Control device, computer program for control device, and method to be performed by control device

The control device addresses vulnerabilities in communication devices by detecting changes in setting values and executing necessary updates, effectively enhancing the security and reliability of communication systems.

JP2025096845APending Publication Date: 2025-06-30BROTHER KOGYO KK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023212786
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-30

AI Technical Summary

Technical Problem

Existing communication devices, such as printers, face vulnerabilities due to changes in specific setting values related to communication, which can lead to attacks and require effective update processes to address these vulnerabilities.

Method used

A control device is introduced that includes a detection unit to identify changes in specific setting values, a determination unit to assess whether an update process is necessary, and an update process execution unit to apply the necessary updates, such as patch programs or firmware updates, to mitigate vulnerabilities.

Benefits of technology

The control device effectively addresses vulnerabilities in communication devices by detecting changes in setting values and executing appropriate update processes, thereby enhancing the security and reliability of communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025096845000001_ABST
    Figure 2025096845000001_ABST
Patent Text Reader

Abstract

To provide a novel technique for addressing vulnerability in communication devices.SOLUTION: A control device may include a detection unit for detecting that a specific set value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value, a determination unit for determining whether or not to execute update processing based on a change content in the specific set value when it is detected that the specific set value has been changed from the first value to the second value, the update processing being processing for updating data stored in the communication device in order to address vulnerability of the communication device caused by the change in the specific set value of the communication device, and an update processing execution unit for executing the update processing when it is determined that the update processing should be executed.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification discloses a technique for dealing with attacks on printers.

Background Art

[0002] Patent Document 1 discloses a network system including a plurality of information processing apparatuses. In this technique, when a first information processing apparatus receives a DoS attack, each of the other information processing apparatuses prevents the DoS attack by changing the port number corresponding to a specific program used for communication with the first information processing apparatus.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0004] This specification provides a novel technique for dealing with vulnerabilities of communication apparatuses.

Means for Solving the Problems

[0005] This specification discloses a control device. The control device includes a detection unit that detects that a specific setting value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value, and a determination unit that, when it is detected that the specific setting value has been changed from the first value to the second value, determines whether or not to execute an update process based on the content of the change of the specific setting value, where the update process is a process for updating data stored in the communication device in order to address the vulnerability of the communication device caused by the change of the specific setting value of the communication device. The control device may further include an update process execution unit that executes the update process when it is determined that the update process should be executed.

[0006] According to the above configuration, when the control device detects that a specific setting value of the communication device has been changed from a first value to a second value and determines that the update process should be executed, the control device executes the update process. The update process is a process for updating data stored in the memory of the communication device in order to address the vulnerability of the communication device caused by the change of the specific setting value of the communication device. Therefore, the communication device can address the vulnerability caused by the change of the specific setting value.

[0007] A computer program for realizing the above control device, a computer-readable storage medium storing the computer program, and a method executed by the above control device are also novel and useful.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Mode for Carrying Out the Invention

[0009] (First Embodiment) (Configuration of Communication System 2; FIG. 1) As shown in FIG. 1, the communication system 2 includes a printer 10 and a server 100. The printer 10 and the server 100 can communicate with each other via the Internet 4.

[0010] (Configuration of Printer 10) The printer 10 is a peripheral device capable of executing a printing function (for example, a peripheral device of a terminal not shown). The printer 10 includes an operation unit 12, a display unit 14, a communication interface 16, a printing execution unit 18, and a control unit 30. Hereinafter, the interface will be referred to as "I / F".

[0011] The operation unit 12 includes a plurality of keys. The user can input various instructions to the printer 10 by operating the operation unit 12. The display unit 14 is a display for displaying various information. The display unit 14 also functions as a so-called touch panel (i.e., an operation unit). The communication I / F 16 is connected to the Internet 4. The communication I / F 16 may be a wireless I / F or a wired I / F. The printing execution unit 18 includes a printing mechanism such as an inkjet method or a laser method.

[0012] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 includes a main storage device and an auxiliary storage device (not shown). The CPU 32 executes various processes according to a program 40 stored in the auxiliary storage device of the memory 34. Specifically, the CPU 32 loads the program 40 from the auxiliary storage device to the main storage device and executes the program 40 to execute the various processes described above. The main storage device is, for example, a RAM and a cache memory. The auxiliary storage device may be, for example, a flash memory, an SSD (abbreviation for Solid State Drive), or a ROM, or a combination thereof. The memory 34 further stores a setting table 42.

