Image forming apparatus, control method, program, and information processing device

The system allows secure and efficient data erasure in image forming devices through a management server-initiated process with encrypted notifications, addressing the challenge of remote data erasure and completion notification in image forming devices.

JP2025187252APending Publication Date: 2025-12-25CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024095898
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-13
Publication Date
2025-12-25

AI Technical Summary

Technical Problem

Existing image forming devices lack a secure and efficient method for data erasure that allows users other than the specified user to perform the operation and notify the specified user of completion, posing a risk of data leakage and tampering, especially when disposed of away from the main office.

Method used

A system is implemented where data erasure is initiated by a specific user via a management server, with encrypted notification information ensuring secure data deletion and completion notification, allowing users to erase data remotely and securely.

Benefits of technology

Enables secure and efficient data erasure in image forming devices located away from the main office, preventing data leakage and tampering, and ensuring the specified user is notified of completion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025187252000001_ABST
    Figure 2025187252000001_ABST
Patent Text Reader

Abstract

To enable notification to a specific user of the completion of data erasure while preventing leakage and tampering of information concerning data stored in an image forming apparatus.SOLUTION: The image forming apparatus includes erasure means for erasing data stored in a storage unit, and output means for outputting, in encrypted form, notification information indicating that the data has been erased when the erasure means erases the data.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an image forming apparatus, a control method, a program, and an information processing apparatus. [Background technology]

[0002] Image forming apparatuses that have recently been put on the market as printers or multifunction devices are equipped with many functions, and the data stored in these image forming apparatuses is also diverse.

[0003] Patent document 1 discloses a method in which a specific user performs a predetermined operation to execute a data erasure process on an image forming device, and then notifies the specific user of the completion of the data erasure process by means of a printout, email, or the like. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2004-159046 A Summary of the Invention [Problem to be solved by the invention]

[0005] However, the method of Patent Document 1 has a problem in that data stored in the image forming device cannot be erased by anyone other than the specified user, and there is a risk that information indicating data erasure may be tampered with by a third party. [Means for solving the problem]

[0006] An image forming apparatus according to one aspect of the present disclosure is characterized by comprising an erasing means for erasing data stored in a memory unit, and an output means for, when the erasing means erases the data, encrypting and outputting notification information indicating that the data has been erased. [Effects of the Invention]

[0007] According to the present disclosure, it is possible to appropriately output information indicating data erasure. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 illustrates an example of a system configuration. [Figure 2] FIG. 1 is a schematic diagram illustrating an example of the appearance of an image forming apparatus. [Figure 3] FIG. 1 is a schematic diagram illustrating an example of an internal structure of an image forming apparatus. [Figure 4] FIG. 1 is a block diagram showing an example of a configuration of an image forming apparatus. [Figure 5] FIG. 2 is a block diagram showing an example of the configuration of a terminal device. [Figure 6] FIG. 2 is a block diagram illustrating an example of a configuration of a management server. [Figure 7] FIG. 10 is a sequence diagram illustrating an example of information processing. [Figure 8] FIG. 10 is a flowchart illustrating an example of processing executed by a terminal device. [Figure 9] FIG. 10 is a flowchart illustrating an example of processing executed by a management server. [Figure 10] FIG. 4 is a flowchart illustrating an example of processing executed by the image forming apparatus. [Figure 11] FIG. 4 is a flowchart illustrating an example of processing executed by the image forming apparatus. [Figure 12] FIG. 10 is a diagram showing an example of a confirmation screen for data deletion. [Figure 13] FIG. 10 is a diagram illustrating an example of a confirmation necessity screen for a completion notification. [Figure 14] FIG. 10 is a diagram illustrating an example of a selection screen for a notification method for a completion notification. [Figure 15] FIG. 10 is a diagram showing an example of a final confirmation screen for data deletion. DETAILED DESCRIPTION OF THE INVENTION

[0009] Preferred embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the present disclosure, and not all combinations of features described in the following embodiments are necessarily essential to the solutions of the present disclosure. Note that the same components will be described with the same reference numerals.

[0010] In image forming devices that store various types of data, data initialization or deletion may be performed to prevent leakage of personal information when the device is disposed of, replaced, transported, etc. In addition, the use of the data deletion function provided in the image forming device may be restricted to specific users (service personnel, administrators, etc.).

[0011] Recently, there has been an increase in cases where business (e.g., company) image forming devices are installed outside the main office, such as when used for telecommuting. Furthermore, company image forming devices often store confidential information. Therefore, when disposing of an image forming device at a location where no specific user is employed, a user other than the specific user (a general employee) is required to perform the data erasure operation and notify the specific user of the completion of the data erasure process.

[0012] In Patent Document 1 (JP 2004-159046 A), only specific users can perform the predetermined operation that enables the execution of the data erasure process. Therefore, users other than the specific users cannot erase the data stored in the image forming device, and the specific users cannot be notified that the data erasure has been completed.

[0013] For example, when disposing of an image forming device at a location where no specific user is employed, the image forming device must be transported to an administrator to ensure data erasure, which can be time-consuming and costly. Thus, to prevent the leakage and tampering of confidential information contained in the data when disposing of an image forming device, a system is needed that allows data to be erased easily, safely, and securely even in image forming devices located away from the main office.

[0014] In the following embodiment, a method is described in which data stored in an image forming device can be erased based on instructions from a specific user via a management server, and information about the data can be prevented from being leaked or tampered with, while the specific user can be notified that the data has been erased.

