Information processing device, network setting method, and program

The information processing device addresses the oversight of disabling server functions in LAN-less environments by incorporating settings to enable/disable server functions and secure communications, effectively reducing network attack risks.

JP2025107064APending Publication Date: 2025-07-17CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024000805
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-05
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

When connecting an information device with an enabled server function to a LAN-less environment, administrators may overlook the need to disable the server function, increasing the risk of network attacks.

Method used

The information processing device includes server function setting means to enable or disable the server function, connection destination setting means to determine network environments where the server function is not used, and first setting change means to disable the server function when connected to such environments, along with filter setting and filtering means to secure communications.

Benefits of technology

Enables administrators to recognize and restrict server function use, reducing the risk of network attacks by ensuring the server function is disabled in LAN-less environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025107064000001_ABST
    Figure 2025107064000001_ABST
Patent Text Reader

Abstract

To provide an information processing device for setting restriction of usage of a server function in order to deal with a difficulty for an administrator of the information processing device to know that it is necessary to restrict usage of the server function in a case in which an information appliance for which the server function is valid is connected to a LAN-less environment in an initial state.SOLUTION: An information processing device of the present invention includes: server function setting means having a server function and configured to perform setting as to whether the server function is valid or invalid; connection destination setting means for performing setting as to whether to connect the information processing device to a network environment in which the server function is not used; and first setting changing means for performing setting for making the server function invalid in the server setting means in a case in which setting of connecting the information processing device to the network environment in which the server function is not used is performed by the connection destination setting means.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus connected to and used on a network, a network setting method, and a program.

Background Art

[0002] In recent years in offices, there has been a trend (cloud shift) to replace business systems such as storage, mail servers, and applications previously prepared on the in-house network with cloud services. Also, companies that implement all business systems with cloud services have emerged due to the cloud shift.

[0003] When all business systems in a company are in cloud services, each information device connected to the in-house network only communicates with various cloud services as a client, and the employees of the company can perform their work. Therefore, a server function is not required for each information device. Such a network environment is hereinafter referred to as a "LAN-less environment".

[0004] By the way, information devices connected to a network are at risk of being attacked via the network. As a countermeasure against attacks from the network, a method of reducing the risk of being attacked by limiting the available server functions to the minimum necessary is common. For example, Patent Document 1 discloses a method of limiting the available server functions for a communication interface to the minimum necessary using a network filter function.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] Some information devices with server functions have the initial state of the server function enabled for convenience during installation.

[0007] On the other hand, when connecting an information device with a server function to a LAN-less environment, in order to reduce the risk of attacks from the network, it is desirable to make the server function unavailable by using techniques such as applying a network filter to the aforementioned communication interface. In this case, since it is a measure to limit the functions of the information device, it is desirable for the administrator of the information device to perform a setting to limit the use of the server function.

[0008] However, when connecting an information device with the server function initially enabled to a LAN-less environment, the administrator of the information device may not notice the need to limit the use of the server function. In such a case, since the server function of the information device is not disabled, there is a problem that it is not desirable from the perspective of the risk of attacks via the network. An object of the present invention is to limit the use of the server function when connecting an information device with the server function enabled in the initial state to a LAN-less environment.

Means for Solving the Problem

[0009] The information processing apparatus of the present invention has a server function, and includes server function setting means for setting whether the server function is enabled or disabled, connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, and first setting change means for setting the server setting means to disable the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used.

[0010] In addition, the information processing apparatus of the present invention has a server function, and includes connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, filter setting means for setting whether to perform filtering on communication with a network, filter means for performing filtering on communication with the network based on the filter setting, and second setting change means for setting the filter setting means to perform filtering on communication with the network when it is set by the connection destination setting means to connect to a network environment where the server function is not used.

Effect of the Invention

[0011] According to the present invention, the administrator of the information device can recognize that it is necessary to restrict the use of the server function of the information device connected to the LAN-less environment, and can restrict the use of the server function. As a result, when the administrator connects the information device to the LAN-less environment, the administrator can restrict the use of the server function and reduce the risk of being attacked via the network.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Mode for Carrying Out the Invention

[0013] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are given the same reference numerals, and duplicate descriptions are omitted.

[0014] <First Embodiment> In this embodiment, an example of controlling the network settings of an MFP (Multi-Function Peripheral) having two communication lines, namely a main line and a sub-line, will be described. Although the MFP is taken as an example for description, the present invention is not limited to the MFP, and may be an information processing apparatus that provides other functions. Also, here, an MFP having two communication lines is taken as an example for description, but the present invention is a technology applicable to an MFP having one or more communication lines. Further, here, physically different communication lines are taken as an example for description, but the present invention is a technology applicable to virtually separated communication lines using a virtual network interface.

[0015] [System Configuration] Referring to FIG. 1, the network connection configuration of the MFP, client terminal, and gateway according to this embodiment will be described. The MFP 100 is connected to two communication lines, namely the network 110 and the network 120. The network 110 is connected to the Internet. On the other hand, the network 120 is a normal LAN. The MFP 100 and the client terminal 111 are respectively connected to the network 110 and can communicate with each other. Also, it can communicate with the Internet via the gateway 112. Further, the MFP 100 and the client terminal 121 are communicably connected to each other via the network 120.

[0016] The MFP100 is a multi-functional device having multiple functions such as a scanner and a printer, and can transmit and receive data with the client terminals 111 and 121, and can also transmit and receive data with a cloud service (not shown) connected via the Internet. The client terminals 111 and 121 are, for example, personal computers or smartphones, and can transmit a print request to the MFP100 and can also transmit and receive data with a cloud service (not shown) connected via the Internet. The gateway 112 is a network router that relays communication from the MFP100 and the client terminal 111 to and from the Internet. The networks 110 and 120 are communication networks. The network can be either wired or wireless as long as data transmission and reception are possible.

[0017] In the following description, it is assumed that the MFP100 and the client terminal 111 only transmit and receive data with a cloud service (not shown) connected via the Internet without using the server function of the information device connected to the network 110. Also, it is assumed that there are no information devices that use the server function of the MFP100 via the network 110, including the client terminal 111. That is, the network environment composed of the MFP100, the network 110, the client terminal 111, the gateway 112, and the Internet is the LAN-less environment in this embodiment.

