Image processing apparatus and encryption setting method in image processing apparatus
The image processing device enhances user experience by dynamically displaying encryption confirmation or settings screens based on data encryption status, simplifying security compliance procedures.
Patent Information
- Application Number
- JP2024042951
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-10-02
AI Technical Summary
Existing image processing devices, such as multifunction peripherals, lack user-friendly encryption settings, requiring users to repeatedly check if data has been encrypted, complicating the encryption process due to compliance with security regulations.
An image processing device with a control unit that determines whether to display an encryption settings screen or a confirmation screen based on the encryption status of data, ensuring users are informed about encryption without unnecessary steps.
Improves user operability by reducing redundant encryption setting processes, especially when data is already encrypted, thus streamlining security compliance.
Smart Images

Figure 2025143627000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a screen processing device and the like. [Background technology]
[0002] 2. Description of the Related Art One known security measure for image processing devices such as multifunction peripherals is to encrypt stored data to protect the data from damage such as unauthorized access and theft.
[0003] As an example of such encryption technology, Patent Document 1 describes an information processing device that, regarding encryption settings for data to be encrypted (sometimes referred to as encryption target data), displays a button to accept instructions to encrypt the encryption target data when the encryption setting screen is closed with the encryption of the encryption target data decrypted. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2017 / 009988 Summary of the Invention [Problem to be solved by the invention]
[0005] The present disclosure aims to provide an image processing device and the like that can improve user operability regarding encryption settings for data to be encrypted. [Means for solving the problem]
[0006] In order to solve the above problem, the image processing device of the present disclosure comprises an encryption unit that encrypts data, a control unit that controls the acceptance of encryption settings for the data, and a display unit, and is characterized in that the control unit displays either a setting screen that accepts the encryption settings or a confirmation screen that notifies the user that the data has been encrypted on the display unit, depending on the encryption status of the data by the encryption unit.
[0007] In addition, the image processing device of the present disclosure includes an encryption unit that encrypts data based on pre-set setting information, a control unit that controls the acceptance of encryption settings for the data, and a display unit, and the control unit controls the display of a setting screen that accepts the encryption settings on the display unit or the omission of display of the setting screen on the display unit depending on the initialization status of the setting information of the image processing device.
[0008] In addition, the encryption setting method in an image processing device according to the present disclosure is an encryption setting method in an image processing device that includes an encryption unit that encrypts data, a control unit that controls the acceptance of encryption settings for the data, and a display unit, and is characterized in that, depending on the encryption status of the data by the encryption unit, the display unit displays either a setting screen that accepts the encryption settings or a confirmation screen that notifies the user that the data has been encrypted. [Effects of the Invention]
[0009] According to the present disclosure, it is possible to provide an image processing device or the like that can improve user operability regarding encryption settings for data to be encrypted. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a diagram illustrating the overall configuration of an image forming apparatus according to a first embodiment. [Figure 2] FIG. 1 is a diagram illustrating a configuration of an image forming apparatus according to a first embodiment. [Figure 3]1 is a flowchart illustrating a processing flow according to the first embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 5] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 9] 10 is a flowchart illustrating a processing flow according to the second embodiment. [Figure 10] 10 is a flowchart illustrating a processing flow according to the third embodiment. [Figure 11] FIG. 10 is a diagram illustrating an example of operation according to the third embodiment. [Figure 12] 10 is a flowchart illustrating a processing flow according to the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following embodiments are examples for explaining the present disclosure, and the technical content of the description set forth in the claims is not limited to the following description.
[0012] 2. Description of the Related Art Conventionally, encryption settings for encrypting data stored in a storage device or the like implemented in an image processing device such as a multifunction peripheral have been arbitrarily set by a user such as an administrator.
[0013] On the other hand, in order to comply with various laws and regulations (e.g., the Product Security and Telecommunication Infrastructure Bill (PSTI)) to strengthen the security of IoT (Internet of Things) devices and to obtain Common Criteria (CC) certification for the collaborative Protection Profile for Hardcopy Devices (HCDcPP), MFPs released into the markets of these regions and countries are required to comply with the security requirements stipulated in the various laws and regulations and profiles.
[0014] For example, the item on storage encryption (conditionally mandatory) in HCDcPP (version 1.0) stipulates that "If the TOE (target of evaluation) stores user text data or confidential TSF (TOE security function) data on field-replaceable non-volatile storage devices, the TOE must encrypt such data on those devices."
[0015] To meet the security requirements stipulated in HCDcPP and other standards, some multifunction devices encrypt data when shipped from the factory or upon initialization. However, users have no way of checking whether the data has been encrypted, and if the data has already been encrypted, they cannot skip the unnecessary encryption setting screens. In such a configuration, users must start by checking the settings again, which makes it difficult to say that the operability of encryption settings is excellent.
