Device management apparatus, method for controlling device management apparatus and program
The device management apparatus enhances key pair management by enabling selective overwriting and deletion, addressing verification failures and customer burdens, and ensuring compliance with predetermined uses.
Patent Information
- Application Number
- JP2024002865
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-11
- Publication Date
- 2025-07-24
- Estimated Expiration
- 2044-01-11
AI Technical Summary
Existing methods for managing key pairs in devices face issues such as self-signed certificates causing verification failures, the need for certification authorities imposing customer burdens, and limitations in adding or deleting keys for specific uses.
A device management apparatus that allows for selecting whether to overwrite existing key pairs when adding new ones, and managing key pairs by deleting specific uses or adding them to default keys to ensure compliance with predetermined requirements.
Improves the convenience and flexibility of managing key pairs by allowing selective overwriting and deletion, ensuring compliance with predetermined uses while avoiding verification failures and customer burdens.
Smart Images

Figure 2025109132000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a device management apparatus, a control method thereof, and a program.
Background Art
[0002] As a conventional method for managing a key pair of a device, for example, there is a method in which the device itself generates a key pair and uses the key pair. Patent Document 1 discloses a technique for determining whether key pair data exists in a device when the device is powered on, and automatically generating and storing a key pair when the key pair data does not exist. Further, as another method for managing a key pair of a device, Patent Document 2 discloses a technique for requesting a key pair from a certification authority and storing and using the key pair received from the certification authority.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, when the device itself generates a key pair as in Patent Document 1, the generated key pair is a self-signed certificate, and the verification of the certificate fails. For example, when using a key pair generated by the device itself as the certificate of an HTTPS server, the web browser displays a warning indicating that the connection is not secure. Also, when requesting a key pair from a certification authority as in Patent Document 2, it is necessary to prepare a certification authority that accepts the request for the key pair from the device, which imposes a burden on the customer. Further, when the key pair is used for TLS communication, signature, IPSec, IEEE 802.1X authentication, etc., it is necessary to separately specify these uses. When a use is specified for the key pair, there is a restriction that only one key pair for that use always exists, and keys cannot be added or deleted.
[0005] An object of the present invention is to improve the convenience of managing a key pair for which a use managed by a device is specified.
Means for Solving the Problem
[0006] In order to solve the above problems, a device management apparatus of the present invention is a device management apparatus that manages a key pair set in a network device to be managed via a network, and when a key pair having the same use as the use of the key pair instructed to be added to the network device is already set in the network device, selection means for receiving a selection as to whether to overwrite with the key pair instructed to be added, and when a selection to overwrite with the key pair instructed to be added is received, deletion means for deleting the same use as the key pair instructed to be added from the uses of the key pairs set in the network device and adding the key pair instructed to be added. Further, a device management apparatus of the present invention is a device management apparatus that manages a key pair set in a network device to be managed via a network, and has deletion means for deleting a key pair instructed to be deleted from the network device, and the deletion means adds the predetermined use to the use of the default key of the network device when deleting a key pair of a predetermined use that must always exist in the network device.
Advantages of the Invention
[0007] According to the present invention, the convenience of managing key pairs specified for uses managed by a device can be improved.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Modes for Carrying Out the Invention
[0009] (First Embodiment) FIG. 1 is a diagram for explaining the overall configuration of a network device management system. The network device management system (hereinafter referred to as the device management system) provides services (functions) to network devices via a network. When the number of devices to be managed is large, the device management system may be configured by a management device that performs overall management and a plurality of agents that execute processing on the devices according to the instructions of the management device. The device management system of the present embodiment has one device management application server and a plurality of agent application devices.
[0010] The device management server 101 is a device management device having a device management application. The device management application provides functions for managing devices to be managed. The agent 106 and the agent 107 are agent devices having agent applications. That is, the device management system of the present embodiment has one device management server 101 and the agents 106 and 107 as a plurality of agent application devices. The device management system manages the devices 102, 103, 110, and 111 as network devices. The agents and the network devices are linked according to the addresses of the devices. For example, the agent 106 is linked to the devices 102 and 103, and the agent 107 is linked to the devices 110 and 111. In the present embodiment, two agents and four devices are described as an example, but even when managing tens of thousands of devices via a dozen or so agents, the configuration and operation are the same as the description of the present embodiment.
[0011] In addition, the device management system may include a directory server 105. The directory server 105 is an information processing device that manages user information such as user accounts. The device management server 101 and the directory server 105 are interconnected by a network 104. The device management server 101 can also be configured to allow users of the directory server 105 to log in as users of the device management server 101.
[0012] The device management server 101, the directory server 105, the agent 106, the device 102, and the device 103 are interconnected by a network 104. The network 104 is, for example, a WAN. The agent 107, the device 110, and the device 111 are interconnected by a network 108. The network 108 is, for example, a LAN. The network 104 and the network 108 are connected by a router 109. The router 109 can be configured to permit communication between the device management server 101 and the agent 107 on the network 108, while blocking communication between the device management server 101 and the devices 110 and 111.
[0013] In this embodiment, the case where the network 104 is a WAN and the network 108 is a LAN is described as an example. However, the networks 104 and 108 only need to be configured to enable data transmission and reception, and the communication method is not limited. For example, each network can be configured as any one of a LAN, a WAN, a cellular network such as LTE or 5G, a wireless network, a telephone line, a dedicated digital line, etc., or a combination thereof.
[0014] In this embodiment, it is assumed that the communication between the device management server 101 and the devices 102 and 103 is performed via the agent 106. Also, it is assumed that the communication between the device management server 101 and the devices 110 and 111 is performed via the router 109 and the agent 107. Note that in this embodiment, an example in which the device management server 101 and the agent 106 operate on different hosts is described, but it is also possible to operate the device management server 101 and the agent 106 on the same host. When the device management server 101 and the agent 106 are operated on the same host, the devices 102 and 103 can communicate directly with the device management server 101.
[0015] The device management server 101 provides various services (functions) to network devices to be managed. Note that the device management server 101 of this embodiment provides services to network devices using agents. The services provided by the device management server 101 include, for example, a service for managing the key pairs of network devices. Also, the device management server 101 incorporates a web service server regarding the functions provided by the device itself within the device itself. Note that the device management server 101 may be realized by a virtual machine (cloud service) that uses resources provided by a data center including one or more information processing devices, or a combination thereof, in addition to one or more information processing devices. The directory server 105 may also be realized by a virtual machine (cloud service) that uses resources provided by a data center including one or more information processing devices, or a combination thereof. Also, the device management system can be implemented as a web-based application and can be used via a web browser on a PC.
[0016] Agent 106 and Agent 107 are agent devices that communicate with devices based on instructions from the device management server 101. Agent 106 and Agent 107 incorporate a web service server related to the functions provided by the device management server 101. Also, the agents are associated with network devices according to the addresses of the network devices etc. Agent 106 is associated with devices 102 and 103. Agent 107 is associated with devices 110 and 111.
[0017] Devices 102, 103, 110, and 111 are network devices that are under the management of the device management server 101 and can communicate with the device management server 101. The network device is, for example, a multifunction printer (MFP) in which a plurality of functions such as a printing function, a reading function, and a FAX function are integrated. Note that the network device may be an image forming device such as a printer, a scanner device, or a 3D printer, an information processing device such as a PC, an image processing device such as a camera, or smart home appliances, etc. The network device can perform encrypted communication with an external device such as the device management server 101 and has an HTTPS server function. A key pair of a public key and a private key for communication encryption is set in the network device of the present embodiment. The key pair set in the device includes a default key that is managed so as not to be deleted from the device. Also, it is possible to set the use for the key pair. Note that it is also possible not to set the use for the key pair.