[0015] First Embodiment Fig. 1 is a diagram showing an example of the configuration of a system according to this embodiment. The network configuration shown in Fig. 1 is merely an example of an embodiment, and is applicable to a configuration in which communication is possible between the image forming apparatus 100, the host device 200, the terminal device 500, and the management server 600 via wired or wireless communication, and is not limited to the configuration shown in Fig. 1.

[0016] Image forming apparatus 100 performs a printing process to form an image on a recording medium using consumables such as ink. Hereinafter, forming an image on a recording medium will be referred to as printing. Image forming apparatus 100 and host device 200 are connected to a local area network (LAN) 301 configured by an access point 300. Image forming apparatus 100 is also connected to external devices such as a management server 600 via the Internet 400 so as to be able to communicate with each other.

[0017] In this embodiment, the printing method of the image forming apparatus 100 is described as an inkjet method, but is not limited to this. The printing method of the image forming apparatus 100 may be an electrophotographic method, a stencil printing method, or another method. The image forming apparatus 100 may also have a notification function such as email.

[0018] The terminal device 500 is an information processing device capable of communicating with the management server 600 via the Internet 400. The terminal device 500 is, for example, a tablet terminal, and has a web browser function, a maintenance tool for the image forming device 100, and a notification function such as e-mail. In this embodiment, a person who owns the terminal device 500 and manages or owns the image forming device 100 is referred to as a first user. For example, the first user is a person who uses and manages the image forming device 100 at a company where a second user (described later) works.

[0019] The terminal device 500 can transmit requests and receive responses using Hypertext Transfer Protocol (HTTP) communication in a web browser function and a maintenance tool, and can display screens associated with these communications. Note that the functions provided in the terminal device 500 are not limited to these, and other functions may also be provided. Furthermore, the terminal device 500 is not limited to a tablet terminal, and may be other devices such as a desktop PC (personal computer), a notebook PC, or a smartphone.

[0020] The host device 200 is an information processing device capable of communicating with the management server 600 via the Internet 400. The host device 200 is, for example, a desktop PC, and is equipped with a notification function such as email. Note that the functions provided in the host device 200 are not limited to these, and other functions may also be provided. Furthermore, the host device 200 is not limited to a desktop PC, and may be other devices such as a notebook PC, a tablet terminal, or a smartphone.

[0021] In this embodiment, a person who owns the host device 200 and occupies the image forming device 100 is referred to as a second user. For example, a second user is a person who uses the image forming device 100 provided by the company where the second user works or the first user. When there is no need to particularly distinguish between the first user and the second user, they are collectively referred to as users.

[0022] The management server 600 is communicably connected to the image forming apparatus 100, the host device 200, and the terminal device 500 via the Internet 400. The management server 600 holds information about users who use the image forming apparatus 100, and identification information (such as serial numbers) of the image forming apparatus 100 or the terminal device 500. The management server 600 also has a notification function such as e-mail.

[0023] 2 is a schematic diagram showing an example of the appearance of image forming apparatus 100. Image forming apparatus 100 in this embodiment is a multifunction printer (MFP) that combines printing, scanning, faxing, and other functions. Image forming apparatus 100 has an operation display unit 101, a document table 102, a paper feed slot 103, and a paper discharge slot 104, which are provided on the periphery.

[0024] A user can control the image forming apparatus 100 by operating the operation and display unit 101. The operation and display unit 101 has an operation section that accepts instructions to execute various settings and various controls for the image forming apparatus 100, and a display section that displays the status of the image forming apparatus 100 and predetermined messages. Alternatively, the operation and display unit 101 may be configured as a liquid crystal panel (sometimes referred to as a touch panel) in which the operation section and the display section are integrated. The operation and display unit 101 may be provided with physical keys and physical buttons, or soft keys and soft buttons as the operation section. Note that the operation and display unit 101 in this embodiment is merely an example, and its size, type, etc. are not limited as long as it is capable of controlling the image forming apparatus 100.

[0025] The document table 102 is a table made of transparent glass. When a user places a document face down on the document table 102, the image forming apparatus 100 can execute a scan process to read an image of the document. The image data read and generated by the scan process is stored in a storage unit of the image forming apparatus 100.

[0026] Paper feed slot 103 is an insertion slot for inserting a recording medium such as printing paper. The recording medium inserted into paper feed slot 103 is transported inside the image forming device when printing processing begins. An image is then formed on the surface of the recording medium transported by image forming device 100, and the resulting product is discharged from paper discharge slot 104.

[0027] FIG. 3 is a schematic diagram showing an example of the internal structure of the image forming apparatus 100. The image forming apparatus 100 has a carriage 105 and an ink tank 106. The carriage 105 is movable in a direction intersecting the direction in which the recording medium is ejected. The carriage 105 is also provided with a detachable ink head (not shown) that ejects a recording material such as ink. The ink tank 106 is detachable from the carriage 105 and is a container that contains the recording material. The image forming apparatus 100 performs printing by moving the carriage 105 while transporting the recording paper using the recording material supplied from the ink tank 106.

[0028] 4 is a block diagram showing an example of the configuration of the image forming apparatus 100. The image forming apparatus 100 has a main board 110 that controls the entire apparatus, ink tanks 106, and an operation and display unit 101.

[0029] The main board 110 includes a CPU 111, a ROM 113, a RAM 114, a non-volatile RAM (NVRAM) 115, a print unit 116, and a scan unit 117. The main board 110 also includes a communication control unit 118, a HDD 119, an ink tank connection unit 120, and an operation display control unit 121. These elements are connected to each other via a system bus 112.

