Device, system, method, and program
The system facilitates secure use of device server functions by establishing an always-on connection between a device and server, addressing the vulnerability of open server ports in LAN-less environments.
Patent Information
- Application Number
- JP2024004117
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-15
- Publication Date
- 2025-07-28
- Estimated Expiration
- 2044-01-15
AI Technical Summary
Existing technologies leave server ports open, making them vulnerable to attacks in LAN-less environments, compromising the security of device server functions.
A system comprising a device and a server that enables the use of server functions without opening the server port, through a connection request, response acquisition, and transfer mechanism, allowing secure communication via an always-on connection.
Enables secure use of device server functions without exposing the server port, thereby enhancing security in LAN-less environments.
Smart Images

Figure 2025110276000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a server, a device, a system, a method, and a program.
Background Art
[0002] In addition to the conventional on-premises corporate network environment, a technology for constructing an on-premises-equivalent network environment on the cloud called SASE (Secure Access Service Edge) has begun to be used. An environment without an in-house network may be called a LAN (Local Area Network)-less environment. Devices such as multifunction printers may have server functions. Patent Document 1 proposes a technology for safely using the server function of a device from a PC while keeping the server port of the device open in a LAN-less environment.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] If the server port of a device is left open, the server port may be attacked. An aspect of the present invention aims to provide a technology that enables the use of the server function of a device without using the server port of the device.
Means for Solving the Problems
[0005] According to an embodiment, a system includes a device having server functions and a server. The device includes a connection request means for sending a connection request to the server to request establishment of a connection between the device and the server, a receiving means for receiving a service request for the server functions from the server through the connection, an acquisition means for acquiring a response generated by the server functions in response to the service request, and a transmission means for sending the response to the server. The server includes a connection establishment means for establishing the connection in response to the connection request from the device, and a transfer means for transferring the service request received from an information processing device while the connection is established to the device through the connection, and transferring the response from the device in response to the service request to the information processing device. A system is provided.
Effect of the Invention
[0006] According to the above embodiment, the server functions of the device can be used without using the server port of the device.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
MODE FOR CARRYING OUT THE INVENTION
[0008] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0009] <First Embodiment> With reference to FIG. 1, a hardware configuration example of the multifunction machine 100, the server 120, and the personal computer (PC) 130 according to the first embodiment will be described. In the first embodiment, the system 10 is configured by the multifunction machine 100 and the server 120. The system 10 is a system for providing the service provided by the multifunction machine 100 to the PC 130. In the example of FIG. 1, the PC 130 is not included in the system 10. Instead, the PC 130 may be included in the system 10. In the example of FIG. 1, the system 10 includes one multifunction machine 100 and one server 120. Instead, the system 10 may include a plurality of multifunction machines 100 and one server 120. One multifunction machine 100 may be included in only one system 10 or may be included in two or more systems 10. In the example of FIG. 1, one PC 130 is shown. The system 10 may be used by a plurality of PCs 130.
[0010] The multifunction device 100 is a device having at least two of a scanning function, a printing function, and a copying function. Instead of the multifunction device 100, any device (e.g., a dedicated printer, a sensor, a home appliance, etc.) capable of providing services to an external device (e.g., the PC 130) may be used in the system 10. Thus, a device capable of providing services to an external device may be called a device having a server function. In the following example, as an example of the server function of the multifunction device 100, a web server function is dealt with. Instead of or in addition to this, the multifunction device 100 may have other server functions (e.g., a file transfer server function, an authentication server function, etc.).
[0011] The multifunction device 100 may have the hardware components shown in FIG. 1. The multifunction device 100 may not include some of the components shown in FIG. 1, or may include components not shown in FIG. 1. The same applies to the components of the server 120 and the PC 130.
[0012] The CPU (Central Processing Unit) 101 is a processor for controlling the overall operation of the multifunction device 100. The ROM (Read Only Memory) 102 is a read-only non-volatile memory. A boot program may be stored in the ROM 102. The boot program is read and executed by the CPU 101 in response to the power of the multifunction device 100 being turned on. The RAM (Random Access Memory) 103 is a readable and writable volatile memory. The RAM 103 temporarily stores programs, data, etc. for the CPU 101 to control the multifunction device 100.
[0013] The HDD (Hard Disk Drive) 104 is a storage device that semi-permanently stores programs, data, etc. for the CPU 101 to control the multifunction device 100. Instead of or in addition to the HDD, other storage devices such as an SSD (Solid State Drive) may be used. The programs and data stored in the HDD 104 may be read out by the CPU 101 into the RAM 103.
[0014] The network interface (I / F) 105 is a device for communicating with external devices. The communication with external devices may be wired or wireless. The network I / F 105 for performing wired communication may include a connector for connecting a cable and a signal processing circuit for processing the data to be transmitted and received. The network I / F 105 for performing wireless communication may include an antenna for transmitting and receiving data and a signal processing circuit for processing the data to be transmitted and received.
[0015] The printer control unit 107 controls the operation of the printer 108 (e.g., printing). The scanner control unit 109 controls the operation of the scanner 110 (e.g., reading a document). The panel control unit 111 controls the operation of the operation panel 112. The operation panel 112 is a touch panel type operation unit. The operation panel 112 may be composed of a display for displaying information to the user of the multifunction device 100 and a touch sensor for acquiring an instruction input from the user of the multifunction device 100.
[0016] The above-described components of the multifunction device 100 are interconnected by a bus 106. Through the bus 106, control signals from the CPU 101 and data signals between the components are transmitted and received.
[0017] Server 120 is an information processing device for relaying the services provided by multifunction device 100 to PC 130. Since components 121 to 126 of server 120 may be the same as components 101 to 105 of multifunction device 100, duplicate explanations are omitted. Input I / F 127 is a device for connecting an input device (e.g., a mouse or keyboard) for acquiring instruction inputs from the user of server 120. Output I / F 128 is a device for connecting an output device (e.g., a display or speaker) for outputting information to the user of server 120.