[0018] Here, the process flow of providing services to network devices by the network device management system will be described using the agent 106 and the device 102 as examples. The device management server 101 instructs the agent 106 to perform operations on the device 102. The agent 106 performs operations such as sending requests to the device 102 according to the instructions of the device management server 101, and sends the results to the device management server 101. Examples of operations of the agent 106 on the device 102 include obtaining information from the device 102, changing the set values of the device 102, instructing the installation of applications on the device 102, and instructing the change of the key pair settings of the device 102. Thus, communication is performed between the device management server 101 and the agent 106, and between the agent 106 and the device 102. Therefore, the device 102 and the device management server 101 do not communicate directly.
[0019] FIG. 2 is a diagram for explaining the hardware configuration of the device management server 101. Also, the host computers on which the agent 106, the agent 107, and the directory server 105 operate have the same hardware configuration as the device management server 101. The device management server 101 includes a CPU 201, a RAM 202, a ROM 203, a KBDC 204, a VC 205, a DC 206, and a NIC 208. These components are connected to the system bus 209.
[0020] The CPU 201 controls the entire device management server 101. The CPU 201 loads and executes a program stored in a memory (ROM 203 or external storage device 207) into the RAM 202 as needed, and comprehensively controls each unit connected to the system bus 209. Also, the CPU 201 may comprehensively control each unit connected to the system bus 209 by loading and executing software (program) downloaded via a network into the RAM 202 as needed. The RAM 202 (Random Access Memory) is a memory capable of reading / writing data, and functions as the main memory or work area of the CPU 201. The ROM (Read Only Memory) 203 is a memory dedicated to data reading, and stores, for example, the basic control program of the device management server 101. The external storage device 207 is a memory such as a hard disk (HD) or solid state drive (SSD). The external storage device 207 stores various applications including a boot program, an operating system (OS), an authentication server, an authentication client, etc., database data, user files, etc.
[0021] The KBDC 204 controls the input to the device management server 101. The KBDC 204 sends input information from input devices such as a keyboard and pointing device (not shown), a virtual keyboard, voice, etc. to the CPU 201, and controls the input to the device management server 101. The VC 205 is a video controller that controls the display to a display device (not shown). The display device may be, for example, an LCD (Liquid Crystal Display) or a head-mounted display capable of VR (virtual reality) display. The DC 206 is a disk controller that controls access to the external storage device 207. The NIC 208 is a communication controller, and the device management server 101 is connected to the network 104 via the NIC 208. The CPU 201 is connected to the network 104 via the NIC 208, enabling data communication with each device on the network.
[0022] Figure 3 is a diagram showing the software configurations of the device management server and the agent. Figure 3(A) is a diagram explaining the software configuration of the device management server 101. The device management server 101 realizes the processing by the functional modules shown in Figure 3(A) by calling an application program for device management from the memory and having the CPU 201 execute it. The functional modules shown in Figure 3(A) are provided as, for example, a device management application.
[0023] The device management server 101 has an agent management unit 301, a device management unit 302, a task management unit 303, an HTTP / HTTPS server 304, and a firmware management unit 305. The agent management unit 301 manages information regarding the agents 106 and 107. The device management unit 302 manages information regarding the devices 102, 103, 110, and 111. The information regarding the devices includes information on which agent the device is associated with. The task management unit 303 manages tasks. As task management, the task management unit 303 manages the content and results of operations on the devices. Also, the task management unit 303 instructs the agent to perform an operation on the device by executing the task. The management information managed by the task management unit 303 is stored in a database (not shown).
[0024] The device management server 101 has both HTTP and HTTPS functions. The HTTP / HTTPS server 304 is a web service server built into the device management server 101 regarding the services provided by the device management server 101. The HTTP / HTTPS server 304 receives requests from external devices such as agents and devices, and returns responses to the requests. Also, the HTTP / HTTPS server 304 provides a WEB UI for the user to operate the device management server 101. The key pair management unit 305 manages the key pairs in the device and the key pairs set in the device.
[0025] Figure 3(B) is a diagram for explaining the software configuration of the agent. Here, agent 106 will be taken as an example for explanation, but other agents have the same configuration. Agent 106 realizes the processing by the functional modules shown in Figure 3(B) by calling the application program for the device management agent from the memory and having the CPU 201 execute it. The functional modules shown in Figure 3(B) are functional modules related to the services provided by the device management server 101, and are provided, for example, as an agent application provided by the device management server 101.
[0026] Agent 106 has a task execution unit 310 and an HTTP / HTTPS server 311. The task execution unit 310 executes the tasks instructed by the device management server 101. After the task execution unit 310 executes the operations on the device according to the instructions of the device management server 101, it sends the results to the device management server 101. The HTTP / HTTPS server 311 is a web service server built into agent 106 related to the services provided by the device management server 101. The HTTP / HTTPS server 311 receives requests from external devices such as the device management server 101 and the device. The device management server 101 and agent 106 communicate with each other mainly using HTTPS via the HTTP / HTTPS server 304 of the device management server 101 and the HTTP / HTTPS server 311 of agent 106.
[0027] FIG. 4 is a diagram showing an example of a key pair management screen provided by the device management server 101. The key pair management screen includes, for example, a table 401, a new registration button 402, a drop-down list 403, and an execution button 404. The table 401 is a table that displays a list of key pairs registered in the device management server 101. The table 401 includes, for example, items such as name, usage, subject, number of associated devices, number of installed devices, and deletion. "Name" is the name given by the user to the key pair. "Usage" is the usage specified for the key pair. Each key pair ensures uniqueness by a combination of "name", "usage", and the key pair itself.
[0028] The table 401 also includes key pairs registered in each device obtained from device 102, device 103, device 110, and device 111. The "number of associated devices" in the table 401 displays the number of devices associated for registering the key pair. When the device management server 101 detects a click on the "number of associated devices" cell of a row in the table by the user, it transitions to a screen (FIG. 6) for setting the association between the key pair and the device in the clicked row. The "number of installed devices" in the table 401 is the number of devices in which the key pair is registered. When the device management server 101 detects a click on the "number of installed devices" cell of a row in the table by the user, it displays a list of devices in which the key pair in the clicked row is registered (not shown).
[0029] "Delete" visibly displays deletable key pairs. A deletable key pair is a key pair that is not registered on the device (i.e., the "number of installed units" is 0). In the example shown in FIG. 4, a "×" mark is displayed as a delete button in the deletion item of the deletable key pair. On the other hand, when the key pair is already registered on the device (i.e., when the "number of installed units" is 1 or more), the device management server 101 does not display the delete button "×". When the user clicks on the "×" cell in the row within Table 401, the device management server 101 displays a dialog to confirm the deletion of the key pair in the clicked row. Then, when the device management server 101 confirms the deletion instruction from the user, it deletes the key pair from the device management server 101.
[0030] The new registration button 402 is a button for registering a key pair. When the click on the new registration button 402 is detected, the device management server 101 transitions to a screen (FIG. 5) for registering the key pair in the device management server 101 described later. The drop-down list 403 is a drop-down list for selecting a process. The option 405 indicates the options of the drop-down list 403. The options of the drop-down list 403 include, for example, "Obtain key pair from device", "Add key pair to device", and "Delete key pair from device". The user selects the desired process in the drop-down list 405 and presses the execute button 404. When the click on the execute button 404 is detected, the device management server 101 executes a process according to the process selected in the drop-down list 403. When "Obtain key pair from device" is selected, the device management server 101 obtains the information of the key pair registered on the device, saves the result in the database or file system within the device management server 101, and updates the display of Table 401. When "Add key pair to device" is selected, the device management server 101 opens a setting screen for the process of adding the key care to the device shown in FIG. 7. When "Delete key pair from device" is selected, the device management server 101 opens a setting screen for the process of deleting the key pair from the device shown in FIG. 11.