[0013] (Configuration of Server 100) The server 100 is installed on the Internet 4 by the vendor of the printer 10. In a modification, the server 100 may be installed on the Internet 4 by an operator different from the vendor. In another modification, the vendor of the printer 10 may use an environment provided by an external cloud computing service without preparing the hardware of the server 100 by itself. In this case, the vendor of the printer 10 may prepare a program (i.e., software) of the server 100 and introduce it into the above environment to realize the server 100.

[0014] The server 100 includes a communication I / F 116 and a control unit 130. The communication I / F 116 is connected to the Internet 4. The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes according to a program 140 stored in the memory 134. The memory 134 is composed of a volatile memory, a non-volatile memory, etc. The memory 134 further stores a vulnerability table 142.

[0015] (Contents of Each Table; FIG. 2) With reference to FIG. 2, the contents of each table 42, 142 stored in the printer 10 and the server 100 will be described.

[0016] In the setting table 42 stored in the printer 10, setting items (e.g., "FTP (abbreviation for File Transfer Protocol) setting", "TLS (abbreviation for Transport Layer Security) setting"), setting values (e.g., "Enable"), versions (e.g., "1.0", "1.2"), countermeasures (e.g., "patch_fix_ftp_problem_1", "Disable", "Firmware_version_1.1"), and application information (e.g., "TRUE", "FALSE") are stored in association with each other. Hereinafter, "patch_fix_ftp_problem" and "Firmware_version" will be abbreviated as "pffp" and "F", respectively.

[0017] The setting item is information for identifying a setting item related to the communication protocol of the printer 10. The setting value is a value indicating whether to use the communication protocol. The setting value "Enable" indicates using the communication protocol, and the setting value "Disable" indicates not using the communication protocol. The version indicates the version of the communication protocol. The countermeasure indicates a method for coping with an attack from the outside to the printer (i.e., vulnerability of the printer). The countermeasure includes a method of applying a patch program (e.g., "pffp1", "pffp2"), a method of changing the setting value from "Enable" to "Disable", and a method of updating the firmware of the printer 10 itself. The application information is a value regarding whether the countermeasure has been applied. "TRUE" indicates that the countermeasure has been applied, and "FALSE" indicates that the countermeasure has not been applied.

[0018] In the vulnerability table 142 stored in the server 100, models (e.g., "M1", "M2", "M3"), setting items, setting values, versions, and countermeasures are stored in association with each other. The model is the model name of the printer. When it is determined that the communication protocol of the printer is vulnerable to an attack from the outside, the vendor of the printer registers each information including the countermeasure in the vulnerability table 142.

[0019] (Specific processing; FIGS. 3 and 4) With reference to FIGS. 3 and 4, a process for dealing with an attack from an external device (not shown) to the printer 10 will be described. Hereinafter, from the viewpoint of ease of understanding, when describing the processes executed by the CPU 32 of the printer 10 and the CPU 132 of the server 100 according to the programs 40 and 140, the description will be made mainly with respect to the printer 10 and the server 100 rather than mainly with respect to each CPU 32 and 132. Also, all the following communications executed by the printer 10 and the server 100 are executed via the communication I / Fs 16 and 116. Therefore, hereinafter, when describing the processes related to communication, the description of "via the communication I / F 16 (or 116)" will be omitted.

[0020] In the initial state of FIG. 3, no information is yet stored in the setting table 42 of the printer 10. Also, in the initial state of FIG. 3, the version of the communication protocol TLS of the printer 10 is 1.0. The process of FIG. 3 starts at a predetermined timing. The predetermined timing is, for example, when the printer 10 is powered on, a predetermined date and time, etc.

[0021] At T10, the printer 10 transmits a setting table update request including its own model name "M1" to the server 100.

[0022] When the server 100 receives a setting table update request from the printer 10 at T10, at T12, it identifies from the vulnerability table 142 the combination information of the setting items, setting values, versions, and countermeasures associated with the model name "M1" included in the setting table update request. In other words, this process means identifying the vulnerability of the printer 10 with the model name "M1". In the vulnerability table 142, three pieces of combination information are stored in association with the model name "M1". Specifically, the first combination information is a combination of the setting item "FTP setting", the setting value "Enable", the version "none", and the countermeasure "pffp1". The second combination information is a combination of the setting item "TLS setting", the setting value "Enable", the version "1.0", and the countermeasure "Disable". The third combination information is a combination of the setting item "TLS setting", the setting value "Enable", the version "1.2", and the countermeasure "F1.1". Then, at T14, the server 100 transmits the vulnerability information including the three identified pieces of combination information to the printer 10.

