Device management system, device management method, and computer program
The device management system addresses non-compliance with FIPS140-3 by acquiring encryption settings, determining the mode, and selecting appropriate authentication algorithms, ensuring seamless compliance with the security standard.
Patent Information
- Application Number
- JP2024001956
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2025-07-23
AI Technical Summary
Existing device management systems do not comply with the FIPS140-3 security standard, specifically in network environments managed by these systems.
A device management system that includes encryption setting acquisition, determination of FIPS140 mode, verification of FIPS140 version, and display and selection of appropriate authentication algorithms to ensure compliance with FIPS140-3.
Enables easy compliance with the FIPS140-3 standard by determining and adjusting authentication algorithms to meet the required security standards.
Smart Images

Figure 2025108195000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a device management system, a device management method, a computer program, and the like.
Background Art
[0002] Conventionally, a device management system and a management device for acquiring and managing data such as operation information of an image forming apparatus (hereinafter referred to as a device) such as a printer or a multifunction peripheral are known. In such a device management system, it is possible to manage an address book or the like including a plurality of pieces of destination information such as the status, setting values, firmware, and e-mail addresses of network devices to be managed.
[0003] In addition, the device management system can acquire and distribute those data to network devices to be managed via a network, and encryption of communication with the network devices is performed in information acquisition and distribution.
[0004] Patent Document 1 describes a configuration in which an image processing apparatus switches an operation screen provided to an operation terminal apparatus according to a communication level between the own apparatus and the operation terminal apparatus for security.
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] On the other hand, there is the Federal Information Processing Standards (FIPS), which is a standard established by the National Institute of Standards and Technology (NIST), a US government agency that defines requirements regarding the security and confidentiality of encryption modules. FIPS has versions such as FIPS 140-2 and FIPS 140-3.
[0006] In a device management system, SNMP (Simple Network Management Protocol) and various communication protocols are used for monitoring and managing the TCP / IP network environment.
[0007] In such protocols, a hash algorithm can be selected from SHA1 / SHA2-256 / SHA2-384 / SHA2-512, etc. However, with respect to the environment (or subsystem) in which the network devices managed by the device management system are included, it does not comply with FIPS140-3.
[0008] One of the objectives of the present invention is to solve the above problems and provide a device management system that can easily comply with FIPS140-3.
Means for Solving the Problems
[0009] A device management system for managing a plurality of devices connected to a network, encryption setting acquisition means for acquiring system encryption settings, first determination means for determining whether the device management system is in FIPS140 mode, second determination means for determining whether the version of FIPS140 is FIPS140-3, authentication algorithm display means for displaying an authentication algorithm based on the determination results of the first determination means and the second determination means, selection means for selecting the authentication algorithm displayed by the authentication algorithm display means, A device management system characterized by comprising the above.
Effects of the Invention
[0010] According to the present invention, a device management system that can easily comply with FIPS140-3 can be realized.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6A
Figure 6B
Figure 6C
Figure 7A
Figure 7B
Figure 7C
Figure 7D
Figure 8A
Figure 8B
Figure 9
Figure 10
Best Mode for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. However, the present invention is not limited to the following embodiments. In each figure, the same members or elements are denoted by the same reference numerals, and redundant descriptions are omitted or simplified.
[0013] <Embodiment 1> FIG. 1 is a schematic diagram showing a configuration example of a device management system according to Embodiment 1 of the present invention. The device management system according to Embodiment 1 includes one device management server 1000 having a device management application 101, and a plurality of agent applications (hereinafter abbreviated as agents) 106 and 107.
[0014] Further, the device management system according to Embodiment 1 manages devices 102, 103, 110, 111 (hereinafter collectively referred to as device 2000) connected to the network. The device management server 1000, the agent 106, and the devices 102 and 103 are interconnected by a network 104.
[0015] The agent 107 and the devices 110 and 111 are interconnected by a network 108. The network 104 and the network 108 are connected by a router 109 (the networks 104 and 108 are collectively referred to as a communication line 3000).
[0016] The router interconnects both networks and can be configured to permit communication between, for example, the agent 107 and the device management server 1000, but block communication with the devices 110 and 111 on the network 108.
