Information communication device, program, firmware updating system, and firmware updating method
The system updates printer firmware by determining the current encryption method and encrypting the new firmware accordingly, addressing the need for intermediate firmware in conventional updates and ensuring secure and efficient encryption method updates.
Patent Information
- Application Number
- JP2023213664
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-07-01
AI Technical Summary
Conventional printer firmware updates require the introduction of an intermediate firmware that can interpret the new encryption method, making it impossible to update the encryption method without this intermediate firmware.
A system and method that allows firmware updates by determining the current firmware version and encrypting the new firmware using either a first or second encryption method corresponding to the current or newer encryption method, respectively, without the need for an intermediate firmware.
Enables firmware updates based on version number without introducing an intermediate firmware, ensuring secure and efficient encryption method updates.
Smart Images

Figure 2025097457000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information communication device, a program, a firmware update system, and a firmware update method.
Background Art
[0002] Conventionally, in printers, FW (FirmWare) updates using encryption have been performed. Conventionally, in order to update the encryption method, a method has been used in which an intermediate FW that can interpret the new method is introduced once, and then the latest FW is applied (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in order to update the encryption method in a conventional printer, it was not possible to update the FW according to the edition number unless an intermediate FW that can interpret the new method was introduced once.
[0005] Therefore, one or more aspects of the present disclosure aim to be able to update the encryption method and update the FW according to the edition number without introducing an intermediate FW.
Means for Solving the Problems
[0006] An information communication device according to an aspect of the present disclosure includes a storage device that stores a second firmware, a communication unit that communicates with an information processing device that acquires the second firmware, and the storage device via the communication unit. A firmware release confirmation unit that acquires the version number of the second firmware from the storage device by transmitting a request for acquiring the version number of the second firmware, and the information processing device via the communication unit. A firmware version confirmation unit that acquires the version number of the first firmware, which is the firmware set in the information processing device, from the information processing device by transmitting a request for acquiring the version number of the first firmware, and when the version number of the first firmware is older than a predetermined version number, a first firmware acquisition request that is a firmware acquisition request indicating a first encryption method corresponding to the first firmware is transmitted to the storage device via the communication unit, and the first encrypted firmware obtained by encrypting the second firmware with the first encryption method is acquired, and when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, a second firmware acquisition request that is a firmware acquisition request indicating a second encryption method newer than the first encryption method is transmitted to the storage device via the communication unit, and a firmware acquisition unit that acquires the second encrypted firmware obtained by encrypting the second firmware with the second encryption method. It is characterized by comprising.
[0007] A program according to an aspect of the present disclosure causes a computer to function as a communication unit that communicates with a storage device storing second firmware and an information processing device that acquires the second firmware, a firmware release confirmation unit that transmits a request to acquire the version number of the second firmware to the storage device via the communication unit and acquires the version number of the second firmware from the storage device via the communication unit, a firmware version confirmation unit that transmits a request to acquire the version number of first firmware, which is the firmware set in the information processing device, to the information processing device via the communication unit and acquires the version number of the first firmware from the information processing device via the communication unit, and a firmware acquisition unit that transmits a first firmware acquisition request, which is a firmware acquisition request indicating a first encryption method corresponding to the first firmware, to the storage device via the communication unit when the version number of the first firmware is older than a predetermined version number, thereby acquiring first encrypted firmware obtained by encrypting the second firmware with the first encryption method, and transmits a second firmware acquisition request, which is a firmware acquisition request indicating a second encryption method newer than the first encryption method, to the storage device via the communication unit when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, thereby acquiring second encrypted firmware obtained by encrypting the second firmware with the second encryption method.
[0008] A firmware update system according to an aspect of the present disclosure is a firmware update system including a storage device that stores second firmware, an information communication device, and an information processing device that acquires the second firmware via the information communication device, wherein the storage device encrypts the second firmware with a first encryption method corresponding to the first firmware when a version number of the first firmware, which is the firmware set in the information processing device, is older than a predetermined version number, and encrypts the second firmware with a second encryption method newer than the first encryption method when the version number of the first firmware is the predetermined version number or newer than the predetermined version number, and includes a first communication unit that sends the encrypted second firmware to the information communication device.
[0009] The firmware update method according to one aspect of the present disclosure is a firmware update method performed by an information communication device that communicates with a storage device storing a second firmware and an information processing device that acquires the second firmware. The method includes: transmitting a request to acquire the version number of the second firmware to the storage device to acquire the version number of the second firmware from the storage device; transmitting a request to acquire the version number of a first firmware, which is the firmware set in the information processing device, to the information processing device to acquire the version number of the first firmware from the information processing device; when the version number of the first firmware is older than a predetermined version number, transmitting a first firmware acquisition request, which is a firmware acquisition request indicating a first encryption method corresponding to the first firmware, to the storage device to acquire a first encrypted firmware obtained by encrypting the second firmware with the first encryption method; and when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, transmitting a second firmware acquisition request, which is a firmware acquisition request indicating a second encryption method newer than the first encryption method, to the storage device to acquire a second encrypted firmware obtained by encrypting the second firmware with the second encryption method.
Effect of the Invention
[0010] According to one or more aspects of the present disclosure, it is possible to update the FW according to the version number by updating the encryption method without introducing an intermediate FW.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Embodiments for Carrying Out the Invention
[0012] Embodiment 1. FIG. 1 is a block diagram schematically showing the configuration of an FW (FirmWare) update system 100 according to Embodiment 1. The FW update system 100 includes a server 110 as a storage device, a PC (Personal Computer) 130 as an information communication device, and a printer 150 as an information processing device. In the FW update system 100, the server 110 stores the latest FW, and the printer 150 acquires the latest FW via the PC 130. The latest FW is also referred to as the second FW.
