Information processing apparatus, method for controlling information processing apparatus, and program
The information processing device manages setting values using a non-volatile memory to ensure compliance with security policies, reducing processing load and time, thus preventing policy violations.
Patent Information
- Application Number
- JP2024023236
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-19
- Publication Date
- 2025-08-29
AI Technical Summary
The processing load and time increase with the number of setting items in image processing devices, leading to longer waiting times, particularly in low-end devices with lower CPU performance, when applying security policies.
An information processing device equipped with a non-volatile memory and management means to control the import process of setting values, saving and overwriting them to ensure compliance with security policies, thereby preventing policy violations while reducing processing load.
Prevents settings that violate security policies and suppresses increases in processing load and time due to the number of setting items.
Smart Images

Figure 2025126820000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] It is desirable that personal computers (PCs) and server equipment (file servers, authentication servers, etc.) connected to an office network be operated in accordance with the security policy established for each office. A security policy is a basic guideline regarding information security for the entire company, summarizing the policies for preventing the use of information, external intrusions, and information leaks.
[0003] In addition to PCs and servers, devices connected to office networks also include image processing devices such as multifunction peripherals and printers. In recent years, image processing devices have gone beyond simply printing and sending images; they now provide users with a Web UI that allows them to operate the image processing device from a web browser on their PC, and they also provide various cloud services in conjunction with cloud servers. In other words, image processing devices are beginning to play the same role as other PCs and server devices on the network. Therefore, to maintain a safe and secure office environment, image processing devices, like PCs and server devices, are also required to comply with security policies.
[0004] Complying with the security policy here means, for example, imposing restrictions on the security operations of the image processing device to prevent unauthorized use and information leaks, such as requiring user authentication when operating the image processing device or requiring encryption of communication paths.
[0005] In such image processing devices, control is performed to maintain a state in accordance with the security policy. Specifically, once a certain security policy is set, the setting items related to that security policy are set to fixed values and cannot be changed by users other than the security administrator.
[0006] Furthermore, recent image processing devices have a variety of functions, and many settings are required to operate these functions properly. Some devices have a function to collect these settings, export them as a file outside the device, and then import them later at a certain opportunity (hereinafter referred to as a "settings import function").
[0007] One example of the aforementioned triggers is when simplified procedures are implemented within a company to apply settings such as network settings, address books, and security policies due to external environmental influences such as changes in departmental or assignment status. Another example is when settings are backed up immediately before initialization when a device is delivered to a manufacturer service center for repairs, and the settings are restored after the repair is complete. Furthermore, various triggers and scenarios, such as the installation of devices in companies or homes, including relocation, or when settings are transferred during replacement or settings are applied in specific environments, are calling for measures to improve convenience by restoring settings from existing states or by batch converting settings to suit the environment.
[0008] At this time, in order to maintain a state in accordance with the security policy, it is necessary to execute a setting value initialization function for specific setting values that are restricted by the security policy so as not to deviate from the security policy. Patent Document 1 proposes a technique for checking whether each of the numerous setting items of an image processing apparatus satisfies a security policy, and importing only the setting items that satisfy the policy. [Prior art documents] [Patent documents]
[0009] [Patent Document 1] Patent No. 6403591 Summary of the Invention [Problem to be solved by the invention]
[0010] In a conventional configuration where each setting item is checked to see if it complies with the security policy and a decision is made as to whether to import the setting item, the processing load for making the decision increases in proportion to the number of setting items and security policy items. As a result, the processing time for the setting value import function increases, which may result in longer waiting times for users. This impact is particularly noticeable in low-end image processing devices with relatively low CPU performance.
[0011] The present invention has been made to solve the above-mentioned problems, and aims to provide a mechanism that can prevent settings that violate the security policy when a setting value import function is executed on a device to which a security policy is applied, while suppressing increases in processing load and processing time due to the number of setting items. [Means for solving the problem]
[0012] The present invention is an information processing device equipped with a non-volatile memory, comprising a first management means for managing security policy settings, a second management means for managing setting values of a group of setting items that affect at least one or more operations of the information processing device, a receiving means for receiving a group of setting values to be imported, and a control means for controlling the import process of the setting values, wherein the non-volatile memory holds operational settings of the information processing device, and the control means controls the import process to perform, as a series of processes, a first process for saving at least a portion of the group of setting values received by the receiving means as the operational settings held in the non-volatile memory, and a second process for overwriting and saving, after the first process, the setting values managed by the second management means as part of the operational settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means. [Effects of the Invention]
[0013] According to the present invention, when the setting value import function is executed on a device to which a security policy is applied, it is possible to prevent settings that violate the security policy while suppressing increases in processing load and processing time due to the number of setting items. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram showing an example of a network configuration according to an embodiment of the present invention. [Figure 2] 1 is an external view of an image processing apparatus showing an example of an information processing apparatus according to an embodiment of the present invention. [Figure 3] FIG. 1 is a diagram showing an example of the hardware configuration of an image processing apparatus. [Figure 4] FIG. 2 is a diagram illustrating an operation display unit of the image processing apparatus. [Figure 5] FIG. 2 is a diagram illustrating the software configuration of the image processing apparatus. [Figure 6] FIG. 3 is a diagram showing setting item management information of the image processing apparatus. [Figure 7] FIG. 10 is a diagram showing the dependency relationship between the security policy setting and other settings of the image processing apparatus. [Figure 8A] 10 is an example of a screen displayed on a terminal device when setting a security policy. [Figure 8B] 10 is an example of a screen displayed on a terminal device when setting a security policy. [Figure 9] 10 is a flowchart showing a security policy setting process. [Figure 10] An example of a settings screen for a setting item whose changes are restricted by security policy. [Figure 11A] 10 is an example of a setting screen when executing the setting value export function of the image processing device. [Figure 11B] 10 is an example of a setting screen when executing the setting value export function of the image processing device. [Figure 12] 10 is a flowchart showing a setting value export process of the image processing apparatus. [Figure 13A] 10 is an example of a setting screen when executing the setting value import function of the image processing device. [Figure 13B] 10 is an example of a setting screen when executing the setting value import function of the image processing device. [Figure 13C] 10 is an example of a setting screen when executing the setting value import function of the image processing device. [Figure 14] 10 is a flowchart showing a setting value import process of the image processing apparatus. DETAILED DESCRIPTION OF THE INVENTION
[0015] Preferred embodiments of the present invention will be described below by way of example with reference to the drawings. However, it should be understood that the scope of the present invention also includes appropriate modifications and improvements to the embodiments described below based on the ordinary knowledge of those skilled in the art, provided that the modifications and improvements do not deviate from the spirit of the present invention.
[0016] [First embodiment] First, the network configuration in this embodiment will be described with reference to Fig. 1. Note that the network configuration described below is merely an example of an embodiment, and is applicable to various configurations that allow wired or wireless communication between an image processing device and a terminal device, and is not limited to the configuration shown in this diagram. Also, in documents and diagrams, the network may be referred to as NW for abbreviation. FIG. 1 is a diagram showing an example of a network configuration according to an embodiment of the present invention.
[0017] 1, the network configuration of this embodiment shows a local area network (hereinafter referred to as "LAN") 101 configured by an access point 100, and an image processing device 200 and a terminal device 300 connected to the network. Here, the connection form of the LAN 101 may be wired communication or wireless communication, and for example, it is assumed that the connection is made by Wi-Fi (Wireless Fidelity) (registered trademark), which is a communication standard conforming to the IEEE802.11 series.
[0018] In the LAN 101, different IP addresses are assigned to the image processing device 200 and the terminal device 300 by the access point 100. This allows devices within the LAN 101 to specify IP addresses as destinations and communicate with each other.
[0019] The image processing device 200 is an example of an information processing device of the present invention. The image processing device 200 is, for example, an inkjet printer, and provides users with functions such as printing, scanning, and faxing. Furthermore, the image processing device 200 has a web server function and is capable of receiving requests and sending responses using Hypertext Transfer Protocol (hereinafter referred to as "HTTP") communication. Note that the functions included in the image processing device 200 are not limited to these; some of the functions presented may not be included, or functions other than those presented may be included. Furthermore, the image processing device 200 is not limited to an inkjet printer, but may be other devices such as a laser beam printer or an office multifunction peripheral. Furthermore, the present invention is not limited to image processing devices, and can be applied to various information processing devices such as network home appliances and other electronic devices.