[0018] PC 130 is an information processing device for using the services provided by system 10. Instead of PC 130, other information processing devices (e.g., a smartphone or tablet) may be used. Since components 131 to 138 of server 120 may be the same as components 101 to 105 of multifunction device 100 and components 127 to 128 of server 120, duplicate explanations are omitted. The input device connected to input I / F 137 and the output device connected to output I / F 138 may be built into PC 130.
[0019] Multifunction device 100, server 120, and PC 130 are connected to network 140. Multifunction device 100 and server 120 can communicate with each other through network 140. Server 120 and PC 130 can communicate with each other through network 140. Multifunction device 100 and PC 130 may be able to communicate directly or may not be able to communicate directly. Network 140 may be a private network such as a local area network or a public network such as the Internet.
[0020] Referring to FIG. 2, a software configuration example of the multifunction device 100, the server 120, and the PC 130 will be described. The multifunction device 100 may have the software components shown in FIG. 2. The multifunction device 100 may not include some of the components shown in FIG. 2, or may include components not shown in FIG. 2. The software components of the multifunction device 100 may be realized by the CPU 101 reading from the ROM 102 or the HDD 104 and executing in the RAM 103. Alternatively, at least a part of the software components of the multifunction device 100 may be realized by a dedicated integrated circuit such as an ASIC (Application Specific Integrated Circuit). The same applies to the components of the server 120 and the PC 130.
[0021] First, the software configuration of the multifunction device 100 will be described. The setting management unit 201 manages the settings of the multifunction device 100. For example, the settings of the multifunction device 100 may be stored in the HDD 104. The setting management unit 201 may store new settings in the HDD 104, update or delete the settings stored in the HDD 104 in response to requests from the user, an external device, or other components of the multifunction device 100. The setting management unit 201 may respond with the settings stored in the HDD 104 in response to requests from the user, an external device, or other components of the multifunction device 100.
[0022] The setting management unit 201 may acquire requests regarding the settings of the multifunction machine 100 from the user through the operation panel 112, and may also display the settings of the multifunction machine 100 on the operation panel 112. In addition to this, the setting management unit 201 may have a web server function. The setting management unit 201 may use the web server function to acquire requests regarding the settings of the multifunction machine 100 from an external device (for example, the PC 130) through the network I / F 105, and may also respond to the settings of the multifunction machine 100 to the external device. Thus, the setting management unit 201 may be an application having a web server function. For example, the setting management unit 201 may accept a connection request by HTTP (Hyper Text Transfer Protocol) from an external device on port 80. Instead of or in addition to this, the setting management unit 201 may accept a connection request by HTTPS (HTTP Secure) from an external device on port 443. The setting management unit 201 may transmit and receive data (for example, requests and responses) used for processing regarding the settings of the multifunction machine 100 through the connection established by these protocols.
[0023] The web server function of the setting management unit 201 may be set to be enabled or disabled. When the web server function is enabled, the setting management unit 201 accepts requests from an external device through the network 140. When the web server function is disabled, the setting management unit 201 rejects requests from an external device through the network 140. For example, the setting management unit 201 may discard packets transmitted to a port (for example, port 80 or port 443) for providing the web server function.
[0024] The display control unit 202 displays information on the operation panel 112. For example, the display control unit 202 may generate a screen to be displayed on the operation panel 112. The registration request unit 203 requests the server 120 to register the multifunction machine 100. This request may include identification information and authentication information of the multifunction machine 100. The transfer unit 204 transfers data between the server function of the multifunction machine 100 (for example, the web server function of the setting management unit 201) and the server 120.
[0025] The communication control unit 205 is connected to the network 140 using the network I / F 105 and communicates with other devices (e.g., the server 120) through the network 140. The communication between the above-described components of the multifunction device 100 and other devices is performed through the communication control unit 205.
[0026] Next, the software configuration of the server 120 will be described. The multifunction device management unit 221 manages the multifunction device 100 included in the system 10. For example, the multifunction device management unit 221 manages the multifunction device 100 by storing the identification information of this multifunction device 100 in the HDD 124 in response to receiving a registration request from the multifunction device 100. The information of the multifunction device 100 managed by the multifunction device management unit 221 may be acquired from the user of the server 120 through the input I / F 127 of the server 120.
[0027] The transfer unit 222 transfers data between the multifunction device 100 and the PC 130. Since the communication control unit 223 may be the same as the communication control unit 205, duplicate explanations will be omitted.
[0028] Next, the software configuration of the PC 130 will be described. The browser 231 is client software that uses services provided by a web server (e.g., the web server function of the multifunction device 100). The browser 231 displays on the display of the PC 130 a screen generated based on the data received from the web server. Also, the browser 231 transmits user input made to this screen to the web server. Since the communication control unit 232 may be the same as the communication control unit 205, duplicate explanations will be omitted.
[0029] Referring to FIG. 3, an example of a screen generated by the system 10 will be described. First, the screen 300 in FIG. 3(a) will be described, and the other screens in FIG. 3 will be described later.
[0030] Screen 300 is a screen for obtaining settings related to the remote setting function from the user. The remote setting function may be a web server function for setting the multifunction device 100 from an external device (e.g., PC 130) through the network 140. When the remote setting function is valid, the user can check and change the settings of the multifunction device 100 from an external device through the network 140. When the remote setting function is invalid, the user cannot check and change the settings of the multifunction device 100 from an external device through the network 140. Even in this case, the user can check and change the settings of the multifunction device 100 using the operation panel 112 of the multifunction device 100.
[0031] Screen 300 may be displayed on the operation panel 112 of the multifunction device 100 in response to a request from the user. Inputs to screen 300 may be acquired by the operation panel 112 of the multifunction device 100.
[0032] When the remote setting function of the setting management unit 201 is valid, in response to a request from the browser 231 of the PC 130, data for generating screen 300 may be transmitted from the multifunction device 100 to the PC 130, and screen 300 may be displayed on the display of the PC 130. Also, inputs to screen 300 may be acquired by the input device of the PC 130 and transmitted to the multifunction device 100.
[0033] When the remote setting function is valid, the data for generating screen 300 may be transmitted directly from the multifunction device 100 (i.e., without passing through the server 120) to the PC 130, or may be transmitted from the multifunction device 100 to the PC 130 via the server 120.