[0030] A microprocessor-type CPU 111 reads a control program stored in a ROM 113 into a RAM 114 and executes the read control program to realize various controls. Data for various settings of the image forming apparatus 100 (such as contract information required for maintenance of the image forming apparatus 100, recording of various data, and information related to images to be printed) is stored in a non-volatile memory, NVRAM 115, and is read and written in accordance with the control program. Data such as image data is stored in a hard disk drive (HDD) 119. Note that, in this embodiment, an example will be described in which the NVRAM 115 and the HDD 119 are separate storage devices, but the NVRAM 115 and the HDD 119 may be integrated and provided inside the image forming apparatus 100.

[0031] The CPU 111 controls the print unit 116 to print onto a recording medium an image stored in an image memory that occupies part of the RAM 114. The CPU 111 also controls the scan unit 117 to read an original document and store the image data in the image memory.

[0032] The CPU 111 can control the transmission of various data stored in the image forming apparatus 100 to the host apparatus 200, the terminal apparatus 500, the management server 600, and other devices via the communication control unit 118. The CPU 111 can also control the reception of various information from the host apparatus 200, the terminal apparatus 500, the management server 600, and other devices via the communication control unit 118.

[0033] The CPU 111 controls the operation display control unit 121 to receive operation information from the operation display unit 101. The CPU 111 also controls the operation display control unit 121 to cause the operation display unit 101 to display the status of the image forming apparatus 100 and a function selection menu, etc.

[0034] 5 is a block diagram showing an example of the configuration of a terminal device 500. The terminal device 500 has a CPU 501 that controls the entire device, a ROM 503, a RAM 504, an HDD 505, a communication control unit 506, and an operation display control unit 507. These elements are connected to one another via a system bus 502. In addition, an operation display unit 508 is connected to the operation display control unit 507.

[0035] The CPU 501 operates in accordance with a control program and an operating system (OS) stored in the ROM 503, and data stored in the RAM 504. The CPU 501 can control the transmission of various data stored in the terminal device 500 to the image forming device 100, the host device 200, the management server 600, and other devices via the communication control unit 506. The CPU 501 can also control the reception of various information from the host device 200, the terminal device 500, the management server 600, and other devices via the communication control unit 506.

[0036] The CPU 501 controls the operation display control unit 507 to receive operation information from the operation display unit 508. The CPU 501 controls the operation display control unit 507 to display, for example, a page provided by the management server 600 on the operation display unit 508 using a web browser function. The CPU 501 also controls the operation display control unit 507 to display a predetermined notification received from a device capable of communicating with the terminal device 500. The operation display unit 508 is, for example, a liquid crystal panel (sometimes referred to as a touch panel) having a function capable of detecting a predetermined operation (for example, a touch operation) on the operation display unit 508.

[0037] 6 is a block diagram showing an example of the configuration of a management server 600. The management server 600 has a CPU 601 that controls the entire management server, a ROM 603, a RAM 604, an HDD 605, and a communication control unit 606. These elements are connected to each other via a system bus 602.

[0038] The CPU 601 can control the transmission of various data stored in the management server 600 to the image forming apparatus 100, the host device 200, the terminal device 500, and other devices via the communication control unit 606. For example, the CPU 601 can send a data deletion password (described later) to the host device 200 using a notification function such as e-mail.

[0039] Furthermore, the CPU 601 can control the reception of various types of information from the image forming apparatus 100, the host device 200, the terminal device 500, and other devices via the communication control unit 606.

[0040] Next, a description will be given of a series of information processing steps related to the process of erasing data stored in the storage unit of image forming apparatus 100. Fig. 7 is a sequence diagram showing an example of information processing in this embodiment. Note that the "erasing process" in this embodiment includes an initialization process that returns the data stored in the storage unit of image forming apparatus 100 and the setting values ​​set in image forming apparatus 100 to their initial states.

[0041] In S701, terminal device 500 accesses a predetermined page (hereinafter referred to as the data erasure page) provided by management server 600 using a browser installed on terminal device 500 for erasing data stored in image forming device 100. For example, a first user inputs a URL (Uniform Resource Locator) for accessing the data erasure page into a URL input form displayed on the browser. At this time, before allowing access to the data erasure page, management server 600 verifies the administrator ID and administrator password registered in advance to confirm that the operation is being performed by an administrator. If there is no problem with the verification, management server 600 allows access to the data erasure page.

[0042] In this embodiment, the administrator is a person who has the authority to erase data stored in the image forming apparatus 100. For example, the administrator is a person who knows the administrator ID and the administrator password and who owns the image forming apparatus 100. In the following description, it is assumed that the first user is the administrator.

[0043] In S702, management server 600 registers data erasure information. Data erasure information in this embodiment refers to, for example, information necessary for erasing data, specifically, a serial number for identifying image forming apparatus 100, the type of data to be erased, and a password for erasing data. The type of data to be erased is the type of data designated by the first user, and is treated as designation information for identifying the data to be erased in image forming apparatus 100.

[0044] In S701, the first user enters data erasure information into the data erasure page displayed by the browser of the terminal device 500 and performs an operation to complete the entry. When the terminal device 500 detects that the first user has completed the entry of the data erasure information using the browser, it transmits the entered data erasure information to the management server 600. Then, upon receiving the data erasure information, the management server 600 stores the information in the HDD 605 or the like.

[0045] In S703, after registering the data erasure information in S702, the management server 600 notifies the terminal device 500 that the registration of the data erasure information has been completed.

