Information processing apparatus, communication system, communication method, and program
The information processing device secures image forming device communication by using manufacturer-specific protocols to encrypt packets, addressing unauthorized access and maintaining data confidentiality.
Patent Information
- Application Number
- JP2024055678
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-10-10
AI Technical Summary
Existing communication systems with image forming devices lack security measures to prevent unauthorized access by third parties, posing risks to information stored in these devices.
An information processing device that communicates with image forming devices using different protocols based on manufacturer information, ensuring secure access by encrypting packets when necessary, thereby restricting access to sensitive information.
Enhances security by preventing unauthorized access to image forming device information, maintaining data confidentiality through protocol-specific communication methods.
Smart Images

Figure 2025153286000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, a communication system, a communication method, and a program, and more particularly to an information processing device, a communication system, a communication method, and a program for communicating with an image forming device. [Background technology]
[0002] Patent Document 1 discloses a system that includes a computer used by a user, multiple printers that perform printing processing, and an information management server that manages printer information. Patent Document 1 also discloses that when a user installs a printer driver on their computer, the information management server presents a list of printers. Patent Document 1 also discloses that the system obtains the IP (Internet Protocol) address required for installing the printer that will print out, selected from the presented printer list. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2000-330742 Summary of the Invention [Problem to be solved by the invention]
[0004] In the technology disclosed in Patent Document 1, a computer is connected to multiple printers via a network, and the computer can obtain the printers' IP addresses from an information management server. However, Patent Document 1 does not disclose any security measures when a third party other than the printer user or printer manufacturer accesses the printer. Therefore, the technology disclosed in Patent Document 1 poses security issues regarding information stored in the image forming device. [Means for solving the problem]
[0005] The information processing device disclosed herein is an information processing device that is communicatively connected to a plurality of image forming devices, and includes: a manufacturer information acquisition unit that acquires manufacturer information corresponding to a first image forming device in response to a request for access to a first image forming device among the plurality of image forming devices; an access processing unit that performs processing to access the first image forming device in accordance with the manufacturer information; and a response output unit that outputs a response to the request to the requestor that made the access request, wherein the access processing unit performs processing to access information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and predetermined conditions are satisfied, and performs processing to access information stored in the first image forming device using a second protocol different from the first protocol when the manufacturer information does not indicate the predetermined manufacturer.
[0006] In addition, the communication system disclosed herein includes a plurality of image forming devices and an information processing device communicatively connected to the plurality of image forming devices, wherein the information processing device includes a manufacturer information acquisition unit that acquires manufacturer information corresponding to a first image forming device in response to a request for access to a first image forming device among the plurality of image forming devices, an access processing unit that performs processing to access the first image forming device in accordance with the manufacturer information, and a response output unit that outputs a response to the request to the requestor that made the access request, wherein the access processing unit performs processing to access information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and predetermined conditions are satisfied, and performs processing to access information stored in the first image forming device using a second protocol different from the first protocol when the manufacturer information does not indicate the predetermined manufacturer.
[0007] In addition, the communication method disclosed herein is a communication method executed by an information processing device communicatively connected to multiple image forming devices, and in response to a request for access to a first image forming device among the multiple image forming devices, obtains manufacturer information corresponding to the first image forming device, and if the manufacturer information indicates a predetermined manufacturer and predetermined conditions are satisfied, performs processing to access information stored in the first image forming device using a first protocol, and if the manufacturer information does not indicate the predetermined manufacturer, performs processing to access information stored in the first image forming device using a second protocol different from the first protocol, and outputs a response to the request to the requestor that made the access request.
[0008] In addition, the program disclosed herein is a program executed by an information processing device communicatively connected to a plurality of image forming devices, and causes the computer to execute the following steps in response to a request for access to a first image forming device among the plurality of image forming devices: acquiring manufacturer information corresponding to the first image forming device; if the manufacturer information indicates a predetermined manufacturer and predetermined conditions are satisfied, performing processing to access information stored in the first image forming device using a first protocol; if the manufacturer information does not indicate the predetermined manufacturer, performing processing to access information stored in the first image forming device using a second protocol different from the first protocol; and outputting a response to the request to the requestor that made the access request. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating a communication system according to a first embodiment. [Figure 2] FIG. 2 is a diagram for explaining an outline of processing in the communication system according to the first embodiment. [Figure 3] FIG. 2 is a diagram illustrating a plaintext packet transmitted in the communication system according to the first embodiment. [Figure 4]3 is a diagram illustrating an example of an encrypted packet transmitted in the communication system according to the first embodiment; [Figure 5] FIG. 2 is a diagram illustrating a disclosure information file according to the first embodiment. [Figure 6] FIG. 1 is a diagram illustrating a configuration of an information processing device according to a first embodiment. [Figure 7] 1 is a diagram illustrating a configuration of an image forming apparatus according to a first embodiment. [Figure 8] FIG. 2 is a diagram for explaining details of processing in the communication system according to the first embodiment. [Figure 9] FIG. 4 is a diagram illustrating connection information registered by the login process according to the first embodiment. [Figure 10] 10 is a flowchart showing a login process executed by the access software according to the first embodiment; [Figure 11] 10 is a flowchart showing a response process executed by the access software according to the first embodiment; DETAILED DESCRIPTION OF THE INVENTION
[0010] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. In addition, the same elements in each drawing are designated by the same reference numerals, and duplicate explanations have been omitted as necessary.
[0011] FIG. 1 is a diagram illustrating a communication system 1 according to a first embodiment. The communication system 1 includes an information processing device 100 and a plurality of image forming devices 200. In the example of FIG. 1, the communication system 1 includes a plurality of image forming devices 200A, 200B, and 200C. The information processing device 100 is connected to a wired or wireless network 2. The image forming device 200 is also connected to the network 2. Therefore, the information processing device 100 is connected to the image forming device 200 so as to be able to communicate with each other via the network 2. The plurality of image forming devices 200A, 200B, and 200C may be devices owned by the same user.
[0012] Image forming apparatus 200 is an apparatus that performs printing. Image forming apparatus 200 is, for example, a printer. Image forming apparatus 200 has the function of an information processing apparatus such as a computer. Here, image forming apparatus 200A and image forming apparatus 200B are apparatuses provided by a specific manufacturer, maker X. Image forming apparatus 200C is an apparatus provided by a manufacturer different from maker X.
[0013] Here, the image forming apparatus 200 is associated with apparatus identification information that identifies the image forming apparatus 200. The apparatus identification information may be, for example, an IP address. The image forming apparatus 200 also has a management information database, which is a database of multiple pieces of information managed by an administrator of the image forming apparatus 200, for example. The management information database may be, for example, a MIB (Management Information Base) defined by SNMP (Simple Network Management Protocol). In the following description, the information that constitutes the management information database may be referred to as an "object."
[0014] Each piece of information constituting the management information database is information that is to be accessed by an administrator or the like. Each piece of information constituting the management information database is associated with object identification information, which is identification information that identifies that information, i.e., an object. The object identification information may be, for example, an OID (Object Identifier) in SNMP. Some or all of the information constituting the management information database is information that is to be encrypted when accessed.
[0015] Furthermore, image forming apparatus 200A is a device of a model in which at least a portion of its information is disclosed to a predetermined third party, third party SP1. In other words, image forming apparatus 200A is a device of a model in which access to third party SP1 is not restricted. Image forming apparatus 200B is a device of a model in which information is not disclosed to third party SP1. In other words, image forming apparatus 200B is a device of a model in which access to third party SP1 is restricted. Here, the "third party" refers to a third party that is different from manufacturer X and the user of image forming apparatus 200. A third party may also be referred to as a third vendor. A third party may be, for example, a service provider that provides some kind of service to the user of image forming apparatus 200, etc., using objects that constitute the management information database of image forming apparatus 200.
[0016] The communication system 1 may include a plurality of image forming apparatuses 200A. The communication system 1 may include a plurality of image forming apparatuses 200B. The communication system 1 may include a plurality of image forming apparatuses 200C. The plurality of image forming apparatuses 200C may be apparatuses provided by different manufacturers other than the manufacturer X.
[0017] The information processing device 100 is, for example, a computer. The information processing device 100 may be, for example, a terminal device of a third party SP1. The third party SP1 uses the information processing device 100, such as a terminal device, to make a request to access predetermined information of a predetermined image forming device 200. In response to the request from the third party SP1, the information processing device 100 performs processing to access the predetermined information of the predetermined image forming device 200. Therefore, the third party SP1 can be said to be the request source that requests access to the image forming device 200.