[0034] Button 301 is a graphics object for obtaining a user instruction to enable the remote setting function. In response to button 305 being pressed while button 301 is selected, the setting management unit 201 enables the remote setting function. Specifically, the setting management unit 201 may open port 80 and port 443. Button 302 is a graphics object for obtaining a user instruction to disable the remote setting function. In response to button 305 being pressed while button 302 is selected, the setting management unit 201 disables the remote setting function. Specifically, the setting management unit 201 may close port 80 and port 443. When button 306 is pressed, the setting management unit 201 does not reflect the settings for screen 300.
[0035] When button 301 is selected, the setting management unit 201 may further display window 303. Window 303 is an object for setting whether to limit the protocol accepted by the remote setting function to HTTPS (Hypertext Transfer Protocol Secure) using TLS (Transport Layer Security). When it is set to be limited to HTTPS, the setting management unit 201 may accept requests by HTTPS and reject requests by HTTP. Specifically, the setting management unit 201 may close port 80 and open port 443. When it is set not to be limited to HTTPS, the setting management unit 201 may accept requests by HTTP and requests by HTTPS. Specifically, the setting management unit 201 may open port 80 and port 443.
[0036] Button 304 is a graphics object for obtaining a user instruction to perform cloud connection settings. In response to button 304 being pressed, the setting management unit 201 displays screen 310 in FIG. 3(b). Details of screen 310 will be described later.
[0037] Referring to the sequence diagram of FIG. 4, the overall operation of the system 10 will be described. In FIG. 4, a case where the web server function (for example, the remote setting function) of the multifunction device 100 (specifically, the setting management unit 201) is disabled will be described. For example, the administrator of the multifunction device 100 may disable the web server function when the multifunction device 100 is used in a LAN-less environment. The operation of FIG. 4 may also be executable when the web server function of the multifunction device 100 is enabled.
[0038] The operation of the system 10 may include a registration operation 400, a connection operation 410, and a service provision operation 420. The registration operation 400 is an operation of registering the multifunction device 100 with the server 120. The connection operation 410 is an operation of establishing a connection between the multifunction device 100 and the server 120. The service provision operation 420 is an operation in which the system 10 provides the service provided by the web server function of the multifunction device 100 to the PC 130. Since the connection operation 410 is performed as a preparation for executing the service provision operation 420, it may be called a preparation operation. Since a request from the PC 130 is transferred from the server 120 to the multifunction device 100 in the service provision operation 420, the service provision operation 420 may be called a transfer operation.
[0039] First, the registration operation 400 will be described with reference to FIGS. 4 and 5. FIG. 5(a) illustrates a method executed by the multifunction device 100 in the registration operation 400. The multifunction device 100 may start the operation of FIG. 5(a) in response to an instruction from a user of the multifunction device 100 (for example, in response to the button 314 being pressed). FIG. 5(b) illustrates a method executed by the server 120 in the registration operation 400. The server 120 may repeatedly execute the operation of FIG. 5(b) during operation. In FIG. 5(b), the operation of the server 120 with respect to the multifunction device 100 is described, but the server 120 may execute a similar operation for other multifunction devices or other devices.
[0040] In S501, the registration request unit 203 of the multifunction device 100 sends a request to the server 120 to register the multifunction device 100 with the server 120 (corresponding to S401 in FIG. 4). In the following description, a request to register the multifunction device 100 with the server 120 is referred to as a registration request.
[0041] The registration request may include the identification information of the multifunction device 100. As will be described later, the identification information of the multifunction device 100 is used by a user who uses the web server function of the multifunction device 100 to identify the multifunction device 100 in the service provision operation 420. The identification information of the multifunction device 100 may be any information for the user to identify the multifunction device 100. For example, the identification information of the multifunction device 100 may be a combination of the DNS (Domain Name System) name of the domain to which the multifunction device 100 belongs, the serial number of the multifunction device 100, the model name of the multifunction device 100, and the installation location of the multifunction device 100. Instead of or in addition to this, the identification information of the multifunction device 100 may include at least one of the IP (Internet Protocol) address of the multifunction device 100, the MAC (Media Access Control) address of the multifunction device 100, and the device name of the multifunction device 100 set by the user. The identification information of the multifunction device 100 may be set by the user before the execution of the method in FIG. 5(a), or may be set at the time of manufacture of the multifunction device 100 and stored in the HDD 104.
[0042] When the server 120 requires user authentication to register the multifunction device 100, the registration request may include the credentials of the user who instructs the multifunction device 100 to send the registration request. The credentials may be, for example, a combination of a username and a password. Instead of this, the credentials may be other information that can authenticate that the user is legitimate, such as a client certificate. The user's credentials may be used as user identification information for identifying the user.
[0043] Referring to FIG. 3(b), the screen 310 used to obtain an instruction to send a registration request from the user will be described. As described above, the screen 310 may be displayed on the operation panel 112 of the multifunction machine 100 in response to the button 304 on the screen 300 being pressed.
[0044] The field 311 is a graphics object for entering the URL (Uniform Resource Locator) of the server 120. The field 312 is a graphics object for entering the user name. The field 313 is a graphics object for entering the password. In response to the button 305 being pressed with the fields 311 to 313 filled, the setting management unit 201 generates a registration request including the information entered in the fields 312 and 313 and the identification information of the multifunction machine 100, and sends this registration request to the URL entered in the field 311. When the button 315 is pressed, the setting management unit 201 does not send the registration request. When the server 120 does not require user authentication to register the multifunction machine 100, the screen 310 may not include the fields 312 and 313, and the registration request may not include the user's credentials. The information entered in the fields 311 to 313 may be stored in the HDD 104 for subsequent processing.
[0045] In S511, the multifunction machine management unit 221 of the server 120 determines whether a registration request has been received from the multifunction machine 100. If it is determined that a registration request has been received from the multifunction machine 100 (YES in S511), the process proceeds to S512; otherwise (NO in S511), S511 is repeated.