[0017] Here, the agents 106 and 107, and the devices 102, 103, 110, 111, etc. are associated according to the addresses of the respective devices. For example, assume that agent 106 is associated with devices 102 and 103, and agent 107 is associated with devices 110 and 111.
[0018] 105 is a directory server, and the device management server 1000 can be set so that the users of the directory server 105 can access the device management server 1000.
[0019] Hereinafter, an example of the operation of device 102 by agent 106 will be described. The device management server 1000 instructs agent 106 to perform an operation on device 102. Agent 106 performs operations such as sending a request to device 102 according to the instruction, and sends the result to the device management server 1000.
[0020] Examples of operations include obtaining information from device 102, changing the set value of device 102, instructing installation of an application to device 102, instructing firmware update of device 102, etc.
[0021] Device 102 and device management server 1000 do not communicate directly, and the communication is performed between device management server 1000 and agent 106, and between agent 106 and device 102.
[0022] Note that in FIG. 1, there are 2 agents and 4 devices, but a configuration in which tens of thousands of devices are managed via a dozen or so agents may also be possible. Even in that case, the configuration and operation are the same as the description of this embodiment.
[0023] Figure 2 is a diagram showing an example of the hardware configuration of the device management server 1000 according to Embodiment 1. The CPU 10 executes various computer programs such as the OS and device management software stored in the ROM 11 and the HDD 19, using the RAM 12 as a work area. Also, 13 is a system bus.
[0024] Also, the device management server 1000 is connected to a display device (LCD) 15 via a video card (VC) 14, and is connected to a keyboard (KB) 17 and a pointing device such as a mouse (not shown) via a keyboard controller (KBC) 16.
[0025] Also, the device management server 1000 can control a Disk Drive 20 that can mount storage media such as a CD-ROM, DVD, magnetic tape, and IC memory card via a disk controller (DKC) 18.
[0026] Also, the device management server 1000 can perform data communication with devices on the communication line 3000 via a network interface board (NIC) 21.
[0027] Figure 3 is a functional block diagram showing an example of the module configuration of the software of the device management server 1000 according to Embodiment 1. The device management server 1000 includes a UI control unit 30, a device control unit 31, a schedule control unit 32, and a function control unit 33 as a module configuration of software for managing the device 2000.
[0028] These modules are realized by the CPU 10 executing device management software, which is a computer program stored in the RAM 12, ROM 11, and HDD 19 of FIG. 2.
[0029] However, some or all of them may be realized by hardware. As the hardware, a dedicated circuit (ASIC) or a processor (reconfigurable processor, DSP) can be used.
[0030] Also, each functional block shown in FIG. 3 does not have to be built in the same housing, and may be configured by separate devices connected to each other via signal paths. Note that the above description regarding FIG. 3 also applies to FIG. 4 in the same manner.
[0031] The UI control unit 30 is composed of a device display unit 301, a schedule display unit 302, a function display unit 303, etc. The device control unit 31 is composed of a device connection unit 311, a device data management unit 312, a device data storage unit 313, etc.
[0032] The schedule control unit 32 is composed of a schedule management unit 321, a schedule storage unit 322, etc. The function control unit 33 is composed of a device setting distribution unit 331, an address book distribution unit 332, a function information storage unit 333, etc.
[0033] The UI control unit 30 performs the respective UI controls in the device control unit 31, the schedule control unit 32, and the function control unit 33 by means of the device display unit 301, the schedule display unit 302, and the function display unit 303. Also, it can be implemented as a web-based application, and in that case, it can be used via a web browser.
[0034] The device connection unit 311 has functions of device search, information collection from a device, and setting execution. As an example of the function of the device connection unit 311, there is a device search function for the device 2000 by means of SNMP, IP Broadcast, SLP / Multicast, etc.
[0035] At that time, the device connection unit 311 performs a search for the device 2000 at an arbitrary timing. And the device connection unit 311 has a function of acquiring / changing device information such as MIB (Management Information Base) and security policy information via a communication line 3000 such as a LAN.
