Information processing apparatus, network setting method, and program
The information processing device addresses the risk of unnoticed server function enablement in LAN-less environments by providing configuration and notification mechanisms to restrict server usage, enhancing network security.
Patent Information
- Application Number
- JP2024000806
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-05
- Publication Date
- 2025-07-17
AI Technical Summary
In a LAN-less environment, information devices with enabled server functions may not be properly configured to restrict server usage, posing a risk of network attacks due to unnoticed server function enablement.
An information processing device with server function setting, connection destination setting, and notification means to prompt users to restrict server function usage when connecting to a LAN-less environment.
Ensures administrators are aware of the need to disable server functions in LAN-less environments, reducing network attack risks by configuring appropriate settings and notifications.
Smart Images

Figure 2025107065000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus connected to and used in a network, a network setting method, and a program.
Background Art
[0002] In recent years in offices, there has been a trend (cloud shift) to replace business systems such as storage, mail servers, and applications previously prepared on the in-house network with cloud services. Also, companies that implement all business systems with cloud services have emerged due to the cloud shift.
[0003] When all business systems in a company are in cloud services, each information device connected to the in-house network only communicates with various cloud services as a client, and the employees of the company can perform their work. Therefore, a server function is not required for each information device. Such a network environment is hereinafter referred to as a "LAN-less environment".
[0004] By the way, information devices connected to a network are at risk of being attacked via the network. As a countermeasure against attacks from the network, a method of reducing the risk of being attacked by limiting the available server functions to the minimum necessary is common. For example, Patent Document 1 discloses a method of limiting the available server functions for a communication interface to the minimum necessary with a network filter function.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] Some information devices with server functions have the initial state of the server function enabled for convenience during introduction.
[0007] On the other hand, when connecting an information device with a server function to a LAN-less environment, in order to reduce the risk of attacks from the network, it is desirable to make the server function unavailable by using technologies such as applying a network filter to the aforementioned communication interface. In this case, since it is a measure to restrict the functions of the information device, it is desirable for the administrator of the information device to implement settings to restrict the use of the server function.
[0008] However, in the initial state, when connecting an information device with an enabled server function to a LAN-less environment, the administrator of the information device may not notice that it is necessary to restrict the use of the server function. In such a case, since the server function of the information device is not disabled, there is a problem that it is not desirable from the perspective of the risk of attacks via the network. An object of the present invention is to notify the administrator of the information device that it is necessary to restrict the use of the server function when connecting an information device with an enabled server function to a LAN-less environment in the initial state.
Means for Solving the Problem
[0009] The information processing apparatus of the present invention has a server function, and includes a server function setting means for setting whether the server function is enabled or disabled, a connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, and a notification means for prompting the user to change the setting so as to restrict the use of the server function in the network environment where the server function is not used when the server function is set to be enabled by the server function setting means and it is set to be connected to a network environment where the server function is not used by the connection destination setting means.
Effects of the Invention
[0010] According to the present invention, the administrator of an information device can be made aware that it is necessary to restrict the use of the server function of the information device connected to a LAN-less environment. As a result, when connecting an information device to a LAN-less environment, the administrator can restrict the use of the server function and reduce the risk of being attacked via the network.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Modes for Carrying Out the Invention
[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0013] <First Embodiment> In this embodiment, an example of controlling the network settings of an MFP (Multi-Function Peripheral) having two communication lines, a main line and a sub-line, will be described. Although the MFP is taken as an example for description, the present invention is not limited to the MFP, and may be an information processing apparatus that provides other functions. Also, here, an MFP having two communication lines is described as an example, but the present invention is a technology applicable to an MFP having one or more communication lines. Further, here, physically different communication lines are described as an example, but the present invention is a technology applicable to communication lines virtually separated using a virtual network interface.
[0014] [System Configuration] With reference to FIG. 1, the network connection configuration of the MFP, the client terminal, and the gateway according to this embodiment will be described. The MFP 100 is connected to two communication lines, the network 110 and the network 120. The network 110 is connected to the Internet. On the other hand, the network 120 is a normal LAN. The MFP 100 and the client terminal 111 are respectively connected to the network 110 and can communicate with each other. Also, it can communicate with the Internet via the gateway 112. Further, the MFP 100 and the client terminal 121 are communicably connected to each other via the network 120.
[0015] The MFP100 is a multifunction peripheral having a plurality of functions such as a scanner and a printer, and can transmit and receive data with the client terminals 111 and 121, and can transmit and receive data with a cloud service (not shown) connected via the Internet. The client terminals 111 and 121 are, for example, personal computers, smartphones, etc., and can transmit a print request to the MFP100, and can transmit and receive data with a cloud service (not shown) connected via the Internet. The gateway 112 is a network router that relays communication from the MFP100 and the client terminal 111 to and from the Internet. The networks 110 and 120 are communication networks. The network may be wired or wireless as long as data can be transmitted and received.
[0016] In the following description, the MFP100 and the client terminal 111 are assumed to transmit and receive data only with a cloud service (not shown) connected via the Internet without using the server function of the information device connected to the network 110. Also, it is assumed that there is no information device that uses the server function of the MFP100 via the network 110, including the client terminal 111. That is, the network environment composed of the MFP100, the network 110, the client terminal 111, the gateway 112, and the Internet is the LAN-less environment in the present embodiment.
[0017] [Hardware Configuration of MFP] Referring to FIG. 2, the hardware configuration of the MFP 100 will be described. The MFP 100 is composed of a control unit 200, an operation unit 209, a printer unit 210, a scanner unit 211, and wired LAN devices 212 and 213. The control unit 200 is composed of a CPU 201, a ROM 202, a RAM 203, an HDD 204, an operation unit I / F 205, a printer I / F, a scanner I / F, and a network I / F 208, and controls the operation of the entire MFP 100. The CPU 201 reads out the control program stored in the ROM 202 and executes and controls various functions of the MFP 100 such as reading, printing, and communication. The RAM 203 is used as a temporary storage area such as the main memory and work area of the CPU 201. In this embodiment, it is assumed that one CPU 201 uses one memory (RAM 203 or HDD 204) to execute each process shown in the flowchart described later, but it is not limited to this. For example, a plurality of CPUs, a plurality of RAMs, or HDDs may cooperate to execute each process.