[0018] [Hardware Configuration of MFP] Referring to FIG. 2, the hardware configuration of the MFP 100 will be described. The MFP 100 is composed of a control unit 200, an operation unit 209, a printer unit 210, a scanner unit 211, and wired LAN devices 212 and 213. The control unit 200 is composed of a CPU 201, a ROM 202, a RAM 203, an HDD 204, an operation unit I / F 205, a printer I / F, a scanner I / F, and a network I / F 208, and controls the overall operation of the MFP 100. The CPU 201 reads out the control program stored in the ROM 202 and executes and controls various functions of the MFP 100 such as reading / printing / communication. The RAM 203 is used as a temporary storage area such as the main memory and work area of the CPU 201. In this embodiment, it is assumed that one CPU 201 executes each process shown in the following flowchart using one memory (RAM 203 or HDD 204), but it is not limited to this. For example, a plurality of CPUs, a plurality of RAMs, or HDDs may cooperate to execute each process.

[0019] The HDD 204 is a large-capacity storage unit that stores image data and various programs. The operation unit I / F 205 is an interface that connects the operation unit 209 and the control unit 200. The operation unit 209 is provided with a touch panel, a keyboard, etc., and receives operations / inputs / instructions from the user. The printer I / F 206 is an interface that connects the printer unit 210 and the control unit 200. Print image data is transferred from the control unit 200 to the printer unit 210 via the printer I / F 206 and printed on a recording medium. The scanner I / F 207 is an interface that connects the scanner unit 211 and the control unit 200. The scanner unit 211 reads a document set on a document table or ADF (Auto Document Feeder) (not shown) to generate image data and inputs it to the control unit 200 via the scanner I / F 207. The MFP 100 can print (copy) the image data generated by the scanner unit 211 from the printer unit 210 and can also send an email.

[0020] The network I / F 208 is an interface that connects the control unit 200 (MFP 100) to the wired devices 212 and 213. In this embodiment, it will be described in a form where two wired LAN devices 212 and 213 are connected to the network I / F 208. However, it is not limited to this, and the present invention is also applicable to other LAN devices such as wireless LAN devices and LAN devices connected to USB (Universal Serial Bus), and other connection forms. The control unit 200 realizes communication on the network 110 by controlling the wired LAN device 212 via the network I / F 208. Also, the control unit 200 realizes communication on the LAN 120 by controlling the wired LAN device 213.

[0021] [Software Configuration] Referring to FIG. 3, the software configuration executed by the control unit 200 of the MFP 100 will be described. Each function of the software executed by the control unit 200 is realized by the CPU 201 reading the control program stored in the ROM 202 or the HDD 204 into the RAM 203 and executing it.

[0022] The display control unit 301 executes display of a user-oriented screen on the operation unit 209 of the MFP 100, detection of user operations, and processing associated with screen components such as buttons displayed on the screen. The data storage unit 302 stores and reads various data in the HDD 204 or the ROM 202 based on requests from other control units. For example, when a user wants to change some device settings, the display control unit 301 detects and acquires the content input by the user on the operation unit 209, and based on a request from the display control unit 301, the data storage unit 302 saves it as a set value in the HDD 204.

[0023] The network control unit 303 issues instructions for network settings such as IP addresses to the TCP / IP control unit 304 at system startup or when a setting change is detected, in accordance with the set values stored in the data storage unit 302. The TCP / IP control unit 304 performs transmission and reception processing of network packets via the network I / F 208 in accordance with instructions from other controls. The network filter control unit 305 performs filtering processing on the packets transmitted and received according to the instructions of the TCP / IP control unit 304.

[0024] The main-line network filter table 306 and the sub-line network filter table 307 hold rules for the network filter control unit 305 to determine whether to accept or discard the target packets. In the description of this embodiment, it is assumed that the rules are predefined.

[0025] Here, with reference to FIG. 8, the rules used for the determination of packet filtering processing will be described. The main-line network filter table 306 and the sub-line network filter table 307 hold the information shown in FIG. 8. The network filter table 800 is a table that exists for each line. In this embodiment, the main-line network filter table 306 is the filter table for the main line, and the sub-line network filter table 307 is the filter table for the sub line.

[0026] In the network filter table 800, two types of values, "Deny / Allow" or "Allow / Deny", are specified for the filter policy 801. In the case of "Deny / Allow", it is a whitelist method that prohibits all communications and then allows those that match the exception specification. In the case of "Allow / Deny", it is a blacklist method that allows all communications and then prohibits those that match the exception specification. The exception specification 802 is data in a list format that enumerates exception rules consisting of an "IP address range", "receiving port number", and "protocol". The "IP address range" specifies the range of IP addresses to which the exception rule applies. The "receiving port number" specifies the port number to which the exception rule applies or "ANY" indicating all port numbers. The "protocol" specifies the protocol to which the exception rule applies from "TCP" or "UDP".

[0027] Return to the description of FIG. 3. The LPD control unit 308 controls the LPD server function according to an instruction from the network control unit 303. Specifically, by communicating using the Line Printer Daemon Protocol (LPD protocol) as an LPD server, a print request is received from a client terminal such as the client PC 121. In this embodiment, the LPD protocol is taken as an example of the server function related to printing, but the MFP 100 may also have server functions of other protocols. For example, protocols related to printing include, in addition to LPD, RAW, SMB (Server Message Block), HTTP (Hypertext Transfer Protocol), etc. Also, protocols related to the management of the MFP include SNMP (Simple Network Management Protocol), mDNS (multicast DNS), etc.

[0028] [Screen Configuration] Hereinafter, with reference to FIGS. 4 to 7, an example of the screen configuration according to this embodiment will be described. Note that the screen configuration and screen transition shown below are examples, and other configurations may also be possible. FIG. 4(a) shows a configuration example of the menu screen 400 displayed on the operation unit 209 and is for the user to instruct the execution of various functions of the MFP 100. The copy button 401 is used for the user to instruct the copy function. The scan and save button 402 is used for the user to instruct the function of scanning and saving. The scan and send button 403 is used for the user to instruct the function of scanning and sending. The setting button 404 is used for the user to instruct the change of device settings. When the setting button 404 is operated, the setting screen 410 shown in FIG. 4(b) is displayed. The status line 405 displays a message indicating the status such as the remaining amount of consumables of the MFP running out or the occurrence of an error, and is used to notify the user of the status of the MFP 100.

[0029] FIG. 4(b) shows a configuration example of the setting screen 410 displayed on the operation unit 209 and is for the user to instruct various settings. There are no specific setting items on the setting screen 410 itself, and it is an intermediate layer that serves as a guide to detailed setting items. When the network setting button 411 is operated, the network setting screen 500 shown in FIG. 5(a) is displayed. When the device setting button 412 is operated, a device setting screen (not shown) is displayed. When the user setting button 413 is operated, a user setting screen (not shown) is displayed. The method of device setting using the device setting screen and the method of user setting using the user setting screen are not particularly limited.