[0036] In addition, the device connection unit 311 controls communication settings with the device 2000, obtains device information such as the device name, product name, and IP address as a result of device search, and saves it in the device data storage unit 313. The device data management unit 312 manages the data in the device data storage unit 313.
[0037] The schedule management unit 321 cooperates with each function of the function control unit 33, generates and manages the schedule input from the schedule display unit 302, and saves it in the schedule storage unit 322. The device setting distribution unit 331 of the function control unit 33 performs setting distribution to the device based on the input from the function display unit 303.
[0038] In addition, the address book distribution unit 332 performs address book distribution to the device based on the input from the function display unit 303. At that time, each piece of information is stored in the function information storage unit 333. Here, the device data storage unit 313, the schedule storage unit 322, and the function information storage unit 333 are data recording media such as databases operating on the HDD 19, and schedule lists, device lists, function information, etc. are stored.
[0039] FIG. 4 is a functional block diagram showing an example of the internal configuration of the device 2000 according to Embodiment 1, and shows an example of the software configuration of the information control unit 40 operating on the device 2000. The device 2000 has an information control unit 40 for managing a plurality of dynamically changing information groups as software modules. Note that the device 2000 according to Embodiment 1 is, for example, a printer.
[0040] The counter information management unit 401 manages the number of printed pages, etc., and saves it in the counter storage unit 402. The MIB information management unit 403 manages the MIB information, which is the previous device information, and saves it in the MIB information storage unit 404. The power supply information management unit 405 manages power-off information and reboot information, and saves it in the power supply information storage unit 406.
[0041] The status information management unit 407 manages status information such as online, offline, and error, and stores it in the status information storage unit 408. The address book information management unit 409 manages information such as the configuration and data of the address book, and stores it in the address book information storage unit 410. Also, the information of the distributed address book is managed and stored here.
[0042] The setting value information management unit 411 stores various setting values such as settings for device printing and network-related settings in the setting value information storage unit 412. Each data is sent to the device management server 1000 according to the request of the device management server 1000 by SNMP or other protocols.
[0043] FIG. 5 is a diagram showing an example of a display UI related to the device search result according to Embodiment 1, and FIGS. 6A to 6C are diagrams showing examples of display UIs related to communication settings and the like in Embodiment 1. The flow of device search will be described with reference to FIGS. 5 and 6.
[0044] The device management server 1000 searches for devices 2000 to be managed on the network. That is, the device search settings are made from the "Task" menu in FIG. 5, and the search is performed. SNMP is used for this search algorithm.
[0045] An example of the UI related to the device search result after the search is shown in FIG. 5. Here, together with the names of the searched devices, the information of those devices (device name, product name, IP address, serial number, etc.) is displayed. Also, on this screen, a specific device can be specified and excluded from the management target.
[0046] Note that before the search, the communication settings with the device are made in advance. Select "Communication Settings with Device" from the "Device" menu. FIG. 6A is a diagram showing an example of the UI for communication settings with the device. Here, as the authentication settings, necessary settings such as SNMPv1, SNMPv3, and user authentication settings are made.
[0047] In the example of FIG. 6A, the SNMPv1 setting has already been configured as the authentication method. Here, when performing SNMPv3, select SNMPv3 as the authentication method, select, for example, "Read Only" as the access restriction, and click the "Add" button.
[0048] When the "Add" button in FIG. 6A is clicked, a detailed screen of the authentication information is displayed. FIG. 6B is a diagram showing an example of the display UI regarding the details of the authentication information in Embodiment 1. In FIG. 6B, enter "User Name", "Authentication Password", "Encrypted Password", "Context Name", "Scope" (target agent range), and description, and click the "Add" button in FIG. 6B. Thereby, a new authentication method is added, and the screen transitions to FIG. 6C. FIG. 6C is a diagram showing an example of the display UI regarding the communication settings with the device in Embodiment 1.
[0049] In addition, in FIG. 6B, any one of SHA1 / SHA2-256 / SHA2-384 / SHA2-512 can be selected as the hash algorithm for the "Authentication Password". Based on the communication settings set in advance in this way, device search and information acquisition are performed.