[0018] The HDD 204 is a large-capacity storage unit that stores image data and various programs. The operation unit I / F 205 is an interface that connects the operation unit 209 and the control unit 200. The operation unit 209 is equipped with a touch panel, a keyboard, etc., and receives operations / inputs / instructions from the user. The printer I / F 206 is an interface that connects the printer unit 210 and the control unit 200. Print image data is transferred from the control unit 200 to the printer unit 210 via the printer I / F 206 and printed on a recording medium. The scanner I / F 207 is an interface that connects the scanner unit 211 and the control unit 200. The scanner unit 211 reads a document set on a document table or ADF (Auto Document Feeder) (not shown) to generate image data and inputs it to the control unit 200 via the scanner I / F 207. The MFP 100 can print (copy) the image data generated by the scanner unit 211 from the printer unit 210 and can also send an email.
[0019] The network I / F 208 is an interface that connects the control unit 200 (MFP 100) to the wired devices 212 and 213. In this embodiment, it will be described in a form where two wired LAN devices 212 and 213 are connected to the network I / F 208. However, it is not limited to this, and the present invention is also applicable to other LAN devices such as wireless LAN devices and LAN devices connected to USB (Universal Serial Bus), and other connection forms. The control unit 200 realizes communication on the network 110 by controlling the wired LAN device 212 via the network I / F 208. Also, the control unit 200 realizes communication on the LAN 120 by controlling the wired LAN device 213.
[0020] [Software Configuration] Referring to FIG. 3, the software configuration executed by the control unit 200 of the MFP 100 will be described. Each function of the software executed by the control unit 200 is realized by the CPU 201 reading the control program stored in the ROM 202 or the HDD 204 into the RAM 203 and executing it.
[0021] The display control unit 301 executes display of a user-oriented screen on the operation unit 209 of the MFP 100, detection of user operations, and processing associated with screen components such as buttons displayed on the screen. The data storage unit 302 stores and reads various data in the HDD 204 or the ROM 202 based on requests from other control units. For example, when a user wants to change some device settings, the display control unit 301 detects and acquires the content input by the user on the operation unit 209, and based on a request from the display control unit 301, the data storage unit 302 stores it in the HDD 204 as a set value.
[0022] The network control unit 303 issues instructions for network settings such as IP addresses to the TCP / IP control unit 304 at system startup or when a setting change is detected, according to the set values stored in the data storage unit 302. The TCP / IP control unit 304 performs transmission and reception processing of network packets via the network I / F 208 according to instructions from other controls. The network filter control unit 305 performs filtering processing on the packets transmitted and received according to instructions from the TCP / IP control unit 304.
[0023] The main-line network filter table 306 and the sub-line network filter table 307 hold rules for the network filter control unit 305 to determine whether to accept or discard the target packets. In the description of this embodiment, it is assumed that the rules are predefined.
[0024] Here, with reference to FIG. 8, the rules used for determining the packet filtering process will be described. The main-line network filter table 306 and the sub-line network filter table 307 hold the information shown in FIG. 8. The network filter table 800 is a table that exists for each line. In this embodiment, the main-line network filter table 306 is the filter table for the main line, and the sub-line network filter table 307 is the filter table for the sub line.
[0025] In the network filter table 800, two types of values, "Deny / Allow" or "Allow / Deny", are specified for the filter policy 801. In the case of "Deny / Allow", it is a white list method that prohibits all communications and then allows those that match the exception specification. In the case of "Allow / Deny", it is a black list method that allows all communications and then prohibits those that match the exception specification. The exception specification 802 is data in a list format that enumerates exception rules consisting of an "IP address range", "received port number", and "protocol". The "IP address range" specifies the range of IP addresses to which the exception rule applies. The "received port number" specifies the port number to which the exception rule applies or "ANY" indicating all port numbers. The "protocol" specifies the protocol to which the exception rule applies from "TCP" or "UDP".
[0026] Return to the description of FIG. 3. The LPD control unit 308 controls the LPD server function according to an instruction from the network control unit 303. Specifically, by communicating according to the Line Printer Daemon Protocol (LPD protocol) as an LPD server, a print request is received from a client terminal such as the client PC 121. In this embodiment, the LPD protocol is taken as an example of the server function related to printing, but the MFP 100 may also have server functions of other protocols. For example, as protocols related to printing, in addition to LPD, RAW, SMB (Server Message Block), HTTP (Hypertext Transfer Protocol), etc. can be mentioned. Also, as protocols related to the management of the MFP, SNMP (Simple Network Management Protocol), mDNS (multicast DNS), etc. can be mentioned.
[0027] [Screen Configuration] Hereinafter, with reference to FIGS. 4 to 7, an example of the screen configuration according to this embodiment will be described. Note that the screen configuration and screen transition shown below are examples, and other configurations may also be possible. FIG. 4(a) shows a configuration example of a menu screen 400 displayed on the operation unit 209, and is for the user to instruct the execution of various functions of the MFP 100. The copy button 401 is used for the user to instruct the copy function. The scan and save button 402 is used for the user to instruct the function of scanning and saving. The scan and send button 403 is used for the user to instruct the function of scanning and sending. The setting button 404 is used for the user to instruct the change of device settings. When the setting button 404 is operated, a setting screen 410 shown in FIG. 4(b) is displayed. The status line section 405 displays a message indicating the status such as the remaining amount of consumables of the MFP running out or the occurrence of an error, and is used to notify the user of the status of the MFP 100.
[0028] FIG. 4(b) shows a configuration example of a setting screen 410 displayed on the operation unit 209, and is for the user to instruct various settings. There are no specific setting items on the setting screen 410 itself, and it is an intermediate layer that serves as a guide to detailed setting items. When the network setting button 411 is operated, a network setting screen 500 shown in FIG. 5(a) is displayed. When the device setting button 412 is operated, a device setting screen (not shown) is displayed. When the user setting button 413 is operated, a user setting screen (not shown) is displayed. The method of device setting using the device setting screen and the method of user setting using the user setting screen are not particularly limited.