[0030] FIG. 5(a) shows a configuration example of a network setting screen 500 displayed on the operation unit 209, which is an intermediate layer for a user to perform various network settings. When the interface selection button 503 is operated, an interface selection setting screen 510 shown in FIG. 5(b) is displayed. When the LPD setting button 504 is operated, an LPD setting screen 520 shown in FIG. 5(c) is displayed. When the main line setting button 501 is operated, a main line setting screen 600 shown in FIG. 6(a) is displayed. When the sub-line setting button 502 is operated, a sub-line setting screen 700 shown in FIG. 7(a) is displayed. When the setting reflection button 505 is operated, after the settings selected by the user are stored in the data storage unit 302, an instruction to reflect the settings is given to the network control unit 303.

[0031] FIG. 5(b) shows a configuration example of the interface selection setting screen 510 according to the present embodiment, and the user can select whether the communication line used by the MFP 100 is one or two. When the OK button 513 is operated, the setting content of the interface selection setting screen 510 is saved in the data storage unit 302. As described above, two types of communication lines, the main line and the sub-line, are available as the communication lines according to the present embodiment. When "main line only" 511 is selected on the interface selection setting screen 510, only the wired LAN device 212 is activated. When "main line + sub-line" 512 is selected, the wired LAN device 212 and the wired LAN device 213 are activated simultaneously. In the present embodiment, a configuration in which only the wired LAN device 213 is activated (a configuration in which only the sub-line is activated) is not provided, but the present invention is applicable even if such a configuration is provided.

[0032] When "main line + sub-line" 512 is selected, the wired LAN device 212 is set as the main line and the wired LAN device 213 is set as the sub-line. The difference between the main line and the sub-line is, for example, that the priorities are different when one of them has to stop operating. Specifically, when the same IP address is assigned to both the main line and the sub-line, they cannot operate simultaneously. Therefore, the network control unit 303 controls to invalidate the sub-line so that the main line can continue operating. In addition, when a functional difference is required due to communication protocols or application constraints, the functions of the main line and the sub-line are different. Note that this embodiment is not limited to the classification of the main line and the sub-line. For example, in the case of a device corresponding to more lines (communication interfaces), different operations may be defined according to the uses of each line. Also, in this embodiment, the main line is described as being connected to the above-mentioned LAN-less environment. Note that the line connected to the LAN-less environment is not limited to the main line, and the present invention is also applicable when the sub-line is connected to the LAN-less environment.

[0033] FIG. 5(c) shows a configuration example of the LPD setting screen 520 displayed on the operation unit 209 and is used for the user to instruct the setting of the LPD server function. The LPD activation state specifying unit 521 specifies whether to enable or disable the LPD server function of the MFP 100. The enable / disable setting here is an alternative setting item. When the LPD setting is enabled, it indicates that the LPD server function is available in the MFP 100. When the OK button 522 is operated, the items selected on the LPD setting screen 520 are saved in the data storage unit 302. Note that in this embodiment, the LPD function is described as an example. However, when the MFP 100 has other server functions in addition to the LPD function, it goes without saying that a setting screen for setting the enable / disable of the server function is provided in the same manner as the LPD setting screen 520.

[0034] FIG. 6(a) shows a configuration example of the main line setting screen 600 displayed on the operation unit 209, which is an intermediate layer for setting the main line. When the IP address setting button 601 is operated, the main line IP address setting screen 610 shown in FIG. 6(b) is displayed. When the LAN-less setting button 602 is operated, the main line LAN-less setting screen 620 shown in FIG. 6(c) is displayed. When the network filter setting button 603 is operated, the main line network filter setting screen 630 shown in FIG. 6(d) is displayed.

[0035] FIG. 6(b) shows a configuration example of the main line IP address setting screen 610 displayed on the operation unit 209, which is used for the user to instruct IP address-related settings for the main line. The IP address input section 611 allows the user to input an arbitrary IP address as the IP address for the main line. The subnet mask input section 612 allows the user to input an arbitrary subnet mask as the subnet mask for the main line. The default gateway input section 613 allows the user to input an arbitrary default gateway as the default gateway for the main line. In this embodiment, the IP address of the gateway 112 is input as the value of the default gateway input section 613. When the OK button 614 is operated, the values of the items selected on the main line setting screen 610 are saved in the data storage unit 302.

[0036] FIG. 6(c) shows a configuration example of the main line LAN-less setting screen 620 displayed on the operation unit 209, which is used for the user to instruct whether the network environment to which the main line is connected is a LAN-less environment and related settings. The LAN-less setting section 621 specifies whether the network environment to which the main line is connected is a LAN-less environment. The valid / invalid setting here is an alternative setting item. When set to valid, it indicates that the main line is connected to a LAN-less environment. When the OK button 622 is operated, the items selected on the main line LAN-less setting screen 620 are saved in the data storage unit 302.

[0037] FIG. 6(d) shows a configuration example of the main line network filter setting screen 630 displayed on the operation unit 209, and is used for the user to instruct the setting of the network filter for the main line. In the main line network filter setting screen 630, an initial value is set and presented, and the user can change the value. The active state designating unit 631 designates whether to enable or disable the setting of the network filter for the main line. The enable / disable setting here is an alternative setting item. When it is disabled, it means receiving all network packets without discarding them. When it is enabled, network filter processing for the main line is performed according to the rules specified on the main line network filter setting screen 630. The filter policy designating unit 632 allows the user to specify the filter policy described with reference to FIG. 8 for the main line. The "Deny / Allow" / "Allow / Deny" setting here is an alternative setting item. The network filter rule 633 is an area for displaying and inputting the exception designation currently set for the main line. The exception designation here corresponds to that described with reference to FIG. 8. When the OK button 634 is operated, the items selected on the main line network filter setting screen 630 are stored in the data storage unit 302.

[0038] FIG. 7(a) shows a configuration example of the secondary line setting screen 700 displayed on the operation unit 209, and is an intermediate layer for setting the secondary line. When the IP address setting button 701 is operated, the secondary line IP address setting screen 710 shown in FIG. 7(b) is displayed. When the LAN-less setting button 702 is operated, the secondary line LAN-less setting screen 720 shown in FIG. 7(c) is displayed. When the network filter setting button 703 is operated, the secondary line network filter setting screen 730 shown in FIG. 7(d) is displayed.