[0031] FIG. 5 is a diagram showing an example of a key pair registration screen provided by the device management server 101. When the device management server 101 detects the pressing of the new registration button 402, it displays the key pair registration screen shown in FIG. 5. On the key pair registration screen, the key pair to be added to the device is registered with the device management server 101. Here, the case of registering a key pair with the device 102 will be described as an example. The key pair registration screen includes, for example, a reference button 501, a file name 502, a name 503, a password 504, a usage 505, an add button 506, and a cancel button 507.
[0032] The reference button 501 is a button for specifying a file that stores the key pair data stored in the host computer. The key pair data is stored, for example, in a file in PKCS#12 format. Note that the format of the key pair data is not limited to the PKCS#12 format. When the reference button 501 is clicked, a dialog for file selection provided by the OS or WEB browser is opened. The user selects the file name corresponding to the key pair data in the displayed dialog. The file name 502 is the file name including the key pair selected by the click of the reference button 501. In the example shown in FIG. 5, the key pair with the file name 502 being "printer03.pfx" is specified as the registration target.
[0033] The name 503 is a text box for entering the name of the key pair. The name of the key pair is used by the device management server 101 and the device 102 as information for the user to identify the key pair. The password 504 is a text box for entering the password of the key pair in PKCS#12 format indicated by the file name 502. The usage 505 is a check box for specifying the usage of the key pair to be added within the device 102. Here, multiple check boxes can be selected. As the usage 505 of the key pair in the device 102, for example, "TLS", "IEEE 802.1X", "IPSec", and "SIP" can be selected. Note that the usage of the key pair is not limited to this. The key pair for the "TLS (Transport Layer Security)" usage is the key pair of the server used when the device has an HTTPS server function. The HTTPS server function of the device uses TLS as the communication protocol and uses the key pair for TLS usage in TLS communication. The key pair for the "IEEE 802.1X" usage is the key pair used in the IEEE 802.1x authentication function. The key pair for the "IPSec (Security Architecture for Internet Protocol)" usage is the key pair used in the encrypted communication of IPSec. The key pair for the "SIP (Session Initiation Protocol)" usage is the key pair used in the encrypted communication of SIP. In the example shown in FIG. 5, the check box for "TLS" is checked as the usage 505.
[0034] The add button 506 is a button for adding and registering a key pair specified by the user to the device management server 101 on the key pair registration screen. The device management server 101 enables the add button 506 when the file specification 502, the input of the name 503, and the input of the password 504 are valid. Note that it is possible to register the key pair even without specifying the use 505. When detecting a click on the add button 506 by the user, the device management server 101 checks the content input on the key pair registration screen. Specifically, the device management server 101 checks whether the key pair file in PKCD#12 format indicated by the file name 502 is a valid key pair and whether the password of the key pair file matches the password input in the password 504. If the result of the check is correct, the device management server 101 saves the key pair data of the file name 502 together with the name 503, the password 504, and the use 505 in the database or file system within the device management server 101. Then, when the registration of the key pair is completed, the device management server 101 transitions to the key pair management screen shown in FIG. 4. On the other hand, if the result of the check is incorrect, for example, if the key pair file is invalid or the passwords do not match, the device management server 101 displays an error dialog and does not perform the key pair registration. When detecting a click on the cancel button 507 by the user, the device management server 101 transitions to the key pair management screen shown in FIG. 4.
[0035] FIG. 6 is a diagram showing an example of a screen for setting the association between the key pair and the device provided by the device management server 101. When detecting a click on the "association" cell of a row in the table 401 on the key pair management screen (FIG. 4), the device management server 101 displays the association setting screen. The association setting screen is a screen for setting and managing the association between the key pair selected on the key pair management screen and the network device. The association setting screen includes, for example, key pair information 601, a table 602, a save button 603, and a cancel button 604.
[0036] The key pair information 601 is an area that displays information about the key pair to be associated. For example, the name, usage, and subject of the key pair are displayed in the key pair information 601. The table 602 is a table for selecting a device to be associated with the key pair. For example, a checkbox and device information are displayed in the table 602. The device information includes, for example, the device name, product name, IP address of the device, and installation location of the device. The user designates a device to be associated with the key pair by selecting the checkbox in the table 602.
[0037] When detecting a click on the save button 603 by the user, the device management server 101 associates the device selected by the checkbox in the table 602 with the key pair to be associated displayed in the key pair information 601 and saves it in the database. When detecting a click on the cancel button 604 by the user, the device management server 101 transitions to the key pair management screen shown in FIG. 4.
[0038] The data for the device management server 101 and the device 102 to exchange key pair information is composed of, for example, a group of files compressed and integrated using ZIP or TAR. The group of files is composed of a configuration file (for example, an XML file or a JSON file) describing the key pair information and a directory storing files obtained by converting each key pair data into the PKCS#12 format. An example of the key configuration file of the device 102 is shown below. <?xml version=”1.0”?>\n <device_configuration xmlns=”http: / / www.my.company.com / ns / deviceConfiguration”>\n <configuration_settings>\n <password>X'78B0851086BA1A9A8741903A515A085D07D17A8A9152B44D44BB1D27C7DD0B877A'< / password> < / configuration_settings>\n <key_management_settings>\n <key> <device_default_key usage=”1” / > <device_keys> <device_key name=”printer03_TLS_key” usage=”1”> device_key_file_01.p12 < / device_key> <device_key name=”printer03_wifi_key” usage=”2”> device_key_file_02.p12 < / device_key> < / device_keys> < / key> < / key_management_settings> < / device_configuration>
[0039] In the "password" of "configuration_settings" in the configuration file, the password information of the configuration file is stored. The confidential information in the configuration file is encrypted by the information generated from this password. Also, the password of the configuration file is the password of the PKCS#12 format file of the key pair included in the configuration data. The password information of the configuration file is, for example, a value calculated from the hash of the password, and the password cannot be inferred from the configuration file.
[0040] The keys in device 102 are composed of one default key pair automatically generated by device 102 and multiple key pairs registered by the user. The key_management_settings block includes the usage of the default key pair (usage of device_default_key) and the information of multiple key pairs registered by the user (device_keys). The default key is a key pair that is stored in the device since the device was shipped from the factory and is managed so that it cannot be deleted. Therefore, the default key always exists in the device.
[0041] Each key pair registered by the user includes the name of the key pair set by the user (device_key name) and the usage of the key pair (usage) as attributes, and the file name of the key pair data as the value. For example, the usage is indicated by 4 bits, and the presence or absence of usage is assigned to each of the 4 digits. Each digit means the following usage. 1st digit = 0001 = 1 = TLS 2nd digit = 0010 = 2 = IEEE 802.1X 3rd digit = 0100 = 4 = IPSec 4th digit = 1000 = 8 = SIP For example, "4" (0100 in binary) means "IPSec", and "10" (1010 in binary) means "IEEE802.1X" and "SIP". Also, regarding the use of keys, there are the following restrictions. 1. The same use cannot be assigned to multiple key pairs including the default key pair. 2. The key pair for TLS use must necessarily exist. Therefore, the key pair for TLS use is the key pair for a predetermined use that must necessarily exist in the network device.
