Information processing device, control method for information processing device, and program

The information processing apparatus addresses information leakage by generating a CSR and certificate using a private key, enabling secure TLS communication post-reset by selectively erasing only the CSR and certificate, thus ensuring secure and convenient operation.

JP2025107685APending Publication Date: 2025-07-22CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024001034
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-09
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing printing devices face issues with information leakage during disposal or transfer due to the erasure of private keys and server certificates during full setting resets, which disrupt TLS communication.

Method used

An information processing apparatus that generates a CSR using a private key, stores it along with the certificate, and allows selective erasure of the CSR and certificate while retaining the private key, ensuring secure TLS communication post-reset.

Benefits of technology

Prevents information leakage and maintains secure encrypted communication by retaining the private key after resetting, allowing continued functionality and user convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025107685000001_ABST
    Figure 2025107685000001_ABST
Patent Text Reader

Abstract

To make it possible to prevent information leaks and ensure convenience.SOLUTION: An information processing device that performs encrypted communication with an external device is provided. The information processing device includes: generation means for generating a private key for the encrypted communication and a CSR (Certificate Signing Request) using the private key; storage means for storing the private key, the CSR, and a certificate issued based on the CSR; first reception means for accepting an instruction to initialize information stored in the storage means; and control means for performing control to erase the CSR and the certificate but not the private key when the first reception means accepts the instruction to initialize.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus, a control method for the information processing apparatus, and a program.

Background Art

[0002] Among printing apparatuses that can be connected to a network, there are apparatuses that provide a remote UI function that enables confirmation of the state of the printing apparatus and change of setting values from a terminal apparatus connected via the network. In such a printing apparatus, problems such as eavesdropping on communication content between the terminal apparatus and the printing apparatus, and not knowing whether the accessed remote UI is actually that of the desired printing apparatus may occur. Against such eavesdropping and impersonation, countermeasures can be taken by applying a communication mechanism using the TLS (Transport Layer Security) protocol with a server certificate. Also, from the viewpoint of preventing information leakage, there is a printing apparatus that provides means for resetting all setting items set in the printing apparatus to their initial states (referred to as full setting reset) by a predetermined operation so that information about the user can be surely erased from the apparatus at the time of disposal or transfer of the printing apparatus.

[0003] In Patent Document 1, a method is disclosed in which a certification authority issues a certificate in accordance with a certificate signature request created by a multifunction machine, and the issued certificate is installed and used in the multifunction machine. The multifunction machine of Patent Document 1 stores a CSR (Certificate Signing Request) and a private key in a pair in the machine, but erases them at the time of full setting reset.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the method of Patent Document 1, even if the server certificate issued by the certification authority using the CSR generated before all settings are reset is stored in the device, the private key is also erased and lost together with the server certificate after all settings are reset. For this reason, there is a problem that the processing associated with communication using the TLS protocol (hereinafter referred to as TLS communication) cannot be correctly performed.

[0006] An object of the present disclosure is to provide an information processing apparatus that can prevent information leakage and ensure convenience.

Means for Solving the Problems

[0007] An information processing apparatus according to an aspect of the present disclosure is an information processing apparatus that performs encrypted communication with an external device, and includes a private key for the encrypted communication, a generation unit that generates a CSR (Certificate Signing Request) using the private key, a storage unit that stores the private key, the CSR, and a certificate issued based on the CSR, a first reception unit that receives an instruction to initialize the information stored in the storage unit, and a control unit that, when receiving the instruction to initialize by the first reception unit, performs control to erase the CSR and the certificate and not to erase the private key.

Effects of the Invention

[0008] According to the present disclosure, in the use of an information processing apparatus, information leakage can be prevented and convenience can be ensured.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Mode for Carrying Out the Invention

[0010] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the matters of the present disclosure, and not all combinations of the features described in the following embodiments are essential for the solution means of the present disclosure. For the same configuration, the same reference numerals will be used for description.

[0011] As an example of an information processing apparatus connectable to a network, a printing apparatus can be cited. There is a printing apparatus that provides a remote UI function that enables confirmation of the state of the printing apparatus and change of setting values, etc., from a terminal apparatus connected via a network. The remote UI function is a function that displays a screen related to the printing apparatus, such as a setting screen for performing various settings of the printing apparatus, on the display unit of an external apparatus. As an implementation form of the remote UI, there is a method in which an HTTP server function and a Web application function are implemented in the printing apparatus and the printing apparatus operates as a so-called Web server. According to this form, it becomes possible to connect to the Web server of the printing apparatus from a Web browser installed in a terminal apparatus such as a personal computer or a smartphone, and confirm the state of the printing apparatus and change the setting values. As printing apparatuses that provide such a remote UI function become widespread, issues in terms of security have also become apparent when connecting to a printing apparatus from a remote terminal apparatus via a network.

[0012] For example, problems such as the communication content between the terminal device and the printing device being eavesdropped, and not knowing whether the remote UI being accessed is really that of the desired printing device occur. As countermeasures against such eavesdropping and impersonation, like a general Web server, the printing device is made to support the TLS protocol. In the TLS protocol, as a means of verifying the authenticity of a Web server, there is a mechanism for server authentication using a server certificate. Server authentication is that the terminal device verifies the information signed with the private key by the printing device with the public key for the server certificate received from the printing device that has received the TLS connection request, to detect forgery and confirm authenticity. As methods for the Web server implemented in the printing device to support server authentication, several techniques can be considered. As one of the methods for supporting server authentication, there is a method of generating a key pair of a private key and a public key in the printing device, generating a CSR (called a signature request) based on it, and downloading the generated CSR from the Web browser of the terminal device. In this case, the user uses the terminal device to request the certification authority to issue a digital certificate based on the downloaded CSR, and installs the issued digital certificate as the server certificate of the printing device in the printing device. In this method, since the private key is not taken out of the printing device and the signature on the server certificate is also performed by an authoritative certification authority, it can be said to be a highly reliable method. However, the issuance of a digital certificate by a reliable certification authority is often paid, and for the user, the issued digital certificate is positioned as an important information asset.