[0039] FIG. 7(b) shows a configuration example of a secondary line IP address setting screen 710 displayed on the operation unit 209 and is used for the user to instruct IP address-related settings for the secondary line. The IP address input unit 711 allows the user to input an arbitrary IP address as the IP address for the secondary line. The subnet mask input unit 712 allows the user to input an arbitrary subnet mask as the subnet mask for the secondary line. When the OK button 713 is operated, the values of the items selected on the secondary line setting screen 710 are stored in the data storage unit 302.

[0040] FIG. 7(c) shows a configuration example of a secondary line LAN-less setting screen 720 displayed on the operation unit 209 and is used for the user to instruct whether the network environment to which the secondary line is connected is a LAN-less environment and related settings. The LAN-less setting unit 721 designates whether the network environment to which the secondary line is connected is a LAN-less environment. The valid / invalid setting here is an alternative setting item. When set to valid, it indicates that the secondary line is connected to a LAN-less environment. When the OK button 722 is operated, the items selected on the secondary line LAN-less setting screen 720 are stored in the data storage unit 302.

[0041] FIG. 7(d) shows a configuration example of a secondary line network filter setting screen 730 displayed on the operation unit 209, which is used for the user to instruct the setting of the network filter for the secondary line. In the secondary line network filter setting screen 730, an initial value is set and presented, and the user can change the value. The active state designating unit 731 designates whether to enable or disable the setting of the network filter for the secondary line. The enable / disable setting here is an alternative setting item. When it is disabled, it means receiving all network packets without discarding them. When it is enabled, network filter processing for the secondary line is performed according to the rules specified on the secondary line network filter setting screen 730. The filter policy designating unit 732 allows the user to specify the above-described filter policy for the secondary line. The "Deny / Allow" / "Allow / Deny" setting here is an alternative setting item. The network filter rule 733 is an area for displaying and inputting the currently set exception designation for the secondary line. The exception designation here corresponds to that described with reference to FIG. 8. When the OK button 734 is operated, the items selected on the secondary line network filter setting screen 730 are stored in the data storage unit 302.

[0042] [Security Policy Setting] Here, the security policy will be described. The security policy is the basic policy regarding the security of the entire organization, the security countermeasure standards, the individual specific implementation procedures, etc. As one of the security policies of a device having a server function, there is port control (port usage policy) of the server function. In the port usage policy, it is common to formulate and operate a policy that prohibits the use of server functions not used to reduce the risk of attacks from the network. Even in an MFP having a server function, when used in an organization that formulates and operates the above-described port usage policy, operation in accordance with the port usage policy is required.

[0043] Return to the description of the embodiment. Referring to FIG. 9, the setting of the security policy will be described. FIG. 9 shows a configuration example of a port usage policy setting screen 900 based on the security policy displayed on the operation unit 209. The port usage policy setting screen 900 is used for the user to instruct the MFP 100 on whether to enable the use of server functions based on the port usage policy of the organization. The policy specifying unit 901 specifies whether to prohibit the use of each server function of the MFP 100. Checking the check box of each server function item indicates that the use of the corresponding server function is prohibited. For example, in FIG. 9, when setting to prohibit LPD, the activation state designation of the server function such as the LPD activation state designation unit 521 is changed to "invalid". Also, the instruction on whether to enable the use of server functions according to the security policy takes precedence over the designation of the validity of the server functions. In FIG. 9, when setting to prohibit LPD, it becomes impossible to set it to valid in the validity setting of the LPD setting in FIG. 5. When the OK button 902 is operated, the items selected on the port usage policy setting screen 900 are saved in the data storage unit 302.

[0044] In an organization using the MFP 100, the permission and prohibition of the use of various server functions may be defined in the security policy. In such a case, by setting the policy specifying unit 901, it is possible to set the MFP 100 on whether to enable the use of server functions based on the security policy of the organization. If the security policy is set, it takes precedence over the setting of the server functions. Also, when the communication line used by the MFP 100 is the main line / secondary line, if the server function is disabled in the server function setting, the server function will also become invalid for lines other than the LAN-less operation. Therefore, instead of disabling it in the server function setting, it is necessary to set network filters individually for the main line / secondary line to block communication to the MFP 100 and limit the use of the server function.

[0045] When operating the MFP100 in the LAN-less mode, there are three methods to restrict the use of server functions. They are the permission and prohibition of using server functions according to security policies, the enable / disable setting in the server function settings, and the blocking of communication to the MFP100 by setting the network filter. In the previous explanations, the user has set the LAN-less setting to be enabled or disabled. However, as a security policy, the LAN-less mode (server function disabled) can also be set. Also, the blocking of communication can be achieved not only by setting the server function and the network filter, but also by applying reception rejection in the firewall settings.

[0046] [Processing Flow in the First Embodiment] (LAN-less Setting Process) Using FIG. 10, the LAN-less setting process for each communication line of the MFP100 according to this embodiment will be described. Each operation (step) shown in the flowchart of FIG. 10 is realized by the CPU 201 of the MFP100 reading the control program stored in the ROM 202 or the HDD 204 into the RAM 203 and executing it. Hereinafter, the step numbers of each process included in the flowchart are indicated by numbers starting with "S". The same applies to the following flowcharts.

[0047] Due to the operation of the OK button 622 on the main line LAN-less setting screen 620 shown in FIG. 6(c) (hereinafter referred to as the change of the main line LAN-less setting), and the operation of the OK button 722 on the sub-line LAN-less setting 720 shown in FIG. 7(c) (hereinafter referred to as the change of the sub-line LAN-less setting), the communication line for which the LAN-less setting is changed (hereinafter described as the target line) is given as an input and this processing flow is started. Note that this processing flow may be executed for each line selected on the interface selection screen 510 as the target line before performing the startup process described in FIG. 13.

[0048] In S1001, the MFP 100 determines whether the LAN-less setting of the target line is "valid". When making the determination, the network control unit 303 refers to the value corresponding to the LAN-less setting unit (621 when the target line is the main line, 721 when the target line is the sub-line) of the setting value stored in the data storage unit 302. If it is determined to be valid (YES in S1001), the process proceeds to S1002. If it is determined to be invalid (NO in S1001), this processing flow ends.