[0050] FIG. 7A is a flowchart showing an example of the processing in the device management method according to Embodiment 1. In addition, in this embodiment, the device management server 1000 shown in FIG. 1 executes a device management method for managing a plurality of devices connected to the network.
[0051] Moreover, by the CPU or the like as a computer in the device management server 1000 executing the device management software as a computer program stored in the memory, the operations of each step of the flowcharts in FIGS. 7A to 7D are sequentially performed.
[0052] When the device management server 1000 manages a device, as described above with reference to FIG. 5, it searches for the device. Also, prior to that, it performs communication settings with the device. That is, it selects "Communication Settings with Device" from the "Device" button in FIG. 5. Then, as described above, from the communication settings screen with the device shown in FIG. 6A, it selects the authentication method "SNMPv3" and clicks the "Add" button.
[0053] When clicking on the selection display 601 of the "Authentication Algorithm" of the "Authentication Password" in FIG. 6B described above, in step S701 of FIG. 7A, the device connection unit 311 acquires the system encryption settings.
[0054] That is, in the device management system, the device management server 1000 operating on Windows acquires information regarding whether Windows is operating in FIPS 140 mode or not. Here, step S701 functions as an encryption settings acquisition step (encryption settings acquisition means).
[0055] In step S702, the device connection unit 311 determines whether the operation of the device management system is in FIPS 140 mode based on the information acquired in step S701. If it is determined as Yes in step S702, it proceeds to step S703. Otherwise, it proceeds to step S707. Here, step S702 functions as a first determination step (first determination means) for determining whether the device management system is in FIPS 140 mode.
[0056] In step S703, the device connection unit 311 checks the FIPS 140 version. Here, step S703 functions as a version check step (version check means) for checking the FIPS 140 version.
[0057] In step S704, the device connection unit 311 determines whether the version of FIPS140 is FIPS140-3. Here, step S704 functions as a second determination step (second determination means) for determining whether the version of FIPS140 is FIPS140-3.
[0058] If the determination in step S704 is Yes, the process proceeds to step S705. Otherwise, the process proceeds to step S708.
[0059] In step S705, the device display unit 301 displays the "authentication algorithm" for FIPS140-3. Also, in step S706, the device connection unit 311 selects the "authentication algorithm" and returns to the detailed screen of the authentication information. Here, step S706 functions as a selection step (selection means) for selecting the authentication algorithm displayed by the authentication algorithm display step (authentication algorithm display means).
[0060] In step S707, the device display unit 301 displays the normal authentication algorithm. In step S708, the device display unit 301 displays the authentication algorithm for FIPS140-2.
[0061] Here, step S705, step S707, and step S708 function as an authentication algorithm display step (authentication algorithm display means) for displaying the authentication algorithm based on the determination results of the first determination means and the second determination means. Note that the authentication algorithm display means can display the authentication algorithm for FIPS140-3 or the authentication algorithm for FIPS140-2.
[0062] Figure 7B is a flowchart showing a detailed flow example of step S703 in Figure 7A. In the confirmation of the FIPS140 version in step S703, in step S709, the device connection unit 311 performs SHA1 hash calculation.
[0063] Next, in step S710, the device connection unit 311 determines whether an exception has occurred. More specifically, the device connection unit 311 attempts to perform SHA1 hash calculation using the operating system library.
[0064] At this time, if the operating system is operating in FIPS 140-3 mode, an exception will be returned to the device connection unit 311 as a result of the calculation. For example, when the operating system is Windows 11 or the like, a value of InvalidOperationException is returned as an exception.
[0065] Based on the processing here, the device connection unit 311 determines whether an exception has occurred. Note that steps S709 and S710 function as a third determination step (third determination means) for performing SHA1 hash calculation and determining whether an exception occurs.
[0066] If it is determined Yes in step S710, the process proceeds to step S712. Otherwise, the process proceeds to step S711.
[0067] In step S711, the device connection unit 311 determines as FIPS140-2, ends the flow of FIG. 7B, and proceeds to step S704. On the other hand, in step S712, the device connection unit 311 determines as FIPS140-3, ends the flow of FIG. 7B, and proceeds to step S704.