[0018] Here, the information processing device 100 has service software 110 and access software 120. In other words, the service software 110 and the access software 120 are installed in the information processing device 100. The service software 110 is software provided by a third party SP1. The service software 110 is software used by the third party SP1 to provide a predetermined service to the user. The access software 120 is software provided by a manufacturer X. The access software 120 is software used to access the image forming device 200. Note that the service software 110 is operated by the third party SP1, but the access software 120 is not directly operated by the third party SP1.
[0019] In response to a request from the service software 110, the information processing device 100 communicates with the image forming device 200 using the access software 120 via a predetermined communication protocol. Specifically, the access software 120 communicates with the image forming device 200 via a predetermined communication protocol in response to an access request output from the service software 110 by operation of the third party SP1. The information processing device 100 may communicate with the image forming device 200 via a communication protocol such as SNMP. In the information processing device 100, the service software 110 may exchange information with the access software 120 via a communication protocol such as SNMP. In addition, the information processing device 100 uses the access software 120 to perform different processes for each of the image forming device 200A, the image forming device 200B, and the image forming device 200C. This will be described in more detail below.
[0020] Here, "accessing information" includes reading information and writing information. In other words, "accessing information" includes reading the information and changing the value of the information.
[0021] The information processing device 100 performs processing to access the first image forming device, which is the image forming device 200 to be accessed, using either a first protocol or a second protocol, depending on the model of the first image forming device. The first protocol is a communication protocol in which at least a portion of packets exchanged with the first image forming device are encrypted. In other words, packets exchanged between the information processing device 100 and the first image forming device using the first protocol are packets in which at least a portion is encrypted, i.e., encrypted packets. The second protocol is a communication protocol different from the first protocol. Specifically, the second protocol is a communication protocol in which packets exchanged with the first image forming device are not encrypted. In other words, packets exchanged between the information processing device 100 and the first image forming device using the second protocol are unencrypted plaintext packets, i.e., plaintext packets. Plaintext packets may be defined, for example, by RFC (Request for Comments).
[0022] The packet defined by the second protocol may be, for example, a packet defined by SNMPv1. The packet defined by the first protocol may be, for example, a packet defined by SNMPv3. Alternatively, the packet defined by the first protocol may be, for example, a packet defined by SNMPv1, with a portion of the packet encrypted. Examples of plaintext packets and encrypted packets will be described later. Note that the plaintext packets and encrypted packets transmitted from the information processing device 100 to access the image forming device 200 may be collectively referred to as access packets. The access packet is a packet transmitted to the first image forming device by the access software 120 of the information processing device 100 in order to access the first image forming device in response to a request from the service software 110.
[0023] Here, the encryption method for encrypted packets specified in the first protocol is specified by manufacturer X. Therefore, encryption and decryption of encrypted packets can only be performed by access software 120 and image forming apparatuses 200 provided by manufacturer X, i.e., image forming apparatuses 200A and 200B. Therefore, the encryption method for encrypted packets of the first protocol is not provided to third party SP1. Furthermore, service software 110 and image forming apparatus 200C cannot encrypt and decrypt encrypted packets.
[0024] FIG. 2 is a diagram illustrating an overview of processing in the communication system 1 according to the first embodiment. In the example of FIG. 2, it is assumed that all information constituting the management information databases of all models of manufacturer X, i.e., image forming apparatus 200A and image forming apparatus 200B, is encrypted using a method defined by manufacturer X. That is, in the example of FIG. 2, all information constituting the management information databases of all models of manufacturer X is kept confidential. The management information database of image forming apparatus 200A is permitted to be disclosed to third party SP1. On the other hand, the management information database of image forming apparatus 200B is not permitted to be disclosed to third party SP1. Note that the management information database of image forming apparatus 200C, which is provided by a manufacturer other than manufacturer X, is disclosed to third party SP1.
[0025] As indicated by arrow P1, in the information processing device 100, the service software 110 transmits an access request packet to the access software 120 in response to an operation by the third party SP1. The "access request packet" is a packet indicating a request to access certain information in the management information database of the first image forming device, which is the image forming device 200 to be accessed. The access request packet may be a packet defined by the second protocol. For example, the access request packet may be a packet defined by SNMPv1. Therefore, the access request packet may be a plaintext packet.
[0026] The access request packet includes, for example, device identification information of the first image forming device, object identification information corresponding to the object to be accessed, and a type of access. The device identification information of the first image forming device may be an IP address associated with the first image forming device. The type of access may include "read" or "write." If the access request packet is a packet defined by SNMPv1, the type of access may be specified by a "PDU type." If the access type is "write," the access request packet may include information to be written to an area indicated by the object identification information. The "read" may be the reading of a value indicating the status or settings of the image forming device 200, among the information constituting the management information database. For example, the "read" may be the reading of the remaining ink level. The "write" may be the changing of setting information, among the information constituting the management information database. For example, the "write" may be the changing of the printing speed of the image forming device 200.
[0027] When the access software 120 receives an access request packet from the service software 110, it performs processing according to the access destination specified in the access request packet. Specifically, when the access software 120 receives the access request packet, it acquires manufacturer information corresponding to the first image forming device. That is, the access software 120 acquires manufacturer information corresponding to the first image forming device in response to a request for access to the first image forming device from the third party SP1. The manufacturer information indicates the manufacturer that provided the first image forming device. The manufacturer information may also indicate the manufacturer's name. A method for acquiring the manufacturer information will be described later.
[0028] If the manufacturer information does not indicate manufacturer X, the first image forming apparatus is the image forming apparatus 200C. In this case, the access software 120 performs processing to access information stored in the first image forming apparatus, i.e., the image forming apparatus 200C, using the second protocol, as indicated by arrow P2. That is, the access software 120 performs processing to access information in the management information database of the first image forming apparatus, image forming apparatus 200C, using the second protocol. Specifically, the access software 120 transmits a plaintext packet defined by the second protocol to the first image forming apparatus. Then, the access software 120 receives a response packet indicating the access result from the first image forming apparatus. The access software 120 outputs the received response packet to the service software 110. The response packet will be described later.
[0029] If the manufacturer information indicates manufacturer X, the first image forming apparatus is the model of image forming apparatus 200A or the model of image forming apparatus 200B. In this case, if a predetermined condition is satisfied, the access software 120 performs processing to access information stored in the first image forming apparatus using the first protocol. Specifically, the access software 120 refers to the disclosure information file 100a to determine whether to access the first image forming apparatus. Note that the access software 120 may also refer to the disclosure information file 100a to determine whether to access the first image forming apparatus using the first protocol or the second protocol.
[0030] Here, the disclosure information file 100a indicates information that is permitted to be disclosed to the third party SP1. In other words, the disclosure information file 100a indicates the range of the management information database that can be disclosed to the third party SP1. The disclosure information file 100a includes disclosed model identification information, which is identification information for the model of the image forming device 200 that is permitted to disclose information to the third party SP1. Note that the model identification information may be, for example, the model name of the image forming device 200. In the example of FIG. 2, the disclosure information file 100a indicates the model identification information of the image forming device 200A. Furthermore, the disclosure information file 100a indicates disclosed object identification information, which is object identification information for information in the management information database that is permitted to be disclosed to the third party SP1. An example of the disclosure information file 100a will be described later.
[0031] The disclosure information file 100a may be stored in the information processing device 100. Alternatively, the disclosure information file 100a may be stored in another device, such as a server, that is communicatively connected to the information processing device 100. The disclosure information file 100a may be provided for each third party SP1 that is permitted to disclose at least some of the information of multiple image forming devices 200. The disclosure information file 100a is data provided by manufacturer X. The disclosure information file 100a is encrypted using an encryption method specified by manufacturer X. Therefore, the disclosure information file 100a can be decrypted by manufacturer X and access software 120.
[0032] If the device identification information of the first image forming device indicated in the access request packet corresponds to image forming device 200A, the model identification information of the first image forming device is included in disclosure information file 100a. Therefore, access software 120 determines that the management information database of the first image forming device is accessible. If the object identification information indicated in the access request packet is included in disclosure information file 100a, access software 120 determines that the access requested in the access request packet is possible.