[0046] In S704, the management server 600 transmits the data erasure password to the host device 200. For example, after registering the data erasure information in S702, the management server 600 transmits the data erasure password to the host device 200 via a notification function such as email. The data erasure password is encrypted using hashing such as SHA-3 or SHA-512. For example, upon receiving the encrypted data erasure password, the host device 200 encrypts the password contained in the email and determines whether the encrypted password matches the received data erasure password. This allows the host device 200 to determine whether the received data erasure password has been tampered with. If the host device 200 determines whether the encrypted password matches the received data erasure password, it can present a message corresponding to the determination result to the second user. The host device 200 may also decrypt the encrypted data erasure password upon receiving it. In this case, the host device 200 can present the decrypted data erasure password to the second user.

[0047] When the data erasure password is sent by email, the receiving host device 200 authenticates whether the sender domain is valid using DomainKeys Identified Mail (DKIM). Alternatively, an authentication method using server authentication with Sender Policy Framework (SPF), a mechanism for checking whether email sender information is forged, a digital certificate, or a self-signed certificate may be used.

[0048] In S705, the management server 600 transmits data erasure information and the like to the image forming apparatus 100. For example, after registering the data erasure information in S702, the management server 600 transmits the data erasure information and an erasure preparation instruction for preparing to erase the data to be erased to the image forming apparatus 100. Note that, of the above-mentioned steps S703 to S705, any one of the processes may be performed first in the management server 600 as long as it is performed after S702.

[0049] In S706, the image forming apparatus 100 stores the data erasure information received in S705 in the NVRAM 115 or the like.

[0050] In S707, upon receiving the erasure preparation instruction in S705, the image forming apparatus 100 performs a preparation process for erasing the data to be erased indicated by the data erasure information. The preparation process is, for example, a control executed by the image forming apparatus 100 to enable input of a password on a password input screen (not shown) for data erasure so that the data erasure process can be started.

[0051] Here, the data deletion password input screen is a screen that can be transitioned to by a user's operation from a specific menu screen (not shown) displayed on the operation display unit 101 of the image forming apparatus 100. Note that the data deletion password input screen in this embodiment is controlled by the image forming apparatus 100 so that a password cannot be input on the screen if the image forming apparatus 100 does not receive data deletion information from the management server 600.

[0052] Upon receiving the data erasure information, image forming apparatus 100 releases the restriction on password input on the data erasure password input screen so that the user can input a password on that screen. Then, the second user operates operation display unit 101 to display the data erasure password input screen, and enters the data erasure password on that screen while checking the data erasure password received by host device 200. Image forming apparatus 100 then verifies the entered data erasure password and starts the data erasure process based on the second user's operation, which will be described later. In this way, the data erasure process is started by the second user's input operation of the data erasure password and image forming apparatus 100's process of verifying the password.

[0053] The image forming apparatus 100 temporarily stores the data deletion information stored in S706 and information necessary for a completion notification (to be described later) in the RAM 114, and deletes this information after issuing the completion notification.

[0054] In S708, upon completing the data erasure process started in S707, image forming apparatus 100 notifies management server 600 that the process has been completed (this is referred to as a completion notification). For example, image forming apparatus 100 can transmit notification information such as the contents of the erased data, its own serial number, and the date and time when the data erasure process was executed to management server 600 as the completion notification. Details of the completion notification method will be described later.

[0055] FIG. 8 is a flowchart showing the flow of operations executed by the terminal device 500 in this embodiment up to the transmission of data erasure information. The flowchart shown in FIG. 8 is implemented by the CPU 501 of the terminal device 500 reading a control program stored in the ROM 503 into the RAM 304 and then executing the read control program. Note that some or all of the functions of the steps in FIG. 8 may be implemented by hardware such as an ASIC or electronic circuit. The symbol "S" in the explanation of each process indicates a step in the flowchart (the same applies to other flowcharts in this specification). The flowchart shown in FIG. 8 starts after the management server 600 permits access to the data erasure page.

[0056] In S801, the CPU 501 displays a data erasure page on the operation display unit 508 of the terminal device 500 using a browser or the like, where data erasure information can be input.

[0057] In S802, when the CPU 501 detects an input operation by the first user of a serial number for identifying the image forming apparatus 100 via a browser or the like, it sets the input serial number to be included in the data erasure information.

[0058] In S803, when the CPU 501 detects a selection operation by the first user via a browser or the like for the type of data to be erased, it sets the selected data type to be included in the data erasure information. In this embodiment, the first user can select one of "all data erasure," "HDD data erasure," or "initialization of settings" using a check box as the type of data to be erased.

[0059] Here, by selecting "Erase all data", when performing a data erasure process later, CPU 111 erases all data stored in HDD 119 and NVRAM 115 of image forming apparatus 100. By selecting "Erase HDD data", CPU 111 erases data stored in HDD 119 of image forming apparatus 100. By selecting "Initialize settings", CPU 111 overwrites the setting values ​​set in image forming apparatus 100 to the initial state.

[0060] In S804, when the CPU 501 detects an input operation of a data erasure password by the first user via a browser or the like, it sets the input password to be included in the data erasure information. Note that any of the processes from S802 to S804 may be performed first in the terminal device 500. Furthermore, when the CPU 501 completes S802 to S804, it proceeds to S805.

[0061] The data erasure page may be provided with a setting form that allows the user to set a shutdown command that instructs the image forming apparatus 100 to turn off after the data erasure process. In this case, when the CPU 501 detects a setting operation of a shutdown command by the first user via a browser or the like, it sets the shutdown command to be included in the data erasure information.

[0062] In S805, the CPU 501 uses a browser or the like to display a confirmation page for confirming the contents set on the data erasure page on the operation display unit 508 of the terminal device 500. The confirmation page has a complete button for accepting agreement that the set contents are correct, and a change button for accepting changes to the set contents.