[0013] By the way, various setting items are required to operate the printing device, and the printing device stores the values set using the provided operation panel or the like in a non-volatile memory or the like in the device and uses them for control. Among the setting items, there are highly confidential information such as user names and passwords required to log in to cloud services, as well as personal information. Therefore, it is necessary to pay attention to keeping these in the device in terms of protecting user information. For example, when the device is discarded, transferred to others, or sent for repair, if this information remains in the device, there is a risk of leakage of user information from there.

[0014] In order to solve such problems, it is strongly demanded to provide a printing device with an erasing means that can surely erase this information from the device at the time of disposal or transfer. However, providing an erasing means for each individual data stored in the printing device may not be appropriate from the viewpoint of usability. Therefore, it is desirable for the printing device to adopt an all-settings reset means that returns all the setting items set in the printing device to the initial state by a predetermined operation as one of the erasing means for erasing stored personal information and the like. Hereinafter, in this specification, returning all the setting items to the initial state by a predetermined operation will be referred to as an all-settings reset.

[0015] On the other hand, if the private key and server certificate stored in the printing device using the server authentication mechanism are erased by the all-settings reset means, there is a problem that the processing associated with TLS communication cannot be performed correctly. That is, when the stored private key and server certificate are erased, after the TLS connection request, problems such as the transmission of the server certificate for server authentication and the decryption of the information encrypted with the public key by the terminal device by the printing device cannot be performed. Therefore, a printing device that can perform encrypted communication even after an all-settings reset while preventing information leakage is desired.

[0016] <<First Embodiment>> FIG. 1 is a diagram showing an example of the configuration of system 100 in the present disclosure. System 100 is composed of a printer 300 and a smartphone 500 connected via a local area network 102. The printer 300 and the smartphone 500 are connected to the local area network 102 by wirelessly connecting to a wireless LAN access point 101 respectively. Here, a wireless LAN infrastructure mode connection 103 is used between the printer 300 and the smartphone 500 and the wireless LAN access point 101. The printer 300 has a mode in which it operates as a wireless LAN access point. When the printer 300 is operating as an access point, the smartphone 500 can be directly connected to the printer 300 operating as an access point. This is referred to as a direct connection 104.

[0017] Other terminals, such as a terminal 400 such as a personal computer (PC), can be connected to the local area network 102. Also, the local area network 102 is connected to the Internet 106 via a router 105. The printer 300, the smartphone 500, and other devices can communicate with a cloud server 200 on the Internet 106 via the router 105. The smartphone 500 is also connected to a mobile phone line network 107. The smartphone 500 can also be connected to a cloud server on the Internet 106 via the mobile phone line network 107. Note that this configuration shows an example of the present disclosure, and the effects of the present disclosure do not change even if a different configuration is adopted. For example, in FIG. 1, the wireless LAN access point 101 and the router 105 are configured as different devices, but it may be configured with a single router device having an access point function.

[0018] FIG. 2 is a block diagram showing an example of the configuration of the control system of the printer 300. Here, an example of applying the content of the present disclosure to the printer 300 will be described. Further, as the printer 300, an example of applying the content of the present disclosure to a so-called multifunction printer (MFP) in which a printing mechanism and a reading mechanism are incorporated in the same housing to support a composite function such as a copying function will be described.

[0019] The printer 300 includes a main board 210 that controls the entire apparatus, an operation panel 220 provided on the outer surface of the apparatus, and various units such as a wireless LAN unit 230. The main board 210 includes a CPU 211, a program memory 213, a data memory 214, a nonvolatile memory 215, a printing mechanism control circuit 216, a reading mechanism control circuit 217, an operation unit control circuit 218, and a wireless LAN control circuit 219.

[0020] The CPU 211 in the form of a microprocessor arranged on the main board 210 expands the control program stored in the program memory 213 in the form of a ROM, which is connected via the internal bus 212, to the data memory 214 in the form of a RAM. Then, by executing the expanded control program, the CPU 211 comprehensively controls the printer 300. In addition to this, the main board 210 includes a non-volatile memory 215 that can retain the stored information even when the power supply is cut off. The CPU 211 can write various set values and data, etc. to the non-volatile memory 215, so that when the power supply is received again after the power has been turned off once, it can continue to operate based on the same set values and data. The CPU 211 can control the reading mechanism via the reading mechanism control circuit 217, read the document, and store it as image data information in the data memory 214. Also, the CPU 211 can control the printing mechanism via the printing mechanism control circuit 216 and print the image data in the data memory 214 on a recording medium. The CPU 211 controls the wireless LAN unit 230 via the wireless LAN control circuit 219 to perform wireless LAN communication with other devices. The CPU 211 can display the status of the printer 300 and the function selection menu, etc. on the operation panel 220 by controlling the operation unit control circuit 218. Also, the CPU 211 can control the operation unit control circuit 218 to receive operations from the user.