[0049] In S1002, the MFP 100 determines whether the number of communication lines used by the MFP 100 is one or two or more. When the communication lines used by the MFP 100 are the main line and the sub-line, if the server function is disabled in the server function setting, the server function will also be disabled for lines other than LAN-less operation. Therefore, it is necessary to limit the use of the server function by setting network filters individually for the main line and the sub-line to block communication instead of disabling it in the server function setting. When making the determination, the network control unit 303 refers to the value corresponding to the content of the interface selection screen 510 of the setting value stored in the data storage unit 302. If "only main line" 511 is selected, it is determined as "one". If "main line + sub-line" 512 is selected, it is determined as "plural". If it is determined to be "one" (YES in S1002), the process proceeds to S1003. If it is determined to be "plural" (NO in S1002), the process proceeds to S1008.

[0050] In S1003, the MFP 100 determines whether a security policy is set. If a security policy is set, the setting of prohibiting the server function in the port usage policy setting of the security policy takes precedence over the setting of the server function. When making the determination, the network control unit 303 refers to the value corresponding to the policy designating unit 901 of the port usage policy setting among the settings stored in the data storage unit 302. If at least one of the setting items of the policy designating unit 901 is "valid", it is determined that a security policy is set. If it is determined that a security policy is set (YES in S1003), the process proceeds to S1004, and if it is determined that it is not set (NO in S1003), the process proceeds to S1005. In S1004, the MFP 100 displays the security policy setting review recommendation screen 1100. As a display method, the network control unit 303 requests the display control unit 301 to display the security policy setting review recommendation screen 1100 on the operation unit 209. Then, this processing flow ends.

[0051] Here, the review recommendation screen 1100 for security policy settings will be described with reference to FIG. 11. On the review recommendation screen 1100 for security policy settings, a message recommending a review of the security policy settings is displayed because the LAN-less setting is enabled. When the close button 1101 is operated, the review recommendation screen 1100 for security policy settings is closed. When the setting button 1102 is operated, it is possible to transition to the port usage policy setting screen 900 of FIG. 9. The setting button 1102 is an example of an operation object in the present invention. When a security policy is set in the MFP 100, the use permission and prohibition of each server function may be specified in the security policy of the organization using the MFP 100. When the LAN-less environment setting is set to "enabled", it is desirable to change the setting of the server function to be invalid so that the server function is not used. The user needs to check whether the setting change violates the security policy of the organization and then review the policy specification 901 of the port usage policy of the MFP 101. Therefore, in S1004, by displaying the review recommendation screen 1100 for security policy settings, the user can recognize that it is necessary to review the policy specification 901 of the port usage policy.

[0052] Return to the description of FIG. 10. In S1005, the MFP 100 displays a server function inactivation confirmation screen 1200. As a display method, the network control unit 303 requests the display control unit 301 to display the server function inactivation confirmation screen 1200 on the operation unit 209. Then, it proceeds to S1006. Here, the server function deactivation confirmation screen 1200 will be described with reference to FIG. 12. Since the LAN-less setting is effectively configured on the server function deactivation confirmation screen 1200, a message recommending the deactivation of the server function and a confirmation message for whether to deactivate the server function are displayed. When the Yes button 1201 is operated, the network control unit 303 is notified that the confirmation message has been approved, and the server function deactivation confirmation screen 1200 is closed. When the No button 1202 is operated, the network control unit 303 is notified that the confirmation message has been rejected, and the server function deactivation confirmation screen 1200 is closed.

[0053] Return to the description of FIG. 10. In S1006, the MFP 100 determines whether the deactivation confirmation of the server function has been approved. In the determination, the network control unit 303 waits for the Yes button 1201 and the No 1202 on the server function deactivation confirmation screen 1200 to be operated. If the Yes button 1201 is operated, it is determined as "approved". If the deactivation confirmation of the server function is approved (YES in S1006), the process proceeds to S1007; if it is rejected (NO in S1006), this processing flow ends.

[0054] In S1007, the MFP 100 sets the settings of each server function it holds to "invalid". As a setting method, the network control unit 303 changes the setting value corresponding to the LPD activation state designating unit 521 stored in the data storage unit 302 to "invalid". Then this processing flow ends. In this embodiment, the setting change of the LPD function is described as an example. However, if the MFP 100 has server functions other than LPD, the network control unit 303 changes the setting value corresponding to the setting item indicating the activation / inactivation of the server function (not shown) to "invalid". Thereby, when the LAN-less setting of the MFP 100 is effectively configured, the setting can be changed so that the server functions held by the MFP 100 become unavailable.

[0055] Next, the processing flow when the MFP100 uses a plurality of communication lines (NO in S1002) will be described. Each item of the setting item (for example, the LPD activation state specifying unit 521) for instructing the enable / disable of the server function in the present embodiment and the policy specifying unit 901 of the port usage policy is a setting item for controlling the enable / disable of the server function for all communication lines of the MFP100. Therefore, for example, it is not possible to control the availability of the server function for each line, such as the server function being unavailable on the main line and available on the sub-line. In the present embodiment, the network filter setting of the target line is used to control the availability of the server function for each line.

[0056] In S1008, the MFP100 displays the server function deactivation confirmation screen 1200. As a display method, the network control unit 303 requests the display control unit 301 to display the server function deactivation confirmation screen 1200 on the operation unit 209. Then, it proceeds to S1009. In S1009, the network control unit 303 determines whether the deactivation confirmation of the server function has been approved. In the determination, the network control unit 303 waits for the OK button 1201 and the Cancel button 1202 on the server function deactivation confirmation screen 1200 to be operated. If the OK button 1201 is operated, it is determined as "approved". If the deactivation confirmation of the server function is approved (YES in S1009), it proceeds to S1010, and if it is rejected (NO in S1009), this processing flow ends.

[0057] In S1010, the MFP100 sets the network filter setting of the target line to "enabled". As a setting method, the network control unit 303 sets the setting value corresponding to the activation state specifying unit (631 when the target line is the main line and 731 when the target line is the sub-line) of the network filter setting of the target line stored in the storage unit 302 to "enabled". Then, it proceeds to S1011. In S1011, the MFP 100 sets the filter policy setting of the target line to "Deny / Allow". As a setting method, the network control unit 303 sets the setting value corresponding to the filter policy designation unit of the target line (632 when the target line is the main line, 732 when the target line is the sub-line) stored in the storage unit 302 to "valid". Then, it proceeds to S1012.

[0058] In S1012, the MFP 100 deletes all exception designations made for the target line. As a deletion method, the network control unit 303 deletes the value corresponding to the network filter rule of the target line (633 when the target line is the main line, 733 when the target line is the sub-line) stored in the storage unit 302. Specifically, since the network filter rule is a list, all entries in the list are deleted. Then, this processing flow ends. Through the processing from S1010 to S1012, the network filter setting can be changed so that all network packets on the target line side are discarded.