[0029] FIG. 5(a) shows a configuration example of a network setting screen 500 displayed on the operation unit 209, which is an intermediate layer for the user to perform various network settings. When the interface selection button 503 is operated, an interface selection setting screen 510 shown in FIG. 5(b) is displayed. When the LPD setting button 504 is operated, an LPD setting screen 520 shown in FIG. 5(c) is displayed. When the main line setting button 501 is operated, a main line setting screen 600 shown in FIG. 6(a) is displayed. When the sub-line setting button 502 is operated, a sub-line setting screen 700 shown in FIG. 7(a) is displayed. When the apply setting button 505 is operated, after the settings selected by the user are stored in the data storage unit 302, an instruction to reflect the settings is given to the network control unit 303.
[0030] FIG. 5(b) shows a configuration example of the interface selection setting screen 510 according to the present embodiment, where the user can select whether the communication line used by the MFP 100 is one or two. When the OK button 513 is operated, the setting contents of the interface selection setting screen 510 are saved in the data storage unit 302. As described above, two communication lines, namely the main line and the sub-line, can be used as the communication lines according to the present embodiment. When "only main line" 511 is selected on the interface selection setting screen 510, only the wired LAN device 212 is activated. When "main line + sub-line" 512 is selected, the wired LAN device 212 and the wired LAN device 213 are activated simultaneously. In the present embodiment, a configuration for activating only the wired LAN device 213 (a configuration for activating only the sub-line) is not provided, but the present invention is applicable even if such a configuration is provided.
[0031] When "main line + sub - line" 512 is selected, the wired LAN device 212 is set as the main line and the wired LAN device 213 is set as the sub - line. The difference between the main line and the sub - line is, for example, that the priorities are different when one of the operations has to be stopped. Specifically, when the same IP address is assigned to both the main line and the sub - line, they cannot operate simultaneously. Therefore, the network control unit 303 controls to invalidate the sub - line so that the main line can continue to operate. In addition, when there is a need for a functional difference in terms of communication protocols and application constraints, the functions of the main line and the sub - line are different. Note that this embodiment is not limited to the classification of the main line and the sub - line. For example, in the case of a device corresponding to more lines (communication interfaces), different operations may be defined according to the use of each line. Also, in this embodiment, the main line is described as being connected to the above - mentioned LAN - less environment. Note that the line connected to the LAN - less environment is not limited to the main line, and the present invention is also applicable when the sub - line is connected to the LAN - less environment.
[0032] FIG. 5(c) shows a configuration example of the LPD setting screen 520 displayed on the operation unit 209 and is used for the user to instruct the setting of the LPD server function. The LPD active state specifying unit 521 specifies whether to enable or disable the LPD server function of the MFP 100. The enable / disable setting here is an alternative setting item. When the LPD setting is enabled, it indicates that the LPD server function is available in the MFP 100. When the OK button 522 is operated, the items selected on the LPD setting screen 520 are stored in the data storage unit 302. Note that in this embodiment, the LPD function is described as an example. However, when the MFP 100 has other server functions in addition to the LPD function, it goes without saying that a setting screen for setting the enable / disable of the said server function is provided in the same way as the LPD setting screen 520.
[0033] FIG. 6(a) shows a configuration example of the main line setting screen 600 displayed on the operation unit 209, which is an intermediate layer for setting the main line. When the IP address setting button 601 is operated, the main line IP address setting screen 610 shown in FIG. 6(b) is displayed. When the LAN-less setting button 602 is operated, the main line LAN-less setting screen 620 shown in FIG. 6(c) is displayed. When the network filter setting button 603 is operated, the main line network filter setting screen 630 shown in FIG. 6(d) is displayed.
[0034] FIG. 6(b) shows a configuration example of the main line IP address setting screen 610 displayed on the operation unit 209, which is used for the user to instruct IP address-related settings for the main line. The IP address input unit 611 allows the user to input an arbitrary IP address as the IP address for the main line. The subnet mask input unit 612 allows the user to input an arbitrary subnet mask as the subnet mask for the main line. The default gateway input unit 613 allows the user to input an arbitrary default gateway as the default gateway for the main line. In this embodiment, the IP address of the gateway 112 is input as the value of the default gateway input unit 613. When the OK button 614 is operated, the values of the items selected on the main line setting screen 610 are saved in the data storage unit 302.
[0035] Fig. 6(c) shows a configuration example of the main line LAN-less setting screen 620 displayed on the operation unit 209, and is used for the user to indicate whether the network environment to which the main line is connected is a LAN-less environment and related settings. The LAN-less setting unit 621 designates whether the network environment to which the main line is connected is a LAN-less environment. The effective / invalid setting here is an alternative setting item. When set to effective, it indicates that the main line is connected to a LAN-less environment. The warning designation unit 622 alternatively designates whether to display a warning when the server function of the MFP 100 is available in the LAN-less environment. Specifically, when the LAN-less setting unit 621 is designated as "effective" and a server function such as the above-described LPD function is available from the network on the main line side, it alternatively designates whether to display a warning. The warning designation unit 622 indicates that the above-described warning is displayed when a check box is checked. Further, the warning designation unit 622 is a selectable setting item when the LAN-less setting unit 621 is designated as effective. When the OK button 623 is operated, the items selected on the main line LAN-less setting screen 620 are stored in the data storage unit 302.
[0036] FIG. 6(d) shows a configuration example of the main line network filter setting screen 630 displayed on the operation unit 209, which is used for the user to instruct the setting of the network filter for the main line. In the main line network filter setting screen 630, an initial value is set and presented, and the user can change the value. The active state specifying unit 631 specifies whether to enable or disable the setting of the network filter for the main line. The enable / disable setting here is an alternative setting item. When it is disabled, it means receiving all network packets without discarding them. When it is enabled, network filter processing for the main line is performed according to the rules specified on the main line network filter setting screen 630. The filter policy specifying unit 632 allows the user to specify the filter policy described with reference to FIG. 8 for the main line. The "Deny / Allow" / "Allow / Deny" setting here is an alternative setting item. The network filter rule 633 is an area for displaying and inputting the currently set exception specification for the main line. The exception specification here corresponds to that described with reference to FIG. 8. When the OK button 634 is operated, the items selected on the main line network filter setting screen 630 are stored in the data storage unit 302.