[0063] In S806, the CPU 501 determines whether or not the Complete button on the confirmation page displayed in S805 has been operated via a browser, etc. If the CPU 501 determines that the Complete button has been operated via a browser, etc. (Yes), the process proceeds to S808, and if the CPU 501 determines that this has not been the case (No), the process proceeds to S807.

[0064] In S807, the CPU 501 determines whether or not the change button on the confirmation page displayed in S805 has been operated via a browser, etc. If the CPU 501 determines that the change button has been operated via a browser, etc. (Yes), the CPU 501 transitions to a data deletion page and proceeds to S801, and if the CPU 501 determines that this has not been the case (No), the CPU 501 proceeds to S806.

[0065] In S808, in response to the operation of the complete button in S806, the CPU 501 transmits data erasure information including the information entered on the data erasure page to the management server 600, and ends this flowchart.

[0066] 9 is a flowchart showing the flow executed by the management server 600 up to the transmission of an erasure preparation instruction to the image forming apparatus 100. The details of the processing executed by the CPU 601 of the management server 600 will be described with reference to FIG. 9. The flowchart shown in FIG. 9 starts, for example, after the terminal device 500 is permitted to access the data erasure page. The management server 600 repeats the flow of FIG. 9 at regular intervals.

[0067] In S901, the CPU 601 determines whether or not data erasure information has been received from the terminal device 500. If the CPU 601 determines that data erasure information has been received from the terminal device 500 (Yes), the process proceeds to S902, and if the CPU 601 determines that data erasure information has not been received (No), the process returns to S901.

[0068] In S902, when the CPU 601 receives data erasure information from the terminal device 500 in S901, it connects to the Internet 400 via the communication control unit 606 and transmits the data erasure information to the image forming apparatus 100. The CPU 601 also transmits a data erasure password to the host device 200, and ends this flowchart. At this time, the data erasure password is encrypted (hashed) using SHA-3, SHA-512, or the like. When transmitting the data erasure password by email, the CPU 601 also transmits it to the host device 200 via the communication control unit 606 over the Internet 400.

[0069] To enhance confidentiality even more than the above-described method, password information may be transmitted to the host device 200 via the image forming device 100 connected to the LAN 301. In this case, the management server 600 first transmits the data deletion password to the image forming device 100 via the communication control unit 118 of the image forming device 100 and the Internet 400. The data deletion password is then temporarily stored in the memory unit of the image forming device 100. The image forming device 100 then transmits the data deletion password to the host device 200, which is connected to the same LAN 301 as the image forming device 100, using the Simple Mail Transfer Protocol (SMTP) function. SMTP is a communication protocol for transmitting e-mail. This reduces the risk of eavesdropping compared to using the Internet 400, which is a wide-area network.

[0070] Fig. 10 is a flowchart showing the flow of operations executed by image forming apparatus 100 up to the storage of data erasure information. Details of the processing executed by CPU 111 of image forming apparatus 100 will be described with reference to Fig. 10. The flowchart shown in Fig. 10 is started, for example, after image forming apparatus 100 is powered on and has started up normally. Furthermore, image forming apparatus 100 repeats the flow of Fig. 10 at regular intervals.

[0071] In S1001, the CPU 111 determines whether or not data erasure information has been received from the management server 600. If the CPU 111 determines that data erasure information has been received from the management server 600 (Yes), the process proceeds to S1002, and if the CPU 111 determines that data erasure information has not been received (No), the process returns to S1001.

[0072] In S1002, when the CPU 111 receives the data erasure information from the management server 600 in S1001, the CPU 111 stores the data erasure information in the NVRAM 115 or the like, and ends this flowchart.

[0073] 11 is a flowchart showing an example of the flow of processing executed by image forming apparatus 100 to display that the data erasure processing has been completed. Details of the processing executed by CPU 111 of image forming apparatus 100 will be described with reference to Fig. 11. The flowchart shown in Fig. 11 starts, for example, after image forming apparatus 100 receives data erasure information from management server 600.

[0074] In S1101, the CPU 111 displays an input screen (not shown) on the operation display unit 101, where a password for data deletion can be entered. Here, the second user operates the operation display unit 101 while checking the password for data deletion received by the host device 200, and enters the password on the input screen.

[0075] In S1102, the CPU 111 determines whether or not the input password matches the password for data erasure received from the management server 600. If the CPU 111 determines that the input password matches the password for data erasure received from the management server 600 (Yes), the process proceeds to S1103, and if the CPU 111 determines that this does not match (No), the process proceeds to S1101.

[0076] In S1103, the CPU 111 displays a confirmation screen for data deletion on the operation display unit 101. For example, the CPU 111 displays a confirmation screen 1200 as shown in Fig. 12 for prompting the user to confirm that data is to be deleted.

[0077] 12 is a diagram showing an example of a confirmation screen displayed on the operation display unit 101 of the image forming apparatus 100. The confirmation screen 1200 displays the type of data to be erased and a message indicating that the data will be erased. The confirmation screen 1200 also has an erase button 1201 for accepting consent to the erasure of data specified by the management server 600, and a cancel button 1202 for accepting consent to the erasure of the data. The content of the message displayed on the confirmation screen 1200 is the content that would be displayed if the first user selected "HDD data erase" as the type of data to be erased. However, it goes without saying that if the first user selected "all data erase" or "initialize settings" as the type of data to be erased, the content of the message displayed on the confirmation screen 1200 will change depending on the selection.