[0068] That is, when it is determined that an exception has occurred by the third determination means, it is determined as FIPS140-3, and when it is determined that no exception has occurred by the third determination means, it is determined as FIPS140-2.
[0069] FIG. 7C is a flowchart showing a detailed flow example of step S708 in FIG. 7A. In the display of the FIPS140-2 authentication algorithm in step S708, in step S713, an (enumerated) display such as SHA1 / SHA2-256 / SHA2-384 / SHA2-512 is performed.
[0070] That is, when displaying the authentication algorithm for FIPS 140-2, at least one of SHA1, SHA2-256, SHA2-384, and SHA2-512 is displayed. Then, the flow of FIG. 7C is ended and the process proceeds to step S706.
[0071] FIG. 7D is a flowchart showing a detailed flow example of step S705 in FIG. 7A. In the display of the authentication algorithm for FIPS 140-3 in step S705, in step S714, SHA2-256 / SHA2-384 / SHA2-512, etc. are (enumerated) displayed.
[0072] That is, when displaying the authentication algorithm for FIPS 140-3, at least one of SHA2-256, SHA2-384, and SHA2-512 is displayed. Then, the flow of FIG. 7D is ended and the process proceeds to step S706.
[0073] In this embodiment, through this series of operations, it is possible to determine which FIPS version is operating, and to display and change the selection of the SNMPv3 hash algorithm.
[0074] Next, the operation of the UI example is supplemented with reference to FIGS. 5 to 8. Here, it is assumed that Windows is operating in FIPS 140-3 mode. As described above, in order to perform communication settings with the device prior to device management, select "Communication Settings with Device" from the "Device" menu in FIG. 5.
[0075] From the "Communication Settings with Device" screen shown in FIG. 6A, select "SNMPv3" as the authentication method and click the "Add" button. Click on the selection display 601 of the "Authentication Algorithm" in the "Authentication Password" on the "Details of Authentication Information" screen shown in FIG. 6B.
[0076] Then, in steps S701 and S702, it is determined that the operation is in FIPS140, and in the confirmation of the FIPS140 version in step S703, the SHA1 hash calculation in step S709 of FIG. 7B is performed.
[0077] Since Windows is operating in FIPS140-3 mode, SHA1 is an algorithm that cannot operate, and an exception (error) occurs in the SHA1 hash calculation. Therefore, from steps S710 and S712, it is determined to be FIPS140-3.
[0078] After that, in steps S704 and S705, the "authentication algorithm" for FIPS140-3 is displayed. FIG. 8A is a diagram showing an example of the display of the "authentication algorithm" for FIPS140-3. By the process of step S714, as shown in 801 of FIG. 8A, SHA2-256 / SHA2-384 / SHA2-512 are enumerated.
[0079] In step S706, one of the enumerated algorithms is selected, and then by adding the communication setting screen with the device, the communication setting with the device as shown in FIG. 6C is saved.
[0080] When Windows is operating in FIPS140-2 mode, since no exception (error) occurs in the SHA1 hash calculation in the previous step S709, it is determined to be FIPS140-2. In steps S704 and S708, the "authentication algorithm" for FIPS140-2 is displayed.
[0081] That is, FIG. 8B is a diagram showing an example of the display of the "authentication algorithm" for FIPS140-2. By the process of step S713, as shown in 802 of FIG. 8B, SHA1 / SHA2-256 / SHA2-384 / SHA2-512 are enumerated.
[0082] Similarly, in step S706, by selecting the enumerated algorithms and then adding a communication setting screen with the device, the communication setting with the device as shown in FIG. 6C is saved. As described above, according to this embodiment, in the case of performing the setting operation of the FIPS140-3 version, SHA1 can be removed from the selection display by these series of operations.
[0083] <Embodiment 2> In Embodiment 2, in the FIPS operation mode, when the information update of the device by the already saved algorithm setting becomes an exception to SHA1, it is assumed that the FIPS-compatible version is updated by Windows or device update, etc. Then, an icon and a warning display are performed to prompt a transition to the communication setting screen.