[0033] Therefore, as indicated by arrow P3, the access software 120 performs processing to access information stored in the first image forming apparatus, i.e., the image forming apparatus 200A, using the first protocol. That is, the access software 120 performs processing to access information in the management information database of the first image forming apparatus, i.e., the image forming apparatus 200A, using the first protocol. Specifically, the access software 120 transmits an encrypted packet defined by the first protocol to the first image forming apparatus. The access software 120 then receives a response packet indicating the access result from the first image forming apparatus. Note that in this case, the response packet received from the first image forming apparatus is also encrypted. Therefore, the access software 120 decrypts the response packet received from the first image forming apparatus and converts the response packet into a plaintext packet. The access software 120 outputs the plaintext packet obtained by the conversion to the service software 110 as a response packet. The response packet will be described later.
[0034] If the object identification information indicated in the access request packet is not indicated in the disclosure information file 100a, the access software 120 determines that the access requested by the access request packet cannot be performed. That is, the access software 120 determines that the access request packet requests access to information that the third party SP1 is not permitted to disclose. In this case, the access software 120 outputs a response packet to the service software 110 indicating that the access has failed.
[0035] On the other hand, if the device identification information of the first image forming device indicated in the access request packet corresponds to image forming device 200B, the model identification information of the first image forming device is not included in the disclosure information file 100a. Therefore, the access software 120 determines that it cannot access the management information database of the first image forming device. In other words, the access software 120 determines that the access request packet requests access to image forming device 200B, which is not permitted to disclose information to third party SP1. In this case, the access software 120 does not access image forming device 200B, which is the first image forming device, as indicated by arrow P4. The access software 120 then outputs a response packet to the service software 110 indicating that the access failed.
[0036] Also, assume that there is a third party SP2 who is not authorized to disclose information about either image forming device 200A or image forming device 200B provided by manufacturer X. Then, assume that third party SP2 attempts to access image forming device 200A or image forming device 200B using terminal device 90. In this case, terminal device 90 attempts to access image forming device 200A or image forming device 200B using the second protocol. However, image forming device 200A or image forming device 200B will not accept access other than that from access software 120. Specifically, image forming device 200A or image forming device 200B will not accept access unless it receives an encrypted packet specified in the first protocol. Therefore, as indicated by arrow P5, terminal device 90 cannot access image forming device 200A or image forming device 200B.
[0037] If the access software 120 is able to access the information of the first image forming apparatus in response to the access request packet, the access software 120 sends a response packet indicating the result of the access to the service software 110. That is, the access software 120 outputs a response to the request to the source of the access. If the access type in the access request packet is "read," the response packet may include information corresponding to the object identification information. If the access type in the access request packet is "write," the response packet may include information after writing, i.e., the changed information, corresponding to the object identification information. On the other hand, if the access to the first image forming apparatus fails, the access software 120 outputs a response packet indicating the access failure to the service software 110.
[0038] 3 is a diagram illustrating a plaintext packet transmitted in the communication system 1 according to the first embodiment. The plaintext packet illustrated in FIG. 3 corresponds to a packet defined in SNMPv1. As illustrated in FIG. 3, the plaintext packet may include an IP header, a message version, a message ID, a community name, and a PDU (Protocol Data Unit). The IP header may indicate the IP address of the destination of the plaintext packet.
[0039] The PDU includes information about the content to be read or written at the access destination. The PDU may include a PDU type, a request identifier, and MIB information. The request identifier may specify the destination object identifier (OID). The MIB information may include the information to be retrieved and the information to be written. The MIB information may include the object identifier (OID) associated with the information to be retrieved. Similarly, the MIB information may include the object identifier (OID) associated with the information to be written. The MIB information may also include the IP address of the image forming apparatus 200 to be accessed, i.e., the first image forming apparatus.
[0040] If the plaintext packet is a packet requesting reading, the MIB information does not include the information to be acquired. If the plaintext packet is a response packet to a packet requesting reading, the MIB information includes the acquired information. If the plaintext packet is a packet requesting writing, the MIB information includes the information to be written. If the plaintext packet is a response packet to a packet requesting writing, the MIB information may include the written information.
[0041] Fig. 4 is a diagram illustrating an example of an encrypted packet transmitted in the communication system 1 according to the first embodiment. The encrypted packet illustrated in Fig. 4 corresponds to the plaintext packet defined by SNMPv1 illustrated in Fig. 3, in which the MIB information has been encrypted. As described above, the encrypted packet is not limited to the packet in the format illustrated in Fig. 4, but may be a packet defined by SNMPv3.
[0042] As illustrated in FIG. 4, the encrypted packet may include an IP header, a message version, a message ID, a community name, and a PDU. The PDU may include a PDU type, a request identifier indicated by arrow D0, and MIB information indicated by arrow D1. Here, the MIB information indicated by arrow D1 is encrypted using an encryption method specified by manufacturer X. Specifically, the MIB information indicated by arrow D1 is encrypted using a combination key that combines an administrator password known to the administrator of third-party SP1 with a key specified by manufacturer X. Therefore, the MIB information indicated by arrow D1 includes, in encrypted form, information enclosed by a dashed line indicated by arrow D2.
[0043] The MIB information indicated by arrow D1 includes information about the contents to be read or written at the access destination. The MIB information indicated by arrow D1 may include a PDU type, a request identifier indicated by arrow D3, and MIB information. The request identifier indicated by arrow D3 corresponds to the request identifier of the plaintext packet illustrated in FIG. 3 and may specify the destination object identification information (OID). The MIB information indicated by arrow D4 corresponds to the MIB information of the plaintext packet illustrated in FIG. 3 and may include information to be retrieved and information to be written.
[0044] Here, the request identifier indicated by arrow D0 indicates an encrypted object identification (OID) that indicates an area for processing the encrypted packet. That is, in the first embodiment, the encrypted object identification is provided in advance. In the encrypted packet, the request identifier indicated by arrow D0 may be fixed. When the image forming apparatus 200A receives an access packet, if the encrypted object identification is specified in the request identifier indicated by arrow D0, the image forming apparatus 200A determines that the access packet is an encrypted packet and decrypts the encrypted MIB information.
[0045] Fig. 5 is a diagram illustrating a disclosure information file 100a according to the first embodiment. As illustrated in Fig. 5, the disclosure information file 100a includes one or more pieces of disclosed model identification information. In the example of Fig. 5, the disclosure information file 100a includes model A1, model A2, ..., model An as the disclosed model identification information. That is, model A1, model A2, ..., model An correspond to the image forming device 200A shown in Figs. 1 and 2.
[0046] The disclosure information file 100a also includes, for each disclosure model identification, a disclosure object condition for the corresponding model. The disclosure object condition indicates, for example, a list of disclosure object identification information. In other words, the disclosure object condition indicates a list of object identification information (OID) of information that is permitted to be disclosed to the third party SP1. Furthermore, the disclosure object condition may indicate a list of disclosure object identification information of information that is encrypted using a method specified by manufacturer X, among the disclosure object identification information.
[0047] 6 is a diagram illustrating a configuration of an information processing device 100 according to the first embodiment. The information processing device 100 according to the first embodiment has, as its main hardware components, a processing unit 102, a storage unit 104, a communication unit 106, and an interface unit 108 (IF: Interface). The processing unit 102, the storage unit 104, the communication unit 106, and the interface unit 108 may be connected to each other via a data bus or the like.
[0048] The processing unit 102 is a processor such as a CPU (Central Processing Unit). The processing unit 102 may have multiple processors. The processing unit 102 functions as a calculation device that performs control processing, calculation processing, and the like. The processing unit 102 controls the storage unit 104, the communication unit 106, and the interface unit 108. The processing unit 102 also executes at least the service software 110 and the access software 120.
[0049] The storage unit 104 is a storage device such as a memory or a hard disk. The storage unit 104 is, for example, a read-only memory (ROM) or a random access memory (RAM). The storage unit 104 may have multiple memories. The storage unit 104 has a function for storing control programs, calculation programs, etc. executed by the processing unit 102. The storage unit 104 also has a function for temporarily storing processing data, etc. The storage unit 104 may include a database. The storage unit 104 stores the service software 110 and access software 120 installed in the information processing device 100.
[0050] The communication unit 106 performs processing necessary for the information processing device 100 to communicate with other devices via a network. The communication unit 106 may include a communication port, a router, a firewall, etc. The communication unit 106 performs processing for the information processing device 100 to communicate with the image forming device 200 via the network 2.