[0078] In S1104, the CPU 111 determines whether the erase button 1201 has been operated. If the CPU 111 determines that the erase button 1201 has been operated (Yes), the process proceeds to S1105, and if the CPU 111 determines that the cancel button 1202 has been operated (No), the process proceeds to S1101. That is, if the CPU 111 determines that the erase button 1201 has been operated, the CPU 111 displays a confirmation screen for determining whether a completion notification, which will be described later, is required on the operation and display unit 101. If the CPU 111 determines that the cancel button 1202 has been operated, the CPU 111 displays an input screen on the operation and display unit 101 on which a password for data erasure can be entered.

[0079] In S1105, the CPU 111 displays a confirmation screen for confirming whether a completion notification is required on the operation display unit 101. For example, the CPU 111 displays a confirmation screen 1300 as shown in Fig. 13 for prompting the user to confirm whether a completion notification indicating that the data erasure process is completed is required.

[0080] 13 is a diagram showing an example of a necessity confirmation screen displayed on the operation display unit 101 of the image forming apparatus 100. The necessity confirmation screen 1300 displays a message prompting the user to confirm whether or not a completion notification indicating that the data deletion process has been completed is required. The necessity confirmation screen 1300 also has a "No" button 1301 for accepting denial of consent to the issuance of a completion notification, and a "Yes" button 1302 for accepting consent to the issuance of a completion notification.

[0081] In S1106, the CPU 111 determines whether the "Yes" button 1302 has been operated. If the CPU 111 determines that the "Yes" button 1302 has been operated (Yes), the process proceeds to S1107; if the CPU 111 determines that the "No" button 1301 has been operated (No), the process proceeds to S1108. That is, if the CPU 111 determines that the "Yes" button 1302 has been operated, the CPU 111 displays a notification method selection screen, which will be described later, on the operation and display unit 101. If the CPU 111 determines that the "No" button 1301 has been operated, the CPU 111 displays a final confirmation screen, which will be described later, on the operation and display unit 101.

[0082] In S1107, the CPU 111 displays a selection screen for selecting a notification method for the completion notification on the operation display unit 101. For example, the CPU 111 displays a selection screen 1400 as shown in FIG.

[0083] 14 is a diagram showing an example of a selection screen displayed on the operation display unit 101 of the image forming apparatus 100. The selection screen 1400 displays "send to administrator by email" and "print report" as notification methods for the completion notification. The selection screen 1400 also has check boxes 1401 and 1402 that allow the user to select whether to send the completion notification by each notification method. The selection screen 1400 also has a check box 1403 that allows the user to select not to send the completion notification. The selection screen 1400 shows a state in which "send to administrator by email" has been selected as the communication method.

[0084] The selection screen 1400 is provided with a "Next" button 1404. If the CPU 111 determines that the "Next" button 1404 has been operated, the process proceeds to S1108. After determining that the "Next" button 1404 has been operated, the CPU 111 may display a screen such as the one below on the operation display unit 101 before proceeding to S1108.

[0085] For example, when check box 1401 is selected and the second user operates "Next" button 1404, image forming apparatus 100 displays an email address input screen (not shown) on operation display unit 101, where an email address can be input. When the second user inputs the email address of the first user on the email address input screen, image forming apparatus 100 can notify the first user of the completion of the data deletion process by sending an email, which will be described later.

[0086] In S1108, the CPU 111 displays a final confirmation screen for data deletion on the operation display unit 101. For example, the CPU 111 displays a final confirmation screen 1500 as shown in Fig. 15 to prompt the user to confirm again that he or she wants to delete data.

[0087] 15 is a diagram showing an example of a final confirmation screen displayed on the operation display unit 101 of the image forming apparatus 100. A warning message to the effect that data will be erased is displayed on the final confirmation screen 1500. The final confirmation screen 1500 also has a cancel button 1501 for accepting denial of consent to erasing data specified by the management server 600, and a delete button 1502 for accepting consent to erasing the data.

[0088] In S1109, the CPU 111 determines whether the delete button 1502 has been operated. If the CPU 111 determines that the delete button 1502 has been operated (Yes), the process proceeds to S1110, and if the CPU 111 determines that the cancel button 1501 has been operated (No), the process proceeds to S1105. That is, if the CPU 111 determines that the delete button 1502 has been operated, the CPU 111 executes a data deletion process, which will be described later. Then, if the CPU 111 determines that the cancel button 1501 has been operated, the CPU 111 displays the necessity confirmation screen 1300 on the operation display unit 101.

[0089] In addition, in a situation where it is determined in S1106 that the "Yes" button 1302 has been operated, if the CPU 111 determines in S1109 that the cancel button 1501 has been operated, the selection screen 1400 may be displayed on the operation display unit 101.

[0090] In S1110, CPU 111 executes a data erasure process indicated by the type of data to be erased received from management server 600. For example, if the type of data to be erased is "all data erasure," CPU 111 erases all data stored in HDD 119 and NVRAM 115 of image forming apparatus 100. If the type of data to be erased is "HDD data erasure," CPU 111 erases data stored in HDD 119 of image forming apparatus 100. If the type of data to be erased is "setting initialization," CPU 111 overwrites the setting values ​​of image forming apparatus 100 with the initial state. CPU 111 can also display a message such as "HDD data is being erased" on operation display unit 101 to inform the second user that the erasure process is being executed.

[0091] In S1111, if check box 1401 or 1402 was selected in S1107, CPU 111 notifies the completion of data erasure according to the selected notification method. For example, if check box 1401 was selected in S1107, CPU 111 authenticates whether the sender domain is legitimate using email authentication technology such as DKIM. Alternatively, notification may be made by server authentication using a digital certificate, a self-signed certificate, or the like.