[0021] Figure 3 is a diagram showing an example of the module configuration of the software operating on the printer 300. The software operating on the printer 300 operates on the embedded control operating system (OS) 320. Each module is roughly classified into a system control layer 330, a job management layer 340, a middleware layer 350, and an application layer 360.

[0022] The embedded control OS 320 is an operating system (OS) that controls the basic operations of the printer control software, and generally a real-time OS with excellent responsiveness is used.

[0023] The system control layer 330 is a group of modules that mainly control the hardware of the printer 300. The print control module 331 is a control module that controls the print mechanism control circuit 216 to execute the printing operation of the printer 300. The reading control module 332 is a control module that controls the reading mechanism control circuit 217 to execute the reading operation of the document placed on the document table. The panel control module 333 is a control module that controls the display of the operation panel 220 of the printer 300 and detects various key operations provided on the printer 300. The network communication control module 334 is a control module that controls the wireless LAN unit 230 to perform communication physical layer control for LAN communication with an external device.

[0024] The job management layer 340 is a group of modules that execute various operations using the system control layer 330 while performing resource allocation, exclusive control, scheduling, etc. of the hardware in response to a job execution request from the upper layer.

[0025] The middleware layer 350 is located between the application layer 360 and the job management layer 340, and is a collection of a group of modules commonly used by a plurality of function modules in the application layer 360. The application framework 351 is a framework module commonly used when requesting job execution from the application layer 360 to the job management layer 340. The network protocol stack 352 is a module for performing communication in accordance with various network protocols such as HTTP and TCP / IP. The encryption processing module 353 is a module for performing encryption and decryption processing required for network communication and the like. The Web server module 354 is a module for operating the printer 300 as a Web server to deliver remote UI content. The certificate management module 355 is a module for managing information such as digital certificates and related keys.

[0026] The application layer 360 is a group of applications that implement various functions of the printer 300. The copy application 361 is an application module for executing a copy operation that reads and prints a document. The driver job application 362 is an application module for receiving a job from a printer driver such as the smartphone 500 and the PC terminal 400 and executing an operation. Jobs from the driver include a print job for executing a printing operation, a reading job for reading a document and outputting image data, and a maintenance job for exchanging information with an external device and performing settings and management of the printer 300. The remote UI module 363 is a module that uses the web server module 354 to provide the remote UI function of the printer 300 to an external device. By using the remote UI, the user can perform settings and management of the printer 300 from a browser installed on the smartphone 500 or the like.

[0027] FIG. 4 is a diagram showing the process from when the printer 300 generates a CSR until a digital certificate is installed. When generating the CSR, the printer 300 internally generates a random number 410. By generating a random number 410 with sufficient randomness, the security of the key can be enhanced. Next, the printer 300 generates a key pair 420 consisting of a public key 421 and a private key 422 from the random number 410. Examples of algorithms for generating the key pair 420 include methods using prime number determination and methods using elliptic curves. The public key 421 and the private key 422 that make up the key pair 420 are associated with each other, and information encrypted with the public key 421 can only be decrypted with the private key 422. Conversely, information encrypted with the private key 422 can only be decrypted with the public key 421. Utilizing this property, the public key is generally made public, and the private key is stored in a secure location inside the printer 300, enabling secure encryption processing. Thereby, communication between the printer 300 and an external device can be encrypted. Also, the external device can detect forgery, confirm authenticity, etc. by verifying information signed with the private key of the printer 300 using the public key.

[0028] Subsequently, the user inputs owner information 431 into the printer 300 by the method described later. Then, the printer 300 generates a CSR 430 using the owner information 431 input by the user and the public key 421. The owner information 431 is also called a Distinguish Name and can include information such as the URL at the time of connection, the name of the operating organization, and the location. A digital signature 432 by the private key 422 is attached to the CSR 430 to enable confirmation that the CSR was indeed generated by the printer 300. This is the flow of the CSR generation process in the printer 300.

[0029] After the CSR is generated by the printer 300, the user downloads the CSR from the printer 300 using the smartphone 500. The user accesses the remote UI of the printer 300 using the browser of the smartphone 500 and performs an operation to download the CSR. The smartphone 500 sends an instruction to the printer 300 to download the CSR according to the user's operation. Then, the printer 300 that has received the instruction sends the CSR 430 to the smartphone 500. Thereby, the smartphone 500 saves the CSR 440 received from the printer 300. The user makes a signature request to the certification authority 600 using the CSR 440 downloaded to the smartphone 500. Then, the smartphone 500 sends the CSR 440 to the certification authority 600.

[0030] The certification authority 600 generates a digital certificate 460 by attaching a digital signature 461 by the certification authority 600 to the CSR 450 received at the time of the signature request by the user. The generated digital certificate 460 is issued to the user who is the requester. Then, the certification authority 600 sends the digital certificate 460 to the smartphone 500 of the user who is the requester.

[0031] The smartphone 500 receives the digital certificate 470 issued by the certification authority 600 and saves the digital certificate 470 in a non-volatile memory (not shown). The user performs an upload operation to the printer 300 from the certificate upload screen of the remote UI described later. Then, the smartphone 500 sends the digital certificate 470 to the printer 300 according to the user's upload operation.

[0032] The printer 300 verifies whether the uploaded digital certificate 480 matches the private key 422 stored in the printer 300. If there is no problem with the verification result, the printer 300 installs the digital certificate 480 and makes it available.