[0016] In the present disclosure, the following embodiments realize an image processing apparatus and the like that can improve user operability regarding encryption settings for data to be encrypted.
[0017] [1 First Embodiment] In the first embodiment, a multifunction peripheral 10 will be described as an example of an image processing device. The multifunction peripheral 10 is an image processing device that can perform various jobs related to copying, faxing, email, etc. in a single housing. Note that the image processing device may be a printer, copier, fax machine, etc. that has limited job functions for each type, other than the multifunction peripheral 10.
[0018] [1.1 Functional Configuration] 1 is a diagram illustrating the overall configuration of a multifunction peripheral 10 according to the first embodiment. FIG. 2 is a functional configuration diagram of the multifunction peripheral 10.
[0019] The multifunction device 10 includes, as its functional components, a control unit 11, a display unit 13, an operation input unit 15, a communication unit 17, a storage unit 19, an encryption unit 21, and an image processing unit 23.
[0020] The control unit 11 controls the entire multifunction device 10. The control unit 11 can be configured with one or more processing devices (for example, a CPU (Central Processing Unit), an SoC (System on Chip), etc.). The control unit 11 realizes its functions by reading and executing various programs stored in the storage unit 19.
[0021] The display unit 13 is a display device that displays various information to the user, etc. The display unit 13 can be configured, for example, with an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, etc. Based on the control of the control unit 11 that has read out a display control program 193 (described later), the display unit 13 displays, for example, a home screen (not shown), operation screens such as a job execution screen related to the execution of each job, a login screen that accepts input of authentication information (e.g., login user name, login password, etc.) of a user attempting to log in to the multifunction peripheral 10, an initial setting wizard screen that is executed when the multifunction peripheral 10 is powered on or for the first time after the device is started, and a setting wizard screen that is executed after the memory unit is initialized, etc.
[0022] The operation input unit 15 is an input device that accepts information input by a user or the like. The operation input unit 15 can be configured with various input devices, such as operation keys such as hardware keys or software keys, buttons, etc. The operation input unit 15 can also be configured as a touch panel that allows input via the display unit 13. When configured as a touch panel, the operation input unit 15 can detect a user's touch, tap, swipe, etc. on an object displayed via the display unit 13, and acquire coordinate information, pressure-sensitive information, etc. on the touch panel. In this case, the input method of the touch panel can be, for example, a general input method such as a resistive film method, an infrared method, an electromagnetic induction method, or a capacitive method.
[0023] The communication unit 17 has a wired / wireless interface or both for communicating with other terminal devices (not shown) via a network NW such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, a telephone line, a FAX line, etc. The communication unit 17 may also have an interface related to wireless communication technology such as Bluetooth (registered trademark), NFC (Near Field Communication), Wi-Fi (registered trademark), IrDA (Infrared Data Association), or wireless USB (Universal Serial Bus).
[0024] The storage unit 19 is one or more storage devices that store various programs and various data required for the operation of the multifunction device 10. The storage unit 19 can be configured with storage devices such as RAM (Random Access Memory), SSD (Solid State Drive), HDD (Hard Disk Drive), and ROM (Read Only Memory).
[0025] In the first embodiment, the storage unit 19 stores a start control program 191, a control program 192, a display control program 193, an encryption setting program 194, and a job control program 195, and reserves an encryption key storage area 196.
[0026] The boot control program 191 is a program that is read by the control unit 11 when the multifunction peripheral 10 is started up. The control unit 11 that has read the boot control program 191 controls the boot process of the multifunction peripheral 10. Such a boot control program 191 may be included, for example, in boot firmware or main firmware that is started up by verification by the boot firmware. Note that the boot control program 191 may be stored in another storage device (storage area) (not shown) different from the storage unit 19 in order to achieve secure boot, or may be stored in another terminal device (not shown) on the network NW.
[0027] The startup control program 191 includes a wizard setting program 1911. The control unit 11 reads out the wizard setting program 1911 when the startup of the multifunction device 10 requires initial settings, such as the first startup after power-on (initial startup) or startup after initialization of the storage unit 19. Having read out the wizard setting program 1911, the control unit 11 proceeds with the (initial) setting process while displaying on the display unit 13 (operation input unit 15) a wizard screen that assists with the initial settings and accepts input for device settings.
[0028] The control program 192 is a program that is read by the control unit 11 after the device is started up based on the start-up control program 191. The control unit 11 that has read the control program 192 functions as an OS (Operating System) and controls the operation of hardware such as the display unit 13, the operation input unit 15, the communication unit 17, the encryption unit 21, and the image processing unit 23.
[0029] The display control program 193 is a program that is read by the control unit 11 when performing output control of the screen displayed on the display unit 13 or the operation input unit 15 configured as a touch panel. The control unit 11 that reads the display control program 193 controls the screen display on the display unit 13 (operation input unit 15).