[0051] The interface unit 108 is, for example, a user interface. The interface unit 108 has an input device such as a keyboard, a touch panel, or a mouse, and an output device such as a display or a speaker. The interface unit 108 may be configured such that the input device and the output device are integrated, for example, as in a touch screen or a touch panel. The interface unit 108 accepts data input operations by the user of the information processing device 100, and outputs information to the user.
[0052] The information processing device 100 according to the first embodiment includes, as its components, the above-described service software 110, a disclosure information file storage unit 112, a connection information storage unit 114, and the above-described access software 120. The access software 120 includes, as its components, a request acquisition unit 122, a connection information registration unit 130, a response processing unit 140, and a connection information deletion unit 170. The response processing unit 140 includes, as its components, a manufacturer information acquisition unit 142, an access determination unit 144, an access processing unit 150, and a response output unit 162.
[0053] Each of the above-described components can be realized, for example, by executing a program under the control of the processing unit 102. More specifically, each component can be realized by the processing unit 102 executing a program stored in the storage unit 104. Alternatively, each component may be realized by recording the necessary program on an arbitrary non-volatile recording medium and installing it as needed.
[0054] Furthermore, each component may not necessarily be realized by software programs, but may be realized by any combination of hardware, firmware, and software. Each component may also be realized by a user-programmable integrated circuit, such as an FPGA (field-programmable gate array) or a microcomputer. In this case, a program consisting of each of the above components may be realized by using this integrated circuit.
[0055] The disclosure information file storage unit 112 stores the above-mentioned disclosure information file 100a. As described above, the disclosure information file storage unit 112 stores the disclosure information file 100a in an encrypted state. The disclosure information file storage unit 112 may be realized by the memory unit 104.
[0056] The connection information storage unit 114 stores connection information. The connection information is used by the response processing unit 140 (described later) to access the image forming apparatus 200. The connection information will be described later. The connection information storage unit 114 may be realized by the storage unit 104.
[0057] In the access software 120, the request acquisition unit 122 acquires the access request packet output from the service software 110. The request acquisition unit 122 starts the operation of the connection information registration unit 130, the response processing unit 140, or the connection information deletion unit 170, which will be described later, in accordance with the identifier specified by the request identifier included in the PDU of the access request packet. Details will be described later.
[0058] The connection information registration unit 130 performs processing to register connection information to be stored in the connection information storage unit 114. In other words, the connection information registration unit 130 performs processing to prepare for the access software 120 to access the image forming apparatus 200. In other words, the connection information registration unit 130 can be said to perform processing to log in to the access software 120. The connection information registration unit 130 acquires manufacturer information of the image forming apparatus 200 from the image forming apparatus 200. When the manufacturer information indicates a predetermined manufacturer, Manufacturer X, and information is acquired from the image forming apparatus 200 using the first protocol, the connection information registration unit 130 registers connection information related to the image forming apparatus 200. This allows the access processing unit 150, which will be described later, to perform processing to access the first image forming apparatus to be accessed using the registered connection information. Details of the processing by the connection information registration unit 130 will be described later.
[0059] Response processing unit 140 performs processing to access image forming device 200, which is the first image forming device, in response to the access request packet. Response processing unit 140 also receives a response to the access request packet from the first image forming device and performs processing to output the response to service software 110, which is the request source of the access request packet.
[0060] The manufacturer information acquisition unit 142 acquires manufacturer information indicating the manufacturer that provided the first image forming device. Specifically, the manufacturer information acquisition unit 142 acquires the manufacturer information from the first image forming device. More specifically, the manufacturer information acquisition unit 142 acquires the IP address of the first image forming device specified in the access request packet. Then, the manufacturer information acquisition unit 142 transmits a manufacturer information request packet defined by the second protocol to the IP address. That is, the manufacturer information acquisition unit 142 transmits the manufacturer information request packet defined by SNMPv1 to the first image forming device. When the image forming device 200, which is the first image forming device, receives the manufacturer information request packet, it transmits a response packet including its own manufacturer information to the information processing device 100. As a result, the manufacturer information acquisition unit 142 acquires the manufacturer information of the first image forming device.
[0061] The access determination unit 144 determines whether or not it is possible to access the image forming device 200, which is the first image forming device, in response to the access request packet, using the manufacturer information and the disclosure information file 100a stored in the disclosure information file storage unit 112. Furthermore, the access determination unit 144 determines whether to access the image forming device 200, which is the first image forming device, using the manufacturer information and the disclosure information file 100a, using the first protocol or the second protocol.
[0062] Specifically, if the manufacturer information does not indicate manufacturer X, that is, if the first image forming device is provided by a manufacturer other than manufacturer X, access determination unit 144 determines to access the first image forming device using the second protocol. On the other hand, if the manufacturer information indicates manufacturer X, that is, if the first image forming device is provided by manufacturer X, access determination unit 144 determines whether or not it is possible to access the information of the first image forming device.
[0063] Specifically, access determination unit 144 acquires model identification information of the first image forming apparatus. Specifically, access determination unit 144 acquires the IP address of the first image forming apparatus that is the access destination in the access request packet. Then, access determination unit 144 transmits a model identification information request packet defined by the second protocol to the IP address. That is, access determination unit 144 transmits a model identification information request packet defined by SNMPv1 to the first image forming apparatus. When image forming apparatus 200, which is the first image forming apparatus, receives the model identification information request packet, it transmits a response packet including its own model identification information to information processing apparatus 100. As a result, access determination unit 144 acquires the model identification information of the first image forming apparatus.
[0064] The access determination unit 144 determines whether the model identification information acquired from the first image forming device is included in the disclosure information file 100a. In other words, the access determination unit 144 determines whether the model identification information acquired from the first image forming device matches the disclosed model identification information in the disclosure information file 100a. If the model identification information acquired from the first image forming device is not included in the disclosure information file 100a, the access determination unit 144 determines that the first image forming device is image forming device 200B. In other words, the access determination unit 144 determines that the first image forming device is image forming device 200 that is not permitted to disclose information to third party SP1. Therefore, the access determination unit 144 determines not to access the first image forming device and to output a response indicating an error message to third party SP1.
[0065] On the other hand, if the model identification information acquired from the first image forming device is included in the disclosure information file 100a, the access determination unit 144 determines that the first image forming device is the image forming device 200A. In other words, the access determination unit 144 determines that the first image forming device is the image forming device 200 that is permitted to be accessed by the third party SP1.
[0066] In this case, the access determination unit 144 acquires object identification information that identifies the information to be accessed from the access request packet. The access determination unit 144 then determines whether the object identification information acquired from the access request packet is included in the disclosure information file 100a. In other words, the access determination unit 144 determines whether the object identification information acquired from the access request packet matches the disclosed object identification information in the disclosure information file 100a. If the object identification information is not included in the disclosure information file 100a, the access determination unit 144 determines that the access request packet is requesting access to information that the third party SP1 is not permitted to disclose. Therefore, the access determination unit 144 determines not to access the specified information of the first image forming apparatus and to output a response indicating an error message to the third party SP1.
[0067] On the other hand, if the object identification information is included in the disclosure information file 100a, the access determination unit 144 determines that the access request packet is requesting access to information that is permitted to be disclosed to the third party SP1. In this case, the access determination unit 144 uses the disclosure information file 100a to determine whether the information corresponding to the object identification information is to be encrypted. Specifically, the access determination unit 144 determines whether the object identification information is included in the list of disclosed object identification information in the disclosure information file 100a that is to be encrypted using a method specified by manufacturer X. If the information corresponding to the object identification information is to be encrypted, the access determination unit 144 determines that the specified information of the first image forming device is to be accessed using the first protocol. On the other hand, if the information corresponding to the object identification information is not to be encrypted, the access determination unit 144 determines that the specified information of the first image forming device is to be accessed using the second protocol.
[0068] The access processing unit 150 performs processing for accessing the first image forming apparatus using the access method determined by the access determination unit 144. Specifically, the access processing unit 150 performs processing for transmitting, to the first image forming apparatus, an access packet defined by a communication protocol corresponding to the access method determined by the access determination unit 144. More specifically, when the access determination unit 144 determines that the first image forming apparatus is to be accessed using the first protocol, the access processing unit 150 performs processing for accessing information stored in the first image forming apparatus using the first protocol. On the other hand, when the access determination unit 144 determines that the first image forming apparatus is to be accessed using the second protocol, the access processing unit 150 performs processing for accessing information stored in the first image forming apparatus using the second protocol.