[0059] (Startup Processing) Using FIG. 13, the startup of the LPD control unit 308 according to this embodiment, and the setting processing of the main line network filter table 306 and the sub-line network filter table 307 will be described. Each operation (step) shown in the flowchart of FIG. 13 is realized by the CPU 201 of the MFP 100 reading the control program stored in the ROM 202 or the HDD 204 into the RAM 203 and executing it. This processing flow starts at the time of system startup and due to the operation of the reflect button 505 for reflecting the settings of the network setting screen 500 shown in FIG. 5(a).

[0060] In S1301, the MFP 100 determines whether the LPD function is enabled. When making this determination, the network control unit 303 refers to the value corresponding to the LPD activation state designation unit 521 of the set value stored in the data storage unit 302. If it is determined to be enabled (YES in S1301), the process proceeds to S1302. If it is determined to be disabled (NO in S1302), the process proceeds to S1303.

[0061] In S1302, the MFP 100 starts the LPD server. Specifically, the network control unit 303 instructs the LPD control unit 308 to start the LPD server. The LPD control unit changes to a state of waiting for communication of the LPD protocol from the client by waiting for the TCP port 515. Then, the process proceeds to S1303. When the MFP 100 has a server function in addition to LPD, the network control unit 303 performs the activation process for each server function in the same manner as in S1301 and S1302.

[0062] Here, in the LAN-less setting process described with reference to FIG. 10, when S1007 has been executed, since all the server functions of the MFP 100 are set to be disabled, the server functions are not started in this processing flow. Therefore, when connecting the MFP 100 to a LAN-less environment, the MFP 100 can make the server functions unavailable and reduce the risk of attacks via the network.

[0063] In S1303, the MFP 100 determines whether the network filter of the main line is "enabled". When making this determination, the network control unit 303 refers to the value corresponding to the activation state designation unit 631 of the main line network filter setting screen 630 of the set value stored in the data storage unit 302. If it is determined to be enabled (YES in S1303), the process proceeds to S1304. If it is determined to be disabled (NO in S1303), the process proceeds to S1307.

[0064] In S1304, the MFP 100 sets the filter policy for the main line. As a setting method, the network control unit 303 obtains a value corresponding to the filter policy specifying unit 632 of the main line network filter setting screen 630 from the settings stored in the data storage unit 302, and registers it in the main line network filter table 306. Then, it proceeds to S1305.

[0065] In S1305, the MFP 100 checks whether there is an unprocessed exception specification. As a checking method, the network control unit 303 obtains a value corresponding to the network filter rule 633 from the settings stored in the data storage unit 302. Since the network filter rule 633 is an ordered list, network filter entries are obtained in order from the top. The network filter control unit 305 checks the processing status internally held on the RAM 203 to determine how far the list has been processed. If it is determined that there is an unprocessed network filter rule entry (YES in S1305), it proceeds to S1306; if it is determined that there is no unprocessed network filter entry (NO in S1305), it proceeds to S1307.

[0066] In S1306, the MFP 100 sets the exception specification for the main line. As a setting method, the network control unit 303 registers the network filter entry determined to be unprocessed in S1305 in the main line network filter table 306. Then, it returns to S1305.

[0067] Here, in FIG. 10, when the processing from S1010 to S1012 is executed for the main line, the filter policy "Deny / Allow" is set in the main line network filter table 306, and no exception specification is set. That is, all network packets for the main line will be discarded. As a result, when connecting the main line to a LAN-less environment, various server functions of the MFP 100 can be made unavailable on the main line side, and the risk of attacks via the network can be reduced.

[0068] Return to the description of FIG. 13. In S1307, the MFP 100 determines whether the network filter of the secondary line is "valid". When making the determination, the network control unit 303 refers to the value corresponding to the activation state designating unit 731 of the secondary line network filter setting screen 730 of the set values stored in the data storage unit 302. If it is determined to be valid (YES in S1307), the process proceeds to S1308. If it is determined to be invalid (NO in S1307), this process flow ends.

[0069] In S1308, the MFP 100 sets the filter policy of the main line. As a setting method, the network control unit 303 acquires the value corresponding to the filter policy designating unit 732 of the secondary line network filter setting screen 730 among the settings stored in the data storage unit 302, and registers it in the network filter table 307 for the secondary line. Then, the process proceeds to S1309.

[0070] In S1309, the MFP 100 checks whether there is an unprocessed exception specification. As a checking method, the network control unit 303 acquires the value corresponding to the network filter rule 733 among the settings stored in the data storage unit 302. Since the network filter rule 733 is a list with an order, the network filter entries are acquired in order from the top. Where the processing of the list reaches is determined by checking the processing status internally held by the network filter control unit 305 on the RAM 203. If it is determined that there is an unprocessed network filter rule entry (YES in S1309), the process proceeds to S1310. If it is determined that there is no unprocessed network filter entry (NO in S1309), this process flow ends.

[0071] In S1310, the MFP100 sets an exception specification for the secondary line. As a setting method, the network control unit 303 registers the network filter entry determined to be unprocessed in S1309 into the secondary line network filter table 307. Then, it returns to S1309.

[0072] Here, in FIG. 10, when the processes from S1010 to S1012 are executed for the secondary line, in the secondary line network filter table 307, the filter policy "Deny / Allow" is set and no exception specification is set. That is, all network packets for the secondary line will be discarded. Thereby, when connecting the secondary line to a LAN-less environment, various server functions of the MFP100 can be made unavailable on the secondary line side, and the attack risk via the network can be reduced.

[0073] As described above, according to the present embodiment, when connected to a LAN-less environment, a function that makes the server function unavailable in the LAN-less environment can be provided. Therefore, the user can appropriately invalidate the server function of the information device connected to the LAN-less environment and use the device with the attack risk via the network reduced.

[0074] <Second Embodiment> The second embodiment of the present invention will be described with reference to FIGS. 14 and 15. In this embodiment, an example in which an overwrite confirmation is made to the user when there is already an effective network filter setting in the step of changing the network filter setting in the first embodiment will be described. Note that descriptions of portions overlapping with the first embodiment will be omitted.

[0075] FIG. 14 shows the processing flow of this embodiment when the confirmation of invalidation of the server function is approved in S1009 of FIG. 10 (YES in S1009). In S1401, the MFP 100 determines whether the network filter of the target line is "valid". When making the determination, the network control unit 303 refers to the value corresponding to the active state designating unit 631 if the target line is the main line, or the active state designating unit 731 if the target line is the sub-line, among the set values stored in the data storage unit 302. If it is determined to be valid (YES in S1401), the process proceeds to S1402. If it is determined to be invalid (NO in S1401), this processing flow ends and the process proceeds to S1010 in FIG. 10.