[0020] The terminal device 300 is, for example, a smartphone, and provides a web browser function to the user within the device. The web browser function transmits requests and receives responses using HTTP communication, and displays screens associated with these communications. Note that the functions installed in the terminal device 300 are not limited to these, and functions other than those presented may also be installed. Furthermore, the terminal device 300 is not limited to a smartphone, and may be other devices such as a PC (personal computer) or a tablet terminal.
[0021] FIG. 2 is a diagram showing an example of the appearance of the image processing device 200. As shown in FIG. In this embodiment, an inkjet printer is exemplified as the image processing device, which is a multifunction printer (MFP) that combines printing, scanning, faxing (FAX), and other functions.
[0022] The operation display unit 201 includes a display and buttons used to operate the image processing device 200. Details will be explained with reference to FIG. The print paper insertion slot 202 is an insertion slot for setting paper of various sizes. The paper set here is transported one sheet at a time to the printing unit, where the desired printing is performed, and the paper is then discharged from the print paper discharge slot 203.
[0023] The document table 204 is a transparent glass table on which a document is placed to be scanned by the scanner. The document table pressure plate 205 is a cover that presses the document against the document table to prevent it from floating when scanning with the scanner, and also prevents external light from entering the scanning unit.
[0024] The USB communication unit 206 includes a circuit and a USB connector for the image processing device 200 to communicate with an external terminal device 300 or the like via a USB connection. The wireless LAN communication unit 207 has embedded therein circuits such as an antenna for performing wireless communication such as the above-mentioned wireless connection or a direct connection in which the image processing device 200 itself serves as an access point to form a wireless LAN. The FAX communication unit 208 includes a circuit for sending and receiving FAXes and a connector for connecting a telephone cable. The power supply unit 209 includes a power supply circuit and a power jack for supplying power to the image processing device 200 .
[0025] FIG. 3 is a block diagram showing an example of the hardware configuration of the image processing device 200. As shown in FIG. The image processing device 200 comprises a main board 210 that controls the entire device, an operation display unit 201 , a USB communication unit 206 , a wireless LAN communication unit 207 , a FAX communication unit 208 , and a power supply unit 209 .
[0026] A microprocessor-type CPU 211 disposed on the main board 210 operates in accordance with a control program stored in a ROM 213 connected via an internal bus 212 and data stored in a RAM 214. Various operational settings of the image processing device 200 are held in a nonvolatile memory, NVRAM 215, and are read and written in accordance with the control program.
[0027] The CPU 211 controls the scanning unit 217 to read an original document and store the image in an image memory that is part of the RAM 214. The CPU 211 also controls the printing unit 216 to print an image stored in the image memory that is part of the RAM 214 onto a recording medium.
[0028] The CPU 211 controls the USB communication unit 206 via a USB communication control unit 218 to perform USB communication with an external device via a USB connection. The CPU 211 also controls the wireless LAN communication unit 207 via a wireless LAN communication control unit 219 to perform wireless LAN communication with an external device via an infrastructure connection or a direct connection. The CPU 211 also controls the FAX communication unit 208 via a FAX communication control unit 220 to perform FAX communication with an external device using a telephone line.
[0029] The CPU 211 controls the operation display control unit 221 to receive operation information from the operation display unit 201. The CPU 211 also controls the operation display control unit 221 to enable the operation display unit 201 to display the status of the image processing device 200 and a function selection menu.
[0030] 4 is a diagram schematically showing an example of the configuration of the operation and display unit 201 of the image processing device 200. The operation and display unit 201 is composed of a plurality of buttons, a display, LEDs, and the like.
[0031] 4 shows an example in which a touch panel liquid crystal display (hereinafter referred to as "touch display") is used as the display of operation display unit 201. When power is supplied from power supply unit 209, image processing device 200 starts up when a user presses power button 222. When image processing device 200 starts up, a home screen (such as the home screen in FIG. 4) which is the highest level of menus that can be operated by the user is displayed on touch display 226.
[0032] The home screen includes a copy area 231 for receiving an instruction to execute a copy function, a scan area 232 for receiving an instruction to execute a scan function, and a fax area 233 for receiving an instruction to execute a fax function. The home screen also includes a network area 234 that transitions to a menu for changing network settings such as infrastructure connection or direct connection of the image processing device 200 and checking the status. The home screen also includes a setting area 235 that transitions to a menu for changing various other settings, updating firmware, and performing maintenance functions such as cleaning.
[0033] When a character string needs to be input by the user for password authentication or the like, a software keyboard can be displayed on the touch display 226 to accept the input. When a screen in a menu hierarchy other than the home screen is displayed, pressing the home button 223 allows the user to return to the home screen. Also, when a screen in a menu hierarchy other than the home screen is displayed, pressing the back button 224 allows the user to return to the screen in the next higher hierarchy. When various functions such as a copy function or a scan function are being executed and the timing is such that the process can be stopped, the process being executed can be stopped by pressing the stop button 225.
[0034] 5 is a block diagram conceptually illustrating an example of the software configuration for implementing the setting change and setting value import functions of the software operating on the image processing device 200. The processing executed for the setting value import function is referred to as the setting import process, or simply as the import process. The software elements and configuration shown in FIG. 5 are merely an example, and the elements and configuration are not limited to those shown in this diagram.
[0035] 5 realizes various functions in the image processing device 200 by having the CPU 211 execute a control program stored in the ROM 213 using part of the data stored in the associated RAM 214. The software group includes a communication program section 240 that mainly controls communications, an application program section 250 that mainly controls application functions, and a device control program section 260 that mainly controls the lower layers in the image processing device 200.
[0036] The communication program unit 240 includes a network communication control module 241 , a security module 242 , a USB communication control module 243 , a Web server module 244 , and a static content database 245 .
[0037] The network communication control module 241 is a module that controls the wireless LAN communication control unit 219 and is responsible for up to the transport layer of the communication protocol stack, and realizes TCP / IP communication of the image processing device 200 . The security module 242 is a module that handles encryption and decryption of communications, and the associated processes such as authentication and hashing, and realizes TLS / SSL communications of the image processing apparatus 200. The USB communication control module 243 is a module that controls the USB communication control unit 218 and performs operations to act as a USB device, and realizes USB communication of the image processing device 200 .
[0038] The Web server module 244 is a module that performs operations that allow the image processing device 200 to function as a Web server, and realizes HTTP communication with an external terminal device 300 running a Web browser. Specifically, the Web server module 244 analyzes HTTP requests received from the external terminal device 300, operates the WebUI control module 251 and static content database 245 according to the analysis results, and formats and transmits the generated data as an HTTP response. The Web server module 244 receives requests and transmits responses using TCP / IP communication, TLS / SSL communication, or USB communication.
[0039] The static content database 245 is a module that operates as a file system, and reads data such as JPEG data and HTML data stored in the ROM 213 or RAM 214 .
[0040] The application program unit 250 includes a Web UI control module 251, a device UI control module 252, and application modules exemplified by 253 to 256.
[0041] In response to a request from the Web server module 244, the WebUI control module 251 generates data for displaying the WebUI of the image processing device 200 on the Web browser of the external terminal device 300. The WebUI control module 251 acquires the operating status and setting status of the image processing device 200 from each application module and responds with the generated data, thereby displaying the operating status and setting status of the image processing device 200 on the WebUI. The WebUI displayed on the Web browser of the terminal device 300 is also configured to be able to instruct the image processing device 200 to change settings or perform password authentication, etc. When a user operates the Web browser and instructs the image processing device 200 to change settings or perform password authentication, etc., the image processing device 200 receives an HTTP request containing the instruction content. The WebUI control module 251 accepts the instruction via the Web server module 244 and causes the corresponding application module to perform processing, such as setting change or password authentication, in accordance with the instruction content. Upon completion of the processing, the WebUI control module 251 stores the processing result, such as success or failure, in an HTTP response and transmits it via the Web server module 244.
[0042] The device UI control module 252 realizes the UI of the image processing device 200 main body by controlling the operation display control unit 221. The device UI control module 252 stores menu hierarchy information and displays an operation menu or the like corresponding to the current menu hierarchy on the touch display 226. The device UI control module 252 can also acquire and shape the operating status and setting status of the image processing device 200 from each application module and display them on the touch display 226. Furthermore, the device UI control module 252 accepts operations such as setting changes and password authentication from the operation display unit 201 and causes the corresponding application module to perform processing in accordance with the operation. When the processing is completed, the device UI control module 252 displays the processing result, such as success or failure, on the touch display 226.