[0013] In the FW update system 100, the server 110 and the PC 130 are connected to a first network 101, for example, the Internet, and the PC 130 and the printer 150 are connected to a second network 102, for example, a LAN (Local Area Network). Note that the PC 130 is connected to the first network 101 via a relay device 103 such as a router.
[0014] FIG. 2 is a block diagram schematically showing the configuration of the server 110 in Embodiment 1. The server 110 includes a communication unit 111, a storage unit 112, and a control unit 120.
[0015] The communication unit 111 is a first communication unit that communicates with the PC 130. For example, the communication unit 111 communicates with the PC 130 via the first network 101 and the relay device 103. Specifically, the communication unit 111 sends the encrypted FW, which is encrypted as described later, to the PC 130.
[0016] The storage unit 112 stores data and programs necessary for processing in the server 110. For example, the storage unit 112 stores the FW 113 of the printer 150. The FW stored in the storage unit 112 is assumed to be the latest FW.
[0017] The control unit 120 controls the processing in the server 110. The control unit 120 includes an FW management unit 121 and an encryption unit 122.
[0018] The FW management unit 121 receives, via the communication unit 111, a confirmation request for the version number of the FW used in the printer 150 from the PC 130. Then, the FW management unit 121 sends, via the communication unit 111, a confirmation response indicating the most recently released version number as the FW of the printer 150 to the PC 130.
[0019] Further, the FW management unit 121 receives a request to obtain the FW of the printer 150 from the PC 130 via the communication unit 111. The FW management unit 121 checks the encryption method included in the acquisition request and notifies the encryption unit 122 of the encryption method. The FW management unit 121 receives the encrypted FW encrypted with the corresponding encryption method from the encryption unit 122. Then, the FW management unit 121 sends the encrypted FW to the PC 130 via the communication unit 111.
[0020] The encryption unit 122 generates encrypted FW by encrypting the FW 113 stored in the storage unit 112 with the encryption method notified from the FW management unit 121. Specifically, when the version number of the current FW, which is the FW set in the printer 150, is older than a predetermined version number, the encryption unit 122 encrypts the latest FW with the first encryption method (here, method A) corresponding to the current FW to generate encrypted FW. The current FW is also referred to as the first FW. Also, when the version number of the current FW is the predetermined version number or newer than the predetermined version number, the encryption unit 122 encrypts the latest FW with a second encryption method (here, method B) newer than the first encryption method to generate encrypted FW.
[0021] In Embodiment 1, when the encryption unit 122 receives a first FW acquisition request described later via the communication unit 111, it encrypts the latest FW with the first encryption method described later, and when it receives a second FW acquisition request described later via the communication unit 111, it encrypts the latest FW with the second encryption method described later. Then, the encryption unit 122 provides the encrypted FW to the FW management unit 121.
[0022] The server 110 described above can be realized by a computer 10 as shown in FIG. 3, for example. The computer 10 includes a storage 11 such as an HDD (Hard Disk Drive) and an SSD (Solid State Drive), a memory 12, a processor 13 such as a CPU (Central Processing Unit), and a communication I / F (InterFace) 14 such as a NIC (Network Interface Card).
[0023] For example, the storage unit 112 can be realized by the storage 11 or the memory 12. The control unit 120 can be realized by loading the program stored in the storage 11 into the memory 12 and having the processor 13 execute the program. The communication unit 111 can be realized by the communication I / F 14.
[0024] The program may be downloaded from a recording medium (not shown) via a reader / writer (not shown) or from a network via the communication I / F 14 to the storage 11, and then loaded onto the memory 12 and executed by the processor 13. Alternatively, it may be directly loaded onto the memory 12 from a recording medium via a reader / writer or from a network via the communication I / F 14 and executed by the processor 13. In other words, the program may be provided by a program product such as a recording medium.
[0025] FIG. 4 is a block diagram schematically showing the configuration of the PC 130 in the first embodiment. The PC 130 includes a communication unit 131, a storage unit 133, and a control unit 140.
[0026] The communication unit 131 is a second communication unit that communicates with the printer 150 and the server 110. Specifically, the communication unit 131 communicates with the server 110 via the second network 102, the relay device 103, and the first network 101. Also, the communication unit 131 communicates with the printer 150 via the second network 102.
[0027] The storage unit 133 stores data and programs necessary for the processing in the PC 130. For example, the storage unit 133 stores FW version list information associating the version number of the FW of the printer 150 with the encryption method.
[0028] FIG. 5 is a schematic diagram showing an example of the FW version list information. The FW version list information 134 is information in a table format having a version number column 134a and an encryption method column 134b.
[0029] The version number column 134a stores the version number of the FW of the printer 150. The version number of the FW shall be indicated by a version number. The encryption method column 134b stores the encryption method corresponding to the version number of the FW specified by the version number column 134a in the same row. From the FW version list information 134, for example, it can be seen that the FW with a version older than v4.0 only corresponds to the old encryption method, method A, and does not correspond to method B, which is an encryption method newer than method A.
[0030] Returning to FIG. 4, the control unit 140 controls the processing in the PC 130. The control unit 140 includes an FW release confirmation unit 141, an FW version confirmation unit 142, and an FW acquisition unit 143.
[0031] The FW release confirmation unit 141 sends a request to the server 110 to acquire the version number of the latest FW via the communication unit 131, and acquires the version number of the latest FW from the server 110 via the communication unit 131. Specifically, the FW release confirmation unit 141 sends a request to confirm the version number of the FW most recently released as the FW of the printer 150 via the communication unit 131, and receives the confirmation response.
[0032] The FW version confirmation unit 142 sends a request to the printer 150 via the communication unit 131 to obtain the version number of the current FW, which is the FW set in the printer 150, and then obtains the version number of the current FW from the printer 150 via the communication unit 131. And if the version number of the FW set in the printer 150 is older than the version number obtained from the server 110, the FW version confirmation unit 142 determines that it is necessary to update the FW.