[0030] The encryption setting program 194 is a program read by the control unit 11 when accepting encryption settings from a user. After reading the encryption setting program 194, the control unit 11 determines whether to display a setting screen for accepting encryption settings or a confirmation screen notifying users that the data has been encrypted, depending on the status of data encryption by the encryption unit 21. Here, encryption according to the present disclosure refers to a general technology that restricts access by users other than authenticated users by encrypting data to be encrypted based on a predetermined algorithm. In this case, access to the data to be encrypted can be restricted by directly encrypting the data to be encrypted or by concealing the storage location of the data to be encrypted. Furthermore, the data to be encrypted according to the present disclosure may be in units of files, folders, storage areas of a specific size, or entire storage units of the storage unit 19.
[0031] 2, the encryption setting program 194 can be configured as a native application that functions when read by the control unit 11, or the wizard setting program 1911 can be given the functions of the encryption setting program 194. In this case, the functions performed by the encryption setting program 194 can be provided as one function of the initial setting wizard.
[0032] The job control program 195 is a program that the control unit 11 reads out when executing a print job related to printing, copying, etc., or a job related to faxing or image transmission. After reading the job control program 195, the control unit 11 transitions to a job mode (e.g., print mode, copy mode, fax mode, image transmission mode, etc.) for executing each job and executes the job. When executing a job, the control unit 11 can display, as necessary, an operation screen on the operation input unit 15 configured as a touch panel that accepts selection of setting values and functions required for job execution from the user. The control unit 11 can execute the job based on the setting values and functions accepted via the operation input unit 15.
[0033] The encryption key storage area 196 is a storage area that stores an encryption key for decrypting data encrypted by the encryption unit 21 (sometimes referred to as encrypted data) and accessing the encrypted data. Access to the encryption key storage area 196 (the encryption key stored therein) is restricted according to the protection mode of the encryption unit 21. The encryption key storage area 196 may be stored in another storage device (storage area) (not shown) different from the storage unit 19, or may be stored in another terminal device (not shown) on the network NW.
[0034] The encryption unit 21 can be configured as a self-encrypting drive equipped with a dedicated chip that encrypts and decrypts data to be encrypted. The encryption unit 21, configured as a self-encrypting drive, encrypts stored data to be encrypted using a predetermined algorithm. The encryption unit 21 can operate in two different operating modes: a non-protected mode and a protected mode. In the non-protected mode, the encryption unit 21 does not restrict access to the encryption key storage area 196 (the encryption key stored therein). In the non-protected mode, encrypted data can be decrypted and accessed without restriction using the encryption key. On the other hand, in the protected mode, the encryption unit 21 restricts (protects) access to the encryption key storage area 196 (the encryption key stored therein). In the protected mode, only authenticated users are permitted to decrypt and access encrypted data using the encryption key. The encrypted state of data is maintained for users other than authenticated authorized users, preventing unauthorized access or use of encrypted data by other users. The encryption unit 21 can also be configured as a native application stored in the storage unit 19. In this case, the encryption key storage area 196 is preferably stored in another storage device (storage area) (not shown) different from the storage unit 19, or in another terminal device (not shown) on the network NW.
[0035] In the present disclosure, the state in which the operation mode of the encryption unit 21 is the non-protection mode is defined as the data encryption status being "data is not encrypted," and the state in which the operation mode of the encryption unit 21 is the protection mode is defined as the data encryption status being "data is already encrypted." The control unit 11 that reads the encryption setting program 194 can determine the encryption status of the data to be encrypted based on the operation mode of the encryption unit 21.
[0036] The encrypted data storage area 211 is a storage area for storing data to be encrypted (encrypted data) encrypted by the encryption unit 21.
[0037] Image processing unit 23 includes image forming unit 231 and image input unit 233. Image forming unit 231 feeds paper from paper feed unit 25, forms an image on the paper based on image data, and then discharges the paper to paper discharge unit 27. Image forming unit 231 can be configured, for example, by a laser printer that employs an electrophotographic method. In this case, image forming unit 231 forms an image using toner supplied from toner cartridges (not shown) that correspond to toner colors (for example, cyan, magenta, yellow, and black).
[0038] The image input unit 233 generates image data by scanning an original. The image input unit 233 may be configured as a scanner device equipped with an image sensor such as a CCD (Charge Coupled Device) or a CIS (Contact Image Sensor), an automatic document feeder (ADF), a flatbed for placing and reading an original, and the like. The image input unit 233 is not particularly limited in configuration as long as it is capable of reading a reflected light image from an original image using an image sensor. The image input unit 233 may also be configured as an interface capable of acquiring image data stored in a storage medium such as a USB memory or image data transmitted from a terminal device (not shown). The image processing unit 23 may be configured to perform, for example, shading correction or density correction on the image data input from the image input unit 233 to generate image data for image transmission.