[0084] FIG. 9 is a flowchart showing a processing example of the device management method in Embodiment 2. The processing shown in FIG. 9 is realized by the CPU 10 as a computer executing device management software stored in a memory as a storage medium.
[0085] Similar to Embodiment 1, it is assumed that the communication setting with the device is performed as shown in FIG. 6C. Also, it is assumed that the devices have already been searched and managed as in the display screen of the device list in FIG. 5, and the setting for periodic device update has been made.
[0086] When the display of the device list shown in FIG. 5 is performed, the flow of FIG. 9 starts. In step S901 of FIG. 9, the device connection unit 311 acquires the system encryption setting. In step S902, based on the information acquired in step S901, the device connection unit 311 determines whether the device management system is in the FIPS140 mode.
[0087] If it is determined Yes in step S901, the process proceeds to step S903. If it is determined No in step S901, the flow of FIG. 9 ends and the device list screen continues. Note that the flows of steps S901 to S908 in FIG. 9 are periodically repeated.
[0088] In step S903, the device connection unit 311 selects a device to be the target for icon display and warning display according to the user's operation. Here, step S903 functions as a device selection step (device selection means) for selecting a target device.
[0089] In step S904, the device connection unit 311 determines whether an SHA1 exception has occurred in the target device selected in step S903. Here, step S904 functions as an exception determination step (exception determination means) for determining whether an SHA1 exception has occurred in the target device.
[0090] If it is determined as Yes in step S903, the process proceeds to step S905. If it is determined as No in step S903, the flow of FIG. 9 ends and the device list screen continues.
[0091] In step S905, the device display unit 301 performs icon display. In step S906, the device display unit 301 determines whether there is a cursor on the icon displayed in step S905.
[0092] If it is determined as Yes in step S906, the process proceeds to step S907. If it is determined as No in step S906, the flow of FIG. 9 ends and the device list screen continues. In step S907, the device display unit 301 performs warning message display. In step S908, the device display unit 301 performs link display to the authentication information details screen.
[0093] Here, the operation of Embodiment 2 shown in FIG. 9 will be supplemented and explained using the UI examples shown in FIGS. 5, 6, and 10. Assume that SNMPv3 communication settings with the device are made as shown in FIG. 6C. Also, assume that it was operating in FIPS140-2 mode before that, and the SHA1 was set as its authentication algorithm. Also, assume that devices have already been searched and managed as in the display screen of the device list in FIG. 5, and periodic device update settings have been made.
[0094] In steps S901 and S902 of FIG. 9, it is determined that the operation is in FIPS140. In step S903, assume that, for example, Device2 in FIG. 5 is selected. Then, in step S904, it is determined whether a SHA1 exception has occurred.
[0095] Here, assume that an exception has occurred. Then, in step S905, an icon is displayed. The figure exemplifying this is FIG. 10. For example, an icon such as "!" is displayed at the right end of the row of Device2.
[0096] Also, in step S906, it is determined whether there is a cursor on the icon. Here, assume that the user has moved the cursor over the icon. Then, a determination of Yes is made in step S906.
[0097] Then, in step S907, a warning message is displayed. That is, as shown in FIG. 10, a message 1001 such as "SHA1 algorithm error. The FIPS version may have been updated." is displayed below the icon of Device2.
[0098] Also, in step S908, as shown in message 1001 of FIG. 10, a link "To the detailed authentication information screen" is displayed. By clicking this, it is possible to move to the "Detailed authentication information" screen (authentication information setting screen) as shown in FIGS. 6B, 8A, and 8B. And the authentication algorithm setting can be changed.
[0099] Here, steps S904 to S908 function as a notification step (notification means) to notify the user when it is determined by the exception determination step (exception determination means) that a SHA1 exception has occurred. Note that the notification means may perform at least one of icon display, warning display, and a link to the authentication information setting screen.
[0100] In Embodiment 2, according to such a flow, when the information update of the device due to the already saved algorithm setting becomes a SHA1 exception, it is assumed that the FIPS-compatible version has been updated due to an update of Windows or the device. Then, an icon or warning display can be performed, and the transition to the detailed screen of the authentication information can be prompted.