[0069] More specifically, if the manufacturer information does not indicate manufacturer X, the access processing unit 150 performs processing to access information stored in the first image forming device using the second protocol. More specifically, the access processing unit 150 converts the access request packet into a plaintext packet specified by the second protocol. Then, the access processing unit 150 transmits the plaintext packet specified by the second protocol as an access packet to the first image forming device. As a result, the first image forming device transmits a response packet specified by the second protocol to the information processing device 100, indicating the result of the access requested in the access request packet. Then, the access processing unit 150 receives the response packet from the first image forming device. Note that a method for converting the access request packet into a plaintext packet specified by the second protocol will be described later.
[0070] Furthermore, when the manufacturer information indicates manufacturer X and a predetermined condition is satisfied, the access processing unit 150 performs processing to access information stored in the first image forming device using the first protocol. Specifically, consider a first case in which the manufacturer information indicates manufacturer X and the first image forming device is image forming device 200A. In this first case, the access processing unit 150 performs processing to access the first image forming device using the first protocol if a predetermined condition, described below, is satisfied. More specifically, consider a second case in which, in the first case, the model identification information of the first image forming device is included in the disclosure information file 100a. In this second case, the access processing unit 150 performs processing to access the first image forming device using the first protocol if a predetermined condition, described below, is satisfied.
[0071] Specifically, consider a third case in which, in the second case, the object identification information of the information to be accessed in the first image forming apparatus is included in the disclosure information file 100a. In this third case, if a predetermined condition described below is satisfied, the access processing unit 150 performs processing to access the first image forming apparatus using the first protocol. Specifically, if the disclosure information file indicates that the object identification information is to be encrypted, the access processing unit 150 performs processing to access the first image forming apparatus using the first protocol. Specifically, the access processing unit 150 generates an encrypted packet using an access request packet. Then, the access processing unit 150 transmits the generated encrypted packet to the first image forming apparatus as an access packet. In response, the first image forming apparatus transmits a response packet specified by the first protocol to the information processing apparatus 100, indicating the result of the access requested in the access request packet. Then, the access processing unit 150 receives the response packet from the first image forming apparatus. Since the response packet received from the first image forming apparatus is encrypted, the access processing unit 150 decrypts the response packet to generate a plaintext response packet. That is, the access processing unit 150 converts the response packet defined in the first protocol into a response packet defined in the second protocol. A method for generating an encrypted packet using an access request packet will be described later.
[0072] In the third case described above, if a predetermined condition described later is not satisfied, the access processing unit 150 performs processing to access the first image forming apparatus using the second protocol. Specifically, if the disclosure information file indicates that the object identification information is not subject to encryption, the access processing unit 150 performs processing to access the first image forming apparatus using the second protocol. The processing by the access processing unit 150 at this time may be substantially the same as the processing performed when the manufacturer information does not indicate manufacturer X.
[0073] The response output unit 162 outputs a response to the access request to the request source that made the access request. Specifically, the response output unit 162 outputs a response corresponding to the response packet received from the first image forming apparatus to the service software 110 of the third party SP1. The response output unit 162 outputs a response packet defined by the second protocol to the service software 110.
[0074] If the access fails, the response output unit 162 outputs a response indicating that the access has failed to the service software 110. In the first case described above, if the model identification information of the first image forming device is not included in the disclosure information file 100a, the response output unit 162 outputs a response indicating that the access has failed to the service software 110 of the third party SP1. In other words, if the model identification information of the first image forming device is not included in the disclosure information file 100a, the response output unit 162 outputs a response indicating that the access has failed.
[0075] Furthermore, in the second case described above, if the object identification information of the information to be accessed in the first image forming apparatus is not included in the disclosure information file 100a, the response output unit 162 outputs a response indicating that the access has failed to the service software 110 of the third party SP1. In other words, if the object identification information corresponding to the information to be accessed is not included in the disclosure information file 100a, the response output unit 162 outputs a response indicating that the access has failed.
[0076] The connection information deletion unit 170 performs processing to delete the connection information stored in the connection information storage unit 114. In other words, the connection information deletion unit 170 performs processing to terminate the processing in which the access software 120 accesses the image forming apparatus 200. In other words, it can be said that the connection information deletion unit 170 performs processing to log out from the access software 120.
[0077] 7 is a diagram showing the configuration of the image forming apparatus 200 according to the first embodiment. The image forming apparatus 200 has, as its main hardware components, a processing unit 202, a storage unit 204, a communication unit 206, an interface unit 208, and a printing unit 210. The processing unit 202, the storage unit 204, the communication unit 206, the interface unit 208, and the printing unit 210 may be connected to each other via a data bus or the like.
[0078] The processing unit 202 is, for example, a processor such as a CPU. The processing unit 202 may have multiple processors. The processing unit 202 functions as a calculation device that performs control processing, calculation processing, and the like. The processing unit 202 controls the storage unit 204, the communication unit 206, the interface unit 208, and the printing unit 210.
[0079] The storage unit 204 is a storage device such as a memory or a hard disk. The storage unit 204 is a ROM or a RAM. The storage unit 204 has a function for storing control programs, calculation programs, etc. executed by the processing unit 202. The storage unit 204 also has a function for temporarily storing processing data, etc. The storage unit 204 may include a database.
[0080] The communication unit 206 performs processing necessary for the image forming apparatus 200 to communicate with other apparatuses via a network. The communication unit 206 may include a communication port, a router, a firewall, etc. The communication unit 206 performs processing for the image forming apparatus 200 to communicate with the information processing apparatus 100 via the network 2. The communication unit 206 also sends and receives packets defined by SNMP.
[0081] The interface unit 208 has an input device such as a button, keyboard, touch panel, or mouse, and an output device such as a display or speaker. The interface unit 208 may be configured with an input device and an output device integrated together. The interface unit 208 accepts data input operations by the user and outputs information to the user. The interface unit 208 includes an operation panel.
[0082] The printing unit 210 has a printing function for forming an image on paper, i.e., a print medium. The printing unit 210 includes a print engine. A print engine is a mechanical configuration that prints an image on a print medium. The print engine may have, for example, a mechanism that prints using toner using an electrophotographic method. Alternatively, the print engine may have, for example, a mechanism that prints using an inkjet method. The print engine may also have a transport mechanism that transports the print medium.
[0083] The image forming apparatus 200 according to the first embodiment also includes a monitoring unit 220 as a component. The monitoring unit 220 monitors a management information database stored in the image forming apparatus 200. The monitoring unit 220 can correspond to an SNMP agent defined by SNMP. The monitoring unit 220 also includes a management information storage unit 222, a request receiving unit 224, an information processing unit 226, and a response transmitting unit 230 as components.
[0084] Each of the above-described components can be realized, for example, by executing a program under the control of the processing unit 202. More specifically, each component can be realized by the processing unit 202 executing a program stored in the storage unit 204. Alternatively, each component may be realized by recording the necessary program on an arbitrary non-volatile recording medium and installing it as needed.
[0085] Furthermore, each component may not necessarily be realized by software programs, but may be realized by any combination of hardware, firmware, and software. Each component may also be realized using a user-programmable integrated circuit, such as an FPGA or a microcomputer. In this case, a program consisting of each of the above components may be realized using this integrated circuit.
[0086] The management information storage unit 222 stores a management information database (MIB) related to the image forming apparatus 200. The request receiving unit 224 receives an access packet transmitted from the information processing apparatus 100, that is, a plaintext packet or an encrypted packet.
[0087] The information processing unit 226 performs processing according to the request indicated in the access packet. If the access packet is encrypted, that is, if the access packet is an encrypted packet, the information processing unit 226 decrypts the access packet. The information processing unit 226 analyzes the content of the request indicated in the access packet. The information processing unit 226 reads or writes information according to the content of the request. Then, the information processing unit 226 generates a response packet indicating the access result. If the access packet is encrypted, the information processing unit 226 encrypts the response packet using an encryption method specified by manufacturer X.
[0088] Furthermore, the information processing unit 226 determines the type of access indicated in the access packet. If the type of access indicated in the access packet is "Read," the information processing unit 226 reads information corresponding to the object identification information indicated in the access packet from the management information database stored in the management information storage unit 222. Then, the information processing unit 226 generates a response packet including the read information. If the type of access indicated in the access packet is "Write," the information processing unit 226 writes the information indicated in the access packet to an area corresponding to the object identification information indicated in the access packet. In other words, the information processing unit 226 rewrites the information corresponding to the object identification information indicated in the access packet with the information indicated in the access packet. Then, the information processing unit 226 generates a response packet indicating the result of the write. The response packet may be a packet specified by SNMP. The plaintext response packet may be a packet specified by the second protocol. The encrypted response packet may be a packet specified by the first protocol.