[0046] In S512, the MFP management unit 221 of the server 120 authenticates the user who instructed the transmission of the registration request. For example, before executing the method in Fig. 5(b), a list of credentials of users who can execute the registration of the MFP 100 may be stored in the HDD 124 of the server 120. The MFP management unit 221 may determine that authentication is successful when the credentials included in the registration request are included in the list of credentials stored in the HDD 124. On the other hand, the MFP management unit 221 may determine that authentication has failed when the credentials included in the registration request are not included in the list of credentials stored in the HDD 124.
[0047] When it is determined that the authentication of the user is successful (\"YES\" in S512), the MFP management unit 221 of the server 120 transitions the process to S513, and in other cases (\"NO\" in S512), the process transitions to S514. When the server 120 does not require user authentication to register the MFP 100, S512 may be omitted, and S513 may be executed after S511.
[0048] In S513, the MFP management unit 221 of the server 120 registers the MFP 100. Specifically, the MFP management unit 221 generates an access token for the MFP 100 and stores this access token in the HDD 124 in association with the identification information of the MFP 100 included in the registration request. The MFP in which the identification information and the access token are stored in association is the MFP registered in the server 120. When the MFP management unit 221 cancels the registration of the MFP, this information may be deleted from the HDD 124. Further, the MFP management unit 221 may register the user identification information related to the registration request in association with the MFP 100. The user identification information related to the registration request may be the credentials of the user received in S512, or may be other information.
[0049] The multifunction device management unit 221 of the server 120 transmits the generated access token to the multifunction device 100 (corresponding to S402 in FIG. 4). In S514, the multifunction device management unit 221 of the server 120 transmits an error notification to the multifunction device 100. The error notification may indicate that the user authentication has failed. After S513 or S514, the multifunction device management unit 221 of the server 120 waits for a registration request from the multifunction device 100 or another device in S511.
[0050] In S502, the registration request unit 203 of the multifunction device 100 determines whether the registration of the multifunction device 100 has been successful. If it is determined that the registration of the multifunction device 100 has been successful (YES in S502), the registration request unit 203 transitions the process to S503, and in other cases (NO in S502), the registration request unit 203 transitions the process to S504. The registration request unit 203 may determine that the registration of the multifunction device 100 has been successful based on receiving an access token from the server 120. The registration request unit 203 may determine that the registration of the multifunction device 100 has failed based on receiving an error notification from the server 120.
[0051] In S503, the multifunction device 100 stores the access token received from the server 120 in the HDD 104. Specifically, the registration request unit 203 passes the access token received from the server 120 to the transfer unit 204 and instructs the transfer unit 204 to store it in the RAM 103 (corresponding to S403 in FIG. 4). In response to this instruction, the transfer unit 204 stores the access token in the RAM 103. Then, the transfer unit 204 instructs the setting management unit 201 to store the access token stored in the RAM 103 in the HDD 104 (corresponding to S404 in FIG. 4). In response to this instruction, the transfer unit 204 stores the access token in the HDD 104.
[0052] In S504, the registration request unit 203 of the multifunction device 100 may display an error message indicating that the registration of the multifunction device 100 has failed on the operation panel 112.
[0053] Next, the connection operation 410 will be described with reference to FIGS. 4 and 6. FIG. 6(a) illustrates a method executed by the multifunction device 100 in the connection operation 410. The multifunction device 100 may start the operation of FIG. 6(a) in response to the completion of S503, in response to the power of the multifunction device 100 being turned on, or in response to an instruction from the user. FIG. 6(b) illustrates a method executed by the server 120 in the connection operation 410. The server 120 may repeatedly execute the operation of FIG. 6(b) during operation. In FIG. 6(b), the operation of the server 120 with respect to the multifunction device 100 is described, but the server 120 may perform the same operation with respect to other multifunction devices or other devices.
[0054] In S601, the transfer unit 204 of the multifunction device 100 transmits a request to the server 120 to establish a connection between the multifunction device 100 and the server 120 (corresponding to S411 in FIG. 4). In the following description, a request to establish a connection between the multifunction device 100 and the server 120 is referred to as a connection request. This connection may include a TCP (Transmission Control Protocol) connection.
[0055] The connection request may include the identification information and access token of the multifunction device 100. The identification information of the multifunction device 100 may be the same as the identification information included in the registration request transmitted in S501. The access token may be the access token received in S502 and stored in the HDD 104.
[0056] The connection established between the server 120 and the multifunction device 100 is maintained semi-permanently. For example, this connection is maintained unless the power of the multifunction device 100 or the server 120 is turned off or explicitly disconnected by the user of the system 10. Therefore, in the following description, this connection is referred to as an always-on connection.
[0057] The connection request may explicitly or implicitly include an indication prohibiting the server 120 from disconnecting the connection between the multifunction device 100 and the server 120. For example, the connection request including the identification information and the access token of the multifunction device 100 may be this indication. Alternatively, the connection request may include a flag indicating that the server 120 is prohibited from disconnecting the connection between the multifunction device 100 and the server 120.
[0058] In S611, the transfer unit 222 of the server 120 determines whether it has received a connection request from the multifunction device 100. When it is determined that the transfer unit 222 has received a connection request from the multifunction device 100 (\"YES\" in S611), the process transitions to S612, and in other cases (\"NO\" in S611), S611 is repeated.
[0059] In S612, the transfer unit 222 of the server 120 determines whether the multifunction peripheral 100 that sent the connection request is registered in the server 120. If it is determined that the multifunction peripheral 100 that sent the connection request is registered in the server 120 (”YES” in S612), the transfer unit 222 transitions the process to S613, and in other cases (”NO” in S612), the transfer unit 222 transitions the process to S614. Specifically, the transfer unit 222 may inquire of the multifunction peripheral management unit 221 whether the multifunction peripheral 100 that sent the connection request is registered in the server 120 (corresponding to S412 in FIG. 4). The multifunction peripheral management unit 221 may determine that the multifunction peripheral 100 that sent the connection request is registered in the server 120 when the combination of the identification information and the access token included in the connection request is stored in the HDD 104. The multifunction peripheral management unit 221 may determine that the multifunction peripheral 100 that sent the connection request is not registered in the server 120 when the combination of the identification information and the access token included in the connection request is not stored in the HDD 104. As described above, the identification information of the multifunction peripherals registered in the server 120 and the access tokens associated therewith are stored in the HDD 104. The multifunction peripheral management unit 221 returns the determination result to the transfer unit 222 (corresponding to S413 in FIG. 4). In the above example, it is determined whether the multifunction peripheral 100 is registered in the server 120 based on the combination of the identification information and the access token. Alternatively, it may be determined whether the multifunction peripheral 100 is registered in the server 120 based on only one of the identification information and the access token.