[0043] The security policy setting application 253 receives instructions from the Web UI control module 251 and the device UI control module 252, and acquires the security policy setting status and changes the security policy setting.
[0044] The NW setting application 254 receives instructions from the Web UI control module 251 and the device UI control module 252, and acquires the NW setting status and changes the NW setting. The address book setting application 255 receives instructions from the Web UI control module 251 and the device UI control module 252, and performs operations such as obtaining address book information (address setting data that constitutes the address book) including fax destination information, and adding or deleting new destination information to the address book information.
[0045] The setting value import / export application 256 receives instructions from the WebUI control module 251 and performs import and export processing of setting values, security policies, and address books of the image processing device 200. In this embodiment, they are each referred to as a different application, such as setting value import application 256a and setting value export application 256b. Note that in this embodiment, operations for importing and exporting setting values are performed only from the WebUI. This is because the export processing, which outputs setting values to an external device as an electronic file, and the import processing, which uses the electronic file as input, must be performed in the Web browser as download and upload, respectively.
[0046] The device control program section 260 includes a system control module 261 and a setting value storage module 262 . The system control module 261 is responsible for controlling the entire software system, such as starting and stopping the image processing device 200. In this embodiment, the system control module 261 receives a restart request from the security policy setting application 253 and performs restart processing for the image processing device 200.
[0047] The setting value saving module 262 operates to control saving of setting values of the image processing device 200, and upon receiving a setting value saving instruction from other modules such as each application module, writes the setting value to the NVRAM 215. Furthermore, the setting value saving module 262 reads out setting values from the NVRAM 215 upon receiving a setting value reference instruction from other modules such as each application module.
[0048] FIG. 6 is a diagram showing an example of setting item management information of the image processing apparatus according to this embodiment. In FIG. 6, the setting values of each setting item stored in the NVRAM 215 via the setting value storage module 262 and their management information are combined and shown as a part of setting item management information 400.
[0049] As shown in column 401, all setting items can be uniquely identified by an item ID, and setting values can be written or read by specifying an item ID. Column 402 shows the current setting value for each setting item.
[0050] Column 403 shows the factory default setting value for each setting item. When the setting reset function among the main body setting items is executed, each setting item targeted by the setting reset function is reset to the initial value, which is the factory default setting shown in column 403.
[0051] Column 404 shows the attributes of each setting item. The attributes of each setting item consist of the following three elements, and values indicating the setting value type (data type) for holding the setting value, the minimum setting value, and the maximum setting value are set. Of these setting value attributes, the setting value type is referenced when acquiring the setting value from internal memory when exporting it, and is also used as information constituting the data type of the tag to be output. Furthermore, of the setting value attributes, the minimum setting value and maximum setting value are values referenced to determine the consistency of the setting value when importing.
[0052] 6, the setting item management information 400 is shown in a table format, but the format in which this information is stored in the image processing device 200 is not limited to this. For example, it may be stored in a specific database format, or in a format such as JSON. Furthermore, only the setting values shown in column 402 may be stored in the RAM 214 or NVRAM 215, and other information may be represented as a program stored in the ROM 213 or as statically defined table data.
[0053] FIG. 7 is a diagram showing a schematic diagram of the dependency relationship between the security policy setting and other settings of the image processing apparatus according to this embodiment. 7 schematically shows part of the dependency relationship 410 between security policy settings and other settings, which is managed and controlled by the security policy setting application 253. The dependency relationship here means that the content of the setting value of the dependency source affects the content of the setting value of the dependency destination.
[0054] Column 411 indicates the setting item of the security policy setting that is the dependency source and the condition under which the dependency occurs. Column 412 indicates the setting item on which a dependency is made and how the setting value is forced when a dependency occurs.
[0055] For example, the security policy setting "Prohibit use of direct connection" indicated by item ID 10001 will affect the setting values of the dependent items if the setting value of that setting item is "ON", i.e. enabled. In that case, the setting value of "Direct connection setting" indicated by item ID 00001 will be forced to "OFF", and the setting value of "Automatic startup of easy connection" indicated by item ID 00002 will also be forced to "OFF", i.e. disabled.
[0056] For example, the security policy setting "Minimum Password Length" indicated by item ID 10007 will affect the dependent setting value if the setting value of that setting item is an integer between 1 and 32. In that case, the setting value of "Rule: Minimum Password Length" indicated by item ID 01005 will be forced to the same value as the value set in the security policy setting "Minimum Password Length."
[0057] For example, the security policy setting indicated by item ID 10012, "Allow sending only to addresses registered in the address book," affects the setting value of the dependent item when the setting value of that setting item is "ON," i.e., enabled. In that case, the setting value of "Allow adding new addresses," indicated by item ID 02001, is forced to "OFF," i.e., disabled, and furthermore, changes to the setting values of all address book information listed in the lines from item ID 02002 onwards are prohibited.
[0058] 7 shows the dependency relationships 410 between the security policy settings and other settings in a table format, but the format in which this information is stored in the image processing device 200 is not limited to this. For example, the information may be stored in a specific database format, in a format such as JSON, or expressed as a program stored in the ROM 213.
[0059] Next, a process for setting a security policy from the WebUI will be described with reference to Figures 8A, 8B, and 9. Hereinafter, Figures 8A and 8B will be collectively referred to as Figure 8. FIG. 8 is a diagram showing an example of a screen displayed by the web browser of the terminal device 300 when setting a security policy in this embodiment. Fig. 9 is a flowchart showing an example of security policy setting processing of the image processing device 200 in this embodiment. Each step shown in Fig. 9 is processed by the CPU 211 executing a program stored in the ROM 213. The processing shown in the flowchart in Fig. 9 starts when the Web server module 244 of the image processing device 200 receives an HTTP request (described below) from the Web browser of the terminal device 300.
[0060] 9, the Web server module 244 checks whether the received HTTP request is a security policy setting screen request. Whether it is a security policy setting screen display request is determined based on the requested URL and request parameters. If it is determined that it is not a security policy setting screen request (No in S601), the Web server module 244 ends the processing of this flowchart. Note that an actual image processing device can accept requests other than security policy setting screen requests, so it continues to check whether it is another acceptable request and process it, but this processing is omitted as it is outside the scope of this explanation.
[0061] On the other hand, if it is determined that the request is for a security policy setting screen (Yes in S601), the Web server module 244 requests the WebUI control module 251 to generate a security policy setting screen. In response to this request, the WebUI control module 251 executes the process of S602.
[0062] In S602, the WebUI control module 251 determines whether a security administrator password has been set. Specifically, the WebUI control module 251 acquires the setting value for the security administrator password from the NVRAM 215 via the security policy setting application 253 and the setting value storage module 262. If the acquired setting value is "ON," it is determined that a security administrator password has been set, and if it is "OFF," it is determined that a security administrator password has not been set.
[0063] If it is determined that a security administrator password has been set (Yes in S602), the WebUI control module 251 advances the process to S603. On the other hand, if it is determined that the security administrator password has not been set (No in S602), the WebUI control module 251 advances the process to S605.
[0064] In S603, the WebUI control module 251 generates a security administrator password authentication screen and returns the security administrator password authentication screen to the terminal device 300 via the Web server module 244.
[0065] FIG. 8A shows an example of a screen 510 that is displayed when the web browser of the terminal device 300 receives the security administrator password authentication screen in response from the image processing device 200. An input field 511 is for inputting a security administrator password, and an OK button 512 is a button for performing authentication using the security administrator password. When a user inputs a security administrator password into the input field 511 and presses the OK button 512, information about the input security administrator password is sent to the image processing device 200 by the web browser of the terminal device 300.
[0066] Hereafter, we return to the explanation of the flowchart in FIG. In S604, the WebUI control module 251 receives the HTTP request including the security administrator password information sent by the terminal device 300 via the Web server module 244, and authenticates the security administrator password. Specifically, the WebUI control module 251 compares the received security administrator password information with the "security administrator password value" stored in the NVRAM 215, and determines whether the authentication is successful or not based on whether they match.
[0067] If the received password does not match the stored password, the WebUI control module 251 determines that the security administrator password authentication has failed (No in S604), returns the process to S603, and controls the terminal device 300's web browser to once again display a security administrator password authentication screen and prompt the user to re-enter the password. On the other hand, if the received password matches the stored password, the WebUI control module 251 determines that the security administrator password authentication has been successful (Yes in S604), and proceeds to S605.