[0039] [1.2 Processing flow] Next, a processing flow according to the first embodiment will be described using the flowchart in Fig. 3. The processing described in the flowchart in Fig. 3 is processing executed by the control unit 11 by reading out the startup control program 191 (wizard setting program 1911), the control program 192, the display control program 193, the encryption setting program 194, etc. Fig. 3 also describes a mode in which processing related to encryption setting is included in the setting items (security-related settings) included in the initial setting wizard.
[0040] After starting up the multifunction device 10, the control unit 11 starts the initial setting wizard by reading out the start-up control program 191 (wizard setting program 1911) (step S100). When the initial setting wizard starts, the control unit 11 accepts the language setting by the user via a "language setting" wizard screen (step S110).
[0041] Next, the control unit 11 displays a wizard screen based on the language (a language that the user can understand) accepted in step S110 (step S120). Then, the control unit 11 accepts input of necessary setting values and the like via the wizard screen (step S130).
[0042] The control unit 11 determines whether the setting contents received via the wizard screen are security settings (step S140). If it is determined that the setting contents received via the wizard screen are security settings, the control unit 11 displays a query screen inquiring whether to encrypt data (data to be encrypted) of the multifunction device 10 (step S140; Yes → step S150). If it is determined that the setting contents received via the wizard screen are not security settings, the control unit 11 repeats displaying the wizard screen and receiving input of setting values, etc. until the setting contents received via the wizard screen are security-related settings (step S140; No → step S120).
[0043] When the control unit 11 receives an instruction to execute encryption via the inquiry screen, the encryption unit 21 determines whether the data to be encrypted has already been encrypted (step S160; Yes → step S170). If the encryption unit 21 determines that the data to be encrypted has already been encrypted, the control unit 11 decides to display a confirmation screen notifying the user that the data to be encrypted has already been encrypted, and displays the confirmation screen (step S170; Yes → step S210). Then, the control unit 11 proceeds to step S220 (step S210 → step S220).
[0044] On the other hand, if the encryption unit 21 determines that the data to be encrypted has not already been encrypted, the control unit 11 decides to display a setting screen for accepting encryption settings, and displays the setting screen (step S170; No → step S180).
[0045] Next, the control unit 11 determines whether an instruction to execute encryption has been received via the setting screen (step S190). If the control unit 11 determines that an instruction to execute encryption has been received via the setting screen, it outputs an instruction to encrypt the data to be encrypted to the encryption unit 21. Having received the instruction to encrypt the data to be encrypted, the encryption unit 21 encrypts the data to be encrypted by switching the operation mode from the non-protection mode to the protection mode (step S190; Yes → step S200). Then, the control unit 11 proceeds to step S220 (step S200 → step S220). If the control unit 11 determines that an instruction to execute encryption has not been received via the setting screen, it proceeds to step S220 (step S190; No → step S220).
[0046] Meanwhile, in step S160, when the control unit 11 determines that an instruction to execute encryption has not been received via the inquiry screen, it determines whether or not the display of all wizard screens has finished (step S160; No → step S220). When it determines that the display of all wizard screens has finished, the control unit 11 ends the initial setting wizard and starts using the device (step S220; Yes → step S230). When it determines that the display of all wizard screens has not finished, the control unit 11 returns the process to step S120 (step S220; No → step S120).
[0047] [1.3 Example of operation] Next, an example of operation according to the first embodiment will be described. FIG. 4 is a diagram illustrating an example of the configuration of a wizard screen W10 related to "language setting." The "language setting" wizard screen W10 is a wizard screen displayed by the control unit 11 in step S110 of FIG. 3. The wizard screen W10 includes a language selection area R10 and a Next button B10. The language selection area R10 is a selection area that accepts a language selection by the user. When the desired language is selected by the user, the selected language is displayed in an identifiable manner (for example, highlighted), allowing the user to understand the selected language. The Next button B10 is a selection button that accepts an instruction to confirm the language selection by the user. When the control unit 11 accepts an instruction to select the Next button B10 by the user, it displays a wizard screen displayed in the language selected by the user.
[0048] FIG. 5 is a diagram illustrating an example of the configuration of a "Start Confirmation" wizard screen W20 of the initial setup wizard. The "Start Confirmation" wizard screen W20 is an example of a wizard screen that the control unit 11 displays after the "Language Setting" wizard screen W10 is displayed. The "Start Confirmation" wizard screen W20 includes a notification that the initial setup wizard will start via the wizard screen (for example, "Initial setup will start. Do not turn off the device until setup is complete."), a Next button B10, and a Back button B12. After confirming that the initial setup wizard will start, the user selects either the Next button B10 or the Back button B12.