[0060] In S613, based on the fact that the multifunction peripheral 100 is registered in the server 120, the transfer unit 222 of the server 120 establishes a permanent connection between the multifunction peripheral 100 and the server 120 (corresponding to S414 in FIG. 4). The server 120 maintains this permanent connection. In S614, the transfer unit 222 of the server 120 sends an error notification to the multifunction peripheral 100. The error notification may indicate that the multifunction peripheral 100 is not registered in the server 120. After S613 or S614, the transfer unit 222 of the server 120 waits for a connection request from the multifunction peripheral 100 or another device in S611.
[0061] In S602, the transfer unit 204 of the multifunction device 100 determines whether the establishment of the always-on connection has been successful. If it is determined that the establishment of the always-on connection has been successful (\"YES\" in S602), the transfer unit 204 transitions the process to S603; otherwise (\"NO\" in S602), the transfer unit 204 transitions the process to S604. The transfer unit 204 may determine that the establishment of the always-on connection has been successful based on the notification of connection completion from the server 120. The transfer unit 204 may also determine that the establishment of the always-on connection has failed based on receiving an error notification from the server 120.
[0062] In S603, the transfer unit 204 of the multifunction device 100 maintains the always-on connection. That is, the multifunction device 100 does not disconnect the always-on connection during operation. In S604, the transfer unit 204 of the multifunction device 100 may display an error message indicating the failure to establish the always-on connection on the operation panel 112. Instead of displaying the error message on the operation panel 112 when the method in Fig. 6(a) is started without being instructed by the user, the transfer unit 204 may record the error message in a log.
[0063] Subsequently, the service provision operation 420 will be described with reference to Figs. 4 and 7. Fig. 7(a) illustrates the method executed by the PC 130 in the service provision operation 420. The PC 130 may start the operation in Fig. 7(a) in response to obtaining an instruction from the user of the PC 130 to display a list of multifunction devices registered in the server 120. Fig. 7(b) illustrates the method executed by the server 120 in the service provision operation 420. The server 120 may repeatedly execute the operation in Fig. 7(b) during operation. In Fig. 7(b), the operation of the server 120 with respect to the multifunction device 100 is described, but the server 120 may execute a similar operation for other multifunction devices or other devices. Fig. 7(c) illustrates the method executed by the multifunction device 100 in the service provision operation 420. After the always-on connection is established, the multifunction device 100 may repeatedly execute the operation in Fig. 7(c).
[0064] In S701, the browser 231 of the PC 130 sends a request to the server 120 to obtain a list of the MFPs registered in the server 120 (corresponding to S421 in FIG. 4). In the following description, this request is referred to as a list request. The URL of the server 120 may be input by the user. As will be described below, the PC 130 can connect to the MFPs registered in the server 120 via the server 120 and use the web server function of this MFP. When user authentication is required to request a list of the MFPs registered in the server 120, the list request may include the user's credentials.
[0065] In S711, the MFP management unit 221 of the server 120 determines whether it has received a list request from the PC 130. When it is determined that the MFP management unit 221 has received a list request from the PC 130 ( "YES" in S711), the process transitions to S712, and in other cases ( "NO" in S711), the process transitions to S713.
[0066] In S712, the MFP management unit 221 of the server 120 responds to the PC 130 with a list of the MFPs registered in the server 120 (corresponding to S422 in FIG. 4). For example, the server 120 responds to the PC 130 with data for displaying a screen including the list of the MFPs. Information about the MFPs registered in the server 120 is stored in the HDD 124. The MFP management unit 221 may include the identification information of the MFPs stored in the HDD 124 (that is, the identification information included in the registration request obtained in S511) in the response. When user authentication is required to respond with the list, the MFP management unit 221 may perform user authentication and respond with the list only when the authentication is successful. The user authentication may be performed in the same manner as in S512 or by other methods.
[0067] The multi-function device management unit 221 may respond to the PC 130 with a list of all multi-function devices registered in the server 120. Alternatively, the multi-function device management unit 221 may respond with a list of multi-function devices registered in association with the user identification information acquired in relation to the list request among the multi-function devices registered in the server 120. In this case, the user of the PC 130 can acquire information only about the multi-function devices registered by himself / herself. What kind of list the server 120 responds with may be preset and stored in the HDD 124.
[0068] In S702, the browser 231 of the PC 130 displays a screen including the list received from the server 120 on the display of the PC 130. Referring to FIG. 3(c), an example of such a screen 320 is shown. The graphics object 321 is a list of multi-function devices (i.e., multi-function devices registered in the server 120) responded from the server 120.
[0069] The processing when the button 332 is pressed with any one of the multi-function devices selected by the radio button of the graphics object 321 will be described. In the following description, it is assumed that the multi-function device 100 is selected. In S703, the browser 231 of the PC 130 transmits a request to connect to the web server function (e.g., remote setting function) of the multi-function device 100 to the server 120 (corresponding to S423 in FIG. 4). In the following description, such a request is referred to as a service request. The service request may be a request via HTTPS. When the button 323 is pressed, the browser 231 does not transmit a service request.
[0070] In S713, the transfer unit 222 of the server 120 determines whether it has received a service request from the PC 130. When it is determined that the transfer unit 222 has received a service request from the PC 130 (YES in S713), the process transitions to S714, and in other cases (NO in S713), the process transitions to S715. When S713 is executed, a constant connection is established.