[0033] Installation refers to storing the digital certificate 480 and the private key 422 in the printer 300 and making them available for use as encryption means in network communication and verification means for digital signatures attached to information generated by the printer 300. For example, when the printer 300 conducts TLS communication with an external device, it is used as follows. When there is a TLS connection request from the external device, the printer 300 transmits the digital certificate 480 to the external device. The external device encrypts the data with the public key stored in the digital certificate and transmits it to the printer 300. The printer 300 decrypts the encrypted data received from the external device with the private key 422 stored inside the printer 300. In such a process, the printer 300 conducts TLS communication with the external device. Also, when the printer 300 transmits data read by the reading mechanism to the external device, it can attach a digital signature with the private key 422. The external device that has received the read data acquires the digital certificate 480 from the printer 300 and verifies the digital signature attached to the read data with the public key stored in the digital certificate 480. Thereby, the external device that has received the read data can verify that the read data was indeed generated by this printer 300.

[0034] FIG. 5 is a diagram showing an example of the screen of the remote UI displayed on the operation unit (not shown) of the smartphone 500. The user can perform settings and management of the printer 300, requests to the printer 300, etc. by operating the screen as shown in FIG. 5 displayed on the web browser of the smartphone 500 using the remote UI function provided by the printer 300.

[0035] FIG. 5(a) is a diagram showing an example of the home screen 510 of the remote UI. The home screen 510 of the remote UI is a page that serves as the entrance to the entire remote UI. On the home screen 510, a status confirmation button 511, an operation setting button 512, a connection setting button 513, and a certificate setting button 514, which are hyperlinked to transition to each other page, are arranged. The status confirmation button 511 is a button that accepts a transition to a printer status display screen (not shown). The operation setting button 512 is a button that accepts a transition to a printer operation setting screen (not shown). The connection setting button 513 is a button that accepts a transition to a network connection setting screen (not shown). The certificate setting button 514 is a button that accepts a transition to a certificate setting screen 520 described later.

[0036] FIG. 5(b) is a diagram showing an example of the certificate setting screen 520. On the certificate setting screen 520, a generation button 521, a CSR download button 522, and a certificate installation button 523 are arranged. The generation button 521 is a button that accepts a transition to a key pair / CSR generation screen 530 described later. The CSR download button 522 is a button that accepts the download of the CSR 430 from the printer 300. The certificate installation button 523 is a button that accepts the upload of the digital certificate 470 to the printer 300 and the installation of the certificate.

[0037] FIG. 5(c) is a diagram showing an example of the key pair / CSR generation screen 530. On the key pair / CSR generation screen 530, a text input box 531, an OK button 532, and a cancel button 533 are provided. The text input box 531 is a text input box that accepts the input of the owner information 431 used for CSR generation by the operation of the user. The OK button 532 is a button that accepts an execution instruction for the generation process of the key pair and the CSR. The cancel button 533 is a button that accepts the end of the key pair / CSR generation screen 530 without giving an execution instruction for the generation process of the key pair and the CSR.

[0038] FIG. 6 is a diagram showing an example of a screen displayed on the operation panel 220 of the printer 300. FIG. 6(a) is a diagram showing an example of the home screen 610. The home screen 610 is a screen on which the printer 300 is displayed in a standby state and can receive a function execution instruction from the user. On the home screen 610, a copy button 611, a scan button 612, and a setting button 613 for instructing the execution of the functions of the printer 300 are arranged. The copy button 611 is a button that accepts a transition to a screen for executing a copy function (not shown). The scan button 612 is a button that accepts a transition to a screen for executing a scan function (not shown). The setting button 613 is a button that accepts a transition to a setting menu screen 620 described later.

[0039] FIG. 6(b) is a diagram showing an example of the setting menu screen 620. The setting menu screen 620 is a screen that is displayed when the setting button 613 on the home screen 610 is selected. On the setting menu screen 620, a network setting button 621, a print setting button 622, and a setting reset button 623 are arranged. The network setting button 621 is a button that accepts a transition to a screen for performing settings for connecting to a network (not shown). The print setting button 622 is a button that accepts a transition to a screen for performing print settings such as the paper size and paper type used for printing (not shown). The setting reset button 623 is a button that functions as a reception means for receiving an execution instruction for a setting reset process described later.

[0040] FIG. 7 is a flowchart showing an example of the processing of the printer 300. The processing shown in FIG. 7 is realized by the CPU 211 of the printer 300 reading a control program stored in the program memory 213 in the form of a ROM into the data memory 214 in the form of a RAM and the CPU 211 executing it. Note that part or all of the functions of some of the steps in FIG. 7 may be realized by hardware such as an ASIC or an electronic circuit. The symbol "S" in the description of each process means that it is a step in the flowchart diagram (the same applies to the flowchart diagrams in this specification hereinafter). The processing shown in FIG. 7 is started by the CPU 211 of the printer 300 when the power of the printer 300 is turned on, and the processing from S701 to S710 is repeatedly executed while the power of the printer 300 is on.

[0041] In S701, the CPU 211 starts a loop process. After that, the CPU 211 proceeds to the process of S702. In S702, at the beginning of the loop, the CPU 211 waits for the occurrence of an event. When the CPU 211 detects the occurrence of an event in S702, it proceeds to the process of S703.

[0042] In S703, the CPU 211 determines the type of the detected event and branches to the necessary process and proceeds. If the CPU 211 determines in S702 that the detected event is the pressing of the power key provided on the operation panel 220, it proceeds to the process of S704 and shifts the printer 300 from the power-on state to the power-off state. Thereby, the loop is exited, and the printer 300 enters a standby state until it detects an event to shift to the power-on state next.