[0042] When the device management server 101 requests the device 102 to obtain the information of the key pairs registered in the device 102, the device 102 processes the information of its own key pairs into data in the format shown above and returns it to the device management server 101. When the device 102 receives the data of the key pair information in the above format from the device management server 101, it verifies the content of the received data. And when there is no problem with the verification result, the registration information of the key pairs inside the device 102 is updated with the content of the data received from the device 102. Although not described in detail in this embodiment, it is natural that authentication and authorization are required when the device management server 101 calls the device 102 for obtaining and setting key pair information.
[0043] FIG. 7 is a diagram showing an example of an additional setting screen for key pairs to a device. The additional setting screen for key pairs to a device is a screen for setting the process of adding the key pairs registered in the device management server 101 to the device 102 provided by the device management server 101. When it is detected that the "Add Key Pair to Device" is selected in the drop-down 403 of the key pair management screen (FIG. 4) and the execution button 404 is clicked, the device management server 101 displays the additional setting screen for key pairs to the device.
[0044] The key pair addition setting screen for the device includes, for example, a check box 701, a table 702, an add button 703, and a cancel button 704. In the check box 701, the processing when a key pair with the same use as the key pair to be added already exists in the device is set. Since there is a restriction that the same use cannot be assigned to a plurality of key pairs including the default key pair for the use of the key, when adding a key pair with the same use, only one of the existing key pair and the newly added key pair can exist as the key pair for that use. Therefore, in the check box 701, it is selected whether to overwrite and register the existing key pair with the key pair for which addition is instructed when a key with the same use exists. The device management server 101 functions as a selection means for receiving a selection of whether to overwrite with the key pair to be added when a key pair with the same use as the key pair to be added to the device 102 already exists by detecting the ON / OFF of the check box 701.
[0045] When the check box 701 is selected, the device management server 101 overwrites and registers with the key pair to be added this time. That is, the device management server 101 deletes the use of the key pair to be added from the key pairs already existing in the device and adds the key pair. When the check box 701 is not selected, the device management server 101 does not add the key pair if a key pair with the use of the key pair to be added already exists in the device.
[0046] Table 702 displays a list of key pairs associated with devices. The user selects a key pair to add from the list of key pairs associated with the devices displayed in Table 702. Table 702 displays a checkbox for selecting a key, the name of the key, its usage, the subject, and the number of associated devices. The user checks the checkbox corresponding to the key to be added. When the device management server 101 detects the user clicking the add button 703, it starts the process of adding the selected key pair to each of the devices associated with the key pair for which the checkbox is selected in Table 702. When the device management server 101 detects the user clicking the cancel button 704, it closes the key pair addition setting screen for the device.
[0047] Figures 8 and 9 are flowcharts showing the process of adding a key pair to a device. Here, the case where the device management server 101 adds a key pair to the device 102 will be described as an example. The process of adding a key pair to a device by the device management server 101 is realized by the CPU 201 of the device management server 101 calling and executing the program of the device management application from the memory (ROM 203 or external storage device 207). Therefore, the CPU 201 of the device management server 101 functions as an addition means for adding a key pair to a device.
[0048] In step S801, the device management server 101 acquires a list of key pairs instructed to be added to the target device. Specifically, the device management server 101 acquires the key pairs associated with the target device from among the key pairs specified for addition by the user and creates a list. In the present embodiment, the device management server 101 acquires the key pairs associated with device 102 from the key pairs selected on the key pair addition setting screen (Figure 7) for the device. In step S802, the device management server 101 checks whether there are key pairs of the same use among the key pairs to be added. In step S803, the device management server 101 determines whether there are key pairs of the same use as a result of the check in step S802. If, as a result of the check, there are key pairs of the same use, the device management server 101 ends this process without setting the key pairs for the device. Note that the device management server 101 may display an error indicating that there are key pairs of the same use. If, as a result of the check, there are no key pairs of the same use, the device management server 101 performs the process of step S804.
[0049] In step S804, the device management server 101 acquires the registration information of the device's key pairs from the device to be added. The key pair information acquired from the device includes the use of the default key pair and the list of registered key pairs. In the present embodiment, the device management server 101 acquires from device 102 the list of key pairs already registered in device 102 and the use of the default key.
[0050] In step S805, the device management server 101 creates a list of key pairs to be registered in the device, a list of key pairs to be set in this device, and a list of differences between the list of key pairs already registered in the device. The list of key pairs to be registered in the device is a list combining the key pairs already registered in the device and the key pairs to be added in the current addition process. Specifically, the device management server 101 creates a list of key pairs to be registered in the device from the list of key pairs instructed to be added to the device obtained in step S801 and the list of key pairs already registered in the device obtained in step S804. Note that the default key is not included in the list. Then, the device management server 101 creates the difference between the created list of key pairs to be set in the device and the list of key pairs already registered in the device obtained in step S804 as a key pair difference list. That is, the list of differences in key pairs is a list of key pairs to be newly added to the device 102. The process of step S805 will be described in detail later with reference to FIG. 10.
[0051] In step S806, the device management server 101 determines whether the difference list created in step S805 is empty. If the list of difference lists is empty, it means that there are no key pairs to be newly added. Therefore, the device management server 101 ends this process without setting the key pairs to the device. If there are differences, that is, if the list of difference lists is not empty, the process of step S807 is performed.
[0052] In step S807, the device management server 101 determines whether a key pair overwrite setting for overwriting the use of an existing key pair with the use of the key pair to be added is set when a key pair with the same use as the use of the key pair for which addition is instructed is set in the device. The device management server 101 determines whether the key pair overwrite setting is set based on the setting of the checkbox 701 on the key pair addition setting screen (Figure 7) for the device. If the checkbox 701 is not checked, it is determined that no overwrite setting has been made, and the device management server 101 performs the process of step S811. On the other hand, if the checkbox 701 is checked, it is determined that an overwrite setting has been made, and the device management server 101 performs the process of step S808.
[0053] There is a restriction that the same use cannot be assigned to a plurality of key pairs including the default key pair for the use of the key. Therefore, when the key pair overwrite setting is set, if the use set for the key pair to be added is the same as the use set for the key pair currently registered in the device 102, the device management server 101 needs to delete the use of the registered key pair. Therefore, by repeating the processes of step S808 and step S809, the use of the key pair to be added is deleted from the uses of the key pairs including the default key already set in the device 102. In step S808, the device management server 101 extracts a key pair (the differential key pair) from the key pair difference list. The key pairs in the key pair difference list are those whose key pair body or use is different from the key pairs currently registered in the device 102, and a part of the use of the key pairs currently registered in the device 102 is overwritten with the use of the key pairs in the difference list.
[0054] In step S809, the device management server 101 deletes the same usage as that of the differential key pair retrieved in step S808 from the usages of the existing key pairs. Specifically, the device management server 101 first deletes the same usage as that of the differential key pair from the usages of the key pairs different from the differential key pair retrieved in step S808 in the list of key pairs to be registered created in step S805. Further, the device management server 101 deletes the same usage as that of the differential key pair from the usage of the default key. Here, the usage of the default key pair is the usage of the default key pair currently set in the device, which is obtained from the device 102 in step 804. By deleting the same usage as that of the differential key pair from the usages of the existing key pairs, it is possible to delete the same usage as that of the key pair to be added.
[0055] In step S810, the device management server 101 determines whether all the key pairs have been retrieved from the list of differential key pair lists. If all the key pairs have been retrieved from the list of differential key pair lists, the process of step S811 is performed. On the other hand, if all the key pairs have not been retrieved from the list of differential key pair lists, the process returns to step S808.