[0023] Note that when communication using FTP is permitted in the printer (e.g., 10) (i.e., when the setting value of the FTP setting in the printer is changed from "Disable" to "Enable"), the printer can be attacked from the outside by communication using FTP. That is, the communication protocol FTP can be vulnerable to external attacks. Therefore, the first combination information including "pffp1", which is a patch program for dealing with the vulnerability, is registered in the server 100. As a result, the printer can use the patch program by receiving the first combination information from the server 100, thereby dealing with the vulnerability.

[0024] When communication using TLS version 1.0 is permitted in the printer (e.g., 10) (i.e., when the setting value of the TLS setting in the printer having TLS version 1.0 is When it is changed from "Disable" to "Enable", it has been confirmed that the printer is likely to be attacked from the outside through communication using TLS. That is, it has been confirmed that the communication protocol TLS is likely to have vulnerabilities against external attacks. Therefore, second combination information including a countermeasure method "Disable" for dealing with the vulnerability is registered in the server 100. Thereby, the printer can change the setting value of the TLS setting from "Enable" to "Disable" by receiving the second combination information from the server 100, that is, can prohibit communication using TLS of version 1.0.

[0025] When communication using TLS of version 1.2 is allowed in the printer (for example, 10) (that is, when the setting value of the TLS setting in the printer having TLS of version 1.2 is changed from "Disable" to "Enable"), the printer may be attacked from the outside through communication using TLS. Here, TLS of version 1.2 has resistance to external attacks compared to TLS of version 1.0. For this reason, it is not necessary to change the setting value of the TLS setting of the printer from "Enable" to "Disable" like TLS of version 1.0. However, when firmware having an effective countermeasure method against external attacks is developed, it is preferable to apply the firmware to the printer. Therefore, in this embodiment, third combination information including a countermeasure method "F1.1" is registered in the server 100. Thereby, the printer can update the firmware by receiving the third combination information from the server 100.

[0026] When the printer 10 receives vulnerability information from the server 100 at T14, at T16, it stores each of the three pieces of combination information included in the vulnerability information in the setting table 42. Since each countermeasure method corresponding to each of these pieces of combination information has not been applied to the printer 10 yet, each piece of application information corresponding to each piece of combination information indicates "FALSE".

[0027] Thereafter, at T30, the printer 10 receives a setting change operation from the user to change the setting value of the FTP setting from "Disable" to "Enable". In this case, at T32, in the setting table 42, since the countermeasure method "pffp1" and the application information "FALSE" are stored in association with the "FTP setting" and "Enable" which are the contents of the setting change, it can be determined that the update process should be executed. In other words, the printer 10 determines that the update process should not be executed when the combined information including "FTP setting" and "Enable" is not stored in the setting table 42, or when the combined information is stored in the setting table 42 but the application information "TRUE" is stored.

[0028] More specifically, the printer 10 determines that the patch program should be applied to the printer 10 based on the character string "patch" included in the countermeasure method "pffp1 (that is, patch_fix_ftp_problem_1)" associated with the "FTP setting" and "Enable". In particular, the printer 10 determines that the patch program "pffp1" indicated by the countermeasure method should be applied. Then, at T34, the printer 10 applies the patch program "pffp1" by adding the patch program "pffp1" to the program 40. Thereby, the printer 10 can cope with the vulnerability caused by the change of the "FTP setting" from "Disable" to "Enable" at T30. When the update process is completed, at T36, the printer 10 stores "TRUE" instead of "FALSE" as the application information in association with the combined information including the "FTP setting" and "Enable".

[0029] Next, in T50 of FIG. 4, the printer 10 receives a setting change operation from the user to change the setting value of the TLS setting from "Disable" to "Enable". In this case, in T52, in the setting table 42, since the version "1.0" that matches the current version of the TSL of the printer 10, the countermeasure method "Disable", and the application information "FALSE" are stored in association with the "TLS setting" and "Enable" which are the contents of the setting change, the printer 10 determines that the update process should be executed. In other words, when the combination information including "TLS setting" and "Enable" is not stored in the setting table 42, when the combination information is stored in the setting table 42 but the version that matches the current version of the TSL of the printer 10 is not stored, or when the combination information is stored in the setting table 42 but the application information "TRUE" is stored, the printer 10 determines that the update process should not be executed.