[0049] The Next button B10 is a selection button that accepts a user's instruction to confirm the start of the initial setup wizard. When the user selects the Next button B10, the control unit 11 transitions the screen to a wizard screen related to the next initial setup wizard. The Back button B12 is a selection button that accepts an instruction to cancel the initial setup wizard. When the user selects the Back button B12, the control unit 11 transitions the screen to the "Language Settings" wizard screen W10 shown in the previous figure.
[0050] 6 is a diagram illustrating an example of the configuration of a "Security Settings" wizard screen W30 that the control unit 11 displays when the setting content received via the wizard screen is security settings related to the security of the multifunction device 10. The "Security Settings" wizard screen W30 is one form of the encryption inquiry screen that the control unit 11 displays in step S150 of FIG.
[0051] The "Security Settings" wizard screen W30 includes a query area R12 that queries the user as to whether or not to encrypt the data to be encrypted, a Next button B10, and a Back button B12. The query area R12 includes a notification querying whether or not to encrypt the data to be encrypted (e.g., "Do you want to encrypt the storage on this device?"), a Yes button B20, and a No button B22. After checking the notification, the user selects either the Yes button B20 or the No button B22.
[0052] The Yes button B20 is a selection button that accepts a provisional selection of an instruction to execute encryption on the data to be encrypted. When a selection instruction for the Yes button B20 is accepted, the control unit 11, for example, dims the Yes button B20 in a identifiable manner to indicate that the Yes button B20 is in a selected state. The No button B22 is a selection button that accepts a provisional selection of an instruction to cancel encryption on the data to be encrypted. When a selection instruction for the No button B22 is accepted, the control unit 11, for example, dims the No button B22 in a identifiable manner to indicate that the No button B22 is in a selected state.
[0053] The Next button B10 is a selection button that accepts an instruction to confirm the provisional selection of the Yes button B20 or the No button B22 in the inquiry area R12. When the control unit 11 accepts an instruction to select the Next button B10 while the Yes button B20 is provisionally selected, the control unit 11 accepts an instruction to execute encryption on the data to be encrypted. When the control unit 11 accepts an instruction to execute encryption on the data to be encrypted, the control unit 11 determines whether the data to be encrypted has already been encrypted by the encryption unit 21. On the other hand, when the control unit 11 accepts an instruction to select the Next button B10 while the No button B22 is provisionally selected, the control unit 11 accepts an instruction to cancel encryption of the data to be encrypted. When the control unit 11 accepts an instruction to cancel encryption of the data to be encrypted, the control unit 11 ends the inquiry process regarding whether encryption can be executed on the data to be encrypted.
[0054] The back button B12 is a selection button that accepts an instruction to cancel security settings made via the "Security Settings" wizard screen W30. When the user selects the back button B12, the control unit 11 transitions the screen to the "Start Confirmation" wizard screen W20 shown in the previous figure.
[0055] Fig. 7 is a diagram illustrating an example of the configuration of a setting screen W40 displayed by the control unit 11 when it is determined that encryption of the encryption target data has not been completed by the encryption unit 21. Fig. 7 shows an example of operation corresponding to the processing of step S170; No → step S180 in Fig. 3.
[0056] The settings screen W40 is a settings screen that accepts an instruction to encrypt the data to be encrypted by the encryption unit 21. The settings screen W40 includes a notification that the encryption unit 21 will encrypt the data to be encrypted (for example, "Enable protection of storage encryption key"), an OK button B30, and a Cancel button B32. After confirming that the encryption unit 21 will encrypt the data to be encrypted, the user selects either the OK button B30 or the Cancel button B32.
[0057] The OK button B30 is a selection button that accepts an instruction to encrypt the data to be encrypted by the encryption unit 21. When the user selects the OK button B30, the control unit 11 outputs an instruction to encrypt the data to be encrypted to the encryption unit 21. The cancel button B32 is a selection button that accepts an instruction to cancel the encryption of the data to be encrypted by the encryption unit 21. When the user selects the cancel button B32, the control unit 11 ends the processing related to the encryption settings.
[0058] Fig. 8 is a diagram illustrating an example of the configuration of a confirmation screen W50 that the control unit 11 displays when it is determined that encryption of the encryption target data has been executed by the encryption unit 21. Note that Fig. 8 is an example of operation corresponding to the processing of step S170; Yes→step S210 in Fig. 3.
[0059] The confirmation screen W50 notifies the user that the encryption target data has been encrypted by the encryption unit 21, and is a confirmation screen for the user to confirm the notification content. The confirmation screen W50 includes a notification that the encryption target data has been encrypted by the encryption unit 21 (for example, "Encryption settings have already been enabled") and an OK button B30. The user who has confirmed that the encryption target data has been encrypted by the encryption unit 21 selects the OK button B30. The control unit 11, having received an instruction to select the OK button B30, ends the processing related to the encryption settings.