[0056] Regarding the usage of the key pair, there is a key pair for a predetermined usage that must necessarily exist in the device. Specifically, in the present embodiment, there is a restriction that the key pair for TLS usage must necessarily exist. Therefore, in step S811, the device management server 101 determines whether there is a key pair for TLS usage, which is a key pair for a predetermined usage that must necessarily exist in the device, in the list of key pairs to be registered. If there is no key pair for TLS usage in the list of key pairs to be registered, the device management server 101 performs the process of step S813. On the other hand, if there is a key pair for TLS usage in the list of key pairs to be registered, the device management server 101 performs the process of step S814.
[0057] In step S813, the device management server 101 adds the TLS usage to the usage of the default key pair. By the process of step S813, when there is no key pair for TLS usage among the key pairs to be registered, the TLS usage can be added to the default key, so the constraint that the key pair for TLS usage must always exist can be observed. In step S814, the device management server 101 cancels (deletes) the setting of the TLS usage from the usage of the default key pair.
[0058] In step S815, the device management server 101 checks whether there is a key pair with the same usage among the key pairs to be registered and the default key pair. As a result of the check, if the usages overlap, the device management server 101 ends this process without setting the key pair to the device. On the other hand, as a result of the check, if there is no overlap in usage, the device management server 101 performs the process of step S817.
[0059] In step S817, the device management server 101 creates registration instruction data for the key pair to be sent to the device 102 based on the list of key pairs to be registered and the usage of the default key pair. Finally, in step S818, the device management server 101 sends the registration instruction data for the key pair created in step S817 to the device 102. The device 102 that has received the registration instruction data for the key pair from the device management server 101 sets the key pair of the device 102 based on the received registration instruction data for the key pair. Thereby, the addition of the key pair to the device 102 is realized while observing the constraints regarding the key pair. The key pair addition process ends here. After the end of the key pair addition process, the device management server 101 acquires the key pair information from the device 102 and updates the list (table 401) of the key pairs in the device management server 101 that is displayed on the key pair management screen (Figure 4).
[0060] Here, the detailed processing of step S805 will be described with reference to FIG. 10. FIG. 10 is a flowchart showing the process of creating a list of key pairs to be registered and a difference list of key pairs. In this process, a list of key pairs to be registered in device 102 and a list of added key pairs (a difference list of key pairs) are created from the list of key pairs for which addition is instructed and the list of key pairs registered in device 102. The process of creating a list of key pairs to be registered and a difference list of key pairs by device management server 101 is realized by CPU 201 of device management server 101 calling and executing the program of the device management application from the memory.
[0061] Device management server 101 has acquired the list of key pairs for which addition to the device was instructed in step S801 and the list of key pairs already registered in the device (the list of key pairs currently registered in device 102) in step S804. In step S901, device management server 101 creates a list (a list) of key pairs to be registered by duplicating the list of key pairs registered in device management server 101. In this process, the list of key pairs to be registered is completed by adding the key pairs determined to be added by the processing from step S903 to step S908 to the list of key pairs to be registered created by duplication in step S901.
[0062] In step S902, device management server 101 creates an empty list of key pairs for difference. In this process, the list of differences of key pairs is completed by adding the key pairs determined to be added by the processing from step S903 to step S908 to the empty list of differences of key pairs created in step S902.
[0063] In step S903, the device management server 101 sequentially extracts key pairs from the list of additionally instructed key pairs obtained in S801. In step S904, the device management server 101 searches the list of key pairs to be registered for the key pair to be added and the key pair whose name and body match, which were extracted in S903. In step S905, the device management server 101 determines, based on the result of the search in step S904, whether a key pair whose name and body match the key pair to be added is found in the list of key pairs to be registered. If a key pair whose name and body match is found, the device management server 101 performs the process of step S906. On the other hand, if a key pair whose name and body match is not found, the device management server 101 performs the process of step S907.
[0064] In step S906, the device management server 101 additionally sets the use of the key pair to be added to the use of the key pair to be registered, which matches the key pair to be added in terms of name and body. Then, the device management server 101 adds the key pair to be registered with the additionally set use to the key pair difference list. For example, assume that the uses of the key pair to be added, which was extracted in step S903, are "IPSec" and "SIP", and the uses of the key pair whose name and body match, which was found from the list of key pairs to be registered, are "IEEE 802.1X" and "SIP". "IPSec" is additionally set to the use of the matching key pair in the list of key pairs to be registered, and the use of the updated key pair becomes "IEEE 802.1X", "IPSec", and "SIP". That is, the union of the uses of the two key pairs (the key pair to be added extracted in step S903 and the key pair in the list of key pairs to be registered whose name and use match that of the said key) is set to the use of the key pair to be registered. Note that if the use of the key pair to be added matches the use of the key pair to be registered, which matches the key pair to be added in terms of name and body, neither the addition of the use nor the addition of the key pair to the key pair difference list is performed.
[0065] In step S907, the device management server 101 adds the key pair to be added retrieved in step S903 to both the list of key pairs to be registered and the difference list. This means that since the key pair to be added retrieved in step S903 is not currently registered in the device 102, it is to be additionally registered. In step S908, the device management server 101 checks whether processing has been performed for all the key pairs in the list of key pairs with additional instructions obtained in step S801, that is, whether all the key pairs have been retrieved in step S903. If the processing for the key pairs with additional instructions has been completed for all the devices 102, the device management server 101 performs the processing in step S909. On the other hand, if the processing for the key pairs with additional instructions has not been completed for all the devices 102, the device management server 101 returns to the processing in step S903.
[0066] In step S909, the device management server 101 completes the creation of the list of key pairs to be registered and the list of key pairs for difference, and returns the created list of key pairs to be registered and the list of difference key pairs to the caller of the processing to end this processing. Note that if the key pair to be added already exists in the device and the uses also match, the difference list will be empty.
[0067] By the processing in FIGS. 8 to 10, for example, the addition of key pairs is executed as follows. In the following, a fingerprint (partially omitted as the display is long) is used as information for identifying the key pair body, but it is not limited to this. In order to more strictly identify, it is also possible to use a combination of a fingerprint, a serial number, and all or part of the subject as information for identifying the key pair body.
[0068] (Example 1) Table 1 shows the key pairs of the device 102 before the addition. Two key pairs, a default key pair and a key pair named "printer03 - wifi", are set in the device 102 before the addition. TLS is set for the use of the default key pair. IEEE802.1X is set for the use of printer03 - wifi.
Table 1
Table 2
[0069] The case where the addition of the key pairs shown in Table 2 is instructed to the device 102 where the key pairs shown in Table 1 are set will be described. First, the case where the checkbox 701 on the key pair addition setting screen (Figure 7) for the device is set to off will be described. If the setting is such that no addition is made when there are keys of the same use in the device, since the key pair with the use of TLS is installed for the use of the default key pair, the device management server 101 does not perform the key pair addition process. Next, the case where the checkbox 701 on the key pair addition setting screen (Figure 7) for the device is set to on will be described. When prioritizing the use of the key pairs to be added when there are key pairs of the same use in the device, the device management server 101 deletes TLS from the use of the default key pair in order to add the key pair with the instructed addition of TLS. Table 3 represents the key pair setting of device 102 after the addition process when the checkbox 701 is set to on. In Table 3, a key pair with the name "printer03 - tls" and the use of TLS is added to device 102, and TLS is deleted from the use of the default key pair.
Table 3
[0070] (Example 2) Next, the case where the addition of the key pairs in Table 4 to the device 102 (Table 1) is instructed will be described. Table 4 represents the key pairs instructed to be added to the device 102. The key pairs instructed to be added are two key pairs: a key pair with the name "printer04-sip" and the use set to SIP, and a key pair with the name "printer04-ipsec-sip" and the uses set to IPSec and SIP. [Table 4] In the example of Table 4, since the use "SIP" of the key to be added is duplicated, the device management server 101 does not execute the addition process by the processes of step S802 and step S803.