[0030] More specifically, the printer 10 determines that the setting value of the TLS setting should be changed from "Enable" to "Disable" based on the character string "Disable" included in the countermeasure method "Disable" associated with "TLS setting", "Enable", and "1.0". Then, in T54, the printer 10 changes the setting value of the TLS setting from "Enable" to "Disable". That is, the printer 10 cancels the setting change operation received from the user at T50. Thereby, the printer 10 can cope with the vulnerability caused by the change of the "TLS setting" from "Disable" to "Enable" at T50. When the update process is completed, in T56, the printer 10 stores "TRUE" instead of "FALSE" for the application information in association with the combination information including "TLS setting", "Enable", and "1.0".

[0031] Next, after the printer 10 updates the TLS version from 1.0 to 1.2 at T70, at T80, the printer 10 receives a setting change operation in which the user changes the setting value of the TLS setting from "Disable" to "Enable". In this case, at T82, in the setting table 42, the printer 10 determines that an update process should be executed because the version "1.2" that matches the current version of the TLS of the printer 10, the countermeasure method "F1.1", and the application information "FALSE" are stored in association with the "TLS setting" and "Enable" which are the contents of the setting change. In other words, when the combined information including "TLS setting" and "Enable" is not stored in the setting table 42, when the combined information is stored in the setting table 42 but the version that matches the current version of the TSL of the printer 10 is not stored, or when the combined information is stored in the setting table 42 but the application information "TRUE" is stored, the printer 10 determines that the update process should not be executed.

[0032] More specifically, the printer 10 determines that the firmware of the printer 10 should be updated based on the character string "Firmware" included in the countermeasure method "F1.1 (i.e., Firmware_version_1.2)" associated with "TLS setting", "Enable", and "1.2". In particular, the printer 10 determines that it should be updated to the firmware "F1.1" indicated by the countermeasure method. Then, at T84, the printer 10 updates the current firmware included in the program 40 to "F1.1". Thereby, the printer 10 can cope with the vulnerability caused by the change of the "TLS setting" from "Disable" to "Enable" at T80. When the update process is completed, at T86, the printer 10 stores "TRUE" instead of "FALSE" for the application information in association with "TLS setting", "Enable", and "1.2".

[0033] Note that the printer 10 and the server 100 execute the processes of T10 to T16 in FIG. 3 every time a predetermined timing arrives. That is, the processes of T10 to T16 are executed periodically. In particular, when new combination information is added to the vulnerability table 142 in the server 100, the printer 10 receives new vulnerability information including the new combination information from the server 100. In this case, the printer 10 stores the new vulnerability information in the setting table 42. In this way, the latest vulnerability information stored in the server 100 is reflected in the setting table 42 of the printer 10. Therefore, the printer 10 can appropriately cope with a new external attack.

[0034] (Effect of this embodiment) According to the above configuration, when the printer 10 detects that the setting value of FTP or TLS has been changed from "Disable" to "Enable" and determines that the update process should be executed, the printer 10 executes the update process (T34 in FIG. 3, T54 and T84 in FIG. 4). The update process is a process for updating the data stored in the memory 34 of the printer 10 in order to cope with the vulnerability of the printer 10 caused by the change in the setting value of FTP or TLS of the printer 10. The update is any one of applying a patch program (T34), changing a setting value (T54), and updating firmware (T84). Therefore, the printer 10 can cope with the vulnerability caused by the change in the setting value of FTP or TLS.

[0035] (Corresponding relationship) The control unit 30 of the printer 10 and the printer 10 are, respectively, examples of a "control device" and a "communication device". Disable and Enable are, respectively, examples of a "first value" and a "second value". A method of applying the patch program "pffp1", a method of changing the setting value to "Disable", and a method of updating the firmware of the printer 10 are examples of "update processing". In the case of the method of applying the patch program "pffp1" or the method of updating the firmware of the printer 10, the program 40 is an example of "data". In the case of the method of changing the setting value to "Disable", the setting value is an example of "data". FTP and TLS are examples of "communication protocols".

[0036] T30 in FIG. 3, T50 in FIG. 4, and T80 are examples of processes executed by the "detection unit". T32 in FIG. 3, T52 in FIG. 4, and T82 are examples of processes executed by the "judgment unit". T34 in FIG. 3, T54 in FIG. 4, and T84 are examples of processes executed by the "update processing execution unit". T14 and T16 in FIG. 3 are examples of a "reception unit" and a "memory control unit", respectively.

