a situation where a predetermined operation is performed on the operation unit after the encrypted image data is transmitted to the terminal device; The second situation is a situation where the predetermined operation is not performed on the operation unit after the encrypted image data is transmitted to the terminal device. The image acquisition device according to Claim 1.
4. The image acquisition device further comprises an operation unit, The image acquisition device acquires the image data according to either a first acquisition instruction received from the terminal device via the communication interface or a second acquisition instruction input to the operation unit; The first data transmission unit transmits the encrypted image data to the terminal device via the communication interface when the first acquisition instruction is received from the terminal device; The image acquisition device further comprises: A second data transmission unit that transmits the image data to the terminal device via the communication interface when the second acquisition instruction is input to the operation unit. The image acquisition device according to Claim 2.
5. The first situation is a situation where the original document corresponding to the image data does not include a predetermined image; The image acquisition device according to claim 1, wherein the second situation is a situation where the document includes the predetermined image.
6. The image acquisition device according to claim 5, wherein the predetermined image includes a confidential image outside the company.
7. The image acquisition device further includes a first display control unit that causes a warning screen to be displayed on the display unit in the second situation, according to the image acquisition device of claim 5.
8. The image acquisition device further includes a second display control unit that causes a confirmation screen to be displayed on the display unit when the document corresponding to the image data includes a predetermined image, wherein the first situation is a situation where the document does not include a predetermined image, the second situation is a situation where the document includes the predetermined image and the image acquisition device does not receive a specific instruction from the user after the confirmation screen is displayed, the key transmission unit further transmits the encryption key to the terminal device via the communication interface in a situation where the document includes the predetermined image and the image acquisition device receives the specific instruction after the confirmation screen is displayed, according to the image acquisition device of claim 1.
9. The image acquisition device further includes a second determination unit that determines whether the attribute of the user of the image acquisition device is a first attribute or a second attribute, wherein the first situation is a situation where the document corresponding to the image data does not include a predetermined image, the second situation is a situation where the document includes the predetermined image and the attribute of the user is determined to be the first attribute, the key transmission unit further transmits the encryption key to the terminal device via the communication interface in a situation where the document includes the predetermined image and the attribute of the user is determined to be the second attribute, according to the image acquisition device of claim 1.
10. The image acquisition device according to any one of claims 1 to 9, wherein the key transmission unit transmits the encryption key to the terminal device after the transmission of the encrypted image data is completed.
11. The image acquisition device further includes a key generation unit that generates a unique encryption key every time the image data is generated, according to the image acquisition device of any one of claims 1 to 9.
12. A computer program for an image acquisition device, wherein the image acquisition device includes a communication interface configured to communicate with a terminal device, and a computer, and is provided with The computer program causes the computer to generate encrypted image data by using an encryption key and the image data acquired by the image acquisition device; transmit the encrypted image data to the terminal device via the communication interface; a key transmission unit that transmits the encryption key to the terminal device via the communication interface in a first situation, and does not transmit the encryption key to the terminal device in a second situation different from the first situation; function as a computer program. **Claim 13** A method for controlling an image acquisition device, wherein the image acquisition device includes a communication interface configured to communicate with a terminal device; the control method includes: a generation step of generating encrypted image data by using an encryption key and the image data acquired by the image acquisition device; a first data transmission step of transmitting the encrypted image data to the terminal device via the communication interface; a key transmission step of transmitting the encryption key to the terminal device via the communication interface in a first situation, and not transmitting the encryption key to the terminal device in a second situation different from the first situation; and the control method comprises the above steps. **Claim 14** A communication system, including an image acquisition module; a control unit capable of communicating with the image acquisition module and a terminal device; and the control unit is configured to: execute an acquisition process for causing the image acquisition module to acquire image data; execute an encryption process for encrypting the image data by using an encryption key when an instruction for acquiring the image data from the terminal device is received; execute a communication process of communicating with the terminal device either encrypted image data or non-encrypted image data; execute either a first process or a second process; wherein the first process includes: communicating the encryption key to the terminal device when communication of the encrypted image data to the terminal device is started by the user on the terminal device and the user authenticates communication of the encryption key; communicating the non-encrypted image data to the terminal device when communication of the non-encrypted image data to the terminal device is started by the user on the image acquisition module. The second process includes communicating the encryption key to the terminal device when communication of the encrypted image data to the terminal device is started by the user using the image acquisition module. Communication system. **Claim 15** The communication system according to claim 14, wherein the image acquisition module includes at least one of a scanning unit, a display unit, and an operation unit. **Claim 16** The communication system according to claim 14, wherein the image acquisition module is connected to a housing. **Claim 17** The control unit further is configured to be capable of executing a determination process for determining whether the user is an authenticated user, in the communication system according to claim 14. **Claim 18** The communication system according to any one of claims 14 to 17, wherein the communication system is configured as a scanner.
Citation Information
Patent Citations
Information processing unit, control method and program of information processing unit
JP2020065129A