[0092] Furthermore, if the check box 1402 is selected in S1107, the CPU 111 causes the print unit 116 to print on the recording medium, after the data erasure process is completed, a message indicating that the data erasure process has been completed.

[0093] In this way, the second user can operate check boxes 1401 and 1402 to cause image forming device 100 to send an email to the administrator, print on a recording medium a message indicating that the data erasure process has been completed, or both.

[0094] Instead of printing a report indicating that the data erasure process has been completed, the image forming device 100 can print a specific image that transitions to a page with access restrictions where the contents of the completion notification can be viewed.

[0095] The specific image in this embodiment is, for example, an image showing a URL linked to a page where the content of the completion notification can be viewed, provided by the management server 600, or a two-dimensional code image in which the URL (transition information) is embedded. The two-dimensional code image is, for example, a QR (Quick Response) Code (registered trademark).

[0096] For example, when granting access to a page where the contents of the completion notice can be viewed, the management server 600 authenticates a preset ID and password to confirm that the person accessing the page is a specific user. If the authentication is successful, the user can access the page and view the contents indicating that the data erasure process has been completed. This can prevent the contents from being tampered with by a third party, compared to printing the contents of the completion notice in report format.

[0097] If the check box 1403 is selected in step S1107, the CPU 111 does not issue a completion notification using the notification method described above after the data erasure process is completed.

[0098] In S1112, when the CPU 111 completes the data erasure process, it displays a guide indicating the completion of the data erasure process on the operation display unit 101. Furthermore, if the CPU 111 has issued a completion notification using a predetermined notification method in S1111, it displays a guide indicating that the completion notification has been issued, in addition to the guide indicating the completion of the data erasure process.

[0099] According to this embodiment, data such as confidential information stored in an image forming device can be erased based on instructions from an administrator via a management server, and specific users can be notified of the completion of data erasure while preventing information about the data from being leaked or tampered with. Furthermore, because the administrator can erase data stored in the image forming device and notify the user of the completion of data erasure without having to directly operate the image forming device, the administrator can use the image forming device with peace of mind.

[0100] <Other embodiments> In the above embodiment, an example has been described in which image forming apparatus 100 erases data in a storage area instructed by management server 600. In this embodiment, image forming apparatus 100 can transmit all data stored in the storage unit to management server 600 in advance before executing the data erasure process, in preparation for the case in which the data erasure process is executed due to an erroneous operation by the administrator. For example, immediately before S1110 in FIG. 11 , CPU 111 transmits all data stored in HDD 119, NVRAM 115, etc. of image forming apparatus 100 to management server 600 as a backup.

[0101] In the above embodiment, an example has been described in which image forming apparatus 100, upon receiving an erasure preparation instruction from management server 600, executes the data erasure process based on the operation of the second user and then notifies management server 600 of the completion. In this embodiment, if management server 600 does not receive the completion notification from image forming apparatus 100, it can notify host device 200 that the completion notification was not received and to request that the data erasure process be executed again. For example, immediately after step S902, management server 600 starts a timer to determine whether the completion notification has been received from image forming apparatus 100. Then, management server 600 determines whether the completion notification has been received from image forming apparatus 100 within a predetermined time (e.g., about two hours) after setting the timer.

[0102] If the management server 600 determines that the completion notification has been received within the predetermined time, it terminates the activated timer. On the other hand, if the management server 600 determines that the completion notification has not been received within the predetermined time, it notifies the host device 200 by a notification method such as email that the completion notification has not been received, and terminates the activated timer.

[0103] In the above-described embodiment, an example has been described in which the second user performs an operation to erase data on the image forming apparatus 100 using a data erasure password received by the host device 200. In this embodiment, a viewing restriction may be set on the email or the password to restrict access to the data erasure password so that only specific individuals can view it. For example, the email or data erasure password received by the host device 200 may be set with a viewing restriction that requires the entry of a separately set password (a password different from the data erasure password). In this case, the management server 600 may send the separately set password to the host device 200 by email or other means, separate from the data erasure password. Then, when the second user enters the separately set password on a screen requesting the separately set password, the host device 200 may lift the viewing restriction and present the contents of the email or the data erasure password.

[0104] In this embodiment, the shutdown command is transmitted to the image forming apparatus 100 after the management server 600 receives a completion notification from the image forming apparatus 100. That is, upon receiving the completion notification from the image forming apparatus 100, the management server 600 transmits a shutdown command to the image forming apparatus 100. In this case, the image forming apparatus 100 turns off its own power and transitions to a soft-off state in accordance with the shutdown command received from the management server 600.

[0105] In this embodiment, when the image forming apparatus 100 transitions to the soft-off state in accordance with a shutdown command received from the management server 600, the image forming apparatus 100 may not be started unless a specific startup operation is performed. In this embodiment, the specific startup operation is, for example, a predetermined command input operation used by a service technician. The image forming apparatus 100 may be configured to start up and transition to the soft-on state by inputting a predetermined command using a key or button provided on the operation / display unit 101. By configuring the image forming apparatus 100 in this manner, it is possible to prevent misuse, unauthorized use, or private use of the apparatus by a third party after data erasure.

[0106] In the above-described embodiment, the image forming apparatus 100 displays an input screen on which a data erasure password can be input, and determines whether the password input on the screen matches the data erasure password received from the management server 600. In this embodiment, the data erasure password received from the management server 600 may have an expiration date. In this case, if an expired data erasure password is input in step S1102, the image forming apparatus 100 does not execute the processes from step S1103 onward, even if the input password matches the data erasure password received from the management server 600. This enhances the security of data erasure. Note that, in order for a second user to be able to perform an operation to erase data, the first user must re-enter data erasure information into the management server 600.