[0037] (Second Embodiment; FIGS. 5 and 6) Subsequently, the second embodiment will be described. In this embodiment, as shown in FIG. 1, the memory 34 of the printer 10 stores an application setting table 44 instead of the setting table 42 of the first embodiment. As shown in FIG. 2, in the application setting table 44, a setting item, a setting value, a version, and a countermeasure method are stored in association with each other. The application setting table 44 is information indicating the countermeasure method applied by the printer 10. In the initial state of FIG. 5, no information is stored in the application setting table 44 of the printer 10. Also, in the initial state of FIG. 5, the version of the communication protocol TLS of the printer 10 is 1.0.

[0038] In the case of the printer 10 in T100, when receiving a setting change operation from the user to change the setting value of the FTP setting from "Disable" to "Enable", the printer 10, in T102, sends a setting change request including its own model name "M1", an application setting table 44 in which no information has been stored yet, and change information indicating that the setting value of the FTP setting has been changed from "Disable" to "Enable", to the server 100.

[0039] When the server 100 receives a setting change request from the printer 10 in T102, in T104, it identifies the countermeasure method "pffp1" associated with each piece of information included in the setting change request from the vulnerability table 142. Specifically, the server 100 identifies the countermeasure method "pffp1" associated with the model "M1" and the content of the setting change indicated by the change information (i.e., FTP setting, "Enable"). This process, in other words, means identifying the countermeasure method for the vulnerability caused by changing the FTP setting of the printer 10 with the model name "M1" to "Enable". Next, the server 100 determines whether the combined information of the FTP setting, "Enable", and the identified countermeasure method "pffp1" is included in the received application setting table 44. In this case, the server 100 determines that the above combined information is not included in the application setting table 44 and determines that the update process should be executed. Note that the server 100 determines that the update process should not be executed when the combined information of the model "M1", the FTP setting, and "Enable" is not stored in the vulnerability table 142 or when the combined information is already stored in the application setting table 44.

[0040] Then, the server 100 executes the update process in T106. Specifically, the server 100 sends request information including the setting item "FTP setting", the setting value "Enable", and the identified countermeasure method "pffp1" to the printer 10.

[0041] When the printer 10 receives request information from the server 100 at T106, at T108, based on the character string "patch" included in the countermeasure method "pffp1 (i.e., patch_fix_ftp_problem_1)" included in the request information, it determines that a patch program should be applied to the printer 10. Then, at T108, the printer 10 applies the patch program "pffp1" by adding the patch program "pffp1" to the program 40. As a result, the printer 10 can address the vulnerability caused by the change of the "FTP setting" from "Disable" to "Enable" at T100. After that, at T110, the printer 10 stores the combined information of the setting item "FTP setting", the setting value "Enable", and the countermeasure method "pffp1" in the application setting table 44.

[0042] Next, at T130, the printer 10 receives a setting change operation from the user to change the setting value of the TLS setting from "Disable" to "Enable". In this case, at T132, the printer 10 sends a setting change request including its own model name "M1", the application setting table 44, the current version of TSL "1.0", and change information indicating that the setting value of the TLS setting has been changed from "Disable" to "Enable" to the server 100.

[0043] When the server 100 receives a setting change request from the printer 10 at T132, at T134, it identifies the countermeasure method "Disable" associated with each piece of information included in the setting change request from the vulnerability table 142. Specifically, the server 100 identifies the countermeasure method "Disable" associated with the model "M1", the content of the setting change indicated by the change information (i.e., TLS setting, "Enable"), and the version "1.0". In other words, this process means identifying the countermeasure method for the vulnerability caused by changing the TLS setting related to TLS of version "1.0" of the printer 10 with the model name "M1" to "Enable". Next, the server 100 determines whether the combined information of the TLS setting, "Enable", version "1.0", and the identified countermeasure method "Disable" is included in the applied setting table 44 that has been received. In this case, the server 100 determines that the applied setting table 44 does not include the combined information and determines that the update process should be executed. Note that if the combined information of the model "M1", TLS setting, "Enable", and version "1.0" is not stored in the vulnerability table 142, or if the combined information is already stored in the applied setting table 44, the server 100 determines that the update process should not be executed.

[0044] Then, at T136, the server 100 executes the update process. Specifically, the server 100 sends request information including the setting item "FTP setting", the setting value "Enable", the version "1.0", and the identified countermeasure method "Disable" to the printer 10.