[0071] In S714, the transfer unit 222 of the server 120 transfers the service request received from the PC 130 to the multifunction device 100 through the always-on connection (corresponding to S424 in FIG. 4). Since the always-on connection is established in response to the connection request from the multifunction device 100, the server 120 can send the service request to the multifunction device 100 even when the port of the web server function of the multifunction device 100 is closed.
[0072] In S721, the transfer unit 204 of the multifunction device 100 determines whether it has received a service request from the server 120 through the always-on connection. When it is determined that the transfer unit 204 has received a service request from the server (\"YES\" in S721), the process transitions to S722, and in other cases (\"NO\" in S721), S721 is repeated.
[0073] In S722, the multifunction device 100 sends a service response to the server 120 in response to the service request. The service response may be a response via HTTPS. The multifunction device 100 may send this service response through the always-on connection.
[0074] Specifically, the transfer unit 204 of the multifunction device 100 sends the service request to the web server function of the setting management unit 201 within the multifunction device 100 through a local loopback connection (corresponding to S425 in FIG. 4). This connection request may be a request via HTTPS. The web server function of the setting management unit 201 generates a connection response to the connection request and returns it to the transfer unit 204 (corresponding to S426 in FIG. 4). The transfer unit 204 transfers this connection response to the server 120 as a service response (corresponding to S427 in FIG. 4).
[0075] In S715, the transfer unit 222 of the server 120 determines whether it has received a service response from the multifunction device 100 through the always-on connection. When it is determined that the transfer unit 222 has received a service response from the multifunction device 100 (\"YES\" in S715), the process transitions to S716, and in other cases (\"NO\" in S715), the process transitions to S711.
[0076] In S716, the transfer unit 222 of the server 120 transfers the service response received from the multifunction peripheral 100 to the PC 130 (corresponding to S428 in FIG. 4). In S704, the browser 231 of the PC 130 displays on the display of the PC 130 a screen generated based on the service response received from the server 120 (for example, a screen provided by the web server function of the setting management unit 201).
[0077] According to the above method, even when the port of the web server function of the multifunction peripheral 100 is closed, the web server function of the multifunction peripheral 100 can return a response to a request via the server 120. Therefore, even when the multifunction peripheral 100 is arranged in a LAN-less environment, the web server function of the multifunction peripheral 100 can be provided to the PC 130 while keeping the port closed (that is, while improving security). For example, even if the PC 130 is connected to a network different from the multifunction peripheral 100, if the PC 130 can access the server 120, the PC 130 can use the web server function of the multifunction peripheral 100, improving convenience.
[0078] In addition, since the server 120 receives a service request from the PC 130 in a state where a connection is always established, the service request can be quickly transferred to the multifunction peripheral 100. Furthermore, since the web server function of the multifunction peripheral 100 (for example, its setting management unit 201) can be used as it is, it is not necessary to create a web server function provided by client operation, and it is possible to suppress the extra maintenance cost for developers.
[0079] In the above embodiment, the multifunction peripheral 100 provides a web server function, and the PC 130 performs HTTPS communication with the multifunction peripheral 100 via the server 120. Instead of this, the multifunction peripheral 100 may provide a server function using another protocol, and the PC 130 may use the server function of the multifunction peripheral 100 via the server 120 using another protocol. For example, a network device management client operating on the PC 130 may obtain information from the multifunction peripheral 100 via the server 120 by SNMP (Simple Network Management Protocol).
[0080] In the above method, S421 and S422 in FIG. 4 and S701, S702, S711, and S712 in FIG. 7 may be omitted. In this case, in S703, PC130 may specify the multifunction device to be connected and send a service request to server 120. Such a form is useful for protocols and applications that do not display a screen.
[0081] <Second Embodiment> Referring to FIG. 8, a system 80 according to the second embodiment will be described. In the following description of the second embodiment, differences from the first embodiment will be mainly described, and descriptions of points that may be the same as those in the first embodiment will be omitted.
[0082] System 80 is different from system 10 in that it has a multifunction device 100 instead of a multifunction device 800. Similar to the first embodiment, system 80 may include a plurality of multifunction devices or other devices, and in particular, may include both a multifunction device 100 and a multifunction device 800.
[0083] Multifunction device 800 is different from multifunction device 100 in that it has a plurality of network I / Fs. In the example of FIG. 8, multifunction device 800 has two network I / Fs, namely network I / F 105 and network I / F 801. Therefore, multifunction device 800 can be connected to different networks. For example, network I / F 105 may be connected to network 140. Network 140 may be a LAN installed in an on-premises environment. Network I / F 801 may be connected to the Internet 803 via access point 802. In this way, multifunction device 800 can be connected to both an on-premises environment and a LAN-less environment.
[0084] The network I / F 801 may communicate with the access point 802 either wired or wirelessly. The network I / F 105 may be treated as the main network I / F, and the network I / F 801 may be treated as the secondary network I / F. Alternatively, the network I / F 105 may be treated as the secondary network I / F, and the network I / F 801 may be treated as the main network I / F.
[0085] Referring to FIG. 9, an example of a screen generated by the system 80 will be described. The screen 900 in FIG. 9(a) is a screen for obtaining settings regarding the remote setting function from the user. The screen 900 is different from the screen 300 in that it further has radio buttons 901, and other points may be the same. The radio buttons 901 are graphical objects for obtaining from the user a specification of which of the network I / F 105 and the network I / F 801 is the target of the setting of the remote setting function. The setting management unit 201 of the multifunction device 800 uses the screen 900 to obtain from the user settings regarding the remote setting function for each of the two network I / Fs 105 and 801. Specifically, when "main line" is selected by the radio button 901, the setting management unit 201 obtains the settings for the network I / F 105. When "sub line" is selected by the radio button 901, the setting management unit 201 obtains the settings for the network I / F 801.
[0086] The screen 910 in FIG. 9(b) is a screen used to obtain an instruction from the user to send a registration request. The screen 910 is different from the screen 310 in that it further has a graphical object 911, and other points may be the same.