[0089] The response transmitting unit 230 transmits the response packet generated by the information processing unit 226 to the information processing device 100. In response to this, the access software 120 that has received the response packet outputs a response to the service software 110.
[0090] FIG. 8 is a diagram illustrating details of the processing in the communication system 1 according to the first embodiment. When the service software 110 outputs a login request to the access software 120, the connection information registration unit 130 of the access software 120 performs login processing (step S10). Here, the login request from the service software 110 is made using a login request packet defined by the second protocol. For example, in the login request packet, an object identification (OID) provided for the access software 120 is specified in the "request identifier" of the plaintext packet illustrated in FIG. 3. Also, for example, in the login request packet, the IP address of the image forming apparatus 200 to which the third party SP1 desires to connect is specified in the "MIB information" of the plaintext packet illustrated in FIG. 3. When the access software 120 receives such a login request packet from the service software 110, the connection information registration unit 130 performs login processing as described below. In the login processing, when communicating with the image forming apparatus 200 provided by the manufacturer X, the connection information registration unit 130 communicates using the first protocol. Furthermore, in the login process, when communicating with the image forming device 200 provided by a manufacturer other than the manufacturer X, the connection information registration unit 130 communicates using the second protocol, which will be described in detail later.
[0091] When the service software 110 outputs an access request to the access software 120, the response processing unit 140 of the access software 120 performs response processing (step S20). Here, the access request from the service software 110 is made by an access request packet defined by the second protocol. For example, in the access request packet, a loopback address is specified in the "request identifier" of the plaintext packet illustrated in FIG. 3. Also, for example, in the access request packet, object identification information of the information to which the third party SP1 wishes to access is specified in the "MIB information" of the plaintext packet illustrated in FIG. 3. Also, for example, in the access request packet, identification information of the image forming apparatus 200 to which the third party SP1 wishes to access and the type of access are specified in the "community name" of the plaintext packet illustrated in FIG. 3. When the access software 120 receives such an access request packet from the service software 110, the response processing unit 140 performs response processing as described below. In response processing, in communication with the image forming device 200 provided by manufacturer X, the response processing unit 140 communicates using the first protocol or the second protocol depending on whether the information is encrypted or not. In response processing, in communication with the image forming device 200 provided by a manufacturer other than manufacturer X, the response processing unit 140 communicates using the second protocol. Details will be described later.
[0092] After the login process is completed, when the service software 110 outputs a logout request to the access software 120, the connection information deletion unit 170 of the access software 120 performs the logout process (step S30). Here, the logout request from the service software 110 is made by a logout request packet defined by the second protocol. The structure of the logout request packet may be substantially the same as the structure of the login request packet. The logout process may be the reverse process of the login process. In the logout process, when communicating with the image forming apparatus 200 provided by manufacturer X, the connection information deletion unit 170 may communicate using the first protocol. In the logout process, when communicating with the image forming apparatus 200 provided by a manufacturer other than manufacturer X, the connection information deletion unit 170 may communicate using the second protocol. The connection information deletion unit 170 deletes the connection information registered by the connection information registration unit 130 and stored in the connection information storage unit 114.
[0093] FIG. 9 is a diagram illustrating an example of connection information registered by the login process according to the first embodiment. The connection information includes, for each image forming apparatus 200, a model ID, a model IP address, a community name (Read), a community name (Read / Write), and an administrator password. The model ID is an identifier assigned to each image forming apparatus 200 by the login process described below. The model IP address is the IP address of the corresponding image forming apparatus 200. The community name (Read) and the community name (Read / Write) are community names defined in SNMPv1. The administrator password can be set when the corresponding image forming apparatus 200 is provided by manufacturer X. That is, in the example of FIG. 9, the image forming apparatuses 200 with connection IDs "1" and "2" are provided by manufacturer X, and the image forming apparatus 200 with connection ID "3" is provided by a manufacturer other than manufacturer X.
[0094] The information associated with the connection ID in the connection information may be information acquired from the service software 110. When the image forming apparatus 200 can be appropriately accessed using this information through a login process described later, the connection information registration unit 130 registers this information as connection information.
[0095] FIG. 10 is a flowchart showing the login process (S10) executed by the access software 120 according to the first embodiment. FIG. 11 shows a communication method executed by the access software 120. The connection information registration unit 130 reads the disclosure information file 100a from the disclosure information file storage unit 112 (step S102). The connection information registration unit 130 acquires manufacturer information (step S104). Specifically, the connection information registration unit 130 acquires manufacturer information of the image forming device 200 from the image forming device 200 having the IP address specified in the "MIB information" of the login request packet. The method of acquiring the manufacturer information is substantially the same as the acquisition method by the manufacturer information acquisition unit 142 described above, and therefore a description thereof will be omitted.
[0096] The connection information registration unit 130 determines whether the manufacturer information indicates manufacturer X (step S106). If the manufacturer information indicates manufacturer X (YES in S106), the connection information registration unit 130 acquires model identification information from the image forming device 200 described above (step S110). The method for acquiring the model identification information is substantially the same as the acquisition method by the access determination unit 144 described above, and therefore, description thereof will be omitted.
[0097] The connection information registration unit 130 determines whether the model identification information acquired in S110 is included in the disclosure information file 100a (step S112). If the model identification information is not included in the disclosure information file 100a (NO in S112), the connection information registration unit 130 does not register the connection information of the image forming device 200 and ends the login process.
[0098] On the other hand, if the disclosure information file 100a contains model identification information (YES in S112), the connection information registration unit 130 attempts to acquire information from the image forming apparatus 200 using the first protocol (step S114). Specifically, the connection information registration unit 130 transmits an encrypted packet to the image forming apparatus 200 requesting the reading of arbitrary information. The encrypted packet is encrypted using a combination key that combines the administrator password acquired from the service software 110 with a key specified by the manufacturer X. The connection information registration unit 130 then determines whether the information can be acquired (step S116). Specifically, the connection information registration unit 130 determines whether the image forming apparatus 200 transmits a response to the encrypted packet transmitted to the image forming apparatus 200 in S114. If the information cannot be acquired (NO in S116), this means that the information acquired from the service software 110, such as the administrator password, is incorrect. Therefore, the connection information registration unit 130 does not register the connection information of the image forming apparatus 200 and terminates the login process.
[0099] On the other hand, if the information is acquired (YES in S116), it means that the information acquired from the service software 110 is correct. Therefore, the connection information registration unit 130 registers the connection information (step S120). Specifically, a connection ID is assigned to the image forming apparatus 200, and the information acquired from the service software 110 is registered in association with the connection ID, as shown in FIG. 9. The connection information registration unit 130 then transmits the connection ID assigned to the image forming apparatus 200 to the service software 110. This allows the service software 110 to make a request to access the desired image forming apparatus 200 using the connection ID, as will be described later.
[0100] On the other hand, in the process of S106, if the manufacturer information does not indicate manufacturer X (NO in S106), the image forming device 200 will be accessed using the second protocol in the response process described below. Therefore, the connection information registration unit 130 registers the connection information (S120) without performing the processes of S110 to S116 described above.
[0101] 11 is a flowchart showing the response processing (S20) executed by the access software 120 according to the first embodiment. FIG. 11 shows a communication method executed by the access software 120. The request acquisition unit 122 acquires an access request packet for requesting access to the first image forming apparatus from the service software 110 (step S200). As described above, the access request packet is a packet defined by SNMPv1, as shown in FIG. 3. If a loopback address is specified in the "request identifier" of the access request packet, the response processing unit 140 of the access software 120 starts the response processing.
[0102] The “community name” of the access request packet specifies a character string that combines the connection ID and connection identifier corresponding to the first image forming apparatus. The connection ID is associated with the first image forming apparatus in the connection information registered in the login process described above and is transmitted from the access software 120 to the service software 110. The connection identifier is a character string that specifies the access type, i.e., read or write. For example, the connection identifier specifying read may be “R.” The connection identifier specifying both read and write may be “RW.” If the access type is “read,” the “community name” is specified as “ID&R.” If the access type is “read and write,” the “community name” is specified as “ID&RW.” When attempting to access the first image forming apparatus, the service software 110 specifies the character string that combines the connection ID and connection identifier as described above as the community name. If “ID&R” is specified as the “community name” of the access request packet, the access software 120 performs processing to access the first image forming apparatus using the “community name (Read)” corresponding to the connection ID in the connection information. Furthermore, if "ID&RW" is specified as the "community name" of the access request packet, the access software 120 performs processing to access using the "community name (Read / Write)" corresponding to the connection ID in the connection information.