[0045] When the printer 10 receives request information from the server 100 at T136, at T138, based on the character string "Disable" included in the countermeasure method "Disable" included in the request information, it determines that the setting value of the TLS setting should be changed from "Enable" to "Disable". Then, the printer 10 changes the setting value of the TLS setting from "Enable" to "Disable". That is, the printer 10 cancels the setting change operation received from the user at T130. Thereby, the printer 10 can cope with the vulnerability caused by the "TLS setting" being changed from "Disable" to "Enable" at T130. After that, at T140, the printer 10 stores the combined information of the setting item "TLS setting", the setting value "Enable", the version "1.0", and the countermeasure method "Disable" in the application setting table 44.

[0046] Next, at T160 in FIG. 6, after updating the TLS version from 1.0 to 1.2, the printer 10 receives, at T170, a setting change operation from the user to change the setting value of the TLS setting from "Disable" to "Enable". In this case, at T172, the printer 10 transmits a setting change request including its own model name "M1", the application setting table 44, the current TLS version "1.2", and change information indicating that the setting value of the TLS setting has been changed from "Disable" to "Enable" to the server 100.

[0047] When the server 100 receives a setting change request from the printer 10 at T172, at T174, it identifies the countermeasure method "F1.1" associated with each piece of information included in the setting change request from the vulnerability table 142. Specifically, the server 100 identifies the countermeasure method "F1.1" associated with the model "M1", the content of the setting change indicated by the change information (i.e., TLS setting, "Enable"), and the version "1.2". In other words, this process means identifying the countermeasure method for the vulnerability caused by changing the TLS setting related to TLS of version "1.2" of the printer 10 with the model name "M1" to "Enable". Next, the server 100 determines whether the combined information of the TLS setting, "Enable", version "1.2", and the identified countermeasure method "F1.1" is included in the application setting table 44 of the received setting change request. In this case, the server 100 determines that the application setting table 44 does not include the combined information and determines that the update process should be executed. Note that if the combined information of the model "M1", TLS setting, "Enable", and version "1.2" is not stored in the vulnerability table 142, or if the combined information is already stored in the application setting table 44, the server 100 determines that the update process should not be executed.

[0048] Then, at T176, the server 100 executes the update process. Specifically, the server 100 sends request information including the setting item "FTP setting", the setting value "Enable", the version "1.2", and the identified countermeasure method "F1.1" to the printer 10.

[0049] When the printer 10 receives request information from the server 100 at T176, at T178, it determines that the firmware of the printer 10 should be updated based on the character string "Firmware" included in the countermeasure method "F1.1" included in the request information. Then, at T178, the printer 10 updates the current firmware included in the program 40 to "F1.1". As a result, the printer 10 can cope with the vulnerability caused by the change of "TLS setting" from "Disable" to "Enable" at T170. After that, at T180, the printer 10 stores the combined information of the setting item "TLS setting", the setting value "Enable", the version "1.2", and the identified countermeasure method "F1.1" in the application setting table 44.

[0050] (Effect of this embodiment) According to the above configuration, when the server 100 detects that the setting value of FTP or TLS has been changed from "Disable" to "Enable" and determines that an update process should be executed (T104, T134 in FIG. 5, 174 in FIG. 6), it transmits request information (T106, T136 in FIG. 5, 176 in FIG. 6). As a result, in order to cope with the vulnerability caused by the change of the FTP or TLS setting value of the printer 10, the data stored in the memory 34 of the printer 10 can be updated (T108, T138 in FIG. 5, 178 in FIG. 6). Therefore, the printer 10 can cope with the vulnerability caused by the change of the FTP or TLS setting value.

[0051] (Corresponding relationship) The server 100 is an example of a "control device". T102, T132 in FIG. 5, and T172 in FIG. 6 are examples of the processes executed by the "detection unit". T104, T134 in FIG. 5, and T174 in FIG. 6 are examples of the processes executed by the "judgment unit". T106, T136 in FIG. 5, and T176 in FIG. 6 are examples of the processes executed by the "update process execution unit". T14, T16 in FIG. 3 are examples of the "reception unit" and the "memory control unit", respectively.

[0052] The specific examples of the present invention have been described in detail above, but these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples illustrated above. The modifications of the above embodiments are listed below.