[0043] If the CPU 211 determines in S702 that the detected event is the pressing of the start key provided on the operation panel 220, it proceeds to the process of S705 and starts a copy operation. However, if the start key is pressed while the display on the operation panel 220 has transitioned from the home screen 610 to the scan execution screen or other screens, the CPU 211 starts a scan operation or other operations according to the state of the displayed screen.

[0044] When the CPU 211 determines that the event detected in S702 is the reception of an external job, it proceeds to the process of S706 and performs job execution processing according to the content of the received job. When the CPU 211 determines that the event detected in S702 is a remote UI request from the outside, it proceeds to the process of S707 and executes the response processing when receiving the remote UI request described later.

[0045] When the CPU 211 determines that the event detected in S702 is an operation on the operation panel 220, it proceeds to the process of S708 and executes the response processing for the panel operation described later. For example, if it is an operation on the touch panel of the operation panel 220, appropriate processing is performed according to the touched coordinates. When a touch on a button arranged on the home screen 610, the setting menu screen 620, and other screens is detected, the CPU 211 causes a transition to an appropriate screen or executes an operation. When the CPU 211 determines that the event detected in S702 is another event, it executes processing according to the event in S709.

[0046] FIG. 8 is a flowchart showing an example of the response processing of the printer 300 when receiving a remote UI request. The process shown in FIG. 8 is executed as a sub-flow of S707 in the flowchart shown in FIG. 7. That is, it is executed by the CPU 211 of the printer 300 when an event occurrence of a remote UI request from a Web browser of an external device to the Web server module 354 of the printer 300 is detected.

[0047] In S801, the CPU 211 determines the type of the received remote UI request, and then performs processing according to the type of the request as follows. In S801, when the CPU 211 determines that the request type is a CSR generation request, it proceeds to the processing of S802. The CSR generation request is transmitted from the Web browser of the external device to the printer 300 when the OK button 532 is pressed on the key pair - CSR generation screen 530 in Fig. 5(c). The CSR generation request also stores the owner information 431 entered in the text input box 531.

[0048] In S802, the CPU 211 generates a key pair 420 consisting of a public key 421 and a private key 422 from the random number 410. Then, the CPU 211 proceeds to the processing of S803. In S803, the CPU 211 acquires the owner information 431 stored in the received CSR generation request. Then, the CPU 211 proceeds to the processing of S804.

[0049] In S804, the CPU 211 generates a CSR 430 from the key pair 420 and the owner information 431. Specifically, a signature by the private key 422 is added to the combination of the owner information 431 and the public key 421. Then, the CPU 211 proceeds to the processing of S805. In S805, the CPU 211 stores the private key 422 and the CSR 430 in the non - volatile memory 215 inside the printer 300, and ends the processing shown in Fig. 8.

[0050] In S801, when the CPU 211 determines that the request type is a CSR download request, it proceeds to the processing of S806. The CSR download request is transmitted from the Web browser of the external device to the printer 300 when the CSR download button 522 is pressed on the certificate setting screen 520 in Fig. 5(b). In S806, the CPU 211 transmits the CSR 430 stored in the non - volatile memory 215 as a response to the source of the CSR download request, and ends the processing shown in Fig. 8.

[0051] In S801, when the CPU 211 determines that the request type is a certificate installation request, it proceeds to the process of S807. A certificate installation request is sent from the web browser of an external device to the printer 300 when the certificate installation button 523 in Fig. 5(c) is pressed. The certificate installation request includes the digital certificate 470 stored in the external device.

[0052] In S807, the CPU 211 temporarily stores the digital certificate 480 included in the received request in the work area in the data memory 214. Then, the CPU 211 proceeds to the process of S808.

[0053] In S808, the CPU 211 verifies whether the digital certificate 480 stored in the work area in S807 is correct using the private key 422 stored in the non-volatile memory 215. That is, the CPU 211 verifies whether the digital certificate 480 is a certificate issued based on the generated CSR 430. Specifically, the CPU 211 generates a digital signature for the owner information and public key stored in the digital certificate 480, and determines whether the generated digital signature matches the digital signature stored in the digital certificate 480. Then, the CPU 211 proceeds to the process of S809.

[0054] In S809, the CPU 211 determines whether the digital certificate 480 is correct based on the verification result. When the CPU 211 determines that the digital certificate 480 stored in the work area is correct (Yes), it proceeds to the process of S810. On the other hand, when the CPU 211 determines that the digital certificate 480 stored in the work area is not correct (No), it does not store the digital certificate 480 in the non-volatile memory 215 and ends the process shown in Fig. 8.

[0055] In S810, the CPU 211 stores the digital certificate 480 stored in the work area in the non-volatile memory 215. After that, the CPU 211 proceeds to the process of S811. In S811, the CPU 211 installs the certificate. That is, the CPU 211 makes the digital certificate 480 and the private key 422 stored in the non-volatile memory 215 available for use in subsequent network communication processing, and ends the process shown in FIG. 8.

[0056] In S801, when the CPU 211 determines that the request type is another request, it proceeds to the process of S812 and performs processing according to the request. After that, the CPU 211 proceeds to the process of S813. In S813, for example, when the CPU 211 receives a request to request a transition to the screen of the remote UI, it performs processing to transition to an appropriate screen of the remote UI corresponding to the received request, and ends the process shown in FIG. 8.