[0037] FIG. 7(a) shows a configuration example of the secondary line setting screen 700 displayed on the operation unit 209, which is an intermediate layer for setting the secondary line. When the IP address setting button 701 is operated, the secondary line IP address setting screen 710 shown in FIG. 7(b) is displayed. When the LAN-less setting button 702 is operated, the secondary line LAN-less setting screen 720 shown in FIG. 7(c) is displayed. When the network filter setting button 703 is operated, the secondary line network filter setting screen 730 shown in FIG. 7(d) is displayed.
[0038] FIG. 7(b) shows a configuration example of a secondary line IP address setting screen 710 displayed on the operation unit 209 and is used for the user to instruct IP address-related settings for the secondary line. The IP address input unit 711 allows the user to input an arbitrary IP address as the IP address for the secondary line. The subnet mask input unit 712 allows the user to input an arbitrary subnet mask as the subnet mask for the secondary line. When the OK button 713 is operated, the values of the items selected on the secondary line setting screen 710 are stored in the data storage unit 302.
[0039] FIG. 7(c) shows a configuration example of a secondary line LAN-less setting screen 720 displayed on the operation unit 209 and is used for the user to instruct whether the network environment to which the secondary line is connected is a LAN-less environment and related settings. The LAN-less setting unit 721 designates whether the network environment to which the secondary line is connected is a LAN-less environment. The valid / invalid setting here is an alternative setting item. When set to valid, it indicates that the secondary line is connected to a LAN-less environment. The warning designation unit 722 alternatively designates whether to display a warning when the server function of the MFP 100 is available in the LAN-less environment. Specifically, when the LAN-less setting unit 721 is designated as "valid" and a server function such as the above-described LPD function can be used from the network on the secondary line side, it alternatively designates whether to display a warning. The warning designation unit 722 indicates that the above-described warning display is to be performed when the check box is checked. Further, the warning designation unit 722 is a selectable setting item when the LAN-less setting unit 721 is designated as valid. When the OK button 723 is operated, the items selected on the secondary line LAN-less setting screen 720 are stored in the data storage unit 302.
[0040] FIG. 7(d) shows a configuration example of a secondary line network filter setting screen 730 displayed on the operation unit 209, and is used for the user to instruct the setting of the network filter for the secondary line. In the secondary line network filter setting screen 730, an initial value is set and presented, and the user can change the value. The active state specifying unit 731 specifies whether to enable or disable the setting of the network filter for the secondary line. The enable / disable setting here is an alternative setting item. When it is disabled, it means receiving all network packets without discarding them. When it is enabled, network filter processing for the secondary line is performed according to the rules specified on the secondary line network filter setting screen 730. The filter policy specifying unit 732 allows the user to specify the above-described filter policy for the secondary line. The "Deny / Allow" / "Allow / Deny" setting here is an alternative setting item. The network filter rule 733 is an area for displaying and inputting the currently set exception specification for the secondary line. The exception specification here corresponds to that described with reference to FIG. 8. When the OK button 734 is operated, the items selected on the secondary line network filter setting screen 730 are stored in the data storage unit 302.
[0041] [Security Policy Setting] Here, the security policy will be described. The security policy includes the basic policy regarding the security of the entire organization, security countermeasure standards, individual specific implementation procedures, and the like. As one of the security policies of a device having a server function, there is port control (port usage policy) of the server function. In the port usage policy, it is common to formulate and operate a policy that prohibits the use of server functions that are not used to reduce the risk of attacks from the network. Even in an MFP having a server function, when it is used in an organization that formulates and operates the above-described port usage policy, operation in accordance with the port usage policy is required.
[0042] Return to the description of the embodiments. Referring to FIG. 9, the setting of the security policy will be described. FIG. 9 shows a configuration example of a port usage policy setting screen 900 based on the security policy displayed on the operation unit 209. The port usage policy setting screen 900 is used for the user to instruct the MFP 100 on whether to use server functions based on the organization's port usage policy. The policy specifying unit 901 specifies whether to prohibit the use of each server function of the MFP 100. Checking the check box of each server function item indicates that the use of the corresponding server function is prohibited. For example, in FIG. 9, when setting to prohibit LPD, the activation state designation of the server function such as the LPD activation state designation unit 521 is changed to "invalid". Also, the instruction on whether to use the server function according to the security policy takes precedence over the designation of the validity of the server function. For example, in FIG. 9, when setting to prohibit LPD, in the validity setting of the LPD setting in FIG. 5, it cannot be set to valid. When the OK button 902 is operated, the items selected on the port usage policy setting screen 900 are stored in the data storage unit 302.
[0043] In an organization using the MFP 100, the use permission and prohibition of various server functions may be defined in the security policy. In such a case, by setting the policy specifying unit 901, it is possible to set the MFP 100 on whether to use server functions based on the organization's security policy. If the security policy is set, it takes precedence over the setting of the server function. Also, when the communication line used by the MFP 100 is the main line / secondary line, if the server function is disabled in the server function setting, the server function will also be disabled for lines other than the LAN-less operation. Therefore, instead of disabling it in the server function setting, it is necessary to set network filters individually for the main line / secondary line to block communication to the MFP 100 and limit the use of the server function.
[0044] When operating the MFP100 in a LAN-less environment, there are three methods to restrict the use of server functions. They are the permission and prohibition of using server functions by security policies, the enabling and disabling settings in the server function settings, and the blocking of communication to the MFP100 by the settings of the network filter. Also, the blocking of communication can be achieved not only by the settings of the server function and the network filter, but also by applying reception rejection in the firewall settings.