[0087] The graphics object 911 is used to obtain from the user a setting as to whether to enable a web server function (e.g., a remote setting function) for service requests sent to the multifunction device 800 without going through a constant connection. When "ON" is selected in the graphics object 911, the setting management unit 201 disables the web server function for service requests sent to the multifunction device 800 without going through a constant connection. When "OFF" is selected in the graphics object 911, the setting management unit 201 enables the web server function for service requests sent to the multifunction device 800 without going through a constant connection.
[0088] The settings made on the screens 900 and 910 are stored in the HDD 104 and may be used in subsequent processing. For example, the setting management unit 201 may read the setting related to the remote setting function stored in the HDD 104 in response to the power of the multifunction device 800 being turned on, and set the server port according to this setting. The graphics object 911 may be used in the first embodiment. That is, for a multifunction device having one network I / F 105 such as the multifunction device 100, it may be possible to set whether to enable the web server function for service requests sent to the multifunction device 800 without going through a constant connection.
[0089] The following Table 1 summarizes whether service requests for the web server function are possible according to the above settings.
[0090]
Table 1
[0091] When the remote setting function is set to be disabled, the setting management unit 201 disables the server port for receiving remote requests for the remote setting function. As described above, the remote setting function is set to be disabled by the button 302 on the screen 900. In this case, neither service requests through a constant connection nor service requests not through a constant connection can be made.
[0092] When the remote setting function is set to be enabled, the setting management unit 201 enables the server port for receiving remote requests for the remote setting function. As described above, the remote setting function is enabled by the button 301 on the screen 900. In this case, service requests without going through a permanent connection are possible. When the remote setting function is enabled and the server 120 is not registered on the screen 910, a permanent connection is not established. Therefore, service requests through a permanent connection cannot be made.
[0093] When the remote setting function is enabled and the server 120 is registered on the screen 910, a permanent connection is established. Therefore, service requests through a permanent connection are possible.
[0094] When it is set to disable the web server function for service requests sent to the multifunction machine 800 without going through a permanent connection on the screen 910, service requests without going through a permanent connection cannot be made. When it is set to enable the web server function for service requests sent to the multifunction machine 800 without going through a permanent connection on the screen 910, service requests without going through a permanent connection are possible.
[0095] For example, when you want to give priority to performance and use the remote setting function in an on-premises environment, for the network I / F 105, the remote setting function can be set to be enabled, and the multifunction machine 800 does not have to be registered with the server 120. This can limit the PC 130 connected to the network 140 from making service requests without going through a permanent connection. On the other hand, for the network I / F 801 connected to the Internet 803, the remote setting function can be set to be enabled, the multifunction machine 800 can be registered with the server 120, and service requests without going through a permanent connection can be set to be disabled. This improves security.
[0096] Next, with reference to FIGS. 10 to 11, the operation of the system 80 will be described. FIG. 10 shows a sequence diagram of the system 80. FIG. 11 explains the method executed by the multifunction machine 800. The multifunction machine 800 may execute the method of FIG. 11 in response to receiving a service request from the PC 130 without going through a constant connection (corresponding to S1001 in FIG. 10).
[0097] In S1101, the setting management unit 201 of the multifunction machine 800 determines whether the remote setting function is valid. If the setting management unit 201 determines that the remote setting function is valid (\"YES\" in S1101), the process transitions to S1102, and in other cases (\"NO\" in S1101), the process ends. The setting management unit 201 may discard the received remote request if the remote setting function is invalid.
[0098] In S1102, the setting management unit 201 of the multifunction machine 800 determines whether the remote setting function is valid for a service request that does not go through a constant connection. If the setting management unit 201 determines that the remote setting function is valid for a service request that does not go through a constant connection (\"YES\" in S1102), the process transitions to S1103, and in other cases (\"NO\" in S1102), the process transitions to S1104.
[0099] In S1103, the setting management unit 201 of the multifunction machine 800 responds to the remote request. For example, the setting management unit 201 responds to the PC 130 with a screen for setting the multifunction machine 800.
[0100] In S1104, the setting management unit 201 of the multifunction machine 800 returns a response to the PC 130 for redirecting the PC 130 to the server 120 (corresponding to S1002 in FIG. 10). For example, this response may include the URL of the server 120. Thereafter, the PC 130 may execute the processes after S701 in FIG. 7(a). Alternatively, the PC 130 may execute the processes after S703 in FIG. 7(a) for the multifunction machine 800. By redirecting the PC 130 in this way, the process for executing the service request is continued.
[0101] In the above-described embodiment, whether to enable the remote setting function for service requests not via the always-on connection is set according to a user instruction. When a setting is made to connect to a LAN-less environment for any network I / F (that is, when it is set to disable the remote setting function for service requests sent to the multifunction device 800 without going through the always-on connection), for this network I / F, the setting management unit 201 of the multifunction device 800 may automatically enable the remote setting function for service requests sent to the multifunction device 800 via the always-on connection. For example, when all the server ports (well-known ports) of the multifunction device 800 are set to be closed, the setting management unit 201 of the multifunction device 800 may automatically enable the remote setting function for service requests sent to the multifunction device 800 via the always-on connection.