[0057] FIG. 9 is a flowchart showing an example of response processing when an operation is performed on the operation panel 220 of the printer 300. This process is executed as a sub-flow of S708 in the flowchart of FIG. 7. That is, the process shown in FIG. 9 is executed by the CPU 211 of the printer 300 when a user's selection operation or the like on the operation screen of the operation panel 220 is detected.

[0058] In S901, the CPU 211 detects a user's operation on the operation screen, determines the type of the detected operation, and hereinafter performs processing according to the type of the operation.

[0059] In S901, when the CPU 211 determines that the operation type is a selection operation of the setting reset menu, it proceeds to the process of S902, erases the CSR 430 and the digital certificate 480 stored in the non-volatile memory 215, and ends the process shown in FIG. 9. Specifically, when the CPU 211 detects an operation of selecting the setting reset button 623 on the setting menu screen 620 displayed on the operation panel 220, it performs the above process. At this time, the private key 422 is left without being erased from the non-volatile memory 215. Here, although the erasure of the information related to the present disclosure has been described, other information may also be erased when the setting reset menu is selected. Generally, a printer equipped with such a setting reset means is configured to function as a full setting reset means for returning the items set by the user and the items stored in the process of using the device by the user to the factory shipment state (initial state). Further, the full setting reset may be executed in response to detecting a predetermined key operation provided in the printer 300.

[0060] It has been explained that information such as the CSR 430 and the digital certificate 480 is erased by the full setting reset. Since the CSR and the digital certificate include personal information such as the owner information 431, it is preferable that they be erased from within the printing device from the viewpoint of preventing information leakage. On the other hand, since the CSR is not information that is frequently accessed by the user of the printing device, it often remains without being erased within the device. Also, there are cases where it is deliberately left within the device in order to check, display, etc. the information stored in the CSR. Further, since the digital certificate is used for server authentication, etc., it is necessary to leave it within the device. In such cases, it is assumed that the user's selection of the full setting reset indicates a situation where the user may erase the CSR, etc. It can be said that it is more appropriate to erase the information including personal information according to such the user's intention. Note that since the digital certificate is stored in the smartphone 500 in the process of the signature request based on the CSR 430, it can be reinstalled in the printer 300 by uploading again even after the full setting reset.

[0061] In S901, when the CPU 211 determines that the operation type is another menu selection operation, it proceeds to the process of S903 and performs a process corresponding to the selected menu. Then, the CPU 211 proceeds to the process of S904. In S904, the CPU 211 causes the operation screen displayed on the operation panel 220 to transition to an appropriate screen and ends the process shown in FIG. 9. For example, when the CPU 211 receives an execution instruction to transition to a screen for performing settings for network connection, the CPU 211 executes a screen transition process to the said screen.

[0062] In S901, when the CPU 211 determines that the operation type is an operation other than menu selection, it proceeds to the process of S905, performs a process corresponding to the operation, and ends the process shown in FIG. 9.

[0063] According to the present embodiment, after the selection operation of the setting reset menu, the CSR 430 including the owner information 431 and the digital certificate 480 are erased from the non-volatile memory 215. Thereby, even if the printer 300 is discarded or transferred to another person, the owner information 431 does not leak therefrom, and a secure state is achieved. Further, when the same user reconfigures the printer 300 and continues to use it after all settings are reset, the private key 422 remains without being erased from the non-volatile memory 215. Therefore, if the already issued digital certificate 470 remains in the user's possession, the digital certificate can be continuously used only by performing an upload operation of the certificate. That is, it is possible to prevent information leakage when a different user uses the device after all settings are reset while maintaining the convenience when the same user continues to use the device after all settings are reset.

[0064] <<Second Embodiment>> As a second embodiment, an example will be described in which, when all settings are reset, the user is inquired whether or not to erase the private key, and the selection of erasure is received and controlled. Since the basic configuration of this embodiment is the same as that of the first embodiment, differences from the first embodiment will be described.

[0065] Figure 10 is a flowchart showing an example of response processing when an operation is performed on the operation panel 220 in this embodiment. This process is executed as a sub-flow of S708 in the flowchart of FIG. 7. That is, the process shown in FIG. 10 is executed by the CPU 211 of the printer 300 when a user's selection operation or the like on the operation screen of the operation panel 220 is detected. Since S901, S903, S904, and S905 shown in FIG. 10 are the same as the processes with the same step numbers shown in FIG. 9, the description thereof is omitted.

[0066] In S901, when the CPU 211 determines that the operation type is a selection operation of the setting reset menu, the process proceeds to the process of S902, and the CSR 430 and the digital certificate 480 stored in the non-volatile memory 215 are erased. At this time, the private key 422 is left without being erased from the non-volatile memory 215. Then, the CPU 211 proceeds to the process of S1001.

[0067] In S1001, the CPU 211 displays a private key deletion confirmation screen 1100, which will be described later, on the operation panel 220 of the printer 300 and waits for the user's selection operation. When the CPU 211 detects the user's selection operation on the private key deletion confirmation screen 1100, the process proceeds to the process of S1002.

[0068] In S1002, when the CPU 211 determines that the operation detected in S1001 is an operation of pressing a delete button 1102, which will be described later, the process proceeds to the process of S1003, and the private key 422 stored in the non-volatile memory 215 is erased. When the CPU 211 determines that the operation detected in S1001 is an operation of pressing a do not delete button 1103, which will be described later, the process of S1103 is not performed, and the process shown in FIG. 10 ends.