[0053] (Modification Example 1) The processes of T10 to T16 in FIG. 3 may not be executed periodically. For example, the printer 10 may execute the processes of T10 to T16 in FIG. 3 triggered by receiving a setting change operation from the user at T30 in FIG. 3, T50 in FIG. 4, or T80. Generally speaking, the "reception unit" may not receive the vulnerability information periodically.

[0054] (Modification Example 2) The "specific setting item" may not be an item related to whether the communication device uses a specific communication protocol. For example, the "specific setting item" may be an item related to whether the communication device uses an encryption method used for communication. In this case, the "first value" may be a value indicating that the communication device uses the encryption method, and the "second value" may be a value indicating that the communication device does not use the encryption method. Also, for example, the "specific setting item" may be an item for registering the device name, IP address, etc. of a device for which communication with the communication device is permitted (or prohibited).

[0055] (Modification Example 3) The "update process" may be only the firmware update, only the application of the patch program, only the change of the setting value, or any two of these. Generally speaking, the "update process" may include at least one of the firmware update, the application of the patch program, and the change of the setting value. In other modification examples, the "update process" may not include any of the above. That is, the "update process" may be a process for updating the data stored in the communication device in order to address the vulnerability of the communication device.

[0056] (Modification Example 4) In the above-described embodiment, the processing of each step in FIGS. 3 to 6 is realized by software (for example, program 40 of printer 10 and program 140 of server 100), but at least one of these processes may be realized by hardware such as a logic circuit.

[0057] In addition, the technical elements described in this specification or the drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Also, the technologies exemplified in this specification or the drawings can achieve multiple purposes simultaneously, and achieving one of these purposes itself has technical utility.

[0058] In the claims of this patent application at the time of filing, even if each claim depends only on some of the claims, each claim is not limited to depending only on some of the claims. Within a technically non - contradictory range, each claim can also depend on other claims that it did not depend on at the time of filing. That is, the technologies of each claim can be combined in various ways as follows. (Item 1) A control device, a detection unit that detects that a specific set value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value; a determination unit that, when it is detected that the specific set value has been changed from the first value to the second value, determines whether or not to execute an update process based on the content of the change of the specific set value, where the update process is a process for updating data stored in the communication device in order to address the vulnerability of the communication device caused by the change of the specific set value in the communication device, the determination unit; an update process execution unit that executes the update process when it is determined that the update process should be executed; A control device comprising: (Item 2) The control device further For each of a plurality of setting items related to communication in the communication device, a memory is provided that stores in association the change content of the setting value corresponding to the setting item and the countermeasure information for dealing with the vulnerability of the communication device caused by the change of the setting value. The determination unit In the memory, when specific countermeasure information is stored in association with the change content of the specific setting value, it is determined that the update process should be executed. In the memory, when the specific countermeasure information is not stored in association with the change content of the specific setting value, it is determined that the update process should not be executed. The update process execution unit, when it is determined that the update process should be executed, executes the update process according to the specific countermeasure information, the control device described in item 1. (Item 3) The control device is a control unit of the communication device. The control device further A receiving unit that receives vulnerability information regarding the vulnerability of the communication device from a server. A storage control unit that stores the vulnerability information in the memory, where the vulnerability information includes, for each of the plurality of setting items, the change content of the setting value corresponding to the setting item and the countermeasure information for dealing with the vulnerability of the communication device caused by the change of the setting value. The control device described in item 2 includes the storage control unit. (Item 4) The receiving unit periodically receives new vulnerability information from the server. The storage control unit, when the new vulnerability information is received from the server, stores the new vulnerability information in the memory in place of the old vulnerability information stored in the memory, the control device described in item 3. (Item 5) The specific setting item is an item regarding whether the communication device uses a specific communication protocol. The first value is a value indicating that the communication device does not use the specific communication protocol. The control device according to any one of items 1 to 4, wherein the second value is a value indicating that the communication device uses the specific communication protocol. (Item 6) The first value is a value indicating that the communication device does not use a predetermined version of the specific communication protocol, The control device according to item 5, wherein the second value is a value indicating that the communication device uses the predetermined version of the specific communication protocol. (Item 7) The update process is updating the firmware of the communication device, applying a patch program to the communication device, changing the specific set value, The control device according to any one of items 1 to 6, including at least one of the above. (Item 8) The control device according to item 7, wherein the change of the specific set value is to change the specific set value from the second value to the first value. (Item 9) The control device is a server capable of communicating with the communication device, When the detection unit receives change information indicating that the specific set value has been changed from the first value to the second value from the communication device, the detection unit detects that the specific set value has been changed from the first value to the second value, The update process according to item 1, including transmitting request information for requesting that the data stored in the communication device be updated to the communication device.