[0071] (Example 3) Table 5 represents the key pairs of the device 102 before the addition. Two key pairs, a default key pair and a key pair with the name "printer03-wifi-sip", are set in the device 102 before the addition. TLS is set for the use of the default key pair. IEEE802.1X and SIP are set for the use of printer03-wifi-sip. [Table 5] Table 6 represents the key pairs instructed to be added to the device 102. The key pairs instructed to be added have the name "printer03-ipsec-sip" and the uses set to IPSec and SIP. [Table 6]
[0072] The case where the device 102 with the key pair shown in Table 5 is instructed to add the key pair shown in Table 6 will be described. First, the case where the checkbox 701 on the key pair addition setting screen (Fig. 7) for the device is set to off will be described. If the setting is such that no addition is made when there is a key pair of the same use in the device, since the key pair for the "SIP" use exists in both the device and the key pair to be added, the device management server 101 does not perform the key pair addition process. Next, the case where the checkbox 701 on the key pair addition setting screen (Fig. 7) for the device is set to on will be described. When giving priority to the use of the key pair to be added, since the "SIP" use exists in the key pair to be added, the device management server 101 deletes the SIP use from the use of the key pair named "printer03 - ipsec - sip" set in the device 102. Table 7 shows the key pair settings of the device 102 after the addition process when the checkbox 701 is set to on. In Table 7, a key pair with the name "printer03 - ipsec - sip" and uses of IPSec and SIP is added to the device 102, and SIP is deleted (removed) from the use of the key pair named "printer03 - ipsec - sip".
Table 7
[0073] Next, the process of the device management server 101 deleting a key pair from the device 102 will be described. Fig. 11 is a diagram showing an example of a key pair deletion setting screen from the device. The key pair deletion setting screen is a screen provided by the device management server 101 for setting the process of deleting a key pair from the device 102. When it detects a click on the execution button 404 in a state where "Delete key pair from device" is selected in the dropdown 403 on the key pair management screen (Fig. 4), the device management server 101 displays the key pair deletion setting screen.
[0074] The key pair deletion setting screen includes a table 1001, a delete button 1002, and a cancel button 1003. The table 1001 is a table for selecting keys to be deleted and displays a list of key pairs registered in the device. In the table 1001, a checkbox for selecting a key, the name of the key, the usage, the subject, and the number of registrations are displayed. Since the key pairs displayed in the table 1001 are the key pairs registered in the device, key pairs with one or more registrations are displayed in the table 1001. The user selects a key pair to be deleted from the list of key pairs registered in the device displayed in the table 1001 and checks the corresponding checkbox. When detecting a click on the delete button 1002 by the user, the device management server 101 starts a process of deleting the selected key pair for each device in which the key pair selected by the checkbox in the table 1001 is registered. When detecting a click on the cancel button 1003 by the user, the device management server 101 closes the key pair deletion setting screen.
[0075] Figures 12 and 13 are flowcharts showing the process of deleting a key pair from a device. Here, a case where the device management server 101 deletes a key pair from the device 102 will be described as an example. The key pair deletion process by the device management server 101 is realized by the CPU 201 of the device management server 101 calling and executing the program of the device management application from the memory (ROM 203 or external storage device 207). Therefore, the CPU 201 of the device management server 101 functions as a deletion means for deleting the key pair from the device.
[0076] In step S1101, the device management server 101 obtains a list of key pairs recorded as being registered in the device 102 among the key pairs specified for deletion in the table 1001 of the key pair deletion setting screen (Figure 11). In step S1102, the device management server 101 obtains key pair information (the usage of the default key pair and the list of key pairs already registered in the device 102) from the device 102.
[0077] In step S1103, the device management server 101 sequentially extracts key pairs from the list of key pairs to be deleted obtained in step S1101. For the extracted key pairs, the device management server 101 performs key pair deletion processing in steps S1104 to S1109. In step S1104, the device management server 101 searches the list of key pairs registered in the device 102 for a key pair whose name and body match those of the key pair to be deleted as the registered key pair to be deleted. In S1105, based on the result of the search in S1104, the device management server 101 determines whether a key pair whose name and body match those of the key pair to be deleted, which is the registered key pair to be deleted, is found in the list of key pairs registered in the device 102. If a key pair whose name and body match those of the key pair to be deleted is not found, the device management server 101 performs the process of step S1110. On the other hand, if a key pair whose name and body match those of the key pair to be deleted is found, the device management server 101 performs the process of step S1106.
[0078] In step S1106, the device management server 101 compares the uses of the key pair to be deleted and the key pair found by the search (the registered key pair to be deleted). In step S1107, based on the comparison result in step S1106, the device management server 101 determines whether the uses match. If the uses match, the device management server 101 performs the process of step S1108. On the other hand, if the uses do not match, the device management server 101 performs the process of step S1109.
[0079] In step S1108, the device management server 101 deletes the found key pair (the registered key pair to be deleted) from the list of registered key pairs in device 102. In step S1109, among the uses of the found key pair (the registered key pair to be deleted) in the list of registered key pairs in device 102, the use that is the same as the use of the key pair to be deleted is deleted. That is, in the list of registered key pairs, only the use of the key pair to be deleted is deleted from the use of the key pair whose name and body match the key pair to be deleted (the registered key pair to be deleted), and the key pair body and the uses that are not the use of the key pair to be deleted are left. For example, if the use of the key pair to be deleted is "SIP" and the uses of the found key pair (the registered key pair to be deleted) are "IEEE 802.1X" and "SIP", the use "SIP" is deleted, and the use of the registered key pair to be deleted becomes "IEEE 802.1X".
[0080] In step S1110, the device management server 101 determines whether deletion processing has been performed for all of the key pairs for which deletion was instructed in step S1101, that is, whether all of the key pairs to be deleted in step S1103 have been retrieved. If deletion processing has been performed for all of the key pairs for which deletion was instructed, the process of step S1111 is performed. On the other hand, if deletion processing has not been performed for all of the key pairs for which deletion was instructed, that is, if there are still key pairs that have not been retrieved in the list of key pairs to be deleted, the process returns to step S1103.
[0081] In step S1111, the device management server 101 checks whether there are any changes to the key pairs to be registered in device 102. If there are no changes, it means that the key pair specified for deletion is not registered in device 102, so the device management server 101 ends this process. On the other hand, if there are changes, that is, if a key pair or a use has been deleted from the list of key pairs registered in device 102, the device management server 101 performs the process of step S1112.
[0082] Regarding the use of key pairs, there is a key pair for a predetermined use that must exist in the device. Specifically, in this embodiment, there is a constraint that the key pair for TLS use must exist. In step S1112, the device management server 101 checks whether a key pair for TLS use, which is a key pair for a predetermined use that must exist in the device, exists in the list of registered key pairs in the device 102. In step S1113, the device management server 101 determines whether the key pair for TLS use is determined to exist in the registered key pair list as a result of the check in step S1112. If the key pair for TLS use exists in the registered key pair list, the device management server 101 performs the process of step S1115. On the other hand, if the key pair for TLS use does not exist in the registered key pair list, the device management server 101 performs the process of step S1114.