[0101] As described above, according to Embodiment 1, it is possible to prevent an algorithm setting that cannot operate in a Windows environment compatible with FIPS140-3 in advance. Also, according to Embodiment 2, when the information update of the device due to the already saved algorithm setting results in an error, it can be determined that the FIPS-compatible version has been updated due to an update of Windows or the device, etc., and the modification of the authentication information can be prompted.
[0102] <Other Embodiments> Note that the present invention may be applied to a system composed of a plurality of devices (for example, a host computer, an interface device, a reader, a printer, etc.), or may be applied to a single combined device (for example, a multifunction device such as a copier or a facsimile device).
[0103] Also, the present invention can also be realized by supplying a recording medium recording program code for realizing the functions of the above-described embodiments to a system or device, and causing a computer of the system or device to read and execute the program code stored in the recording medium.
[0104] In that case, the program code itself read from the storage medium realizes the functions of the foregoing embodiments, and the program code itself and the storage medium storing the program code constitute the present invention.
[0105] Furthermore, the present invention includes a case where, based on an instruction of the program code, an operating system (OS) or the like running on a computer performs part or all of the actual processing, and the functions of the foregoing embodiments are realized by that processing.
[0106] Furthermore, the present invention is also applicable to a case where the program code read from the storage medium is written into a memory provided in a function expansion card inserted into the computer or a function expansion unit connected to the computer.
[0107] In that case, based on an instruction of the written program code, a CPU or the like provided in the function expansion card or the function expansion unit performs part or all of the actual processing, and the functions of the foregoing embodiments are realized by that processing.
[0108] As described above, the present invention has been described in detail based on its preferred embodiments. However, the present invention is not limited to the above embodiments, and various modifications and combinations of the above embodiments are possible based on the spirit of the present invention, and they are not excluded from the scope of the present invention. The present invention includes the following combinations.
[0109] (Configuration 1) A device management system for managing a plurality of devices connected to a network, comprising: encryption setting acquisition means for acquiring a system encryption setting; first determination means for determining whether the device management system is in FIPS140 mode; second determination means for determining whether the version of FIPS140 is FIPS140-3; authentication algorithm display means for displaying an authentication algorithm based on the determination results of the first determination means and the second determination means; and selection means for selecting the authentication algorithm displayed by the authentication algorithm display means.
[0110] (Configuration 2) The authentication algorithm display means of the device management system according to Configuration 1, characterized in that it can display an authentication algorithm for FIPS140-3 or an authentication algorithm for FIPS140-2.
[0111] (Configuration 3) The device management system according to Configuration 2, characterized in that when displaying the authentication algorithm for FIPS140-2, at least one of SHA1, SHA2-256, SHA2-384, and SHA2-512 is displayed.
[0112] (Configuration 4) The device management system according to Configuration 2 or 3, characterized in that when displaying the authentication algorithm for FIPS140-3, at least one of SHA2-256, SHA2-384, and SHA2-512 is displayed.
[0113] (Configuration 5) The device management system according to any one of Configurations 1 to 4, characterized by having version confirmation means for confirming the FIPS140 version.
[0114] (Configuration 6) The device management system according to Configuration 5, characterized in that the version confirmation means has third determination means for performing SHA1 hash calculation and determining whether an exception occurs.
[0115] (Configuration 7) The device management system according to Configuration 6, characterized in that when it is determined by the third determination means that an exception occurs, it is determined as FIPS140-3, and when it is determined by the third determination means that no exception occurs, it is determined as FIPS140-2.
[0116] (Configuration 8) A device management system for managing a plurality of devices connected to a network, comprising: an encryption setting acquisition means for acquiring system encryption settings; a first determination means for determining whether the device management system is in FIPS 140 mode; a device selection means for selecting a target device; an exception determination means for determining whether a SHA1 exception has occurred in the target device; and a notification means for notifying a user when it is determined by the exception determination means that a SHA1 exception has occurred.
[0117] (Configuration 9) The device management system according to Configuration 8, wherein the notification means performs at least one of icon display, warning display, and a link to an authentication information setting screen.