[0060] As described above, the image processing device according to the first embodiment determines whether to display a setting screen for accepting encryption settings or a confirmation screen notifying the user that the data has already been encrypted, depending on the encryption status of the data (data to be encrypted). For example, if the data has already been encrypted by the encryption unit, the image processing device omits displaying the setting screen for accepting encryption settings and notifies the user that the data has already been encrypted. The image processing device according to the first embodiment can reduce the effort required for encryption settings when data has already been encrypted, thereby improving user operability.
[0061] [2 Second Embodiment] In the second embodiment, it is determined whether to display a setting screen for accepting encryption settings for data to be encrypted or a confirmation screen for notifying that the data to be encrypted has already been encrypted, based on the factory settings of the image processing device. In the second embodiment, a case will be described in which the destination to which the image processing device is shipped is a destination (e.g., Europe) where encryption of data to be encrypted at the time of shipment (delivery) is mandatory due to legal regulations, etc.
[0062] The functional configuration of the multifunction peripheral as an image processing device according to the second embodiment can be the same as the functional configuration of the multifunction peripheral 10 according to the first embodiment, and therefore a description thereof will be omitted here.
[0063] [2.1 Processing flow] The processing flow according to the second embodiment is obtained by replacing the flowchart (step S170) of Fig. 3 according to the first embodiment with the flowchart (step S300) of Fig. 9. In the explanation of Fig. 9, the same processes as those explained in the flowchart of Fig. 3 are assigned the same step numbers and explanations thereof will be omitted.
[0064] When the control unit 11 receives an instruction to execute encryption via the inquiry screen, it determines whether the destination of the multifunction device 10 is a destination where encryption of the data to be encrypted is mandatory (step S160; Yes→step S300).
[0065] If it is determined that the destination of the multifunction device 10 is one that requires encryption of the data to be encrypted, the encryption unit 21 determines that the data to be encrypted has already been encrypted. Then, the control unit 11 determines to display a confirmation screen notifying the user that the data to be encrypted has already been encrypted, and displays the confirmation screen (step S300; Yes -> step S210).
[0066] On the other hand, if it is determined that the destination of the multifunction device 10 is another destination that does not require encryption of the data to be encrypted, the control unit 11 determines that the data to be encrypted has not been encrypted by the encryption unit 21. Then, the control unit 11 determines to display a setting screen for accepting encryption settings for the data to be encrypted, and displays the setting screen (step S300; No -> step S180).
[0067] The setting screen or confirmation screen displayed by the control unit 11 in the second embodiment can have the same display configuration as the setting screen W40 (Figure 7) or confirmation screen W50 (Figure 8) described in the first embodiment, so the description here will be omitted.
[0068] As described above, according to the second embodiment, in addition to the effects of the first embodiment, encryption of the data to be encrypted is forcibly performed depending on the destination of the image processing device, so that the user can complete security settings (initial setting wizard) including encryption settings without being aware of the encryption status of the data to be encrypted by the encryption unit.
[0069] [3 Third embodiment] In the third embodiment, whether to display a setting screen for accepting encryption settings for data to be encrypted or a confirmation screen notifying that the data to be encrypted has already been encrypted is determined based on whether encryption settings for data to be encrypted at the time of shipment and the security status of the image processing device. In the third embodiment, two security states of the image processing device will be described: a security state that complies with a security policy provided by a profile such as HCDcPP, installation of a device option, firmware update, etc., and a standard security state that has a lower security level than the security state that complies with the security policy and is implemented as standard in the image processing device.
[0070] The functional configuration of the multifunction peripheral as an image processing device according to the third embodiment can be the same as the functional configuration of the multifunction peripheral 10 according to the first embodiment, and therefore a description thereof will be omitted here.
[0071] [3.1 Processing flow] The processing flow according to the third embodiment is obtained by replacing the flowchart of Fig. 3 according to the first embodiment with the flowchart of Fig. 10. For ease of explanation, Fig. 10 will explain only the processing included in steps S160 to S220. In addition, in the explanation of Fig. 10, the same processing as that explained in the flowchart of Fig. 3 will be assigned the same step numbers and explanations thereof will be omitted.
[0072] When the control unit 11 receives an instruction to encrypt the data to be encrypted via the inquiry screen, it checks whether the encryption setting was enabled at the time of shipment (step S400). If it determines that the encryption setting at the time of shipment is enabled, the control unit 11 checks the security status of the multifunction device 10 (step S400; Yes→step S410).
[0073] If the control unit 11 determines that the security status of the multifunction device 10 is the standard security status, it displays a confirmation screen (step S420; Yes→step S210). On the other hand, if the control unit 11 determines that the security status of the multifunction device 10 is not the standard security status but a security status that complies with the security policy, it displays an encrypted screen based on the security policy (step S420; No→step S430).
[0074] Incidentally, in step S400, if the control unit 11 determines that the encryption setting at the time of shipment is invalid, it checks the security status of the multifunction peripheral 10 (step S400; No→step S410).