[0083] In step S1114, the device management server 101 sets TLS for the use of the default key pair and transitions to step S1115. In step S1115, registration instruction data to be sent to the device 102 is created from the list of registered key pairs and the use of the default key pair. Finally, in step S1116, the device management server 101 sends the registration instruction data created in step S1115 to the device 102. The device 102 that has received the registration instruction data from the device management server 101 sets the key pair of the device 102 based on the received registration instruction data. Thereby, deletion of the key pair from the device 102 is realized while complying with the constraints regarding the key pair. The key pair deletion process ends here. After the end of the key pair deletion process, the device management server 101 acquires the key pair information from the device 102 and updates the list (table 401) of key pairs in the device management server 101 that is displayed on the key pair management screen (Figure 4).
[0084] (Example 4) Table 8 represents the key pairs of device 102 before deletion. Three key pairs are set in device 102 before deletion: the default key pair, a key pair named "printer03 - wifi", and a key pair named "printer03 - ipsec". TLS is set for the use of the default key pair. IEEE802.1X is set for the use of printer03 - wifi. Also, let the key pair body of printer03 - wifi be KEY_III. IPSec is set for the use of printer03 - ipsec.
Table 8
Table 9
Table 10
[0085] (Example 5) Table 8 represents the key pairs of device 102 before deletion. There are three key pairs set in device 102 before deletion: the default key pair, a key pair named "printer03 - wifi", and a key pair named "printer03 - tls". Nothing is set for the use of the default key pair. IEEE802.1X is set for the use of printer03 - wifi. TLS is set for the use of printer03 - tls. Also, the key pair body of printer03 - tls is KEY_IV.
Table 11
Table 12
Table 13
[0086] (Example 6) Table 13 represents the key pairs of device 102 before deletion. There are three key pairs set in device 102 before deletion: the default key pair, the key pair with the name "printer03 - wifi", and the key pair with the name "printer03 - tls". Nothing is set for the use of the default key pair. For the use of printer03 - wifi, IEEE802.1X and IPSec are set. For the use of printer03 - tls, TLS is set. Also, let the key pair body of printer03 - tls be KEY_III.
Table 14
Table 15
[0087] When the deletion process of the key pair for which deletion is instructed is executed, the key pair of device 102 becomes as shown in Table 15. Table 15 represents the key pair of device 102 after deletion. In Table 15, the application IEEE802.1X is deleted from the second key in Table 13. In Example 15, since the key pair for the TLS application was not a deletion target, the TLS application is still set to printer03-tls as it was before deletion.
Table 16
[0088] As described above, according to this embodiment, when adding a key pair, by receiving a selection of whether to overwrite if there is a key pair with the same application, if overwriting is selected, it becomes possible to add a key pair even if there is already a key pair with the same application. When adding and overwriting a key pair, by deleting the application that is the same as the application of the key pair to be added from the existing key pair, it is possible to prevent a key pair with the same application from being set in the device. Also, when deleting a key pair, if the key for a predetermined application (for example, the TLS application) that must always exist in the device is deleted, by setting the predetermined application to the default key, it is possible to ensure that a key pair for the predetermined application always exists in the device.
[0089] (Second Embodiment) When adding a plurality of key pairs to a device, there may be a plurality of key pairs with the same name and key pair body in the list of key pairs to be added. Also, there may be a plurality of key pairs with the same name and key pair body in the list of key pairs already registered in the device. Such a plurality of key pairs can be integrated into one key pair having the name and key pair body, with the union of the applications of each key pair as the application. In this embodiment, the integration of key pairs will be described.
[0090] Here, a specific scenario where the integration process of key pairs is executed will be described. First, the use of the integration process of the key pair list in the key pair addition process will be described. When the device management server 101 obtains the list of key pairs to be added in the key addition process, it integrates the list of key pairs to be added (step S801). Also, instead of duplicating the list of the device's key pairs, the device management server 101 executes an integration process (step S901). Then, the device management server 101 treats the integrated key pair list in step S901 as the list of key pairs to be registered. Next, the use of the integration process of the key pair list in the key pair deletion process will be described. The device management server 101 executes an integration process on the list of key pairs obtained from the device and uses the integrated list as the list of registered key pairs (step S1102).
[0091] Figure 14 is a flowchart showing the integration process of the key pair list. The integration process of the key pair list by the device management server 101 is realized by the CPU 201 of the device management server 101 calling and executing the program of the device management application from the memory (ROM 203 or external storage device 207).
[0092] When starting the integration process of the key pair list, a list of key pairs to be integrated is input to the device management server 101. In step S1201, the device management server 101 creates an empty key pair list for storing the integrated key pair list. Next, in step S1202, the device management server 101 sequentially extracts key pairs from the input list of key pairs to be integrated. The device management server 101 performs the processes of steps S1203 to S1206 on the extracted key pairs.
[0093] In step S1203, the device management server 101 searches for a key pair with the same name and key pair body as the retrieved key pair from the list of integrated key pairs. In step S1204, the device management server 101 determines whether a key pair with the same name and key pair body is found as a result of the search in step S1203. If no key pair with the same name and key pair body is found as a result of the search, the device management server 101 performs the process of step S1205. On the other hand, if a key pair with the same name and key pair body is found as a result of the search, the device management server 101 performs the process of step S1206.
[0094] In step S1205, the device management server 101 adds the retrieved key pair to the list of integrated key pairs. In step S1206, the device management server 101 adds the use of the retrieved key pair to the use of the key pair in the integrated key pair list. If there is no use to add, that is, if the use of the retrieved key pair is the same as the use of the key pair in the integrated key pair list, the device management server 101 does not add the use. In step S1107, the device management server 101 checks whether the processing for all the key pairs in the list of key pairs to be integrated has been completed. If the processing for all the key pairs in the list of key pairs to be integrated has been completed, that is, if all the key pairs in the list of key pairs to be integrated in step S1202 have been retrieved, the device management server 101 performs the process of step S1208. On the other hand, if the processing for all the key pairs in the list of key pairs to be integrated has not been completed, the process returns to step S1202. In step S1208, the device management server 101 returns the list of integrated key pairs to the calling side and ends the process.
[0095] Table 16 represents the key pair list to be integrated. In the key pair list for which integration is instructed, there are two key pairs named "printer05-one" and one key pair named "printer05-two". For the first key pair of "printer05-one", IEEE802.1X and IPSec are configured. For the second key pair of "printer05-one", IEEE802.1X and SIP are configured. For the key pair of "printer05-two", TLS is configured.
Table 17
Table 18
[0096] As described above, according to the present embodiment, the device management server 101 can perform an integration process on the list of key pairs to be added and the list of key pairs already registered in the device. By integrating the list of key pairs, the number of processing cases in subsequent search processes and the like can be reduced.