[0045] [Processing Flow in the First Embodiment] (Warning Notification Processing) Using FIG. 10, the warning notification processing of the MFP100 in the case where the server function of the MFP100 according to this embodiment is available in a LAN-less environment will be described. Each operation (step) shown in the flowchart of FIG. 10 is realized by the CPU 201 of the MFP100 reading out the control program stored in the ROM 202 or the HDD 204 to the RAM 203 and executing it. Hereinafter, the step numbers of each process included in the flowchart are indicated by numbers starting with "S". The same applies to the following flowcharts. This processing flow starts at the time of system startup and when the button 505 on the network setting screen 500 shown in FIG. 5(a) is operated.
[0046] In S1001, the MFP100 determines whether the LPD function is "enabled". When making the determination, the network control unit 303 refers to the value corresponding to the LPD activation state designating unit 521 of the set value stored in the data storage unit 302. If it is determined that the LPD function is enabled (YES in S1001), the process proceeds to S1002. If it is determined that the LPD function is disabled (NO in S1001), this processing flow ends. When the MFP100 has server functions in addition to LPD, the network control unit 303 determines whether each server function is enabled in the same manner as in S1001. In this case, if it is determined that any of the server functions possessed by the MFP100 is enabled, S1001 becomes YES.
[0047] A series of processes from S1002 to S1009 are hereinafter referred to as warning notification determination processes. The warning notification determination process is performed on the line selected on the interface selection screen 510. Among the used lines, which line has been processed up to is determined by checking the processing status internally held in the RAM 203. Here, it will be described as if the warning notification determination process is performed in order from the main line.
[0048] In S1002, the MFP 100 determines whether the LAN-less setting of the main line is "valid". When making the determination, the network control unit 303 refers to the value corresponding to the LAN-less setting unit 621 of the setting value stored in the data storage unit 302. If it is determined that the LAN-less setting is valid (YES in S1002), the process proceeds to S1003. If it is determined that the LAN-less setting is invalid (NO in S1002), the process proceeds to S1010.
[0049] In S1003, the MFP 100 determines whether the warning notification of the main line is "valid". When making the determination, the network control unit 303 refers to the value corresponding to the warning designation unit 622 of the setting value stored in the data storage unit 302. If it is determined that the warning notification is valid (YES in S1003), the process proceeds to S1004. If it is determined that the warning notification is invalid (NO in S1003), the process proceeds to S1010.
[0050] In S1004, the MFP 100 determines whether the communication line used by the MFP 100 is one or two or more. When making the determination, the network control unit 303 refers to the value corresponding to the content of the interface selection screen 510 of the set value stored in the data storage unit 302. If "only main line" 511 is selected, it is determined as "one". If "main line + sub line" 512 is selected, it is determined as "multiple". If it is determined that the communication line is "one" (YES in S1004), the process proceeds to S1005. If it is determined that the communication line is "multiple" (NO in S1004), the process proceeds to S1006. When YES in this S1004, the MFP 100 is connected to a LAN-less environment, indicating that the server function is enabled.
[0051] In S1005, the MFP 100 adds the main line to the interfaces to be warned. Specifically, the network control unit 303 adds the main line to the interface information to be warned that is internally held in the RAM 203.
[0052] In S1006, the MFP 100 determines whether the network filter of the main line is "enabled" or not. When making the determination, the network control unit 303 refers to the value corresponding to the activation state designation unit 631 of the main line network filter setting screen 630 of the set value stored in the data storage unit 302. If it is determined that the network filter is enabled (YES in S1006), the process proceeds to S1007. If it is determined that the network filter is disabled (NO in S1006), the process proceeds to S1005.
[0053] In S1007, the MFP 100 determines whether the filter policy of the main line is "Deny / Allow". When making this determination, the network control unit 303 refers to the value corresponding to the filter policy designation unit 632 of the main line network filter setting screen 630 of the set value stored in the data storage unit 302. If it is determined that the filter policy is "Deny / Allow" (YES in S1007), the process proceeds to S1008. If it is determined that the filter policy is "Allow / Deny" (NO in S1007), the process proceeds to S1009.
[0054] In S1008, the MFP 100 checks whether there is an exception designation for the main line. As a method of checking, the network control unit 303 acquires the value corresponding to the network filter rule 633 among the settings stored in the data storage unit 302. Since the network filter rule 633 is an ordered list, when a network filter entry is acquired, it is determined that there is an exception designation. If it is determined that there is an exception designation (YES in S1008), the process proceeds to S1005. If it is determined that there is no exception designation (NO in S1008), the process proceeds to S1010. When YES in this S1008, it indicates that the server function of the MFP 100 is available from the LAN-less environment to which the main line is connected due to the exception designation of the white list method network filter.
[0055] In S1009, the MFP100 checks for the presence of an exception specification in which the entire IP address range "0.0.0.1 to 255.255.255.255" and "ANY" indicating all port numbers are specified. As a checking method, the network control unit 303 acquires a value corresponding to the network filter rule 633 among the settings stored in the data storage unit 302. Since the network filter rule 633 is an ordered list, the contents of the filter entries from the beginning to the end are checked. If it is determined that there is an exception specification (YES in S1009), the process proceeds to S1010. If it is determined that there is no exception specification (NO in S1009), the process proceeds to S1005. When it becomes YES in this S1009, all communications are prohibited by the exception specification of the blacklist method network filter, indicating that the server function of the MFP100 is not available from the LAN-less environment connected to the main line.
[0056] In S1010, the MFP100 checks whether the warning notification determination process has been performed for all the used lines selected on the interface selection screen 510. In the check, the network control unit 303 checks the processing status internally held in the RAM 203. If the warning notification determination process has been performed for all the used lines (YES in S1010), the process proceeds to S1011. If it has not been performed for all the used lines (NO in S1010), the process returns to S1002 to perform the warning notification determination process for the lines for which it has not been performed. In the present embodiment, when "main line + sub-line" 512 is selected on the interface selection screen 510, S1010 is determined to be NO, and a series of processes from S1002 to S1009 are performed for the sub-line in the same manner as described above.