[0033] When the version number of the current FW is older than a predetermined version number, the FW acquisition unit 143 sends a first FW acquisition request, which is an FW acquisition request indicating a first encryption method that is the encryption method corresponding to the current FW, to the server 110 via the communication unit 131. Also, when the version number of the current FW is older than the version number of the latest FW and the version number of the current FW is equal to or newer than a predetermined version number, the FW acquisition unit 143 sends a second FW acquisition request, which is an FW acquisition request indicating a second encryption method that is newer than the first encryption method, to the server 110 via the communication unit 131.
[0034] Specifically, when the FW version confirmation unit 142 determines that it is necessary to update the FW, the FW acquisition unit 143 refers to the FW version list information 134 stored in the storage unit 133 to identify the encryption method corresponding to the FW set in the printer 150.
[0035] Then, the FW acquisition unit 143 sends information indicating the identified encryption method to the server 110 via the communication unit 131, obtains the encrypted FW from the server 110, and transfers the encrypted FW to the printer 150 via the communication unit 131.
[0036] For example, the FW acquisition unit 143 sends an FW acquisition request including the encryption method specified by the FW version confirmation unit 142 to the server 110 via the communication unit 131, and receives the encrypted FW as a response. Then, the FW acquisition unit 143 sends the encrypted FW received from the server 110 to the printer 150 via the communication unit 131.
[0037] The PC130 described above can also be realized by the computer 10, for example, as shown in FIG. 3.
[0038] For example, the storage unit 133 can be realized by the storage 11 or the memory 12. The control unit 140 can be realized by loading the program stored in the storage 11 into the memory 12 and having the processor 13 execute the program. The communication unit 131 can be realized by the communication I / F 14.
[0039] FIG. 6 is a block diagram schematically showing the configuration of the printer 150 in the first embodiment. The printer 150 includes a communication unit 151, a storage unit 152, a control unit 160, and a printer main body 170 as an information processing apparatus main body.
[0040] The communication unit 151 is a third communication unit that communicates with the PC130 via the first network 101.
[0041] The storage unit 152 stores data and programs necessary for processing in the printer 150. For example, the storage unit 152 stores the FW version number 153. The FW version number 153 is information indicating the version number of the FW set in the printer main body 170. The FW set in the printer main body 170 is also referred to as the current FW.
[0042] The control unit 160 controls the processing in the printer 150. The control unit 160 includes an FW version number management unit 161, a key processing unit 162, and an FW update unit 163.
[0043] The FW version number management unit 161 sends the version number of the FW set in the printer 150 to the PC130 via the communication unit 151 in response to a request from the PC130. Specifically, when the FW version management unit 161 receives a FW version acquisition request from the PC 130 via the communication unit 151, it reads the FW version 153 from the storage unit 152 and responds to the PC 130 with the FW version 153 via the communication unit 151.
[0044] Furthermore, when the FW update unit 163 updates the FW of the printer main body 170, the FW version management unit 161 updates the FW version 153 stored in the storage unit 152 with the version of the updated FW. It is assumed that the FW indicates its version.
[0045] The key processing unit 162 receives the encrypted FW via the communication unit 151, decrypts the encrypted FW, and acquires the FW. The FW thus acquired is provided to the FW update unit 163.
[0046] The FW update unit 163 updates the FW of the printer 150 using the FW acquired by the key processing unit 162. For example, the FW update unit 163 updates the FW by rewriting the FW stored in a storage unit (not shown) of the printer main body 170 with the FW decrypted by the key processing unit 162.
[0047] The printer main body 170 is a part that executes the process of printing an image on a medium. Here, the printer main body 170 may perform printing by an electrophotographic method, an inkjet method, a dot impact method, or the like, and there is no limitation on the printing method.
[0048] Part or all of the control unit 160 of the printer 150 described above can be configured by, for example, a memory 20 and a processor 21 such as a CPU (Central Processing Unit) that executes a program stored in the memory 20, as shown in FIG. 7(A). Such a program may be provided through a network or may be provided by being recorded on a recording medium. That is, such a program may be provided, for example, as a program product.
[0049] Also, part or all of the control unit 160 can be configured by, for example, a processing circuit 22 such as a single circuit, a composite circuit, a processor that operates with a program, a parallel processor that operates with a program, an ASIC (Application Specific Integrated Circuit), or an FPGA (Field Programmable Gate Array), as shown in FIG. 7(B). As described above, the control unit 160 can be realized by a processing circuit network.
[0050] Note that the storage unit 152 can be realized by a storage such as a memory. Also, the communication unit 151 can be realized by a communication I / F such as a NIC. Furthermore, the printer main body 170 can be realized by a printing mechanism that performs printing by an electrophotographic method, an inkjet method, a dot impact method, or the like.
[0051] FIG. 8 is a sequence diagram showing the operation of the FW update system 100 according to the first embodiment. First, the FW release confirmation unit 141 of the PC 130 sends a confirmation request to the server 110 via the communication unit 131 to check whether a new FW has been released as the FW of the printer 150 (S10).
[0052] Upon receiving such a confirmation request, in server 110, the FW management unit 121 checks whether the FW of printer 150 has been newly released since the previous confirmation request, and responds by sending the confirmation result to PC 130 via communication unit 151 (S11). Here, it is described as if a new FW has been released. Also, assume that the confirmation result includes information indicating the version number of the newly released FW. From the above, it can be said that the confirmation request in step S10 is a request to obtain the version number of the latest FW, and the confirmation result in step S11 is a response to answer the latest FW.
[0053] Upon receiving the confirmation response from server 110, in PC 130, the FW release confirmation unit 141 checks that a new FW has been released as the FW of printer 150, and instructs the FW version confirmation unit 142 to confirm the version number of the FW of printer 150 (S12).