[0097] The disclosure of the present embodiment includes the following configuration of the device management apparatus. (Configuration 1) A device management apparatus that manages key pairs set in a network device to be managed via a network, selection means for receiving a selection as to whether to overwrite with the key pair for which addition is instructed when a key pair having the same usage as the usage of the key pair for which addition to the network device is instructed is already set in the network device; When accepting the selection to overwrite with the key pair for which addition has been instructed, deletion means for deleting, from the uses of the key pairs set in the network device, the same use as the key pair for which addition has been instructed, and addition means for adding the key pair for which addition has been instructed, a device management apparatus characterized by having the same. (Configuration 2) The addition means acquires a list of uses of the default key and a list of key pairs registered in the network device from the network device, creates a list of key pairs to be registered in the network device based on the acquired list of key pairs registered in the network device, and adds the key pair for which addition has been instructed to the created list of key pairs to be registered. When accepting the selection to overwrite with the key pair for which addition has been instructed, the addition means deletes, from the uses of the key pairs set in the network device in the list of key pairs to be registered and the uses of the default key, the same use as the use of the key pair for which addition has been instructed. The addition means creates key pair registration instruction data based on the list of key pairs to be registered and the use of the default key, and adds the key pair by transmitting the registration instruction data to the network device. The device management apparatus according to claim 1, characterized in that it performs the addition. (Configuration 3) After deleting the same use as the use of the key pair for which addition has been instructed, the addition means checks whether there is a key pair for a predetermined use that must necessarily exist in the network device in the list of key pairs to be registered. If there is no key pair for the predetermined use, the device management apparatus according to Configuration 2, characterized in that it adds the predetermined use to the use of the default key. (Configuration 4) The key pair is a key pair of a public key and a private key for communication encryption. The predetermined use of the key pair is the use that the network device uses for TLS (Transport Layer Security). The device management apparatus according to Configuration 3, characterized in that it is the use. (Configuration 5) The device management apparatus according to any one of claims 1 to 4, wherein the network device is an image forming apparatus. (Configuration 6) The selection means displays, on a screen for setting the addition of a key pair to a network device, a display for allowing the user to select whether to overwrite a key pair having the same use as the use of the key pair for which addition has been instructed when the key pair exists, The device management apparatus according to any one of Configurations 1 to 5, wherein the addition means does not perform the addition of the key pair for which addition has been instructed when a key pair having the same use exists in the key pair for which addition has been instructed. (Configuration 7) A device management apparatus for managing a key pair set in a network device to be managed via a network, having deletion means for deleting a key pair for which deletion has been instructed from the network device, The device management apparatus, wherein when the deletion means deletes a key pair for a predetermined use that must necessarily exist in the network device, the deletion means adds the predetermined use to the use of the default key of the network device. (Configuration 8) The deletion means acquires a list of the uses of the default key and the key pairs registered in the network device from the network device, When there is a key pair in the list of the registered key pairs whose name and main body match the key pair for which deletion has been instructed, the deletion means deletes the key pair from the list of the registered key pairs if the use of the key pair matches the use of the key pair for which deletion has been instructed, and if the use of the key pair does not match the use of the key pair for which deletion has been instructed, the deletion means deletes only the use that is the same as the use of the key pair for which deletion has been instructed from the use of the key pair in the list of the registered key pairs, When there is no key for a predetermined use in the list of the registered key pairs, the deletion means adds the predetermined use to the use of the default key of the network device, The deletion means creates registration instruction data for the key pair based on the list of the registered key pairs and the use of the default key, and deletes the key pair by transmitting the registration instruction data to the network device. The device management apparatus according to Configuration 7, characterized in that. (Configuration 9) The key pair is a key pair of a public key and a private key for communication encryption, The predetermined use of the key pair is the use that the network device uses for TLS (Transport Layer Security). The device management apparatus according to Configuration 7 or 8, characterized in that.
[0098] (Other Embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium, and having one or more processors in a computer of the system or apparatus read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0099] As described above, the preferred embodiments of the present invention have been described. However, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of the gist thereof.
Claims
1. A device management apparatus for managing a key pair set in a network device to be managed via a network, comprising: selection means for accepting a selection as to whether to overwrite with the key pair for which addition has been instructed when a key pair having the same use as the use of the key pair for which addition to the network device has been instructed is already set in the network device; addition means for deleting the same use as the key pair for which addition has been instructed from the uses of the key pair set in the network device and adding the key pair for which addition has been instructed when a selection to overwrite with the key pair for which addition has been instructed has been accepted, wherein the device management apparatus is characterized by having the addition means.
2. The addition means obtains a list of uses of default keys and a list of key pairs registered in the network device from the network device, creates a list of key pairs to be registered in the network device based on the obtained list of key pairs registered in the network device, adds the key pair for which addition has been instructed to the created list of key pairs to be registered, and when a selection to overwrite with the key pair for which addition has been instructed has been accepted, the addition means deletes the same use as the key pair for which addition has been instructed from the uses of the key pair set in the network device and the uses of the default keys in the list of key pairs to be registered, wherein the addition means creates key pair registration instruction data based on the list of key pairs to be registered and the uses of the default keys, and adds the key pair by transmitting the registration instruction data to the network device, and the device management apparatus according to claim 1 is characterized by this.
3. After deleting the same use as the key pair for which addition has been instructed, the addition means checks whether there is a key pair for a predetermined use that must necessarily exist in the network device in the list of key pairs to be registered, and if there is no key pair for the predetermined use, adds the predetermined use to the use of the default key, and the device management apparatus according to claim 2 is characterized by this.
4. The key pair is a key pair of a public key and a private key for communication encryption, wherein the predetermined use of the key pair is a use that the network device uses for TLS (Transport Layer Security), and the device management apparatus according to claim 3 is characterized by this.
5. The device management apparatus according to claim 1, wherein the network device is an image forming apparatus.
6. The selection means displays, on a screen for setting the addition of a key pair to a network device, a prompt for the user to select whether to overwrite a key pair having the same use as the key pair for which addition has been instructed, if such a key pair exists. The device management apparatus according to claim 1, wherein the addition means does not add the key pair for which addition has been instructed if a key pair having the same use exists among the key pairs for which addition has been instructed.
7. A device management apparatus for managing key pairs set in network devices to be managed via a network, having deletion means for deleting a key pair for which deletion has been instructed from the network device, wherein the deletion means adds the predetermined use to the use of the default key of the network device when deleting a key pair for a predetermined use that must always exist in the network device.
8. The deletion means obtains a list of the uses of the default key and the key pairs registered in the network device from the network device, and when there is a key pair in the list of registered key pairs whose name and body match the key pair for which deletion has been instructed, the deletion means deletes the key pair from the list of registered key pairs if the use of the key pair matches the use of the key pair for which deletion has been instructed, and if the use of the key pair does not match the use of the key pair for which deletion has been instructed, the deletion means deletes only the use that is the same as the use of the key pair for which deletion has been instructed from the use of the key pair in the list of registered key pairs. When there is no key for a predetermined use in the list of registered key pairs, the deletion means adds the predetermined use to the use of the default key of the network device. The deletion means creates registration instruction data for the key pair based on the list of registered key pairs and the use of the default key, and deletes the key pair by transmitting the registration instruction data to the network device. The device management apparatus according to claim 7.
9. The key pair is a key pair of a public key and a private key for communication encryption. The device management apparatus according to claim 7 or 8, wherein the predetermined use of the key pair is a use that the network device uses for TLS (Transport Layer Security).
10. A control method for a device management apparatus that manages a key pair set in a network device to be managed via a network, When a key pair having the same use as the use of the key pair instructed to be added to the network device is set in the network device, a step of receiving a selection of whether to overwrite with the key pair instructed to be added; When a selection to overwrite with the key pair instructed to be added is received, a step of deleting the same use as the key pair instructed to be added from the use of the key pair set in the network device and adding the key pair instructed to be added. A control method for a device management apparatus, characterized by comprising:
11. A control method for a device management apparatus that manages a key pair set in a network device to be managed via a network, A step of deleting a key pair instructed to be deleted from the network device, When a key pair for a predetermined use is deleted, adding the predetermined use to the use of the default key of the network device. A control method for a device management apparatus, characterized by comprising:
12. A program for causing a computer to execute each step according to claim 10.
13. A program for causing a computer to execute each step according to claim 11.
Citation Information
Patent Citations
Data processing device, encryption communication method, and computer program
JP2006014182A
Communication device, image formation device, information processing method and program of the same
JP2013232767A
Information processing apparatus, and control method and program of information processing apparatus
JP2018207404A
Management system, method, and program
JP2020102191A
Information processing system and method for controlling the same, and program
JP2023181454A