[0103] The response processing unit 140 determines whether the connection ID exists in the connection information (step S202). Specifically, the response processing unit 140 determines whether the connection ID included in the "community name" of the access request packet is included in the connection information stored in the connection information storage unit 114. In the example of FIG. 9, if the connection ID included in the "community name" is "1," "2," or "3," the connection ID exists in the connection information. On the other hand, if the connection ID included in the "community name" is "4," the connection ID does not exist in the connection information.
[0104] If the connection ID does not exist in the connection information (NO in S202), the response processing unit 140 determines that the service software 110 is attempting to access the image forming apparatus 200 to which it was unable to properly connect during the login process. In this case, the response output unit 162 outputs a response indicating that the access has failed to the service software 110 (step S203). In other words, the response output unit 162 outputs an error message to the service software 110.
[0105] On the other hand, if the connection ID exists in the connection information (YES in S202), the manufacturer information acquisition unit 142 acquires the manufacturer information from the first image forming apparatus as described above (step S204). The access determination unit 144 determines whether the manufacturer information acquired in S204 indicates manufacturer X (step S206).
[0106] If the manufacturer information acquired in S204 does not indicate manufacturer X (NO in S206), the access processing unit 150 performs processing to access information stored in the first image forming apparatus using the second protocol (step S208). At this time, the access processing unit 150 converts the access request packet into an access packet, which is a plaintext packet defined by the second protocol, as follows. As described above, the destination IP address of the access request packet is a loopback address. Therefore, the access processing unit 150 references the connection information and sets the destination IP address of the access packet to the IP address corresponding to the connection ID specified in the "community name" of the access request packet. Furthermore, the access processing unit 150 references the connection information and sets the "community name" of the access packet to the "community name" corresponding to the connection identifier specified in the "community name" of the access request packet. In the example of FIG. 9, for example, if the community name of the access request packet is specified as "3&R," the access processing unit 150 sets "public," which is the "community name (Read)" corresponding to ID=3, to the "community name" of the access packet. Also, for example, if the "community name" of the access request packet is specified as "3&RW", the access processing unit 150 sets "writeC" of the "community name (Read / Write)" corresponding to ID=3 as the "community name" of the access packet.
[0107] The access processing unit 150 then transmits the access packet, which is a plaintext packet as described above, to the first image forming apparatus. The access processing unit 150 then receives a response packet from the first image forming apparatus. The response output unit 162 then outputs the received response packet, which is a response to the request, to the service software 110, which is the requestor that made the access request.
[0108] On the other hand, if the manufacturer information acquired in S204 indicates manufacturer X (YES in S206), the access determination unit 144 acquires model identification information from the first image forming apparatus (step S210). Specifically, the access determination unit 144 references the connection information and acquires an IP address corresponding to the connection ID specified in the access request packet. Then, the access determination unit 144 sends a model identification information request packet defined by the second protocol to the IP address. As a result, the access determination unit 144 acquires the model identification information of the first image forming apparatus.
[0109] The access determination unit 144 determines whether the model identification information acquired in S210 is included in the disclosure information file 100a (step S212). If the model identification information is not included in the disclosure information file 100a (NO in S212), the access request packet requests access to the image forming device 200B, which is not permitted to disclose information to the third party SP1. Therefore, the response output unit 162 outputs a response indicating that the access has failed to the service software 110 (S203).
[0110] On the other hand, if the model identification information is included in the disclosure information file 100a (YES in S212), the access request packet is a request for access to the image forming device 200A, which is permitted to disclose information to the third party SP1. In this case, the access determination unit 144 acquires object identification information (step S214). Specifically, the access determination unit 144 acquires the object identification information of the information to be accessed from the access request packet. For example, the access determination unit 144 may acquire the object identification information of the information to be accessed from the "MIB information" of the access request packet.
[0111] The access determination unit 144 then determines whether the object identification information acquired in S214 is included in the disclosure information file 100a (step S216). If the object identification information is not included in the disclosure information file 100a (NO in S216), the access request packet requests access to information that the third party SP1 is not permitted to disclose. Therefore, the response output unit 162 outputs a response indicating that the access has failed to the service software 110 (S203).
[0112] On the other hand, if the object identification information is included in the disclosure information file 100a (YES in S216), the access request packet requests access to information that is permitted to be disclosed to the third party SP1. In this case, the access determination unit 144 uses the disclosure information file 100a to determine whether the object of the object identification information is to be encrypted (step S218).
[0113] If the object of the object identification information is to be encrypted (YES in S218), the access request packet requests access to information that is permitted to be disclosed to the third party SP1 and is to be encrypted. Therefore, the access processing unit 150 performs processing to access the first image forming apparatus using the first protocol (step S220). The access processing unit 150 uses the access request packet to generate an access packet, which is an encrypted packet defined by the first protocol, as follows.
[0114] The access processing unit 150 uses the access request packet acquired from the service software 110 to generate an access packet, which is an encrypted packet in the format shown in FIG. 4. The IP address and "community name" of the destination of the access packet are specified using the connection information, similar to the process of S208 described above. The access processing unit 150 also specifies the predetermined encrypted object identification information described above in the "request identifier" of the access packet, indicated by arrow D0 in FIG. 4. The access processing unit 150 also encrypts the PDU in the access request packet using a combination key that combines the administrator password corresponding to the connection ID in the connection information with a key specified by manufacturer X. In this way, the access processing unit 150 encrypts, in the access packet, the object identification information corresponding to the information to be accessed and the information to be written when the access type is write. That is, in the access packet, the object identification information corresponding to the information to be accessed and the information to be written when the access type is write are included in the encrypted "MIB information" indicated by arrow D1 in FIG. 4. For example, in an access packet, information to be written when the access type is write is included in the "MIB information" indicated by arrow D4 in Fig. 4. Also, in an access packet, object identification information corresponding to the information of the access destination may be included in the "request identifier" indicated by arrow D3 in Fig. 4, or may be included in the "MIB information" indicated by arrow D4 in Fig. 4.
[0115] The access processing unit 150 transmits the access packet, which is an encrypted packet as described above, to the first image forming apparatus. The access processing unit 150 then receives a response packet from the first image forming apparatus. The response packet received from the first image forming apparatus is an encrypted packet defined by the first protocol. Therefore, the access processing unit 150 converts the response packet defined by the first protocol into a response packet defined by the second protocol. Specifically, the access processing unit 150 decrypts the response packet to obtain the response packet, which is a plaintext packet defined by the second protocol. More specifically, the access processing unit 150 decrypts the encrypted "MIB information" of the response packet, which is an encrypted packet as illustrated in FIG. 4, and replaces the decrypted "MIB information" with the PDU of the plaintext packet as illustrated in FIG. 3. The response output unit 162 then outputs the converted response packet, which is a response to the request, to the service software 110, which is the request source that made the access request.
[0116] On the other hand, if the object of the object identification information is not to be encrypted (NO in S218), the access request packet requests access to information that is permitted to be disclosed to the third party SP1 but is not to be encrypted. Therefore, the access processing unit 150 performs processing to access the first image forming apparatus using the second protocol (S208). The processing by the access processing unit 150 in this case is substantially the same as the processing when the manufacturer information does not indicate manufacturer X, and therefore a description thereof will be omitted.
[0117] The access software 120 according to the first embodiment performs processing for accessing information stored in the first image forming device using the first protocol when the manufacturer information of the first image forming device indicates a predetermined manufacturer and a predetermined condition is satisfied. Furthermore, the access software 120 according to the first embodiment performs processing for accessing information stored in the first image forming device using the second protocol when the manufacturer information does not indicate a predetermined manufacturer. With this configuration, even in an environment where information permitted for disclosure and information not permitted for disclosure coexist, a third party can appropriately request access to the image forming device 200 using the access software 120. Furthermore, by using the access software 120, a third party can request access to information on the image forming device 200 provided by a predetermined manufacturer without recognizing the specifications of the first protocol. Therefore, the information processing device 100 according to the first embodiment can mitigate security issues.