[0076] In S1402, the MFP 100 checks the filter policy of the target line. When checking, the network control unit 303 refers to the value corresponding to the filter policy designating unit 632 or 732 of the target line among the set values stored in the data storage unit 302. If the filter policy of the target line is "Deny / Allow" (YES in S1402), the process proceeds to S1403. Otherwise (NO in S1402), the process proceeds to S1406.

[0077] In S1403, the MFP 100 determines whether there is an exception specification for the target line. In the determination, the network control unit 303 acquires the value corresponding to the network filter rule 633 or 733 of the target line among the settings stored in the data storage unit 302. Since the network filter rule is an ordered list, if a network filter entry is acquired, it is determined that there is an exception specification. If it is determined that there is an exception specification (YES in S1403), the process proceeds to S1404. If it is determined that there is none (NO in S1403), this processing flow ends.

[0078] In S1404, the MFP 100 displays an exception designation deletion confirmation screen 1500 for confirming with the user whether to delete the existing exception designation on the operation unit 209, and then proceeds to S1405. Here, the exception designation deletion confirmation screen 1500 will be described with reference to FIG. 15(a). On the exception designation deletion confirmation screen 1500, a confirmation message for whether to delete the exception designation of the network filter is displayed. When the Yes button 1501 is operated, the network control unit 303 is notified that the confirmation message has been approved, and the exception designation deletion confirmation screen 1500 is closed. When the No button 1502 is operated, the network control unit 303 is notified that the confirmation message has been rejected, and the exception designation deletion confirmation screen 1500 is closed.

[0079] Return to the description of FIG. 14. In S1405, the MFP 100 determines whether the confirmation message for whether to delete the existing exception designation has been approved. In the determination, the network control unit 303 waits for the Yes button 1501 and the No 1502 on the exception designation deletion confirmation screen 1500 to be operated. If the Yes button 1501 is operated, it is determined as "approved". If the confirmation message for whether to delete the existing exception designation has been approved (YES in S1405), this processing flow ends and proceeds to S1012 in FIG. 10. If it has been rejected (NO in S1405), this processing flow ends. That is, when the confirmation message has been approved, in S1012 of FIG. 10, the setting of the network filter is changed, and the network filter setting of the target line becomes such that the filter policy is "valid" and the exception designation is "none". Thus, the network filter setting can be changed so that all network packets on the target line side are discarded only when the user approves the confirmation message.

[0080] In S1406, the MFP 100 displays a filter policy change confirmation screen 1510 for confirming with the user whether to change the existing filter policy on the operation unit 209, and then proceeds to S1407. Here, the filter policy change confirmation screen 1510 will be described with reference to FIG. 15(b). On the filter policy change confirmation screen 1510, a confirmation message is displayed asking whether to change the filter policy of the network filter from "Allow / Deny" to "Deny / Allow" without exception specification. When the Yes button 1511 is operated, the network control unit 303 is notified that the confirmation message has been approved, and the exception specification deletion confirmation screen 1510 is closed. When the No button 1512 is operated, the network control unit 303 is notified that the confirmation message has been rejected, and the exception specification deletion confirmation screen 1510 is closed.

[0081] Return to the description of FIG. 14. In S1407, the MFP 100 determines whether the confirmation message for changing the filter policy of the network filter from "Allow / Deny" to "Deny / Allow" without exception specification has been approved. In the determination, the network control unit 303 waits for the Yes button 1511 and the No button 1512 on the exception specification deletion confirmation screen 1510 to be operated. If the Yes button 1511 is operated, it is determined as "approved". If it is approved (YES in S1407), this processing flow ends and proceeds to S1011 in FIG. 10. If it is rejected (NO in S1407), this processing flow ends. That is, when the confirmation message is approved, in S1011 and S1012 in FIG. 10, the settings of the network filter are changed, and the network filter settings for the target line become such that the filter policy is "valid" and there is no exception specification. Thereby, the network filter settings can be changed so that all network packets on the target line side are discarded only when the user approves the confirmation message.

[0082] <The Third Embodiment> A third embodiment of the present invention will be described. In this embodiment, an example will be described in which a LAN-less setting for a user to specify whether the network environment to which the MFP 100 is connected is a LAN-less environment is provided as one of the items in the security policy setting instead of the setting screen for each line.

[0083] FIG. 16 shows a configuration example of a connection destination environment policy setting screen 1600 based on the security policy displayed on the operation unit 209. The connection destination environment policy setting screen 1600 is used to give a user instruction to the MFP 100 on the usage policy in the connection destination environment of the MFP 100 in the organization. The LAN-less environment usage designation unit 1601 designates whether to apply the prohibition of using the server function to the MFP 100 as a usage policy for the LAN-less environment. Checking the checkbox indicates that the policy is applied. The target line designation unit 1602 designates the line to which the usage policy for the LAN-less environment is applied. Here, it is a setting item in which either or both of the main line and the sub-line can be selected. When the OK button 1603 is operated, the items selected on the connection destination environment policy setting screen 1600 are stored in the data storage unit 302. In this embodiment, the setting content selected on the connection destination environment policy setting screen 1600 takes precedence over the setting content of the port usage policy setting screen 900 described in FIG. 9.

[0084] In this embodiment, when the OK button 1603 is operated, the MFP 100 executes the processing flow of the LAN-less setting process described in FIG. 10 for each of the lines selected by the LAN-less environment usage designation unit 1601. In the LAN-less setting process flow in this embodiment, in S1002 of FIG. 10, when it is determined that the communication line used by the MFP 100 is one (YES in S1002), the process proceeds to S1005. This is because in this embodiment, since it is specified in the security policy setting that it is used in the LAN-less environment, it is not necessary to recommend a review of the security policy setting. As described above, according to the present embodiment, the invalidation of the server function to be performed when using the MFP 100 in a LAN-less environment can be set as a security policy in the MFP 100.

[0085] <Other Embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiment to a system or apparatus via a network or a storage medium, and causing one or more processors in the computer of the system or apparatus to read and execute the program. Further, it can also be realized by a circuit (for example, ASIC) that realizes one or more functions.

[0086] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, the claims are appended to disclose the scope of the invention.