[0054] Upon receiving such an instruction, the FW version confirmation unit 142 sends a request to obtain the version number of the FW set in printer 150 to printer 150 via communication unit 131 (S13).
[0055] Upon receiving such an acquisition request, in printer 150, the FW version management unit 161 responds by sending the FW version read from the storage unit 152 to PC 130 via communication unit 151 (S14).
[0056] Upon receiving the response of the FW version, in PC 130, the FW version confirmation unit 142 determines whether it is necessary to update the FW of printer 150 based on the version number obtained from server 110 and the version number of the FW set in printer 150. Here, it is described as if the FW version confirmation unit 142 determines that it is necessary to update the FW of printer 150. If it is necessary to update the FW of printer 150, the FW version confirmation unit 142 instructs the FW acquisition unit 143 to acquire the FW.
[0057] The FW acquisition unit 143 of the PC 130 refers to the FW version list information 134 stored in the storage unit 133 in response to an instruction from the FW version confirmation unit 142, thereby identifying the encryption method corresponding to the FW set in the printer 150 (S15). Here, it is assumed that the printer 150 only supports method A, which is not the latest encryption method (method B in the example of FIG. 5).
[0058] Then, the FW acquisition unit 143 sends a FW acquisition request including information indicating the encryption method (here, method A) specified in step S15 to the server 110 via the communication unit 131 (S16).
[0059] In the server 110 that has received such an acquisition request, the encryption unit 122 encrypts the FW stored in the storage unit 112 using the encryption method (here, method A) indicated by the information included in the FW acquisition request, thereby generating an encrypted FW (S17).
[0060] Then, the FW management unit 121 responds by sending the encrypted FW to the PC 130 via the communication unit 111 (S18).
[0061] In the PC 130 that has received the encrypted FW, the FW acquisition unit 143 transfers the encrypted FW to the printer 150 via the communication unit 131 (S19).
[0062] In the printer 150 that has received the encrypted FW, the key processing unit 162 decrypts the encrypted FW using the encryption method of method A to obtain the FW (S20).
[0063] Then, the FW update unit 163 updates the FW of the printer 150 using such FW (S21).
[0064] After the FW is updated, the FW version management unit 161 updates the FW version 153 stored in the storage unit 152 with the version number of the updated FW (S22).
[0065] FIG. 9 is a flowchart showing the operation of the PC 130 in the first embodiment. First, the FW release confirmation unit 141 sends a confirmation request to the server 110 via the communication unit 131 to check whether a new FW has been released as the FW of the printer 150 (S30).
[0066] Next, the FW release confirmation unit 141 sends an acquisition request for the version number of the FW set in the printer 150 to the printer 150 via the communication unit 131 (S31).
[0067] Then, the FW version number confirmation unit 142 receives, via the communication unit 131, the FW version number from the printer 150 as a response to such an acquisition request, and determines whether it is necessary to update the FW of the printer 150 from the version number acquired from the server 110 and the version number of the FW set in the printer 150 (S32). If it is necessary to update the FW of the printer 150 (YES in S32), the process proceeds to step S33. If it is not necessary to update the FW of the printer 150 (NO in S32), the process returns to step S30.
[0068] In step S33, the FW acquisition unit 143 refers to the FW version number list information 134 stored in the storage unit 133 to determine whether the FW set in the printer 150 is an older version than a predetermined version (S33). If the FW set in the printer 150 is an older version than the predetermined version (YES in S33), the process proceeds to step S34. If the FW set in the printer 150 is the same as or a newer version than the predetermined version (NO in S33), the process proceeds to step S36.
[0069] In step S34, since the FW set in the printer 150 is old and only supports an old encryption method (here, method A), the FW acquisition unit 143 sends an acquisition request for the FW including information indicating the old encryption method (here, method A) to the server 110 via the communication unit 131.
[0070] Then, the FW acquisition unit 143 acquires, via the communication unit 131, the encrypted FW encrypted with the old encryption method from the server 110, and transfers the encrypted FW to the printer 150 via the communication unit 131 (S35).
[0071] On the other hand, in step S36, since the FW set in the printer 150 is new and corresponds to the new encryption method (here, method B), the FW acquisition unit 143 sends a FW acquisition request including information indicating the new encryption method (here, method B) to the server 110 via the communication unit 131.
[0072] Then, the FW acquisition unit 143 acquires, via the communication unit 131, the encrypted FW encrypted with the old encryption method from the server 110, and transfers the encrypted FW to the printer 150 via the communication unit 131 (S36).
[0073] By the operations described above, for example, the printer 150 with an old version of FW such as "v4.0" shown in FIG. 5 can receive the encrypted FW encrypted with the old encryption method, method A, decrypt this with method A, and update its own FW to the latest "v6.0". By this FW update, the printer 150 can decrypt the encrypted FW encrypted with method B from the next time onwards, and the user can always keep the FW in the latest state without being aware of the encryption method of the printer 150.
[0074] As described above, according to the first embodiment, the user can benefit from the improved security by encryption applied to the printer 150 without being aware of the FW update.
[0075] Second Embodiment. As shown in FIG. 1, the FW update system 200 according to the second embodiment includes a server 110, a PC 230, and a printer 250. The server 110 of the FW update system 200 according to the second embodiment is the same as the server 110 of the FW update system 100 according to the first embodiment.
[0076] Figure 10 is a block diagram schematically showing the configuration of the PC 230 in Embodiment 2. The PC 230 includes a communication unit 131, a storage unit 133, a display unit 235, an input unit 236, a connection unit 237, and a control unit 240. The communication unit 131 and the storage unit 133 of the PC 230 in Embodiment 2 are the same as those of the communication unit 131 and the storage unit 133 of the PC 130 in Embodiment 1.