[0068] In S605, the WebUI control module 251 generates a security policy setting screen and returns the security policy setting screen to the terminal device 300 via the Web server module 244.
[0069] FIG. 8B shows an example of a screen 520 that is displayed when the web browser of the terminal device 300 receives the security policy setting screen returned by the image processing device 200. Area 523 displays various setting items related to the security policy along with check boxes, text boxes, etc. for enabling each setting. A user operating the web browser of terminal device 300 can change the security policy settings of image processing device 200 by operating the check boxes, text boxes, etc.
[0070] The cancel button 522 is a button for canceling the security policy setting. When the user presses the cancel button 522, an HTTP request is sent from the web browser requesting a menu screen one level higher than the security policy setting menu. The image processing device 200 then generates and responds with data for the requested screen, and the processing of the flowchart shown in FIG. 9 ends.
[0071] OK button 521 is a button for confirming changes to security policy settings. When the user presses OK button 521, a setting change list of security policy settings operated on screen 520 (hereinafter referred to as "setting change list") is temporarily saved in the web browser, and the screen transitions to the screen shown in Figure 8(c).
[0072] FIG. 8( c ) shows an example of a security policy setting execution confirmation screen 530 . Cancel button 532 is a button for canceling transmission of the setting change list. When the user presses cancel button 532, the web browser redisplays screen 520. At this time, the web browser reads out the setting change list that has been temporarily saved, and displays it with the list applied to the check boxes, text boxes, etc. in area 523.
[0073] The OK button 531 is a button for transmitting the setting change list. When the user presses the OK button 531, an HTTP request including the setting change list temporarily saved in the web browser is transmitted to the image processing device 200. Here, the setting change list is, for example, information such as a list of item ID values and post-change setting values for the items for rows included in the category "security policy settings" in column 401 in Fig. 6.
[0074] Hereafter, we return to the explanation of the flowchart in FIG. In S606, the WebUI control module 251 receives the HTTP request including the setting change list sent by the terminal device 300 via the Web server module 244, and starts processing to change the security policy settings. Here, the WebUI control module 251 generates response data indicating that the security policy setting processing is in progress.
[0075] Next, in S607, the WebUI control module 251 sends an HTTP response including response data indicating that the security policy setting process is in progress to the terminal device 300 via the Web server module 244. Furthermore, the WebUI control module 251 passes the received setting change list to the security policy setting application 253.
[0076] FIG. 8(d) shows an example of a screen 540 that is displayed by the web browser of the terminal device 300 after receiving response data from the image processing device 200 indicating that security policy setting processing is currently underway. The screen 540 operates not to accept any user operations, and periodically queries whether the security policy setting process has been completed in the background processing of the web browser, and if completed, operates to display the top screen of the WebUI of the image processing device 200 (not shown).
[0077] Hereafter, we return to the explanation of the flowchart in FIG. The security policy setting application 253, which has received the setting change list from the WebUI control module 251, executes the repeated process shown in S608 to S611. This repeated process is repeated for the received setting change list until the entire list has been processed.
[0078] In the repeated processing, first in S609, the security policy setting application 253 acquires a set of combinations of item IDs and setting values that have not been processed in the repeated processing from the setting change list. Then, the security policy setting application 253 stores the acquired set of setting changes in the NVRAM 215 via the setting value storage module 262. Here, since the setting values are stored based on the item IDs, it is possible to update the specified items in the security policy settings.
[0079] Next, in S610, the security policy setting application 253 performs a setting value restriction process based on the dependency relationship 410 between the security policy setting and other settings, as shown in Figure 7. Specifically, with reference to Figure 7, the application checks column 411 for a row that matches the item ID of the security policy setting that was just saved, and checks whether the saved setting value matches the "setting value when imposing restrictions on other restricted items." If they match, the application enforces the setting value for the dependent setting item, as shown in column 412. For example, if the acquired set of setting changes is "item ID 10001, ON," the application saves "OFF" as the setting value for item ID 00001 and "OFF" as the setting value for item ID 00002 in the NVRAM 215 via the setting value save module 262.
[0080] Next, in S611, if there are any unprocessed pairs remaining in the setting change list, the security policy setting application 253 returns to S608, and if processing has been completed for all pairs in the setting change list, the security policy setting application 253 proceeds to S612. In S612, the security policy setting application 253 requests the system control module 261 to reboot the image processing device 200. In response to the request, the system control module 261 executes the reboot process, and the process of this flowchart ends.
[0081] FIG. 10 is a diagram showing an example of a setting screen for setting items whose setting changes are restricted by a security policy in this embodiment. 10 shows a screen flow when attempting to operate and display RAW print settings as an example of how security policy settings limit UI operations of the image processing device 200. Note that the screen flow shown in Fig. 10 is processed by the CPU 211 executing a program stored in the ROM 213, and is mainly controlled by the device UI control module 252.
[0082] Screen 701 is a network setting menu screen that is displayed when area 234 is touched while the home screen (FIG. 2) is displayed on the touch display 226 of the image processing device 200. Touching "Network Detail Settings" on this screen transitions to screen 702.
[0083] Next, when “RAW print settings” is touched on the screen 702 , the process proceeds to decision 703 . In decision 703, the device UI control module 252 acquires the setting value of security policy setting item ID 10004 "Restrict RAW ports" to determine whether it is "OFF", i.e., disabled, via the security policy setting application 253. If the acquired value is "ON", i.e., enabled (NO in 703), the screen transitions to screen 704. A screen 704 notifies the user that changing the RAW print settings is restricted by security policy settings, and when the OK button is pressed, the screen returns to the screen 702.
[0084] On the other hand, if it is "OFF", that is, disabled (YES in 703), the screen transitions to screen 705. Screen 705 displays options for RAW print settings, and in this example screen, touching either "Enable" or "Disable" transitions to screen 706.
[0085] A screen 706 is displayed to notify the user that the setting change is being processed, and the setting change of the image processing device 200 is carried out. For example, when "Enabled" is touched on the screen 705, the device UI control module 252 changes the setting value of item ID 00009 "RAW print setting" to "ON" via the NW setting application 254 and the setting value saving module 262. On the other hand, when "Disable" is touched on the screen 705, the device UI control module 252 similarly changes the setting value of item ID 00009 "RAW print setting" to "OFF." When the setting change process of the image processing device 200 is completed, the screen transitions to a screen 707, which notifies the user of the completion of the setting change. When the OK button on this screen 707 is pressed, the screen returns to the screen 702.
[0086] 10 shows a case where the settings are changed by operating the UI of the image processing device 200 itself, but the method of changing the settings is not limited to this. For example, the settings may be changed by a Web UI, and in this case, the same setting change procedure and setting change restrictions as those in the screen flow described in FIG. 10 can be implemented.
[0087] Next, a process for exporting setting values from the WebUI will be described with reference to Figures 11A, 11B, and 12. Hereinafter, Figures 11A and 11B will be collectively referred to as Figure 11. In this embodiment, a use case will be described in which a file exported by image processing device 200 is imported back into the same device, and as an example, it will be assumed that all device settings are backed up for manufacturer repair and then restored after the repair. Here, "backup" refers to the exporting of setting values, and "restore" refers to the importing of exported setting values to restore the original state.
[0088] FIG. 11 is a diagram showing an example of a screen displayed by the web browser of the terminal device 300 when exporting setting values in this embodiment. Fig. 12 is a flowchart showing an example of a setting value export process of the image processing device 200 in this embodiment. Note that the part surrounded by a dashed line in Fig. 12 represents the process in the terminal device 300. Each step of the image processing device 200 shown in Fig. 12 is processed by the CPU 211 executing a program stored in the ROM 213. Also, each step of the terminal device 300 is processed by the CPU executing a program stored in a storage device such as an SSD (not shown) of the terminal device 300.
[0089] The process of the flowchart shown in FIG. 12 starts when the Web server module 244 of the image processing device 200 receives an HTTP request, which will be described later, from the Web browser of the terminal device 300.
[0090] In S901, the Web server module 244 determines whether the received HTTP request is a setting value export screen request, and if it is determined that it is not a setting value export screen request (No in S901), the Web server module 244 ends the processing of this flowchart. Note that, since an actual image processing apparatus can accept requests other than a setting value export screen request, it continues to check whether it is another acceptable request and processes it, but this processing is omitted as it is outside the scope of this explanation. On the other hand, if it is determined that the request is for a setting value export screen (Yes in S901), the Web server module 244 requests the WebUI control module 251 to generate a setting value export screen. In response to this request, the WebUI control module 251 executes the process of S902.