[0118] In the first embodiment, the first protocol may be a communication protocol in which at least a portion of packets transmitted to and received from the first image forming apparatus are encrypted. The second protocol may be a communication protocol in which packets transmitted to and received from the first image forming apparatus are not encrypted. This configuration allows a third party to appropriately request access to information about the image forming apparatus 200 provided by a specific manufacturer that is kept confidential from parties other than the specific manufacturer but can be disclosed to third parties. This reduces security issues.
[0119] Furthermore, the access software 120 performs processing to access the first image forming device using the first protocol when the manufacturer information indicates a specific manufacturer, the first image forming device is a target for information disclosure to the requester, and specific conditions are met. Furthermore, the access software 120 performs processing to access the first image forming device using the first protocol when the model identification information is included in the disclosure information file and specific conditions are met. If the model identification information is not included in the disclosure information file, the access software 120 outputs a response indicating that the access has failed to the requester. With this configuration, even if a third party requesting access attempts to access an image forming device for which information disclosure is not permitted, the access software 120 does not output a response to the access request. This prevents information leakage from image forming devices for which information disclosure is not permitted. This reduces security issues.
[0120] Furthermore, if object identification information identifying the information to be accessed is included in the disclosure information file and a predetermined condition is met, the access software 120 performs processing to access the first image forming device using the first protocol. Furthermore, if the object identification information is not included in the disclosure information file, the access software 120 outputs a response indicating that the access has failed. With this configuration, even if a third party requesting access attempts to access information on an image forming device for which disclosure is not permitted, the access software 120 does not output a response to the access request. Therefore, it is possible to prevent the leakage of information on an image forming device for which disclosure is not permitted. Therefore, security issues can be alleviated.
[0121] Furthermore, when the disclosure information file indicates that the object identification information is to be encrypted, the access software 120 performs processing to access the first image forming apparatus using the first protocol. This configuration allows a third party to appropriately request access to the information to be encrypted without knowing the encryption method. This reduces security issues.
[0122] Furthermore, when the manufacturer information of an image forming device indicates a specific manufacturer and information is acquired from the image forming device using the first protocol, access software 120 registers connection information related to the image forming device. Then, access software 120 performs processing to access the first image forming device using the connection information. This configuration allows a third party to easily request access to the image forming device using an access request packet defined by the first protocol. Therefore, security issues can be alleviated.
[0123] (Variation) The present invention is not limited to the above-described embodiment, and modifications may be made as appropriate without departing from the spirit and scope of the present invention. For example, the order of the processes in the above-described flowcharts may be modified as appropriate. Furthermore, one or more of the processes in the above-described flowcharts may be omitted. For example, in the flowchart of FIG. 10, the process of S102 may be performed at any timing before the process of S112.
[0124] Furthermore, in the above-described embodiment, the information processing device 100 has the service software 110 and the access software 120, but this configuration is not limited to this. The device in which the service software 110 is provided may be different from the device in which the access software 120 is provided. For example, the service software 110 may be provided in a third-party terminal device, and the access software 120 may be provided in the information processing device 100, such as a server, that is communicatively connected to the terminal device.
[0125] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disk (DVD), Blu-ray® disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals. The program may also be included in a program product. [Explanation of symbols]
[0126] 1...communication system, 2...network, 90...terminal device, 100...information processing device, 100a...disclosure information file, 102...processing unit, 104...storage unit, 106...communication unit, 108...interface unit, 110...service software, 112...disclosure information file storage unit, 114...connection information storage unit, 120...access software, 122...request acquisition unit, 130...connection information registration unit, 140...response processing unit, 142...manufacturer information acquisition unit, 144...access determination unit, 150...access processing unit, 162...response output unit, 170...connection information deletion unit, 200...image forming device, 202...processing unit, 204...storage unit, 206...communication unit, 208...interface unit, 210...printing unit, 220...monitoring unit, 222...management information storage unit, 224...request receiving unit, 226...information processing unit, 230...response sending unit
Claims
1. An information processing apparatus communicably connected to a plurality of image forming apparatuses, a manufacturer information acquisition unit that acquires manufacturer information corresponding to a first image forming apparatus in response to a request to access the first image forming apparatus among the plurality of image forming apparatuses; an access processing unit that performs processing for accessing the first image forming apparatus in accordance with the manufacturer information; a response output unit that outputs a response to the request to a request source that has made the access request; and The access processing unit performing a process for accessing information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and a predetermined condition is satisfied; If the manufacturer information does not indicate a predetermined manufacturer, a process is performed to access the information stored in the first image forming device using a second protocol different from the first protocol. Information processing device.
2. the first protocol is a communication protocol in which at least a part of packets transmitted to and received from the first image forming apparatus is encrypted; the second protocol is a communication protocol in which packets transmitted to and received from the first image forming apparatus are not encrypted; The information processing device according to claim 1 .
3. when the manufacturer information indicates a predetermined manufacturer, the first image forming apparatus is an image forming apparatus that is a target of information disclosure to the requester, and predetermined conditions are satisfied, the access processing unit performs processing for accessing the first image forming apparatus using the first protocol. The information processing device according to claim 1 .
4. model identification information for identifying the model of the first image forming device is included in a pre-generated disclosure information file indicating information that can be disclosed to the requester, and when a predetermined condition is satisfied, the access processing unit performs processing for accessing the first image forming device using the first protocol. The information processing device according to claim 3 .
5. If the model identification information is not included in the disclosure information file, the response output unit outputs a response indicating that the access has failed. The information processing device according to claim 4 .
6. object identification information that identifies information to be accessed in the first image forming device is included in a pre-generated disclosure information file that indicates information that can be disclosed to the requester, and when a predetermined condition is satisfied, the access processing unit performs processing for accessing the first image forming device using the first protocol; The information processing device according to claim 3 .
7. If the object identification information is not included in the disclosure information file, the response output unit outputs a response indicating that the access has failed. The information processing device according to claim 6 .
8. when the disclosure information file indicates that the information of the object identification information is to be encrypted, the access processing unit performs processing for accessing the first image forming apparatus using the first protocol. The information processing device according to claim 6 .
9. the disclosure information file includes identification information of a model of an image forming apparatus that is a target of information disclosure to the requester, and identification information that identifies information that can be disclosed to the requester; The information processing device according to claim 4 .
10. a connection information registration unit that registers connection information used to access the image forming apparatus; and The connection information registration unit acquires manufacturer information of the image forming device; When the manufacturer information indicates a predetermined manufacturer and information is acquired from the image forming apparatus using the first protocol, the connection information relating to the image forming apparatus is registered; the access processing unit performs processing for accessing the first image forming apparatus using the connection information. The information processing device according to claim 1 .
11. Multiple image forming devices an information processing device communicably connected to the plurality of image forming devices; and The information processing device includes: a manufacturer information acquisition unit that acquires manufacturer information corresponding to a first image forming apparatus in response to a request to access the first image forming apparatus among the plurality of image forming apparatuses; an access processing unit that performs processing for accessing the first image forming apparatus in accordance with the manufacturer information; a response output unit that outputs a response to the request to a request source that has made the access request; and The access processing unit performing a process for accessing information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and a predetermined condition is satisfied; If the manufacturer information does not indicate a predetermined manufacturer, a process is performed to access the information stored in the first image forming device using a second protocol different from the first protocol. Communication system.
12. A communication method executed by an information processing device communicably connected to a plurality of image forming devices, comprising: acquiring manufacturer information corresponding to a first image forming apparatus in response to a request to access the first image forming apparatus; performing a process for accessing information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and a predetermined condition is satisfied; If the manufacturer information does not indicate a predetermined manufacturer, a process is performed to access information stored in the first image forming device using a second protocol different from the first protocol; outputting a response to the request to the request source that made the access request; Communication method.
13. A program executed by an information processing device communicably connected to a plurality of image forming devices, acquiring manufacturer information corresponding to a first image forming apparatus in response to a request to access the first image forming apparatus; performing a process for accessing information stored in the first image forming device using a first protocol when the manufacturer information indicates a predetermined manufacturer and a predetermined condition is satisfied; If the manufacturer information does not indicate a predetermined manufacturer, performing a process for accessing information stored in the first image forming device using a second protocol different from the first protocol; outputting a response to the request to a request source that has made the access request; A program that causes a computer to execute the following.
Citation Information
Patent Citations
Network printer system
JP2000330742A