[0077] The display unit 235 displays various screens. The display unit 235 can be realized by, for example, a display. The input unit 236 receives inputs of various instructions. The input unit 236 can be realized by, for example, an input I / F such as a keyboard or a mouse. Note that the display unit 235 and the input unit 236 may be realized by a touch panel.
[0078] The connection unit 237 is a connection I / F that receives the connection of a USB (Universal Serial Bus) memory 280 as a portable storage device (portable memory) and exchanges data with the USB memory 280.
[0079] The control unit 240 controls the processing in the PC 230. The control unit 240 includes an FW release confirmation unit 141, an FW version number confirmation unit 142, and an FW acquisition unit 243. The FW release confirmation unit 141 and the FW version number confirmation unit 142 of the control unit 240 in Embodiment 2 are the same as those of the FW release confirmation unit 141 and the FW version number confirmation unit 142 of the control unit 140 in Embodiment 1.
[0080] The FW acquisition unit 243 acquires encrypted FW from the server 110 in the same manner as the FW acquisition unit 143 in Embodiment 1. In Embodiment 2, when the FW acquisition unit 243 acquires the encrypted FW from the server 110, the display unit 235 displays a screen for selecting whether to pass the encrypted FW to the printer 250 using a USB memory or to pass the encrypted FW to the printer 250 by communication, and receives an instruction on whether to use the USB memory or communication via the input unit 236.
[0081] When communication is selected, the FW acquisition unit 243 sends the encrypted FW received from the server 110 to the printer 250 via the communication unit 131. On the other hand, when the USB memory is selected, the FW acquisition unit 243 stores the encrypted FW received from the server 110 in the USB memory 280 connected to the connection unit 237.
[0082] In other words, when an instruction to store the encrypted FW in the USB memory is input to the input unit 236, the FW acquisition unit 243 stores the encrypted FW in the USB memory via the connection unit 237, and when an instruction not to store the encrypted FW in the USB memory is input to the input unit 236, the FW acquisition unit 243 transfers the encrypted FW to the printer 250 via the communication unit 131. Note that when an instruction to store the encrypted FW in the USB memory is input to the input unit 236, the FW acquisition unit 243 stores the encrypted FW in the USB memory via the connection unit 237. As a modification, when a USB memory is connected to the connection unit 237, the instruction to store the encrypted FW in the USB memory from the input unit 236 may be omitted, and the encrypted FW may be stored in the USB memory.
[0083] FIG. 11 is a block diagram schematically showing the configuration of the printer 250 in Embodiment 2. The printer 250 includes a communication unit 151, a storage unit 152, a connection unit 254, a control unit 260, and a printer main body 170 as an information processing apparatus main body.
[0084] The communication unit 151, storage unit 152, and printer main body 170 of the printer 250 in Embodiment 2 are the same as those of the communication unit 151, storage unit 152, and printer main body 170 of the printer 150 in Embodiment 1.
[0085] The connection unit 254 is a connection I / F that receives the connection of the USB memory 280 and exchanges data with the USB memory 280.
[0086] The control unit 260 controls the processing in the printer 250. The control unit 260 includes an FW version management unit 161, a key processing unit 262, and an FW update unit 163. The FW version management unit 161 and FW update unit 163 of the control unit 260 in Embodiment 2 are the same as those of the FW version management unit 161 and FW update unit 163 of the control unit 260 in Embodiment 1.
[0087] The key processing unit 262 receives the encrypted FW via the communication unit 151, decrypts the encrypted FW, and obtains the FW. In addition, when the USB memory 280 is connected to the connection unit 254, the key processing unit 262 reads the encrypted FW from the USB memory 280 via the connection unit 254, decrypts the encrypted FW, and obtains the FW.
[0088] In other words, when the key processing unit 262 receives the encrypted FW via the communication unit 151 or reads the encrypted FW from the USB memory 280 via the connection unit 254, the key processing unit 262 decrypts the encrypted FW and obtains the FW. The FW thus obtained is provided to the FW update unit 163.
[0089] FIG. 12 is a sequence diagram showing the operation of the FW update system 200 according to Embodiment 2. In FIG. 11, for processes similar to those included in the operation of the FW update system 100 according to Embodiment 1 shown in FIG. 7, the same reference numerals as those in FIG. 7 are used.
[0090] The processing of steps S10 to S18 in FIG. 11 is the same as the processing of steps S10 to S18 in FIG. 7. However, in FIG. 11, after the processing of step S18, the processing proceeds to step S40.
[0091] In step S40, the FW acquisition unit 243 of the PC 230 causes the display unit 235 to display a selection screen for receiving an input of an instruction to select whether to use a USB memory or communication for FW update.
[0092] FIG. 13 is a front view showing an example of the selection screen. As shown in FIG. 13, the selection screen 290 includes a message display area 290a, a communication selection input area 290b, and a USB memory selection input area 290c.
[0093] In the message display area 290a, a message indicating that an instruction for selecting whether to use communication or a USB memory for FW update is to be received is displayed. The communication selection input area 290b is an area for receiving an input of a selection instruction to use communication for FW update. The USB memory selection input area 290c is an area for receiving an input of a selection instruction to use a USB memory for FW update.
[0094] Returning to FIG. 12, the FW acquisition unit 243 receives a selection instruction of whether to use a USB memory or communication via the input unit 236 (S41). Here, in the selection screen 290 shown in FIG. 13, it is described as an example where an input of an execution instruction for selecting the USB memory selection input area 290c is made, in other words, where it is selected to update the FW using a USB memory.
[0095] In such a case, the FW acquisition unit 243 causes the USB memory 280 connected to the connection unit 237 to store the encrypted FW received from the server 110 (S42).
[0096] When the USB memory 280 storing the encrypted FW is connected to the printer 250 connection part 254, the key processing part 262 reads out the encrypted FW from the USB memory 280 connected to the connection part 254 (S43). The acquired encrypted FW is given to the key processing part 262.