[0091] In S902, the WebUI control module 251 generates a setting value export screen and responds with the setting value export screen to the terminal device 300 via the Web server module 244.
[0092] FIG. 11A shows an example of a screen 810 that is displayed when the web browser of the terminal device 300 receives the setting value export screen returned by the image processing device 200. An OK button 816 is a button for instructing the execution of export of setting values. When the user presses the OK button 816, the password character string (described later) set on screen 810 and the setting type to be exported are temporarily saved in the Web browser, and the subsequent processes for determining whether the input contents are correct are performed before transitioning to the screen shown in Fig. 11(b) (S903 to S906 in Fig. 12).
[0093] Input fields 811 and 812 are used to enter a password character string for encrypting the file contents when exporting setting values, and also for entering a password character string required for decrypting the file contents with the password entered at the time of export when importing. The password entered by the user must be entered twice for confirmation. The process for determining whether the contents entered in input fields 811 and 812 are correct is as follows: If the password confirmation character string entered in input field 812 does not match the password entered in input field 811, a screen (not shown) is generated to prompt the user to confirm the password, and the user is notified. This part is the determination process shown in S903 of FIG. 12, and the screen notifying the user (the password confirmation screen (not shown)) described above is displayed in S904.
[0094] Next, check boxes 813 to 815 are controls for allowing the user to select the type of setting value to be exported. Check box 813 is for selecting a setting value from a group of setting items that affect at least one operation of the image processing device 200 as the type of setting value to be exported. Check box 814 is for selecting a setting value for a security policy setting as the type of setting value to be exported. Check box 815 is for selecting a setting value from an address book that is not included in the setting item of check box 813 as the type of setting value to be exported. At least one of these check boxes must be selected. The process for determining whether the contents entered in check boxes 813 to 815 are correct is as follows: If no selection is made, a screen (not shown) prompting the user to make a selection is generated and a notification is given to the user. This part is the determination process shown in S905 of FIG. 12, and if the determination is No, the process for displaying a screen (not shown) prompting the user to make a selection) to notify the user is performed in S906.
[0095] The password entered by the user and the type of setting value checked are temporarily saved in the web browser, and when the OK button 816 is pressed, it is determined whether the entered content is correct (S903 to S905). If the entered content is correct (Yes in S903 and Yes in S905), the entered content (password, type of setting value to export) is sent to the image processing device 200 together with an HTTP request.
[0096] Hereafter, we return to the explanation of the flowchart in FIG. In S907, the WebUI control module 251 receives (accepts) an HTTP request (including a password and the type of setting value to be exported) from the terminal device 300 via the Web server module 244. Next, in S908, the WebUI control module 251 starts the setting value export process based on the password and the type of setting value to be exported received in S907 above, and at the same time generates and responds with a screen 820 indicating that the setting value export process is in progress. Note that the WebUI control module 251 passes the password and the type of setting value to be exported included in the HTTP request received from the terminal device 300 in S907 above to the setting value export application 256b, causing the setting value export process to be executed.
[0097] FIG. 11B shows an example of a screen 820 that is displayed by the web browser of the terminal device 300 after receiving the screen that indicates that the setting value export process is in progress, as a response from the image processing device 200. 9, the screen 820 displayed in response in S908 does not accept any user operations, and periodically queries whether the setting value export process has been completed in the background of the Web browser. When the setting value export process is completed, the WebUI control module 251 generates and responds with response data indicating that the setting value export process has been completed via the Web server module 244 (S916, described below). When this response data is received, the Web browser transitions to screen 830 shown in FIG. 11(c).
[0098] FIG. 11C shows an example of a screen 830 displayed by the web browser of the terminal device 300 after receiving response data from the image processing device 200 indicating that the setting value export process has been completed.
[0099] Here, the web browser of the terminal device 300 transmits to the image processing device 200 a download request for a file into which the setting values generated by the setting value export application 256b of the image processing device 200 have been exported. The image processing device 200 returns an HTTP response in response to the download request via the web server module 244. At this time, when the exported file is downloaded, a download selection dialog box 832 is displayed that allows the user to select how to handle the downloaded file, similar to normal file downloads via a web browser, and the system waits for user input.
[0100] In this state, in this embodiment, when the user presses the Save As button 834, the terminal device 300 saves the downloaded file in the storage device (not shown) of the terminal device 300 with the desired file name specified on the file selection screen such as that shown in Figure 11(d).
[0101] 11(d) shows an example of a general-purpose selection screen 840 that is displayed when a downloaded file is "save as." On the general-purpose selection screen 840, the location where the file is to be saved is specified, and a file name is selected or entered in an input field 841, and then the file is saved by pressing a save button 842.
[0102] Returning to the explanation of the flowchart in FIG. In S909, the setting value export application 256b references the type of setting value to be exported passed from the WebUI control module 251, and determines whether a setting item is included.
[0103] If it is determined that the setting item is included (Yes in S909), the setting value export application 256b advances the process to S910. On the other hand, if it is determined that the setting item is not included (No in S909), the setting value export application 256b proceeds to the next step S911 for determining the export type.
[0104] In S910, the setting value export application 256b executes a setting item export process. In this setting item export process, the setting value export application 256b loads into the RAM 214 a list of setting values to be exported from among the currently set setting values held in the NVRAM 215 via the setting value storage module 262. Next, the setting value export application 256b converts the list of setting values generated in the RAM 214 into XML format and outputs it to a temporary buffer for file output also loaded in the RAM 214. When the export type is a setting item, an example of a tag, which is an intermediate item in the XML, is <devicesettings>It is configured so that it can be identified with XML tags from other export types, such as:
[0105] In this embodiment, the data to be exported is in XML format, but other data formats are also acceptable. For example, comma-separated values (CSV), JSON, or a proprietary binary format that maps structured data directly to memory are also acceptable. The setting value export application 256b stores the information stored in the NVRAM 215 described above in the setting item management information 400, and adds information such as attributes associated with the setting values to the data to be exported along with the setting values. This information includes the data type, which indicates the size and type of the value data for each setting item, or the number of arrays (if an array), the maximum and minimum values of the data, and may also include a level value that specifies the maximum number of device revisions allowed during import. The setting value export application 256b sets information to be exported across all devices at the beginning of the export process. These values include, for example, the device type, a serial number for identifying the individual device, and the version information of the firmware running on the device. Placing this information in the upper part of the XML allows it to be analyzed early during import, enabling the import process of each setting value to be controlled. Here is an example of an identification tag in XML format for information that should be exported across all devices: <deviceinformation>and so on, so that it can be distinguished from other types.
[0106] Next, once the export of the setting items is complete and the data in XML format is completed, the setting value export application 256b proceeds to step S911, which is the next step for determining the type of export.
[0107] In S911, the setting value export application 256b refers to the type of setting value to be exported passed from the WebUI control module 251, and determines whether a security policy is included.
[0108] If it is determined that a security policy is included (Yes in S911), the setting value export application 256b proceeds to S912. On the other hand, if it is determined that a security policy is not included (No in S911), the setting value export application 256b proceeds to the next step of determining the export type, S913.
[0109] In S912, the setting value export application 256b executes security policy export processing. In this security policy export processing, the setting value export application 256b loads and generates a list of valid security policies stored in the NVRAM 215 into the RAM 214 via the setting value storage module 262. Security policy updates are controlled by the security policy setting application 253, and the latest state is always managed to be stored in the setting value storage module 262. If export of setting items is executed immediately before in S910, output data exists in XML format in the temporary buffer for file output loaded in the RAM 214, but if export of setting items is not executed, the output data will be XML data containing only an identification tag common to the device. In either case, in the security policy export processing, as with the setting items, XML is generated while constructing tags to be exported based on each piece of information in the setting item management information 400, and the XML is concatenated with the character string data stored in the temporary buffer. Here, when the export type is security policy, an example of a tag, which is an intermediate item in the XML, is <securitypolicysettings>and so that it can be distinguished from other export types using XML tags.
[0110] Next, once the export of the security policy is completed and the data in XML format is completed, the setting value export application 256b proceeds to step S913, which is the next step for determining the type of export.
[0111] In S913, the setting value export application 256b refers to the setting type to be exported passed from the WebUI control module 251, and determines whether the address book is included.