[0075] If the control unit 11 determines that the security status of the multifunction device 10 is the standard security status, it determines to display a setting screen for accepting encryption settings, and displays the setting screen (step S440; Yes→step S180). Then, the control unit 11 executes the processes from step S180 onwards.
[0076] On the other hand, if the control unit 11 determines that the security state of the multifunction device 10 is not the standard security state but a security state that complies with the security policy, it displays an encrypted screen based on the security policy (step S440; No → step S430).
[0077] [3.2 Example of operation] 11 is a diagram illustrating an example of the configuration of the encrypted screen W60 based on the security policy that is displayed by the control unit 11 when the security status of the multifunction device 10 complies with the security policy. Note that FIG. 11 is an example of the operation corresponding to the processing of step S430 in FIG.
[0078] The encryption screen W60 is a confirmation screen that notifies the user that the security status of the multifunction device 10 has been encrypted in accordance with the security policy, and allows the user to confirm the notification content. The encryption screen W60 includes a notification that the data to be encrypted has been encrypted in accordance with the security policy (for example, "Encrypted in accordance with the security policy.") and an OK button B30. A user who has confirmed that the data to be encrypted has been encrypted in accordance with the security policy selects the OK button B30. Upon receiving an instruction to select the OK button B30, the control unit 11 ends the processing related to the encryption settings.
[0079] As described above, according to the third embodiment, in addition to the effects of the first embodiment, based on whether encryption settings were configured at the time of shipment and the security status of the image processing device, it is determined whether to display a settings screen that accepts encryption settings for data to be encrypted or a confirmation screen that notifies the user that the data to be encrypted has already been encrypted.Therefore, the user can complete security settings (initial setup wizard) including encryption settings without being aware of the encryption status of the data to be encrypted.
[0080] [4 Fourth embodiment] In the fourth embodiment, when an encryption setting as preset setting information is initialized during repair of an image processing device, a setting screen for accepting the encryption setting is displayed. On the other hand, if the repair of the image processing device involves a part other than the storage unit related to the encryption setting and the preset encryption setting is not initialized, for example, the display of the setting screen for accepting the encryption setting is omitted, thereby preventing the user from performing unnecessary operations.
[0081] The functional configuration of the multifunction peripheral as an image processing device according to the fourth embodiment can be the same as the functional configuration of the multifunction peripheral 10 according to the first embodiment, and therefore a description thereof will be omitted here.
[0082] [4.1 Processing flow] The processing flow according to the fourth embodiment is obtained by replacing the flowchart of Fig. 3 according to the first embodiment with the flowchart of Fig. 12. In the explanation of Fig. 12, the same processes as those explained in the flowchart of Fig. 3 will be assigned the same step numbers and their explanations may be omitted.
[0083] After repair of the multifunction device 10 is completed, the control unit 11 starts the setting wizard (step S500). When the setting wizard starts, the control unit 11 displays an inquiry screen inquiring whether or not to encrypt the data to be encrypted in the multifunction device 10 (step S150).
[0084] When the control unit 11 receives an instruction to execute encryption via the inquiry screen, it determines whether or not the preset encryption setting has been initialized (step S160; Yes → step S510). If it determines that the encryption setting has been initialized, the control unit 11 determines to display a setting screen for accepting the encryption setting, and displays the setting screen (step S510; Yes → step S180).
[0085] In addition, if the repair of the multifunction device 10 involves initializing the encryption settings, the setting screen for accepting the encryption settings will be displayed even if the repaired multifunction device 10 is used within the same company or is shipped to another company.
[0086] After displaying the setting screen, the control unit 11 executes the processes from step S180 to step S200 (step S180 to step S200).
[0087] After encrypting the data in step S200, the control unit 11 accepts input of settings other than those related to encryption settings (step S520). Next, the control unit 11 determines whether or not the display of all wizard screens has finished (step S530). If it is determined that the display of all wizard screens has finished, the control unit 11 ends the post-repair setting wizard and starts using the device (step S530; Yes → step S540). Note that if it is determined that the display of all wizard screens has not finished, the control unit 11 returns the process to step S520 (step S530; No → step S520).
[0088] Meanwhile, in step S160, if the control unit 11 determines that an instruction to execute encryption has not been received via the inquiry screen, the control unit 11 shifts the processing to step S520 (step S160; No→step S520).
[0089] Furthermore, if it is determined in step S510 that the encryption settings have not been initialized, the control unit 11 determines to omit displaying the setting screen for accepting the encryption settings, and proceeds to step S520 without displaying the setting screen (step S510; No -> step S520). In this way, if the repair of the multifunction device 10 does not involve initialization of the encryption settings, and the repaired multifunction device 10 will be used, for example, within the same company, the display of the setting screen for accepting the encryption settings can be omitted. Note that in this case, as exemplified in the first to third embodiments, a confirmation screen may be displayed indicating that the repair does not involve initialization of the encryption settings. On the other hand, even if the repair of the multifunction device 10 does not involve initialization of the encryption settings, it is preferable that the setting screen for accepting the encryption settings be always displayed if the repaired multifunction device 10 is to be shipped to another company.