[0097] The processing of steps S20 to S22 in FIG. 12 is the same as the processing of steps S20 to S22 in FIG. 8.
[0098] FIG. 14 is a flowchart showing the operation of the PC 230 in the second embodiment. Among the processes shown in FIG. 14, the processes similar to the processes of the flowchart shown in FIG. 8 are given the same reference numerals as in FIG. 9.
[0099] The processing of steps S30 to S37 in FIG. 14 is the same as the processing of steps S30 to S37 in FIG. 9. However, after the processing of step S34 in FIG. 14, the process proceeds to step S50.
[0100] In step S50, the FW acquisition part 243 determines whether to use a USB memory for FW update. As described above, the FW acquisition part 243 causes the display part 235 to display a selection screen for receiving an input of an instruction to select whether to use a USB memory or communication for FW update, and receives an input of an instruction from the user via the input part 236. If a USB memory is used for FW update (Yes in S50), the process proceeds to step S52. If a USB memory is not used for FW update (No in S50), the process proceeds to step S35. The processing in step S35 is the same as the processing in step S35 in FIG. 9.
[0101] Also, the processing in step S36 in FIG. 14 is the same as the processing in step S36 in FIG. 9, but in FIG. 14, after the processing in step S36, the process proceeds to step S51.
[0102] In step S51, the FW acquisition unit 243 determines whether to use a USB memory for FW update. If using a USB memory for FW update (Yes in S51), the process proceeds to step S52. If not using a USB memory for FW update (No in S51), the process proceeds to step S37. The processing in step S37 is the same as the processing in step S37 of FIG. 9.
[0103] In step S52, the FW acquisition unit 243 causes the USB memory 280 connected to the connection unit 237 to store the encrypted FW received from the server 110.
[0104] As described above, according to the second embodiment, it is possible to realize an improvement in encrypted security applied to the printer 250 even in a limited communication environment.
[0105] In the first and second embodiments described above, the PCs 130 and 230 store the FW version list information 134, but the first and second embodiments are not limited to such an example. For example, the server 110 or the printers 150 and 250 may store the FW version list information 134.
[0106] For example, when the server 110 stores the FW version list information 134, in the sequence of FIG. 8 or FIG. 12, instead of the processing in steps S10 to S16, a FW acquisition request including information indicating the version number of the FW set in the printers 150 and 250, which is obtained by the same processing as the processing in steps S13 and S14, is sent from the PCs 130 and 230 to the server 110, and the server 110 checks the corresponding encryption method of the printers 150 and 250 and encrypts the FW with that encryption method.
[0107] Specifically, the FW release confirmation units 141 of the PCs 130 and 230 send a request to obtain the version number of the latest FW to the server 110 via the communication unit 131, and obtain the version number of the latest FW from the server 110 via the communication unit 131. Then, the FW release confirmation unit 141 transfers the version number of the latest FW to the printers 150 and 250 via the communication unit 131.
[0108] The FW version number management units 161 of the printers 150 and 250 receive the version number of the latest FW via the communication unit 151, and when the version number of the current FW is older than the version number of the latest FW, send a FW acquisition request indicating the version number of the current FW to the PCs 130 and 230 via the communication unit 151.
[0109] The FW acquisition units 143 and 243 of the PCs 130 and 230 receive the FW acquisition request from the printers 150 and 250 via the communication unit 131, and transfer the FW acquisition request to the server 110 via the communication unit 131.
[0110] When the version number of the current FW indicated in the FW acquisition request is older than a predetermined version number, the encryption unit 122 of the server 110 encrypts the latest FW with the first encryption method, and when the version number of the current FW is the predetermined version number or newer than the predetermined version number, encrypts the latest FW with the second encryption method.
[0111] Also, when the printers 150 and 250 store the FW version list information 134, in the sequences of FIGS. 8 or 12, instead of the processes of steps S10 to S15, the latest version number of the FW obtained by the same processes as steps S10 and S11 is sent from the PCs 130 and 230 to the printers 150 and 250. And when it is determined that FW update is necessary in the printers 150 and 250, the printers 150 and 250 send a FW acquisition request indicating the corresponding encryption method from the printers 150 and 250 to the PCs 130 and 230, and the printers 150 and 250 may send the acquisition request to the server 110 by the same process as step S16.
[0112] Specifically, the FW release confirmation units 141 of the PCs 130 and 230 send a request to the server 110 via the communication unit 131 to obtain the version number of the latest FW. Then, they obtain the version number of the latest FW via the communication unit 131 and transfer the version number of the latest FW to the printers 150 and 250 via the communication unit 131.
[0113] The FW version number management units 161 of the printers 150 and 250 receive the version number of the latest FW via the communication unit 151. When the version number of the current FW is older than a predetermined version number, they send a first FW acquisition request indicating the first encryption method to the PCs 130 and 230 via the communication unit 151. On the other hand, when the version number of the current FW is older than the version number of the latest FW and the version number of the current FW is equal to or newer than the predetermined version number, the FW version number management unit 161 sends a second FW acquisition request indicating the second encryption method to the PCs 130 and 230 via the communication unit 151.
[0114] The FW acquisition units 143 and 243 of the PCs 130 and 230 receive the first FW acquisition request or the second FW acquisition request via the communication unit 131 and transfer the first FW acquisition request or the second FW acquisition request to the server 110 via the communication unit 131.
[0115] When the encryption unit 122 of the server 110 receives the first FW acquisition request via the communication unit 111, it encrypts the latest FW using the first encryption method. On the other hand, when the encryption unit 122 receives the second FW acquisition request via the communication unit 111, it encrypts the latest FW using the second encryption method.