[0102] <Summary of the Embodiment> [Item 1] A system including a device having a server function and a server, wherein the device has connection request means for sending a connection request to the server to request establishment of a connection between the device and the server, receiving means for receiving a service request for the server function from the server through the connection, acquisition means for acquiring a response generated by the server function for the service request, and transmission means for sending the response to the server, and the server has connection establishment means for establishing the connection in response to the connection request from the device, and transfer means for transferring the service request received from the information processing device in a state where the connection is established to the device through the connection and transferring the response from the device for the service request to the information processing device. [Item 2] The acquisition means of the device in the system according to item 1 transmits the service request received from the server to the server function through a local loopback connection. [Item 3] The device further includes a registration request means for transmitting a registration request for registering the device to the server. The server further includes a management means for registering the device that has transmitted the registration request. The connection establishment means of the server in the system according to item 1 or 2 establishes the connection based on the fact that the device is registered. [Item 4] The management means of the server in the system according to item 3 receives a list request for obtaining a list of registered devices from the information processing device, and responds to the list request with a list of registered devices. [Item 5] The management means of the server registers the user identification information obtained in relation to the registration request in association with the device, and responds to the list request with a list of the devices registered in association with the user identification information obtained in relation to the list request. The system according to item 4. [Item 6] The device in the system according to any one of items 1 to 5 further includes a setting means for obtaining from the user a setting as to whether to enable the server function for a service request transmitted to the device without passing through the connection. [Item 7] The device includes a plurality of network interfaces. The setting means of the device in the system according to item 6 obtains the setting from the user for each of the plurality of network interfaces. [Item 8] The system according to item 6 or 7, further comprising redirecting means for redirecting the information processing apparatus that has transmitted a service request to the device without passing through the connection to the server when the device is set to disable the server function for a service request transmitted to the device without passing through the connection. [Item 9] The setting means of the device automatically enables the server function for a service request transmitted to the device via the connection in response to the setting that the server function is disabled for a service request transmitted to the device without passing through the connection. The system according to any one of items 6 to 8. [Item 10] The transfer means of the server transfers the service request to the device via HTTPS. The system according to any one of items 1 to 9. [Item 11] The device is a multifunction device. The system according to any one of items 1 to 10. [Item 12] A method executed in a system including a device having a server function and a server, comprising: a step in which the device transmits a connection request for establishing a connection between the device and the server to the server; a step in which the server establishes the connection in response to the connection request from the device; a step in which the server transfers a service request for the server function of the device received from an information processing apparatus while the connection is established to the device through the connection; a step in which the device receives the service request through the connection; a step in which the device acquires a response generated by the server function for the service request; a step in which the device transmits the response to the server; a step in which the server transfers the response from the device for the service request to the information processing apparatus. [Item 13] A device having a server function, connection request means for sending a connection request to the server to request establishment of a connection between the device and the server, receiving means for receiving a service request for the server function from the server through the connection, acquiring means for acquiring a response generated by the server function in response to the service request, and transmitting means for transmitting the response to the server. A device comprising these. [Item 14] A program for causing a computer to function as each means of the device according to Item 13. [Item 15] A server, connection establishment means for establishing a connection between the device and the server in response to a connection request from a device having a server function, transfer means for transferring a service request for the server function of the device received from an information processing apparatus in a state where the connection is established to the device through the connection, and transferring a response from the device to the service request to the information processing apparatus. A server comprising these. [Item 16] A program for causing a computer to function as each means of the server according to Item 15.
[0103] The invention is not limited to the above embodiments, and various changes and modifications are possible without departing from the spirit and scope of the invention. Therefore, claims are attached to disclose the scope of the invention.
Explanation of Reference Numerals
[0104] 10 System, 100 Multifunction Device, 120 Server, 130 PC
Claims
1. A system comprising a device having a server function and a server, wherein the device comprises connection request means for sending a connection request to the server requesting establishment of a connection between the device and the server, receiving means for receiving a service request for the server function from the server through the connection, acquisition means for acquiring a response generated by the server function in response to the service request, and transmission means for transmitting the response to the server, and the server comprises connection establishment means for establishing the connection in response to the connection request from the device, and transfer means for transferring the service request received from the information processing device in a state where the connection is established to the device through the connection, and transferring the response from the device for the service request to the information processing device, a system.
2. The system according to claim 1, wherein the acquisition means of the device transmits the service request received from the server to the server function by a local loopback connection.
3. The device further comprises registration request means for sending a registration request to the server requesting registration of the device, the server further comprises management means for registering the device that has sent the registration request, and the connection establishment means of the server establishes the connection based on the fact that the device is registered, the system according to claim 1.
4. The system according to claim 3, wherein the management means of the server receives a list request from the information processing device requesting a list of registered devices, and responds to the list request with a list of registered devices.
5. The management means of the server registers the user identification information acquired in relation to the registration request in association with the device, and responds to the list request with a list of the devices registered in association with the user identification information acquired in relation to the list request, the system according to claim 4.
6. The system according to claim 1, wherein the device further comprises setting means for acquiring from the user a setting as to whether to enable the server function for a service request sent to the device without passing through the connection.
7. The device comprises a plurality of network interfaces, The setting means of the device acquires the setting from a user for each of the plurality of network interfaces, the system according to claim 6.
8. The device further includes redirecting means for redirecting the information processing apparatus that has transmitted a service request to the device without passing through the connection to the server when it is set to disable the server function for a service request transmitted to the device without passing through the connection, the system according to claim 6.
9. The setting means of the device automatically enables the server function for a service request transmitted to the device via the connection in response to being set to disable the server function for a service request transmitted to the device without passing through the connection, the system according to claim 6.
10. The transfer means of the server transfers the service request to the device via HTTPS, the system according to claim 1.
11. The device is a multifunction device, the system according to claim 1.
12. A method executed in a system including a device having a server function and a server, a step in which the device transmits a connection request for establishing a connection between the device and the server to the server; a step in which the server establishes the connection in response to the connection request from the device; a step in which the server transfers a service request for the server function of the device received from an information processing apparatus while the connection is established to the device through the connection; a step in which the device receives the service request through the connection; a step in which the device acquires a response generated by the server function for the service request; a step in which the device transmits the response to the server; a step in which the server transfers the response from the device for the service request to the information processing apparatus, the method.
13. A device having a server function, connection request means for transmitting a connection request for establishing a connection between the device and the server to the server; receiving means for receiving a service request for the server function from the server through the connection; An acquisition means for acquiring a response generated by the server function in response to the service request; A device comprising a transmission means for transmitting the response to the server.
14. A program for causing a computer to function as each means of the device according to Claim 13.
15. A server, A connection establishment means for establishing a connection between the device and the server in response to a connection request from a device having a server function; A transfer means for transferring a service request for the server function of the device received from an information processing apparatus in a state where the connection is established to the device through the connection, and transferring a response from the device to the service request to the information processing apparatus. A server comprising:
16. A program for causing a computer to function as each means of the server according to Claim 15.
Citation Information
Patent Citations
Method, system, and computer program commodity for data communication using interconnection architecture
JP2004005661A
Mediation server and computer program for mediation server
JP2023097076A
Network system, direct access method, network household electrical appliance, and program
JP2009151479A