[0069] FIG. 11 is a diagram showing an example of a private key deletion confirmation screen 1100. A notification message 1101 is displayed on the private key deletion confirmation screen 1100. As the notification message 1101, content is displayed that calls attention to the fact that it is a screen on which it is necessary to select whether or not to delete the private key, and that if the private key is deleted, issued digital certificates will no longer be usable. Further, on the private key deletion confirmation screen 1100, a delete button 1102 and a do not delete button 1103 are provided. When the delete button 1102 is pressed, the private key 422 is deleted. On the other hand, when the do not delete button 1103 is pressed, the private key 422 is not deleted. The private key deletion confirmation screen 1100 functions as reception means for receiving a selection as to whether or not to delete the private key 422.

[0070] According to the present embodiment, when the user selects the delete button 1102, which indicates an explicit intention to delete the private key after all settings have been reset, the private key 422 is also deleted together with the CSR 430 and the digital certificate 480. Thereby, it is possible to enhance the user's sense of security when disposing of or transferring the device.

[0071] <<Third Embodiment>> As a third embodiment, an example will be described in which, when all settings are reset, the user is made to select between the case where the same user continues to use the device after the reset and the case where the device is disposed of or transferred to another person, and the printer 300 performs control accordingly. Also in the present embodiment, since the basic configuration is the same as that of the first embodiment, differences from the first embodiment will be described.

[0072] FIG. 12 is a diagram showing an example of a reset type selection screen 1200. A notification message 1201 is displayed on the reset type selection screen 1200. As the notification message 1201, content notifying that it is a screen for the user to select whether to continue using the printer by himself / herself after the setting reset is displayed. Further, on the reset type selection screen 1200, a "Still use" button 1202 and a "Discard / Transfer" button 1203 are provided. Details of the processing when the "Still use" button 1202 or the "Discard / Transfer" button 1203 is pressed will be described in FIG. 13 below.

[0073] FIG. 13 is a flowchart showing an example of response processing when an operation is performed on the operation panel 220. This processing is executed as a sub-flow of S708 in the flowchart of FIG. 7. That is, the processing shown in FIG. 13 is executed by the CPU 211 of the printer 300 when a user's selection operation or the like on the operation screen of the operation panel 220 is detected. Note that since each of S901, S903, S904, and S905 shown in FIG. 10 is the same as the processing of the same step number shown in FIG. 9, the description thereof is omitted.

[0074] In S901, when the CPU 211 determines that the operation type is a selection operation of the setting reset menu, the process proceeds to the process of S1301, the process of transitioning the operation screen of the operation panel 220 to the reset type selection screen 1200 is performed, and the process shown in FIG. 13 ends.

[0075] In S901, when the CPU 211 determines that the operation type is a pressing operation of the "Still use" button 1202, the process proceeds to the process of S1302, the CSR 430 and the digital certificate 480 stored in the non-volatile memory 215 are erased, and the process shown in FIG. 13 ends. At this time, the private key 422 is left without being erased from the non-volatile memory 215.

[0076] In S901, when the CPU 211 determines that the operation type is a press operation of the discard / transfer button 1203, the process proceeds to the process of S1303, and the CSR 430, digital certificate 480, and private key 422 stored in the non-volatile memory 215 are erased. After that, the CPU 211 ends the process shown in FIG. 13.

[0077] According to this embodiment, when resetting all settings, it is possible to explicitly select whether the same user continues to use it or it is discarded or transferred to others, and execute appropriate processing. When the same user continues to use it, the control is such that the private key 422 remains without being erased from the non-volatile memory 215. After resetting all settings, as a case where the same user continues to use it, for example, when the set password is forgotten and initialization for changing the set information is required. Even after resetting all settings, if the already issued digital certificate 470 remains in the user's hand, the digital certificate can be continuously used by simply performing the certificate upload operation. On the other hand, when it is discarded or transferred to others, the control is such that the private key 422 is also erased from the non-volatile memory 215. Therefore, the sense of security of the user at the time of discarding or transferring can be enhanced.

[0078] <<Other Embodiments>> In the above-described embodiment, the case where resetting all settings is selected and executed from the operation menu of the operation panel 220 of the printer 300 has been described, but it may be configured to be able to perform setting reset from the remote UI.

[0079] Also, in the first embodiment, the case where the private key 422 is not erased and remains even after the CSR430 is erased has been described. However, if the CSR430 has been generated but the CSR download has not yet been executed, control may be performed to erase the private key 422. This is because if the CSR430 has not been downloaded, there is no possibility of issuing a digital certificate based on it, so there is no problem in erasing the private key 422. Similarly, in the second embodiment, the case where a screen for confirming whether to erase the private key 422 after erasing the CSR430 is displayed has been described. However, if the CSR download has not been executed, control may be performed to erase the private key 422 without displaying the confirmation screen.

[0080] Also, when there is an authentication function such as an administrator password in the operation panel 220 or the remote UI, when erasing the private key 422, either when erasing it or leaving it without erasing it, or both, the administrator password authentication function may be configured to be required.

[0081] In the above-described embodiments, a printer has been described as an example of an information processing apparatus connectable to a network, but the present invention is not limited thereto. For example, the information processing apparatus may be an apparatus that performs TLS communication with an external apparatus, and may be an apparatus in which a setting operation or the like for processing executed by the information processing apparatus is performed. Also, in the above-described embodiments, a smartphone has been described as an example of the external apparatus, but the present invention is not limited thereto. For example, the external apparatus may be an apparatus having a general web browser, such as a desktop PC (Personal Computer), a notebook PC, a tablet terminal, or a television.