[0057] In S1011, the MFP 100 determines whether there is an interface determined to be a warning target in the warning notification determination process. When making this determination, the network control unit 303 refers to the interface information of the warning target internally held in the RAM 203. If there is an interface determined to be a warning target (YES in S1011), the process proceeds to S1012; if there is no interface determined to be a warning target, this processing flow ends.
[0058] In S1012, the MFP 100 determines whether the number of communication lines used is one or two or more. When the communication lines used by the MFP 100 are the main line and the sub-line, if the server function is disabled in the server function setting, the server function will also be disabled for lines other than LAN-less operation. Therefore, it is necessary to limit the use of the server function by setting network filters individually for the main line and the sub-line to cut off communication, rather than disabling it in the server function setting. The determination method is the same as S1004. If it is determined that the number of communication lines used is "one" (YES in S1012), the process proceeds to S1013; if it is determined that the number of communication lines is "multiple" (NO in S1012), the process proceeds to S1016.
[0059] In S1013, the MFP 100 determines whether a security policy is set. This is because when a security policy is set, the prohibition setting of the server function in the port usage policy setting of the security policy takes precedence over the server function setting. When making this determination, the network control unit 303 refers to the value corresponding to the policy designation unit 901 in the port usage policy setting among the settings stored in the data storage unit 302. If at least one of the setting items of the policy designation unit 901 is "valid", it is determined that a security policy is set. If it is determined that a security policy is set (YES in S1013), the process proceeds to S1014; if it is determined that no security policy is set (NO in S1013), the process proceeds to S1015.
[0060] In S1014, the MFP 100 displays a review warning screen 1300 (Fig. 13(a)) for security policy settings. The explanation of the review warning screen 1300 for security policy settings will be described later. As a display method, the network control unit 303 requests the display control unit 301 to display the review warning screen 1300 for security policy settings on the operation unit 209. Then, this processing flow ends.
[0061] When a security policy is set in the MFP 100, the use permission and prohibition of each server function may be defined in the security policy of the organization using the MFP 100. When connecting to a LAN-less environment, it is desirable to change all server function settings to prohibited so that the server functions are not used. The user needs to check whether the setting change violates the security policy of the organization and then review the policy settings of the port usage policy of the MFP 100. Therefore, in S1014, by displaying the review warning screen 1300 for security policy settings, the user can recognize that it is necessary to review the policy designation of the port usage policy. When the recognized user reviews the policy settings of the port usage policy, the policy is changed on the port usage policy setting screen 900.
[0062] In S1015, the MFP 100 displays a warning screen 1200 (Fig. 12(a)) recommending disabling the server function. The explanation of the warning screen 1200 recommending disabling the server function will be described later. As a display method, the network control unit 303 requests the display control unit 301 to display the warning screen 1200 on the operation unit 209. Then, this processing flow ends.
[0063] In S1016, the MFP 100 displays a warning screen 1210 (Fig. 12(b)) recommending network filter settings. The explanation of the warning screen 1210 recommending network filter settings will be described later. As a display method, the network control unit 303 requests the display control unit 301 to display the warning screen 1210 on the operation unit 209. Then, this processing flow ends.
[0064] By S1015 and S1016, the MFP 100 can be connected to the LAN-less environment, and the user can recognize that it is desirable to make the server functions unavailable from the LAN-less environment. Further, in order to make the server functions unavailable from the LAN-less environment, the user can know whether to change the settings of each server function to "invalid" or to set the network filter of the line connected to the LAN-less environment.
[0065] (Warning Notification Screen Control Process) Using FIG. 11, FIG. 12, and FIG. 13, the control process of the warning notification screen of the MFP 100 according to the present embodiment will be described. Each operation (step) shown in the flowchart of FIG. 11 is realized by the CPU 201 of the MFP 100 reading out the control program stored in the ROM 202 or the HDD 204 to the RAM 203 and executing it. The processing flow of FIG. 11 starts due to the display of any of the warning screens 1200, 1210, and 1300.
[0066] FIG. 12(a) is a configuration example of a setting warning screen for server functions in a wireless LAN environment. On the server function setting warning screen 1200, a message indicating that the server function settings should be disabled because the device is connected to a wireless LAN environment is displayed. When the warning cancellation button 1201 is operated, the server function setting warning screen 1200 is closed. The warning cancellation button 1201 is an example of a first object in the present invention. When the close button 1202 is operated, the server function setting warning screen 1200 is closed, and a warning message 1220 is displayed in the status line section 405 of the menu screen 400. The close button 1202 is an example of a second object in the present invention. The warning message 1220 is displayed in the status line section 405 unless the warning cancellation button 1201 is operated or the server function is not disabled. When the setting button 1203 is operated, the process transitions to the LPD setting screen 520 of FIG. 5(c) for setting the enable / disable state of the server function. The user can disable the server function on the LPD setting screen 520. The setting button 1203 is an example of a third object in the present invention.
[0067] Figure 12(b) is a configuration example of a warning screen recommending network filter settings in a wireless LAN environment. On the network filter settings warning screen 1210, a message indicating that network filter settings should be performed because the device is connected to a wireless LAN environment and the target line are displayed. When the cancel warning button 1211 is operated, the network filter settings warning screen 1210 is closed. The cancel warning button 1211 is an example of the first object in the present invention. When the close button 1212 is operated, the network filter settings warning screen 1210 is closed, and a warning message 1230 is displayed in the status line section 405 of the menu screen 400. The close button 1212 is an example of the second object in the present invention. When the settings button 1213 is operated, the user transitions to the main line settings screen 600 in Fig. 6(a). Thereby, the user can operate the network filter settings button 603 to perform network filter settings. The settings button 1213 is an example of the third object in the present invention. The example in Fig. 12(b) is for the main line, but in the case of the sub-line, by operating the settings button 1213, the user transitions to the sub-line settings screen 700 in Fig. 7(a). Also, in the case of both the main line and the sub-line, two buttons for transitioning to the main line settings screen 600 and the sub-line settings screen 700 respectively may be provided.