[0112] If it is determined that the address book is included (Yes in S913), the setting value export application 256b advances the process to S914. On the other hand, if it is determined that the address book is not included (No in S913), the setting value export application 256b advances the process to S915.
[0113] In S914, the setting value export application 256b executes an address book export process. In this address book export process, the setting value export application 256b loads and generates an address book list stored in the NVRAM 215 into the RAM 214 via the setting value storage module 262. The address book is managed so that updates are controlled by the address book setting application 255 and the latest state is always stored in the setting value storage module 262. The address book stores standard information such as the registrant's name, organization name, telephone number, and email address as character strings as configuration information, and is generated by calling a module that acquires this information from the address book setting application 255, which manages this information holistically. Specifically, the setting value storage module 262 acquires individual IDs stored in the address book, and the acquired IDs are acquired by a detailed information acquisition module provided by the address book setting application 255, thereby generating XML format data. The generated XML format address data for one entry is sequentially concatenated with existing XML string data stored in a temporary buffer to finally configure all addresses. If the export type is an address book, the following is an example of a tag that is a sub-item of the XML: <addressbook>and so that it can be distinguished from other export types using XML tags.
[0114] When the export process for all of the settings selected as the settings types to be exported among the above three export types has been completed, the setting value export application 256b proceeds to S915.
[0115] In step S915, the setting value export application 256b concatenates closing tags to complete the XML data stored in the temporary file output buffer expanded in RAM 214, and encrypts the data with a password. In this embodiment, the XML data file is exported as a password-protected compressed ZIP file, but the method is not limited to this. For example, instead of the ZIP format, a third-party encryption library may be used, or AES encryption using OpenSSL may be performed on the portion of the XML data that will become a value, rather than archiving the entire file with a password.
[0116] When the process of S915 is completed, the setting value export application 256b notifies the WebUI control module 251 of the completion of the export process. In response to this, the WebUI control module 251 executes the process of S916. In S916, the WebUI control module 251 issues an event to the Web server module 244 instructing the completion of export in response to the periodic processing completion request from the terminal device 300. The Web server module 244 forms data indicating the completion of export as an HTTP response and responds. The terminal device 300 receives the HTTP data indicating the completion of export and displays an image 830 shown in FIG. 11(c) on the Web browser.
[0117] Next, in S917, the WebUI control module 251 receives a download request for the exported file accompanying the completion of the setting value export process from the terminal device 300 via the Web server module 244. Here, the file name to be downloaded is fixed, and in this embodiment, it is set to, for example, "devieSettings.bin."
[0118] Next, in S918, the WebUI control module 251 transmits the exported file (for example, "devieSettings.bin") to the Web browser of the terminal device 300 via the Web server module 244 in response to the download request for the exported file received in S917 above. As a result, a download selection dialog box 832 is displayed on the Web browser of the terminal device 300. Here, when the user presses the Save As button 834, specifies a file name on the file selection screen of FIG. 11(d), and presses Save 842, the exported file is saved in a storage device (not shown) of the terminal device 300 with the desired file name. As described above, the setting values can be exported.
[0119] Next, the process for importing setting values from the WebUI will be described with reference to Figures 13A to 13C and 14. Hereinafter, Figures 13A to 13C will be collectively referred to as Figure 13. FIG. 13 is a diagram showing an example of a screen displayed by the web browser of the terminal device 300 when importing setting values in this embodiment. Fig. 14 is a flowchart showing an example of setting value import processing of the image processing device 200 in this embodiment. Note that the part partially surrounded by a dashed line in Fig. 14 represents processing in the terminal device 300. Each step of the image processing device 200 shown in Fig. 14 is processed by the CPU 211 executing a program stored in the ROM 213. Also, each step of the terminal device 300 is processed by the CPU executing a program stored in a storage device such as an SSD (not shown) of the terminal device 300.
[0120] The process of the flowchart shown in FIG. 14 starts when the Web server module 244 of the image processing device 200 receives an HTTP request, which will be described later, from the Web browser of the terminal device 300.
[0121] In S1101, the Web server module 244 determines whether the received HTTP request is a setting value import screen request, and if it is not a setting value import screen request (No in S1101), the Web server module 244 ends the processing of this flowchart. Note that an actual image processing apparatus can accept requests other than a setting value import screen request, so it continues to check whether it is another acceptable request and processes it, but this processing is omitted as it is outside the scope of this explanation. On the other hand, if it is determined that the request is a setting value import screen request (Yes in S901), the Web server module 244 requests the WebUI control module 251 to generate a setting value import screen. In response to this request, the WebUI control module 251 executes the process of S1102.
[0122] In S1102, the WebUI control module 251 generates a setting value import screen and responds with the setting value import screen to the terminal device 300 via the Web server module 244.
[0123] FIG. 13A shows an example of a screen 1110 that is displayed by the web browser of the terminal device 300 after receiving the setting value import screen returned by the image processing device 200. An OK button 1016 is a button for issuing an instruction to execute import of setting values. When the user presses the OK button 1016, the file path to be imported, password, and setting type to be imported, which are set on the screen 1010 and will be described later, are temporarily saved in the Web browser, and the subsequent processing is performed to determine whether the input contents are correct before transitioning to the screen shown in FIG. 13(c) (S1103 to S1106 in FIG. 14).
[0124] An input field 1011 is used to specify a file to be imported and to input a file path including the file name. A file name including the specified file path is input using a selection screen 1020 for opening a general-purpose file shown in FIG. 13(b). In this embodiment, pressing the "..." button 1017 on or to the right of the input field 1011 displays the selection screen 1020 shown in FIG. 13(b). After specifying a file name in the input field 1021, the user presses the "Open" button 1022 to select the file. If the selected file cannot be opened when the user presses the OK button 1016, a "No" determination is made in S1103 of FIG. 14, and a screen (not shown) is generated in S1104 to prompt the user to confirm the file, and a notification is issued. The file to be imported specified here is, for example, a file exported in the export process shown in FIG. 12, and includes a set of setting values to be imported.
[0125] An input field 1012 is used to input a password string required to decrypt an encrypted file when importing setting values.
[0126] Check boxes 1013 to 1015 are controls for allowing the user to select the type of setting value to be imported. At least one of these check boxes must be selected, and if no selection is made, a screen (not shown) is generated to prompt the user to make a selection and notify the user. This part is the determination process shown in S1105 of Fig. 14, and if the determination is No, the process of displaying a screen (not shown) to notify the user (a screen (not shown) to prompt the user to make a selection) is performed in S1106.
[0127] The password entered by the user and the checked setting value types are temporarily saved in the web browser, and when the OK button 1016 is pressed, these are sent together with an HTTP request to the image processing device 200. In addition, the specified file to be imported is read into a temporarily reserved memory area and similarly sent to the image processing device 200 as binary format data.
[0128] Hereafter, we return to the explanation of the flowchart in FIG. In S1107, the WebUI control module 251 receives (accepts) the HTTP request (including the file data, password, and type of setting value to be exported) from the terminal device 300 via the Web server module 244. Next, in S1108, the WebUI control module 251 starts the setting value import process based on the file data, password, and import type received in S1107 above, and at the same time generates and responds with a screen 1030 indicating that the setting value import process is in progress. Note that the WebUI control module 251 passes the file data, password, and import type included in the HTTP request received from the terminal device 300 in S1107 above to the setting value import application 256a, causing the setting value import process to be executed.
[0129] FIG. 13C shows an example of a screen 1030 that is displayed by the web browser of the terminal device 300 after receiving the screen that indicates that the setting value import process is in progress, as a response from the image processing device 200. The screen 1030 displayed in response in S1108 of Fig. 12 operates so as not to accept user operations, and periodically queries whether the setting value import process has been completed in the background of the Web browser. When the setting value import process is completed, the WebUI control module 251 generates and responds with response data indicating that the setting value import process has been completed (S1121, described later). When this response data is received, the Web browser transitions to screen 1040 shown in Fig. 13(d). However, if the import process of only the address book has been completed, the image processing apparatus 200 does not need to be restarted, and therefore returns to the previous screen (not shown) displaying Fig. 13(a).
[0130] 13(d) shows an example of a screen 1140 that is displayed by the web browser of the terminal device 300 after receiving response data indicating that the setting value import process has been completed, as responded by the image processing device 200. The screen 1140 notifies the user that the setting value import process has been completed and that the image processing device 200 is being restarted.