[0087] The disclosure of this specification includes the following information processing apparatus, network setting method, and program. (Item 1) An information processing apparatus having a server function, server function setting means for setting whether the server function is enabled or disabled, connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, first setting change means for setting the server function setting means to disable the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used An information processing apparatus comprising: (Item 2) An information processing apparatus having a server function, connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, filter setting means for setting whether to perform filtering on communication with a network, Filtering means for performing filtering of communication with the network based on the filter setting; Second setting change means for setting the filter setting means to perform filtering of communication with the network when it is set by the connection destination setting means to connect to a network environment where the server function is not used; An information processing apparatus comprising the same. (Item 3) Further comprising first confirmation means for prompting the user to confirm whether to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; When the user approves the invalidation in the first confirmation means, the first setting change means sets the server function setting means to invalidate the server function. The information processing apparatus according to Item 1. (Item 4) Further comprising second confirmation means for prompting the user to confirm whether to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; When the user approves the invalidation in the second confirmation means, the second setting change means sets the filter setting means to perform filtering of communication with the network. The information processing apparatus according to Item 2. (Item 5) Third confirmation means for prompting the user to confirm whether to overwrite the existing filter setting when the second setting change means sets the filter setting means to perform filtering of communication with the network and the existing filter setting is valid; The information processing apparatus according to Item 2 or 4, further comprising the same. (Item 6) Security policy setting means for setting a security policy; When it is set to connect to a network environment where the server function is not used by the connection destination setting means and a security policy is set in the security policy setting means, a notification means for notifying the user that it is recommended to review the setting of the security policy. The information processing apparatus according to any one of Items 1 to 5, further comprising (Item 7) The notification means notifies the user by displaying a warning screen including a display prompting the user to change the setting of the security policy. The warning screen includes an operation object for calling the security policy setting means. The information processing apparatus according to Item 6. (Item 8) A network setting method in an information processing apparatus having a server function, comprising: Server function setting means sets whether the server function is valid or invalid. Connection destination setting means sets whether to connect the information processing apparatus to a network environment where the server function is not used. When the first setting change means is set to connect to a network environment where the server function is not used by the connection destination setting means, the server function setting means sets the server function to be invalid. Network setting method. (Item 9) A network setting method in an information processing apparatus having a server function, comprising: Connection destination setting means sets whether to connect the information processing apparatus to a network environment where the server function is not used. Filter setting means sets a filter setting for whether to perform filtering on communication with the network. Filter means performs filtering of communication with the network based on the filter setting. When the second setting change means is set to connect to a network environment where the server function is not used by the connection destination setting means, the filter setting means is set to perform filtering of communication with the network. Network setting method. (Item 10) A program for an information processing apparatus having a server function, causing a computer of the information processing apparatus to server function setting means for setting whether the server function is valid or invalid; connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; first setting change means for setting the server function setting means to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; and a program for causing it to function. (Item 11) A program for an information processing apparatus having a server function, causing a computer of the information processing apparatus to connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; filter setting means for setting whether to perform filtering on communication with the network; filter means for performing filtering of communication with the network based on the filter setting; second setting change means for setting the filter setting means to perform filtering of communication with the network when it is set by the connection destination setting means to connect to a network environment where the server function is not used and a program for causing it to function.

Explanation of Signs

[0088] 100: MFP, 110: Network, 111, 121: Client terminal, 112: Gateway

Claims

1. An information processing apparatus having a server function, server function setting means for setting whether the server function is valid or invalid; connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; first setting change means for setting the server function setting means to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; An information processing apparatus comprising:

2. An information processing apparatus having a server function, connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; filter setting means for setting whether to perform filtering on communication with the network; filter means for performing filtering on communication with the network based on the filter setting; second setting change means for setting the filter setting means to perform filtering on communication with the network when it is set by the connection destination setting means to connect to a network environment where the server function is not used; An information processing apparatus comprising:

3. further comprising first confirmation means for prompting the user to confirm whether to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; The first setting change means sets the server function setting means to invalidate the server function when the user approves the invalidation in the first confirmation means. The information processing apparatus according to claim 1.

4. further comprising second confirmation means for prompting the user to confirm whether to invalidate the server function when it is set by the connection destination setting means to connect to a network environment where the server function is not used; The second setting change means sets the filter setting means to perform filtering on communication with the network when the user approves the invalidation in the second confirmation means. The information processing apparatus according to claim 2.

5. third confirmation means for prompting the user to confirm whether to overwrite the existing filter setting when the second setting change means sets the filter setting means to perform filtering on communication with the network and the existing filter setting is valid. The information processing apparatus according to claim 4, further comprising

6. Security policy setting means for setting a security policy, When it is set to connect to a network environment in which the server function is not used by the connection destination setting means and a security policy is set by the security policy setting means, notification means for notifying the user that it is recommended to review the setting of the security policy, The information processing apparatus according to claim 1 or 2, further comprising

7. The notification means notifies the user by displaying a warning screen including a display prompting the user to change the setting of the security policy, The warning screen includes an operation object for calling the security policy setting means, The information processing apparatus according to claim 6.

8. A network setting method in an information processing apparatus having a server function, Server function setting means sets whether the server function is valid or invalid, Connection destination setting means sets whether to connect the information processing apparatus to a network environment in which the server function is not used, When it is set by the connection destination setting means to connect to a network environment in which the server function is not used, first setting change means sets the server function setting means to disable the server function, Network setting method.

9. A network setting method in an information processing apparatus having a server function, Connection destination setting means sets whether to connect the information processing apparatus to a network environment in which the server function is not used, Filter setting means sets a filter for whether to perform filtering on communication with the network, Filter means performs filtering of communication with the network based on the filter setting, When it is set by the connection destination setting means to connect to a network environment in which the server function is not used, second setting change means sets the filter setting means to perform filtering of communication with the network, Network setting method.

10. A program for an information processing apparatus having a server function, The computer of the information processing apparatus, Server function setting means for setting whether the server function is valid or invalid, Connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; When it is set by the connection destination setting means to connect to a network environment where the server function is not used, first setting change means for setting the server function to be invalid in the server function setting means; A program for causing it to function.

11. A program for an information processing apparatus having a server function, The computer of the information processing apparatus, Connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; Filter setting means for setting whether to perform filtering on communication with a network; Filter means for performing filtering of communication with the network based on the filter setting; When it is set by the connection destination setting means to connect to a network environment where the server function is not used, second setting change means for setting the filter setting means to perform filtering of communication with the network; A program for causing it to function.

Citation Information

Patent Citations

  • Information processor, method for controlling the same, and program

    JP2020154832A