[0068] Figure 12(c) is an example of a status line display recommending setting changes for server functions in a wireless LAN environment. A warning message 1220 recommending setting changes for server functions is displayed in the status line section 405 of the menu screen 400 described in Fig. 4. When the warning message 1220 is operated, a warning screen 1200 is displayed.
[0069] Figure 12(d) is an example of a status line display recommending network filter settings in a wireless LAN environment. A warning message 1230 recommending network filter settings is displayed in the status line section 405 of the menu screen 400 described in Fig. 4. When the warning message 1230 is operated, the warning screen 1210 is displayed.
[0070] Figure 13(a) is a configuration example of a security policy setting review warning screen. On the security policy setting review warning screen 1300, a message recommending a review of the security policy setting is displayed because the device is connected to a LAN-less environment. Here, as a security policy, a message recommending a review of the port usage policy of the server function is displayed. When the cancel warning button 1301 is operated, the security policy setting review warning screen 1300 is closed. The cancel warning button 1301 is an example of the first object in the present invention. When the close button 1302 is operated, the security policy setting review warning screen 1300 is closed, and a warning message 1310 is displayed in the status line section 405 of the menu screen 400. The close button 1302 is an example of the second object in the present invention. When the settings button 1303 is operated, the process transitions to the port usage policy setting screen 900 in FIG. 9, and the user can change the setting of the port usage policy, for example, change it to a setting that prohibits LPD. The settings button 1303 is an example of the third object of the present invention.
[0071] Figure 13(b) is an example of a status line display recommending a review of the security policy setting in a LAN-less environment. A warning message 1310 recommending a review of the security policy setting is displayed in the status line section 405 of the menu screen 400 described in FIG. 4. Here, a message recommending a review of the port usage policy, similar to that in FIG. 13(a), is displayed. When the warning message 1310 is operated, the security policy setting review warning screen 1300 is displayed.
[0072] Return to the description of the flowchart in FIG. 11. In S1101, the MFP 100 determines whether the warning has been cleared on the warning screen. In the determination, the network control unit waits for the operation of the warning cancellation buttons (1201, 1211, 1301) and the close buttons (1202, 1212, 1302) on each warning screen. If the warning cancellation button (1201, 1211, 1301) is operated, it is determined that the warning has been "cleared". If the close button (1202, 1212, 1302) is operated, it is determined that the warning has not been "cleared". If it is determined that the warning has been "cleared" (YES in S1101), the process proceeds to S1102. Otherwise (NO in S1101), the process proceeds to S1103.
[0073] In S1102, the MFP 100 deletes the interface information of the warning target. Specifically, the network control unit 303 deletes the interface information of the warning target internally held in the RAM 203. Then, the process proceeds to S1104.
[0074] In S1103, the MFP 100 displays a warning message on the status line section 405 of the menu screen 400. As a display method, the network control unit 303 requests the display control unit 301 to display a warning message on the status line section 405. Then, the process proceeds to S1104.
[0075] In S1104, the MFP 100 closes each warning screen and displays the menu screen 400. As a display method, the network control unit 303 requests the display control unit 301 to close each warning screen and display the menu screen 400 on the operation unit 209. Then, this processing flow ends. As a result, when the user closes the warning screen without clearing the warning, by referring to the status line section 405, the MFP 100 can recognize that a warning has occurred.
[0076] As described above, according to the present embodiment, when connected to a wireless LAN environment, it is possible to provide a function that recommends to the user to disable the server function in the wireless LAN environment. Therefore, the user can recognize the necessity of disabling the server function of the information device connected to the wireless LAN environment, and can use the device with reduced risk of attack via the network.
[0077] In the present embodiment, the network control unit 303 can also apply control to instruct the TCP / IP control unit 304 not to receive data from the line targeted for warning after S1005 in FIG. 10. In this case, it can also be configured to cancel the control after S1102 in FIG. 11. Thereby, in the present embodiment, the MFP 100 may be configured to block data reception of the line targeted for warning while the interface targeted for warning exists. By doing so, it is possible to reduce the risk of being attacked via the network in a state where the server function is not disabled.
[0078] <Other Embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiment to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0079] The invention is not limited to the above-described embodiment, and various changes and modifications are possible without departing from the spirit and scope of the invention. Therefore, claims are attached to disclose the scope of the invention.