[0131] Hereafter, we return to the explanation of the flowchart in FIG. In S1109, the setting value import application 256a expands the file image received from the terminal device 300 together with the HTTP request in S1107 into the RAM 214 (for example, in ZIP format), and decrypts it in the API module using the password that was also received.
[0132] Next, in S1110, if the setting value import application 256a fails to decrypt the data on the RAM 214 that has been expanded in the ZIP format using the password (No in S1110), the process proceeds to S1111. In S1111, the setting value import application 256a requests the WebUI control module 251 to generate a screen (not shown) notifying the user of password confirmation, and controls the module 251 to return to screen 1010 of FIG. 13(a) and prompt the user to re-enter the password.
[0133] On the other hand, if decryption using the password is successful (Yes in S1110), the setting value import application 256a advances the process to S1112.
[0134] In S1112, the setting value import application 256a refers to the type of the setting value to be imported passed from the WebUI control module 251, and determines whether the setting item is included.
[0135] If it is determined that the setting item is included (Yes in S1112), the setting value import application 256a advances the process to S1113. On the other hand, if it is determined that the setting item is not included (No in S1112), the setting value import application 256a proceeds to S1114, which is the next step for determining the import type.
[0136] In S1113, the setting value import application 256a executes the import process of the setting items. In this import process of the setting items, the setting value import application 256a first analyzes the device-wide information configured at the time of export from the decrypted XML format file, and sets it in the array memory secured in the RAM 214 as device-wide information. This process is performed only once before processing the type to be imported. For example, if the target of import is not the setting items but the security policy, this process is performed before the import process of the security policy. Next, in the import of the setting items, the setting value import application 256a reads the tag of the middle item of the decrypted XML, <devicesettings>These are identified by XML analysis processing and set one by one in an array secured in RAM 214 as a storage area for setting items. At this time, the setting value import application 256a references information common to the device, and sets the setting values in the array while checking the allowable level for importing and the validity of the setting values by referring to the setting value data table described above. Next, the setting value import application 256a passes the array held in RAM 214 in which all setting items have been set to an API provided by the setting value storage module 262, which stores the array in NVRAM 215.
[0137] Next, in step S1114, the setting value import application 256a refers to the type of the setting value to be imported passed from the WebUI control module 251, and determines whether a security policy is included.
[0138] If it is determined that a security policy is included (Yes in S1114), the setting value import application 256a advances the process to S1115. On the other hand, if it is determined that a security policy is not included (No in S1114), the setting value import application 256a proceeds to S1116.
[0139] In S1115, the setting value import application 256a executes a security policy import process. In this security policy import process, the setting value import application 256a imports the security policy from the middle item tag of the decrypted XML. <securitypolicysettings>The setting value import application 256a identifies the security policy items through XML analysis and sets them one by one in an array secured in RAM 214 as a security policy storage area. At this time, the setting value import application 256a references device-wide information, the tolerance level for importing, and the setting value data table described above to confirm the validity of the setting values while setting them in the array. Next, the setting value import application 256a calls the security policy setting item check module of the security policy setting application 253 by specifying the array in RAM 214, thereby checking whether the imported items deviate from the security policy setting values. If any of the imported security policy items deviate, the security policy setting application 253 overwrites the corresponding item in RAM 214 with the closest value that does not deviate. Through this process, the imported security policy items become values that can be stored in the device, and are passed from the security policy setting application 253 to the setting value storage module 262 and stored in NVRAM 215. However, at this point, the imported security policy may not yet be reflected in the setting items of the image processing device 200, resulting in an incomplete and inconsistent state. Next, the process proceeds to S1116 to execute processing to correct this condition.
[0140] In S1116, the setting value import application 256a determines whether either a setting item or a security policy is included by referring to the setting type to be imported passed from the WebUI control module 251. If neither is included (No in S1116), that is, if only an address book is to be imported, the setting value import application 256a proceeds to S1118, where it determines whether to import an address book. On the other hand, if either of them is included (Yes in S1116), the setting value import application 256a proceeds to the process of S1117.
[0141] In S1117, the setting value import application 256a executes processing to apply the security policy. In the processing to apply the security policy, the setting value import application 256a calls a module that reflects the security policy provided by the security policy setting application 253 in the setting items. Then, the values of the currently valid security policy items managed by the security policy setting application 253 are saved in the NVRAM 215 via the setting value saving module 262. In other words, the values saved here overwrite the values of the setting items that depend on the currently valid security policy among the imported values. Note that for the setting items that depend on a specific security policy item, see the explanation of FIG. 7. The processing of S1117 is a processing that must be performed whenever at least one of the import processing of S1113 and S1115 is executed. The processing of S1117 does not perform a comparison or conditional determination between the value of the setting item and the value that conforms to the security policy, but instead forcibly overwrites the value, thereby suppressing an increase in the processing load within the device and enabling the security policy to be applied in a short time.
[0142] Next, in S1118, the setting value import application 256a refers to the type of setting values to be imported passed from the WebUI control module 251, and determines whether an address book is included.
[0143] If it is determined that the address book is included (Yes in S1118), the setting value import application 256a advances the process to S1119. On the other hand, if it is determined that the address book is not included (No in S1118), the setting value import application 256a advances the process to S1120.
[0144] In S1119, the setting value import application 256a executes the address book import process. In this address book import process, the setting value import application 256a first checks the security policy that was applied immediately before and determines whether or not the import can be executed. Specifically, when the setting value of the security policy setting "Allow sending only to destinations registered in the address book" indicated by item ID 10012 in FIG. 7 is "ON", that is, enabled, the following setting values are affected. First, item ID 02001 "Allow adding new addresses" is restricted to "OFF", and then changes to the address book information described in the lines from item ID 02002 onwards are prohibited, so that the import of the address book is effectively restricted. If the import of the address book is restricted by the security policy, the setting value import application 256a terminates the address book import process without importing the address book. On the other hand, if the import of the address book is not restricted by the security policy, the setting value import application 256a imports the address book. In the address book import, the setting value import application 256a uses the middle item tag of the decrypted XML <addressbook>are identified by XML analysis processing and set one entry at a time in an array secured as an address book storage area in RAM 214. Unlike other setting values, the address book is not associated information, but is expanded in memory by securing and linking data blocks each time, each having a structure for storing standard configuration information such as the registrant's name, organization name, telephone number, and email address. The constructed address book data block is passed to an import module provided by the address book setting application 255, and the new address book imported after initializing the existing address book is saved in NVRAM 215 via the setting value saving module 262.
[0145] When the address book import process is completed, the setting value import application 256a proceeds to S1120. In S1120, the setting value import application 256a determines whether to restart the device. This determination is the same as the determination in S1116, that is, whether the setting type to be imported includes either a setting item or a security policy. If neither is included (i.e., if only the address book was imported), the setting value import application 256a determines No in S1120 and proceeds to S1121 without restarting the device.
[0146] In S1121, the setting value import application 256a notifies the WebUI control module 251 that the import process has been completed. In response to this, the WebUI control module 251 generates an import completion screen 1050 and returns the import completion screen to the terminal device 300 via the Web server module 244. 13(e) shows an example of a screen 1050 indicating the import completion screen returned by the image processing device 200. When the user presses the OK button 1051, the import process ends, and the process of the flowchart shown in FIG.
[0147] On the other hand, if the type of settings to be imported includes either a setting item or a security policy (Yes in S1120), the setting value import application 256a advances the process to S1122. In S1122, the setting value import application 256a issues an event requesting a reboot to the system control module 261, and reboots the device.
[0148] 13(d) shows an example of a screen 1040 that is displayed by the web browser of the terminal device 300 after receiving response data from the image processing device 200 indicating that the device is restarting following the completion of the import. Screen 1040 operates so as not to accept any user operations. The web browser then periodically queries in the background whether device startup has been completed, and if startup has been completed, the top screen of the WebUI of the image processing device 200 is displayed, indicating that the import process is complete.
[0149] In the above description, the items to be exported / imported are setting items, security policies, and address books. However, these items may also include user account data. The import process for user account data is similar to the import process for an address book. Specifically, the setting value import application 256a references the type of setting values to be imported passed from the WebUI control module 251 and determines whether user account data is included. If it is determined that user account data is included, the setting value import application 256a executes the import process for the user account data. In this user account import process, the setting value import application 256a first checks the security policy that was previously applied and determines whether the import can be performed. Specifically, if the security policy settings include a specific security policy setting (a security policy setting that restricts the settings of a user account), the setting value import application 256a terminates the import process for the user account data without importing the user account data. On the other hand, if the security policy settings do not include a specific security policy setting, the setting value import application 256a controls the import of user account data.