Description of Signs

[0059] 2: Communication system, 4: Internet, 10: Printer, 12: Operation unit, 14: Display unit, 16: Communication I / F, 18: Printing execution unit, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 42: Setting table, 44: Application setting table, 100: Server, 116: Communication I / F, 130: Control unit, 132: CPU, 134: Memory, 140: Program, 142: Vulnerability table

Claims

1. A control device, a detection unit that detects that a specific setting value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value; a determination unit that determines whether to execute an update process based on the change content of the specific setting value when it is detected that the specific setting value has been changed from the first value to the second value, where the update process is a process for updating data stored in the communication device in order to address the vulnerability of the communication device caused by the change of the specific setting value of the communication device, the determination unit; an update process execution unit that executes the update process when it is determined that the update process should be executed; A control device comprising the above.

2. The control device further comprises, a memory that stores, for each of a plurality of setting items related to communication in the communication device, the change content of the setting value corresponding to the setting item and the countermeasure information for addressing the vulnerability of the communication device caused by the change of the setting value in association with each other; The determination unit, determines that the update process should be executed when specific countermeasure information is stored in the memory in association with the change content of the specific setting value; determines that the update process should not be executed when the specific countermeasure information is not stored in the memory in association with the change content of the specific setting value; The update process execution unit executes the update process according to the specific countermeasure information when it is determined that the update process should be executed. The control device according to claim 1.

3. The control device is a control unit of the communication device, The control device further comprises, a receiving unit that receives vulnerability information related to the vulnerability of the communication device from a server; a storage control unit that stores the vulnerability information in the memory, where the vulnerability information includes, for each of the plurality of setting items, the change content of the setting value corresponding to the setting item and the countermeasure information for addressing the vulnerability of the communication device caused by the change of the setting value. The control device according to claim 2, comprising the storage control unit.

4. The receiving unit periodically receives new vulnerability information from the server, The control device according to claim 3, wherein when the new vulnerability information is received from the server, the memory control unit stores the new vulnerability information in the memory in place of the old vulnerability information stored in the memory.

5. The specific setting item is an item regarding whether the communication device uses a specific communication protocol. The first value is a value indicating that the communication device does not use the specific communication protocol. The control device according to claim 1, wherein the second value is a value indicating that the communication device uses the specific communication protocol.

6. The first value is a value indicating that the communication device does not use a predetermined version of the specific communication protocol. The control device according to claim 5, wherein the second value is a value indicating that the communication device uses the predetermined version of the specific communication protocol.

7. The update process includes updating the firmware of the communication device, applying a patch program to the communication device, changing the specific setting value, and includes at least one of the above, the control device according to claim 1.

8. The control device according to claim 7, wherein changing the specific setting value is changing the specific setting value from the second value to the first value.

9. The control device is a server capable of communicating with the communication device. When the detection unit receives change information indicating that the specific setting value has been changed from the first value to the second value from the communication device, the detection unit detects that the specific setting value has been changed from the first value to the second value. The control device according to claim 1, wherein the update process includes transmitting request information for requesting that the data stored in the communication device be updated to the communication device.

10. A computer program for a control device, causing the computer of the control device to perform the following units, namely, a detection unit that detects that a specific setting value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value. A determination unit that determines whether to execute an update process based on the content of the change in the specific setting value when it is detected that the specific setting value has been changed from the first value to the second value, where the update process is a process for updating data stored in the communication device in order to address the vulnerability of the communication device caused by the change in the specific setting value of the communication device, the determination unit; An update process execution unit that executes the update process when it is determined that the update process should be executed; A computer program that functions as. **Claim 11** A method executed by a control device, A detection step of detecting that a specific setting value corresponding to a specific setting item related to communication in a communication device has been changed from a first value to a second value; A determination step of determining whether to execute an update process based on the content of the change in the specific setting value when it is detected that the specific setting value has been changed from the first value to the second value, where the update process is a process for updating data stored in the communication device in order to address the vulnerability of the communication device caused by the change in the specific setting value of the communication device, the determination step; An update process execution step of executing the update process when it is determined that the update process should be executed; A method comprising.

Citation Information

Patent Citations

  • Port number management method, information processing apparatus, and computer program

    JP2008048198A

  • Communication device, computer program for communication device, and method to be executed by communication device

    JP2022085622A