[0082] The disclosure of the present embodiment includes configurations represented by the following examples of an information processing apparatus, an example of a control method of the information processing apparatus, and an example of a program.

[0083] <Configuration 1> An information processing apparatus that performs encrypted communication with an external apparatus, a private key for the encrypted communication, and generation means for generating a CSR (Certificate Signing Request) using the private key, Storage means for storing the private key, the CSR, and the certificate issued based on the CSR; First reception means for receiving an instruction to initialize the information stored by the storage means; Control means for performing control to erase the CSR and the certificate and not to erase the private key when the first reception means receives the instruction to initialize; An information processing apparatus, characterized by comprising the above.

[0084] <Configuration 2> The information processing apparatus according to Configuration 1, further comprising reception means for receiving the certificate from the external device.

[0085] <Configuration 3> The information processing apparatus according to Configuration 1 or 2, further comprising second reception means for receiving a selection by the user as to whether to erase the private key when the first reception means receives the instruction to initialize.

[0086] <Configuration 4> The information processing apparatus according to any one of Configurations 1 to 3, further comprising transmission means for transmitting the CSR to the external device in response to an instruction to download the CSR from the external device.

[0087] <Configuration 5> The information processing apparatus according to any one of Configurations 1 to 4, further comprising installation means for making the certificate available based on verification using the private key.

[0088] <Configuration 6> The information processing apparatus according to any one of Configurations 1 to 5, wherein when the first reception means receives the instruction to initialize and a selection indicating that the user continues to use the information processing apparatus, the control means performs the control.

[0089] <Configuration 7> When the first reception means receives the initialization instruction and the selection indicating that the information processing apparatus is to be discarded or transferred, the control means performs control to delete the private key, the CSR, and the certificate stored in the storage means. The information processing apparatus according to any one of Configurations 1 to 5.

[0090] <Configuration 8> When the first reception means receives the initialization instruction in a state where the CSR has not been transmitted to the external device by the transmission means after the CSR is generated by the generation means, the control means controls to delete the CSR and the private key stored in the storage means. The information processing apparatus according to Configuration 4.

[0091] <Configuration 9> The information processing apparatus according to any one of Configurations 1 to 8, wherein the information processing apparatus is a printing apparatus.

[0092] <Configuration 10> A control method for an information processing apparatus that performs encrypted communication with an external device, A generation step of generating a private key for the encrypted communication and a CSR (Certificate Signing Request) using the private key, A storage step of storing the private key, the CSR, and a certificate issued based on the CSR, A first reception step of receiving an instruction to initialize the information stored in the storage step, A control step of, when the instruction to initialize is received in the first reception step, performing control to delete the CSR and the certificate and not to delete the private key A control method for an information processing apparatus, comprising:

[0093] <Configuration 11> A program for causing a computer to execute the control method of the information processing apparatus according to Configuration 10.

Explanation of Signs

[0094] 101 Wireless LAN access point 300 Printer 500 Smartphone

Claims

1. An information processing apparatus that performs encrypted communication with an external device, a generation means for generating a private key for the encrypted communication and a CSR (Certificate Signing Request) using the private key, a storage means for storing the private key, the CSR, and a certificate issued based on the CSR, a first reception means for receiving an instruction to initialize the information stored in the storage means, and a control means for, when receiving the instruction to initialize by the first reception means, deleting the CSR and the certificate and not deleting the private key. An information processing apparatus characterized by comprising the above.

2. The information processing apparatus according to claim 1, further comprising a reception means for receiving the certificate from the external device.

3. The information processing apparatus according to claim 1, further comprising a second reception means for receiving, when receiving the instruction to initialize by the first reception means, a selection by a user as to whether to delete the private key.

4. The information processing apparatus according to claim 1, further comprising a transmission means for transmitting the CSR to the external device in response to an instruction to download the CSR from the external device.

5. The information processing apparatus according to claim 1, further comprising an installation means for making the certificate available based on verification using the private key.

6. The information processing apparatus according to claim 1, wherein when the first reception means receives the instruction to initialize and a selection indicating that the user continues to use the information processing apparatus, the control means performs the control.

7. The information processing apparatus according to claim 1, wherein when the first reception means receives the instruction to initialize and a selection indicating that the information processing apparatus is to be discarded or transferred, the control means performs control to delete the private key, the CSR, and the certificate stored in the storage means.

8. The information processing apparatus according to claim 4, wherein when the first reception means receives the instruction to initialize in a state where the CSR has not been transmitted to the external device by the transmission means after the CSR is generated by the generation means, the control means controls to delete the CSR and the private key stored in the storage means.

9. The information processing apparatus according to claim 1, wherein the information processing apparatus is a printing apparatus.

10. A control method for an information processing apparatus that performs encrypted communication with an external device, a generation step of generating a private key for the encrypted communication and a CSR (Certificate Signing Request) using the private key; a storage step of storing the private key, the CSR, and a certificate issued based on the CSR; a first reception step of receiving an instruction to initialize the information stored in the storage step; a control step of, when the instruction to initialize is received in the first reception step, deleting the CSR and the certificate and not deleting the private key; A control method for an information processing apparatus, comprising the steps described above.

11. A program for causing a computer to execute the control method for an information processing apparatus according to claim 10.

Citation Information

Patent Citations

  • Information processing apparatus and computer program

    JP2012028978A