[0118] (Method 1) A device management method for managing a plurality of devices connected to a network, comprising: an encryption setting acquisition step for acquiring system encryption settings; a first determination step for determining whether the device management system is in FIPS 140 mode; a second determination step for determining whether the version of FIPS 140 is FIPS 140-3; an authentication algorithm display step for displaying an authentication algorithm based on the determination results of the first determination step and the second determination step; and a selection step for selecting the authentication algorithm displayed in the authentication algorithm display step.
[0119] (Method 2) A device management method for managing a plurality of devices connected to a network, comprising: an encryption setting acquisition step for acquiring system encryption settings; a first determination step for determining whether the device management system is in FIPS 140 mode; a device selection step for selecting a target device; an exception determination step for determining whether a SHA1 exception has occurred in the target device; and a notification step for notifying a user when it is determined by the exception determination step that a SHA1 exception has occurred.
[0120] A computer program for controlling each means of the device management system described in any one of Configurations 1 to 9 by a computer.
Explanation of Signs
[0121] 101: Device management application 1000: Device management server 2000: Device 3000: Communication line
Claims
1. A device management system for managing a plurality of devices connected to a network, comprising: encryption setting acquisition means for acquiring system encryption settings; first determination means for determining whether the device management system is in FIPS 140 mode; second determination means for determining whether the version of FIPS 140 is FIPS 140-3; authentication algorithm display means for displaying an authentication algorithm based on the determination results of the first determination means and the second determination means; selection means for selecting an authentication algorithm displayed by the authentication algorithm display means; A device management system characterized by comprising the above.
2. The device management system according to claim 1, wherein the authentication algorithm display means is capable of displaying an authentication algorithm for FIPS 140-3 or an authentication algorithm for FIPS 140-2.
3. The device management system according to claim 2, wherein when displaying the authentication algorithm for FIPS 140-2, at least one of SHA1, SHA2-256, SHA2-384, and SHA2-512 is displayed.
4. The device management system according to claim 2, wherein when displaying the authentication algorithm for FIPS 140-3, at least one of SHA2-256, SHA2-384, and SHA2-512 is displayed.
5. The device management system according to claim 1, further comprising version confirmation means for confirming the FIPS 140 version.
6. The device management system according to claim 5, wherein the version confirmation means performs SHA1 hash calculation and has third determination means for determining whether an exception occurs.
7. The device management system according to claim 6, wherein when it is determined by the third determination means that an exception occurs, it is determined as FIPS 140-3, and when it is determined by the third determination means that no exception occurs, it is determined as FIPS 140-2.
8. A device management system for managing a plurality of devices connected to a network, comprising: encryption setting acquisition means for acquiring system encryption settings; first determination means for determining whether the device management system is in FIPS 140 mode; device selection means for selecting a target device; Exception determination means for determining whether a SHA1 exception has occurred in the target device, Notification means for notifying a user when it is determined by the exception determination means that a SHA1 exception has occurred, A device management system characterized by comprising the same.
9. The device management system according to claim 8, wherein the notification means performs at least one of icon display, warning display, and a link to a screen for setting authentication information.
10. A device management method for managing a plurality of devices connected to a network, comprising: An encryption setting acquisition step of acquiring system encryption settings, A first determination step of determining whether the device management system is in FIPS140 mode, A second determination step of determining whether the version of FIPS140 is FIPS140-3, An authentication algorithm display step of displaying an authentication algorithm based on the determination results of the first determination step and the second determination step, A selection step of selecting the authentication algorithm displayed in the authentication algorithm display step, A device management method characterized by comprising the same.
11. A device management method for managing a plurality of devices connected to a network, comprising: An encryption setting acquisition step of acquiring system encryption settings, A first determination step of determining whether the device management system is in FIPS140 mode, A device selection step of selecting a target device, An exception determination step of determining whether a SHA1 exception has occurred in the target device, A notification step of notifying a user when it is determined by the exception determination step that a SHA1 exception has occurred, A device management method characterized by comprising the same.
12. A computer program for controlling each means of the device management system according to any one of claims 1 to 9 by a computer.