[0150] As described above, after the process of overwriting the setting items (and security policy setting values) with the imported values is performed, the setting items are further overwritten with the security policy setting values. Regarding the address book, the security policy is checked, and if the security policy restricts the import of the address book, the address book is not imported. This allows the setting value restrictions imposed by the security policy to be maintained during the setting value import process. Furthermore, compared to the conventional configuration, which checks whether all setting items in the device are restricted by the security policy, the number of comparisons and checks is reduced, thereby minimizing the increase in processing load due to the number of setting items and shortening the user's waiting time. In other words, compared to the conventional configuration, the processing load due to the number of setting items can be reduced and setting values can be imported in a short time so that the security policy restrictions are maintained, thereby significantly improving usability. For example, even if all device settings are exported for repairs and then imported after the repairs, the process can be completed in a short time, significantly reducing the burden on administrators involved in device maintenance and management compared to the conventional configuration.
[0151] It goes without saying that the configurations and contents of the various data described above are not limited to those described above, and that the data may be configured in various configurations and contents depending on the application and purpose. Although one embodiment has been described above, the present invention can be embodied as, for example, a system, an apparatus, a method, a program, a storage medium, etc. Specifically, the present invention may be applied to a system made up of multiple devices, or may be applied to an apparatus made up of a single device. Furthermore, the present invention also includes any combination of the above embodiments.
[0152] Other Embodiments The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions. Furthermore, the present invention may be applied to a system made up of multiple devices, or to an apparatus made up of a single device. The present invention is not limited to the above-described embodiments, and various modifications (including organic combinations of the embodiments) are possible based on the spirit of the present invention, and these modifications are not excluded from the scope of the present invention. In other words, all configurations that combine the above-described embodiments and their modifications are included in the present invention.
[0153] The disclosure of this embodiment includes the following configuration, method, and program. (Configuration 1) An information processing device including a nonvolatile memory, a first management means for managing security policy settings; a second management means for managing setting values of a group of setting items that affect at least one operation of the information processing device; a receiving means for receiving a group of setting values to be imported; a control means for controlling the import processing of the setting values; The nonvolatile memory stores operation settings of the information processing device, the control means controls the import process to perform, as a series of processes, a first process of saving at least a portion of the group of setting values received by the receiving means as the operation settings held in the non-volatile memory, and, after the first process, a second process of overwriting and saving the setting values managed by the second management means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means. (Configuration 2) The information processing device described in configuration 1, characterized in that, if the security policy setting is included in the group of setting values accepted by the accepting means, in the first processing, the control means stores at least the security policy setting accepted by the accepting means as the operational setting held in the non-volatile memory. (Configuration 3) a third management means for managing address setting data that constitutes an address book and that is not included in the setting items managed by the second management means; The information processing device according to configuration 2, wherein the control means, when the address setting data is included in the group of setting values accepted by the accepting means, performs a third process in a series of processes in the import process after the first process, which determines whether a specific security policy is set in the security policy settings managed by the first management means, and when the specific security policy is set, does not save the accepted address setting data as the operation setting to be held in the non-volatile memory, and when the specific security policy is not set, saves the accepted address setting data as the operation setting to be held in the non-volatile memory. (Configuration 4) a fourth management means for managing user account data that is not included in the setting items managed by the second management means; The information processing device according to configuration 2, wherein the control means, when the user account data is included in the group of setting values accepted by the accepting means, performs a fourth process in a series of processes in the import process after the first process, in which it determines whether a specific security policy is set in the security policy settings managed by the first management means, and when the specific security policy is set, it does not save the accepted user account data as the operation setting to be held in the non-volatile memory, and when the specific security policy is not set, it saves the accepted user account data as the operation setting to be held in the non-volatile memory. (Method 1) A method for controlling an information processing device including a nonvolatile memory, a first management means for managing security policy settings, and a second management means for managing setting values of a group of setting items that affect at least one or more operations of the device, a receiving step of receiving a group of setting values to be imported; a control step of controlling the import processing of the setting values, The nonvolatile memory stores operation settings of the information processing device, a control method for an information processing device, characterized in that the control step controls to perform, as a series of processes in the import process, a first process of saving at least a part of the group of setting values accepted by the accepting means as the operation settings held in the non-volatile memory, and a second process of overwriting and saving, after the first process, the setting values managed by the second managing means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first managing means. (Program 1) An information processing device comprising: a nonvolatile memory; a first management means for managing security policy settings; and a second management means for managing setting values of a group of setting items that affect at least one or more operations of the information processing device; a receiving means for receiving a group of setting values to be imported; A program that functions as a control means for controlling the import process of setting values, The nonvolatile memory stores operation settings of the information processing device, The program is characterized in that the control means controls the import process to perform, as a series of processes, a first process of saving at least a portion of the group of setting values accepted by the accepting means as the operation settings held in the non-volatile memory, and, after the first process, a second process of overwriting and saving the setting values managed by the second management means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means.< / addressbook> < / securitypolicysettings> < / devicesettings> < / addressbook> < / securitypolicysettings> < / deviceinformation> < / devicesettings>
Claims
1. An information processing device including a nonvolatile memory, a first management means for managing security policy settings; a second management means for managing setting values of a group of setting items that affect at least one operation of the information processing device; a receiving means for receiving a group of setting values to be imported; a control means for controlling the import processing of the setting values; The nonvolatile memory stores operation settings of the information processing device, The information processing device is characterized in that the control means controls the import processing to perform, as a series of processes, a first process of saving at least a portion of the group of setting values accepted by the accepting means as the operation settings held in the non-volatile memory, and, after the first process, a second process of overwriting and saving the setting values managed by the second management means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means.
2. The information processing device according to claim 1, characterized in that, when the security policy setting is included in the group of setting values accepted by the accepting means, the control means stores at least the security policy setting accepted by the accepting means as the operation setting held in the non-volatile memory in the first processing.
3. a third management means for managing address setting data that constitutes an address book and that is not included in the setting items managed by the second management means; 3. The information processing device according to claim 2, wherein, when the address setting data is included in the group of setting values accepted by the accepting means, the control means performs a third process in a series of processes in the import process, after the first process, to determine whether a specific security policy is set in the security policy settings managed by the first management means, and if the specific security policy is set, not to save the accepted address setting data as the operation setting to be held in the non-volatile memory, and if the specific security policy is not set, to save the accepted address setting data as the operation setting to be held in the non-volatile memory.
4. a fourth management means for managing user account data that is not included in the setting items managed by the second management means; 3. The information processing device according to claim 2, wherein, when the user account data is included in the group of setting values accepted by the accepting means, the control means performs a fourth process in the series of processes in the import process, after the first process, to determine whether a specific security policy is set in the security policy settings managed by the first management means, and if the specific security policy is set, not save the accepted user account data as the operation setting to be held in the non-volatile memory, and if the specific security policy is not set, save the accepted user account data as the operation setting to be held in the non-volatile memory.
5. A method for controlling an information processing device including a nonvolatile memory, a first management means for managing security policy settings, and a second management means for managing setting values of a group of setting items that affect at least one or more operations of the device, a receiving step of receiving a group of setting values to be imported; a control step of controlling the import processing of the setting values, The nonvolatile memory stores operation settings of the information processing device, A control method for an information processing device, characterized in that the control step controls to perform a series of processes in the import process, including a first process of saving at least a portion of the group of setting values accepted by the accepting means as the operation settings held in the non-volatile memory, and a second process of overwriting and saving, after the first process, the setting values managed by the second management means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means.
6. An information processing device including a nonvolatile memory, a first management means for managing security policy settings, and a second management means for managing setting values of a group of setting items that affect at least one or more operations of the information processing device, a receiving means for receiving a group of setting values to be imported; A program that functions as a control means for controlling the import process of setting values, The nonvolatile memory stores operation settings of the information processing device, The program is characterized in that the control means controls the import processing to perform, as a series of processes, a first process of saving at least a portion of the group of setting values accepted by the accepting means as the operation settings held in the non-volatile memory, and after the first process, a second process of overwriting and saving the setting values managed by the second management means as part of the operation settings held in the non-volatile memory so as to satisfy the security policy settings managed by the first management means.
Citation Information
Patent Citations
Combustible poison rod
JP1989003591A