[0090] As described above, according to the fourth embodiment, when an image processing device is repaired, if the pre-set encryption settings are initialized, a setting screen for accepting the encryption settings is displayed. On the other hand, if, for example, the repair content of the image processing device is a part other than the memory unit (storage) related to the encryption settings and the pre-set encryption settings are not initialized, the display of the setting screen for accepting the encryption settings is omitted, thereby preventing the user from performing unnecessary operations.
[0091] The present disclosure is not limited to the above-described embodiments, and various modifications are possible. In other words, embodiments obtained by combining technical means that are appropriately modified within the scope of the gist of the present disclosure are also included in the technical scope of the present disclosure.
[0092] Furthermore, although the above-described embodiments are described separately for the sake of convenience, they may of course be combined and executed within the scope of technical feasibility.
[0093] In addition, the programs that run on each device in the embodiments are programs that control the CPU, etc. (programs that make a computer function) so as to realize the functions of the above-described embodiments. Information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memories) and HDDs, and is read, modified, and written by the CPU as needed.
[0094] Here, the computer-readable non-transitory recording medium on which the program is recorded in the information processing device may be any of semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray (registered trademark) Disc, etc.)), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). In this case, the program recorded on the recording medium is read by the computer of the information processing device and executed by the computer, thereby realizing not only the functions of the above-mentioned embodiments, but also the functions of the present disclosure, which are realized by processing in cooperation with an operating system or other application programs, etc., based on instructions from the program.
[0095] Furthermore, when distributing the program on the market, the program can be stored in a portable recording medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is also included in the present disclosure.
[0096] Additionally, each functional block or feature of the device used in the above-described embodiments may be implemented or performed by an electrical circuit, such as an integrated circuit or multiple integrated circuits. The electrical circuit designed to realize the functions described herein may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gates or Tronistor logic, discrete hardware components, or a combination thereof. The general-purpose processor may be a microprocessor, a conventional processor, a controller, a microcontroller, or a state machine. The electrical circuit may be composed of digital circuits or analog circuits. Furthermore, as advances in semiconductor technology emerge, one or more aspects of the present disclosure may utilize new integrated circuits based on that technology. [Explanation of symbols]
[0097] 11 Control section 13 Display section 15 Operation input section 17 Communications Department 19 Memory section 191 Startup Control Program 1911 Wizard Setup Program 192 Control Program 193 Display Control Program 194 Encryption Configuration Program 195 Job Control Program 196 Encryption Key Storage Area 21 Encryption section 211 Encrypted Data Storage 23 Image processing section 231 Image forming unit 233 Image Input Unit
Claims
1. an encryption unit that encrypts data; a control unit that controls acceptance of encryption settings for the data; a display unit, The control unit An image processing device characterized in that, depending on the encryption status of the data by the encryption unit, the display unit displays either a setting screen that accepts the encryption settings or a confirmation screen that notifies the user that the data has been encrypted.
2. The control unit 2. The image processing apparatus according to claim 1, wherein the image processing apparatus displays either the setting screen or the confirmation screen based on a factory setting of the image processing apparatus.
3. The factory settings are:
3. The image processing apparatus according to claim 2, wherein the settings are made at the time of shipment according to the destination of the image processing apparatus.
4. The control unit further 3. The image processing apparatus according to claim 2, wherein either the setting screen or the confirmation screen is displayed based on the security status of the image processing apparatus.
5. The control unit 2. The image processing apparatus according to claim 1, wherein, when the encryption status of the data is "already encrypted," the display of the setting screen on the display unit is omitted, and the confirmation screen is displayed on the display unit.
6. an encryption unit that encrypts data based on preset setting information; a control unit that controls acceptance of encryption settings for the data; a display unit, The control unit An image processing device characterized by controlling whether to display a setting screen for accepting encryption settings on the display unit or omit displaying the setting screen on the display unit depending on the initialization status of the setting information of the image processing device.
7. The control unit 7. The image processing apparatus according to claim 6, wherein, when the setting information has been initialized, the setting screen is displayed by a setting wizard after initialization.
8. 1. An encryption setting method for an image processing device including an encryption unit that encrypts data, a control unit that controls acceptance of encryption settings for the data, and a display unit, comprising: An encryption setting method characterized by displaying on the display unit either a setting screen accepting the encryption setting or a confirmation screen notifying that the data has been encrypted, depending on the encryption status of the data by the encryption unit.
Citation Information
Patent Citations
Information processing device, data hiding method, and data hiding program
WO2017009988A1