[0116] Also, when the purpose is to update the encryption method, in Embodiments 1 and 2, the corresponding encryption method is determined by obtaining the FW version number. However, Embodiments 1 and 2 are not limited to such examples. For example, the PCs 130 and 230 may obtain information indicating the corresponding encryption method from the printers 150 and 250. Specifically, the PCs 130 and 230 send commands that are only applicable in the new encryption method to the printers 150 and 250, and based on whether the printers 150 and 250 can return a response to the commands, it can be determined whether the printers 150 and 250 support the new encryption method. Also, the PCs 130 and 230 can inquire the printers 150 and 250 about file information that only exists in the new encryption method, and based on whether the printers 150 and 250 can return a response, it can be confirmed whether the printers 150 and 250 support the new encryption method.
[0117] In the above-described Embodiments 1 and 2, only the encryption method of the FW was taken as an example, but it may also be applicable to updates of the mechanism of encrypted communication and the like.
[0118] Also, instead of the printers 150 and 250, other image forming apparatuses (other information processing apparatuses) such as a multifunction printer or a FAX may be used. Furthermore, instead of the PCs 130 and 230, other information communication apparatuses such as a smartphone or a tablet may be used. Also, instead of the server 110, other storage apparatuses such as a NAS (Network Attached Storage) may be used.
Explanation of Signs
[0119] 100, 200 FW update system, 110 server, 111 communication unit, 112 memory unit, 113 FW, 120 control unit, 121 FW management unit, 122 encryption unit, 130, 230 PC, 131 communication unit, 133 memory unit, 134 FW version list information, 235 display unit, 236 input unit, 237 connection unit, 140, 240 control unit, 141 FW release confirmation unit, 142 FW version confirmation unit, 143, 243 FW acquisition unit, 150, 250 printer, 151 communication unit, 152 memory unit, 153 FW version, 254 connection unit, 160, 260 control unit, 161 FW version management unit, 162, 262 key processing unit, 163 FW update unit, 170 printer body, 280 USB memory.
Claims
1. A storage device that stores a second firmware, and a communication unit that communicates with an information processing device that acquires the second firmware; a firmware release confirmation unit that acquires the version number of the second firmware from the storage device via the communication unit by transmitting a request to acquire the version number of the second firmware to the storage device via the communication unit; a firmware version confirmation unit that acquires the version number of a first firmware, which is the firmware set in the information processing device, from the information processing device via the communication unit by transmitting a request to acquire the version number of the first firmware to the information processing device via the communication unit; a firmware acquisition unit that acquires a first encrypted firmware obtained by encrypting the second firmware with the first encryption method by transmitting, via the communication unit, a first firmware acquisition request, which is a firmware acquisition request indicating the first encryption method corresponding to the first firmware, to the storage device when the version number of the first firmware is older than a predetermined version number, and acquires a second encrypted firmware obtained by encrypting the second firmware with a second encryption method, which is newer than the first encryption method, by transmitting, via the communication unit, a second firmware acquisition request, which is a firmware acquisition request indicating the second encryption method, to the storage device when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number; An information communication device characterized by the above.
2. The communication unit transfers the first encrypted firmware or the second encrypted firmware to the information processing device. The information communication device according to claim 1, characterized by the above.
3. A connection unit that receives the connection of a portable storage device; An input unit that receives an input of an instruction on whether to store the first encrypted firmware or the second encrypted firmware in the portable storage device; further comprising: When an instruction to store the first encrypted firmware or the second encrypted firmware in the portable storage device is input, the firmware acquisition unit stores the first encrypted firmware or the second encrypted firmware in the portable storage device via the connection unit. When an instruction not to store the first encrypted firmware or the second encrypted firmware in the portable storage device is input, the firmware acquisition unit transfers the first encrypted firmware or the second encrypted firmware to the information processing device via the communication unit. The information communication device according to claim 1, characterized in that.
4. A computer, A communication unit that communicates with a storage device that stores second firmware and an information processing device that acquires the second firmware, A firmware release confirmation unit that acquires the version number of the second firmware from the storage device via the communication unit by transmitting a request to acquire the version number of the second firmware to the storage device via the communication unit, A firmware version confirmation unit that acquires the version number of the first firmware, which is the firmware set in the information processing device, from the information processing device via the communication unit by transmitting a request to acquire the version number of the first firmware to the information processing device via the communication unit, and When the version number of the first firmware is older than a predetermined version number, a first firmware acquisition request, which is a firmware acquisition request indicating a first encryption method corresponding to the first firmware, is transmitted to the storage device via the communication unit, and the first encrypted firmware obtained by encrypting the second firmware with the first encryption method is acquired. When the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is equal to or newer than the predetermined version number, a second firmware acquisition request, which is a firmware acquisition request indicating a second encryption method newer than the first encryption method, is transmitted to the storage device via the communication unit, and the second encrypted firmware obtained by encrypting the second firmware with the second encryption method is acquired. Function as a firmware acquisition unit. A program characterized by that.