[0080] The disclosure of this specification includes the following information processing apparatus, network setting method, and program. (Item 1) An information processing apparatus having a server function, server function setting means for setting whether the server function is enabled or disabled, Connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; Notification means for prompting the user to change the setting so as to restrict the use of the server function in a network environment where the server function is not used when the server function is set to be effective by the server function setting means and it is set to connect to a network environment where the server function is not used by the connection destination setting means; An information processing apparatus comprising: (Item 2) The notification means displays a warning screen including a display prompting the user to change the setting so as to restrict the use of the server function. The information processing apparatus according to Item 1. (Item 3) The warning screen further includes a first object. While the warning screen is being displayed, data reception to the information processing apparatus is blocked, and when the first object is operated, the warning screen is closed and the data reception blocking is released, and it comprises a network control unit. The information processing apparatus according to Item 2. (Item 4) The warning screen further includes a second object. When the second object is operated, the notification means closes the warning screen and displays a display prompting the user to change the setting so as to restrict the use of the server function on the status line. The information processing apparatus according to Item 2 or 3. (Item 5) The warning screen further includes a third object for calling a setting means for restricting the use of the server function. The information processing apparatus according to any one of Items 2 to 4. (Item 6) The setting for restricting the use of the server function is a setting for whether the server function is valid or invalid. The information processing apparatus according to any one of Items 1 to 5. (Item 7) The setting for restricting the use of the server function is the setting of the network filter. The information processing apparatus according to any one of Items 1 to 5. (Item 8) It further includes security policy setting means for setting a security policy. The setting for restricting the use of the server function is the setting of the security policy. The information processing apparatus according to any one of Items 1 to 5. (Item 9) When the information processing apparatus is connected to a plurality of networks, and the server function is set to be effective by the server function setting means, and the server function is set not to be used in a network environment by the connection destination setting means, the notification means prompts the user to set the network filter. The information processing apparatus according to any one of Items 1 to 5 and 7. (Item 10) When the information processing apparatus is connected to a single network line, and the server function is set to be effective by the server function setting means, and the server function is set not to be used in a network environment by the connection destination setting means, the notification means prompts the user to set the server function to be ineffective. The information processing apparatus according to any one of Items 1 to 6. (Item 11) It further includes security policy setting means for setting a security policy. When the server function is set to be effective by the server function setting means, and the server function is set not to be used in a network environment by the connection destination setting means, and a security policy is set in the security policy setting means, the notification means notifies the user to recommend reviewing the setting of the security policy. The information processing apparatus according to any one of Items 1 to 5 and 8. (Item 12) Notification setting means for notifying the user to make a setting change so as to invalidate the server function in a network environment where the server function is not used is further provided. When the server function is set to be valid by the server function setting means, and when it is set to connect to a network environment where the server function is not used by the connection destination setting means, and when the notification setting means is set to perform notification, the notification means prompts the user to make a setting change so as to restrict the use of the server function in a network environment where the server function is not used. The information processing apparatus according to any one of Items 1 to 12. (Item 13) A network setting method for an information processing apparatus having a server function, The server function setting means sets whether the server function is valid or invalid. The connection destination setting means sets whether to connect the information processing apparatus to a network environment where the server function is not used. When the server function is set to be valid by the server function setting means and is set to connect to a network environment where the server function is not used by the connection destination setting means, the notification means prompts the user to make a setting change so as to restrict the use of the server function in a network environment where the server function is not used. A network setting method for an information processing apparatus. (Item 14) A program for an information processing apparatus having a server function, The program causes the computer of the information processing apparatus to Server function setting means for setting whether the server function is valid or invalid, Connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, When the server function is set to be valid by the server function setting means and is set to connect to a network environment where the server function is not used by the connection destination setting means, a notification means for prompting the user to change the setting so as to restrict the use of the server function in the network environment where the server function is not used. A program for enabling the function.
Explanation of Signs
[0081] 100: MFP, 110: Network, 111, 121: Client Terminal, 112: Gateway
Claims
1. An information processing apparatus having a server function, comprising: server function setting means for setting whether the server function is valid or invalid; connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used; notification means for prompting the user to change the setting so as to restrict the use of the server function in a network environment where the server function is not used when the server function is set to be valid by the server function setting means and is set to be connected to a network environment where the server function is not used by the connection destination setting means; An information processing apparatus comprising the above.
2. The notification means displays a warning screen including a display prompting the user to change the setting so as to restrict the use of the server function. The information processing apparatus according to claim 1.
3. The warning screen further includes a first object, and while the warning screen is being displayed, a network control unit that blocks data reception to the information processing apparatus and closes the warning screen and releases the block of data reception when the first object is operated. The information processing apparatus according to claim 2.
4. The warning screen further includes a second object, and when the second object is operated, the notification means closes the warning screen and displays a display prompting the user to change the setting so as to restrict the use of the server function on the status line. The information processing apparatus according to claim 2.
5. The warning screen further includes a third object for calling a setting means for restricting the use of the server function. The information processing apparatus according to claim 2.
6. The setting for restricting the use of the server function is a setting for whether the server function is valid or invalid. The information processing apparatus according to any one of claims 1 to 5.
7. The setting for restricting the use of the server function is a setting of a network filter. The information processing apparatus according to any one of claims 1 to 5.
8. Further comprising security policy setting means for setting a security policy, and the setting for restricting the use of the server function is a setting of the security policy. The information processing apparatus according to any one of claims 1 to 5.
9. When the notification means is set such that the information processing apparatus is connected to a plurality of networks, the server function is set to be effective by the server function setting means, and the information processing apparatus is connected to a network environment where the server function is not used by the connection destination setting means, the user is prompted to set the network filter. The information processing apparatus according to claim 1.
10. When the notification means is set such that the information processing apparatus is connected to a single network line, the server function is set to be effective by the server function setting means, and the information processing apparatus is connected to a network environment where the server function is not used by the connection destination setting means, the user is prompted to disable the server function. The information processing apparatus according to claim 1.
11. The information processing apparatus further includes security policy setting means for setting a security policy. When the notification means is set such that the server function is set to be effective by the server function setting means, the information processing apparatus is connected to a network environment where the server function is not used by the connection destination setting means, and a security policy is set by the security policy setting means, the user is notified that it is recommended to review the security policy setting. The information processing apparatus according to claim 1.
12. The information processing apparatus further includes notification setting means for setting whether to notify the user to prompt the user to change the setting so as to disable the server function in a network environment where the server function is not used. When the notification means is set such that the server function is set to be effective by the server function setting means, the information processing apparatus is connected to a network environment where the server function is not used by the connection destination setting means, and the notification setting means is set to notify, the user is prompted to change the setting so as to limit the use of the server function in a network environment where the server function is not used. The information processing apparatus according to claim 1.
13. A network setting method for an information processing apparatus having a server function, comprising: setting, by server function setting means, whether the server function is enabled or disabled; setting, by connection destination setting means, whether to connect the information processing apparatus to a network environment where the server function is not used; The notification means prompts the user to change the setting so as to restrict the use of the server function in a network environment where the server function is not used when the server function is set to be effective by the server function setting means and is set to be connected to a network environment where the server function is not used by the connection destination setting means. A network setting method for an information processing apparatus.
14. A program for an information processing apparatus having a server function, wherein the program causes a computer of the information processing apparatus to server function setting means for setting whether the server function is effective or not, connection destination setting means for setting whether to connect the information processing apparatus to a network environment where the server function is not used, and notification means for prompting the user to change the setting so as to restrict the use of the server function in a network environment where the server function is not used when the server function is set to be effective by the server function setting means and is set to be connected to a network environment where the server function is not used by the connection destination setting means. A program for causing the functions.
Citation Information
Patent Citations
Information processor, method for controlling the same, and program
JP2020154832A