5. A firmware update system comprising a storage device that stores second firmware, an information communication device, and an information processing device that acquires the second firmware via the information communication device, wherein the storage device when the version number of the first firmware, which is the firmware set in the information processing device, is older than a predetermined version number, encrypts the second firmware with a first encryption method corresponding to the first firmware, and when the version number of the first firmware is the predetermined version number or newer than the predetermined version number, encrypts the second firmware with a second encryption method newer than the first encryption method; an encryption unit a first communication unit that sends the encrypted second firmware to the information communication device characterizes the firmware update system
6. the information communication device a second communication unit that communicates with the storage device and the information processing device a firmware release confirmation unit that acquires the version number of the second firmware from the storage device via the second communication unit by sending a request for acquiring the version number of the second firmware to the storage device via the second communication unit a firmware version confirmation unit that acquires the version number of the first firmware from the information processing device via the second communication unit by sending a request for acquiring the version number of the first firmware to the information processing device via the second communication unit when the version number of the first firmware is older than the predetermined version number, sends a first firmware acquisition request, which is a firmware acquisition request indicating the first encryption method, to the storage device via the second communication unit, and when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, sends a second firmware acquisition request, which is a firmware acquisition request indicating the second encryption method, to the storage device via the second communication unit; a firmware acquisition unit When the encryption unit receives the first firmware acquisition request via the first communication unit, it encrypts the second firmware using the first encryption method, and when it receives the second firmware acquisition request via the first communication unit, it encrypts the second firmware using the second encryption method The firmware update system according to claim 5, characterized in that
7. The firmware acquisition unit acquires the encrypted second firmware via the second communication unit, and transfers the encrypted second firmware to the information processing device via the second communication unit The information processing device A third communication unit that communicates with the information communication device A key processing unit that receives the encrypted second firmware via the third communication unit, decrypts the encrypted second firmware, and acquires the second firmware A firmware update unit that updates the first firmware using the second firmware, comprising The firmware update system according to claim 6, characterized in that
8. The information communication device A first connection unit that receives a connection of a portable storage device An input unit that receives an input of an instruction on whether to store the encrypted second firmware in the portable storage device, further comprising When an instruction to store the encrypted second firmware in the portable storage device is input, the firmware acquisition unit stores the encrypted second firmware in the portable storage device via the first connection unit, and when an instruction not to store the encrypted second firmware in the portable storage device is input, the firmware acquisition unit transfers the encrypted second firmware to the information processing device via the communication unit The information processing device A third communication unit that communicates with the information communication device A second connection unit that receives a connection of the portable storage device When the encrypted second firmware is received via the third communication unit, or when the encrypted second firmware is read from the portable storage device via the second connection unit, a key processing unit that decrypts the encrypted second firmware and acquires the second firmware A firmware update unit that updates the first firmware using the second firmware The firmware update system according to claim 6, characterized in that
9. The information communication device A second communication unit that communicates with the storage device and the information processing device By transmitting a request to obtain the version number of the second firmware to the storage device via the second communication unit, obtaining the version number of the second firmware from the storage device via the second communication unit, and transferring the version number of the second firmware to the information processing device via the second communication unit, a firmware release confirmation unit Receiving, from the information processing device, a firmware acquisition request indicating the version number of the first firmware via the second communication unit, and transferring the firmware acquisition request to the storage device via the second communication unit, a firmware acquisition unit The information processing device A third communication unit that communicates with the information communication device Receiving the version number of the second firmware via the third communication unit, and when the version number of the first firmware is older than the version number of the second firmware, transmitting the firmware acquisition request to the information communication device via the third communication unit, a firmware version number management unit When the version number of the first firmware indicated by the firmware acquisition request is older than the predetermined version number, the encryption unit encrypts the second firmware using the first encryption method, and when the version number of the first firmware indicated by the firmware acquisition request is the predetermined version number or newer than the predetermined version number, encrypting the second firmware using the second encryption method The firmware update system according to claim 5, characterized in that
10. The information communication device A second communication unit that communicates with the storage device and the information processing device By transmitting a request to obtain the version number of the second firmware to the storage device via the second communication unit, obtaining the version number of the second firmware from the storage device via the second communication unit, and transferring the version number of the second firmware to the information processing device via the second communication unit, a firmware release confirmation unit When the version number of the first firmware is older than the predetermined version number, a first firmware acquisition request, which is a firmware acquisition request indicating the first encryption method, is received from the information processing apparatus via the second communication unit, and the first firmware acquisition request is transferred to the storage device via the second communication unit. When the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, a second firmware acquisition request, which is a firmware acquisition request indicating the second encryption method, is received from the information processing apparatus via the second communication unit, and the second firmware acquisition request is transferred to the storage device via the second communication unit. A firmware acquisition unit is provided. The information processing apparatus A third communication unit that communicates with the information communication apparatus Receives the version number of the second firmware via the third communication unit. When the version number of the first firmware is older than the predetermined version number, the first firmware acquisition request is transmitted to the information communication apparatus via the third communication unit. Thus, when the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, the second firmware acquisition request is transmitted to the information communication apparatus via the third communication unit. A firmware version number management unit is provided. When the first firmware acquisition request is received via the first communication unit, the encryption unit encrypts the second firmware using the first encryption method. When the second firmware acquisition request is received via the first communication unit, the encryption unit encrypts the second firmware using the second encryption method. The firmware update system according to claim 5, characterized in that.
11. The firmware acquisition unit acquires the encrypted second firmware via the second communication unit and transfers the encrypted second firmware to the information processing apparatus via the second communication unit. The information processing apparatus A key processing unit that receives the encrypted second firmware via the third communication unit, decrypts the encrypted second firmware, and obtains the second firmware; A firmware update unit that updates the first firmware using the second firmware, and further comprising The firmware update system according to claim 9 or 10, characterized in that
12. A firmware update method performed by an information communication device that communicates with a storage device that stores second firmware and an information processing device that obtains the second firmware, comprising: By sending a request to obtain the version number of the second firmware to the storage device, obtaining the version number of the second firmware from the storage device; By sending a request to obtain the version number of the first firmware, which is the firmware set in the information processing device, to the information processing device, obtaining the version number of the first firmware from the information processing device; When the version number of the first firmware is older than a predetermined version number, by sending a first firmware acquisition request, which is a firmware acquisition request indicating the first encryption method corresponding to the first firmware, to the storage device, obtaining the first encrypted firmware obtained by encrypting the second firmware with the first encryption method; When the version number of the first firmware is older than the version number of the second firmware and the version number of the first firmware is the predetermined version number or newer than the predetermined version number, by sending a second firmware acquisition request, which is a firmware acquisition request indicating a second encryption method newer than the first encryption method, to the storage device, obtaining the second encrypted firmware obtained by encrypting the second firmware with the second encryption method A firmware update method, characterized in that
Citation Information
Patent Citations
Secure software update
JP2009503698A