[0107] Furthermore, the password used for the match determination in S1102 may not be the password for erasing data received from the management server 600, but may be a password that the first user has preset in the image forming device 100 before handing it over to the second user.

[0108] In this case, the first user uses the terminal device 500 to send a password preset in the image forming device 100 to the management server 600 as a data deletion password. The management server 600 can then send the data deletion password received from the terminal device 500 to the host device 200, without sending it to the image forming device 100. In this way, the preset password may be used in the match determination in S1102.

[0109] The present disclosure can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0110] The disclosure of the present embodiment includes configurations typified by the following image forming apparatus example, control method example, program example, and information processing apparatus example.

[0111] <Configuration 1> an erasing means for erasing data stored in the storage unit; an output means for encrypting and outputting notification information indicating that the data has been erased when the data has been erased by the erasing means; An image forming apparatus comprising:

[0112] <Configuration 2> The image forming apparatus according to configuration 1 further comprises a receiving unit that receives data erasure information for erasing the data from an external device.

[0113] <Configuration 3> 3. The image forming apparatus according to claim 2, wherein the receiving means receives an erasure preparation instruction for preparing to erase the data together with the data erasure information.

[0114] <Configuration 4> The image forming apparatus according to configuration 3 further comprises a control means for, when the receiving means receives the erasure preparation instruction, enabling a user to input the password for erasing the data by the erasing means on an input screen that restricts input of the password.

[0115] <Configuration 5> 5. The image forming apparatus according to any one of configurations 2 to 4, wherein the data erasure information is information generated by the external device in response to an operation by a user who has authority to erase the data.

[0116] <Configuration 6> the data erasure information includes designation information that designates erasure of all or part of the data stored in the storage unit, 6. The image forming apparatus according to any one of configurations 2 to 5, wherein the erasing unit erases data designated by the designation information.

[0117] <Configuration 7> 7. The image forming apparatus according to any one of configurations 2 to 6, wherein the output unit encrypts the notification information and outputs it to the external device.

[0118] <Configuration 8> the data erasure information includes an erasure password for erasing the data; The image forming apparatus according to any one of configurations 2 to 7, wherein the erasing means erases the data when the erasing password received from the external device matches the password entered by the user.

[0119] <Configuration 9> The image forming apparatus according to any one of configurations 2 to 8, further comprising a printing unit configured to print a two-dimensional code image in which transition information for transitioning to a page provided by the external device and having access restrictions for restricting access to the notification information is embedded.

[0120] <Configuration 10> 10. The image forming apparatus according to any one of configurations 2 to 9, further comprising a transmitting unit that transmits all data stored in the memory unit to the external device before the data is erased by the erasing unit.

[0121] <Configuration 11> The data erasure information includes a shutdown command to turn off the power, 9. The image forming apparatus according to any one of configurations 2 to 8, further comprising a control unit that performs control to turn off the power and transition to a soft-off state after the output unit has performed the output.

[0122] <Configuration 12> The image forming apparatus according to configuration 11, wherein the control means, when transitioning to a soft-off state based on the shutdown command, is started up based on a specific start-up operation on an operation unit provided on the outer periphery, and controls transitioning to a soft-on state.

[0123] <Configuration 13> 13. The image forming apparatus according to any one of configurations 1 to 12, wherein the output unit outputs the notification information by sending it by email or by printing it.

[0124] <Configuration 14> an erasing step of erasing data stored in the storage unit; an output step of encrypting and outputting notification information indicating that the data has been erased when the data has been erased in the erasure step; 10. A method for controlling an image forming apparatus, comprising:

[0125] <Configuration 15> A program for causing a computer to function as each means of the image forming apparatus described in configuration 1.

[0126] <Configuration 16> a receiving unit for receiving data erasure information for erasing data stored in a storage unit of the image forming apparatus; a transmitting means for transmitting the data erasure information to the image forming apparatus; a storage means for storing notification information indicating that the data has been erased, which is received by the receiving means from the image forming apparatus from which the data has been erased; An information processing device comprising:

[0127] <Configuration 17> 17. The information processing apparatus according to configuration 16, wherein the transmission means encrypts the password for erasing the data and transmits the encrypted password to a host device that notifies the user of the password.

[0128] <Configuration 18> 18. The information processing device according to configuration 17, wherein if the receiving means does not receive the notification information, the transmitting means transmits to the host device content indicating that the notification information has not been received.

[0129] <Configuration 19> The information processing device according to configuration 17 or 18, wherein the transmission means transmits, together with the password, a password different from the password for lifting the viewing restriction that restricts viewing of the password to the host device. [Explanation of symbols]

[0130] 100 Image forming device 101 Operation display unit 111 CPU 115 NVRAM 116 Printing Department 118 Communication Control Unit 119 HDD 200 Host Device 500 Terminal Equipment 600 Management Server

Claims

1. an erasing means for erasing data stored in the storage unit; an output means for encrypting and outputting notification information indicating that the data has been erased when the data has been erased by the erasing means; An image forming apparatus comprising:

2. 2. The image forming apparatus according to claim 1, further comprising a receiving unit for receiving data erasure information for erasing the data from an external device.

3. 3. The image forming apparatus according to claim 2, wherein the receiving means receives an erasure preparation instruction for preparing to erase the data together with the data erasure information.

4. The image forming apparatus according to claim 3, further comprising a control means for, when the receiving means receives the erasure preparation instruction, enabling a user to input the password for erasing the data by the erasure means on an input screen that restricts input of the password.

5. 3. The image forming apparatus according to claim 2, wherein the data erasure information is information generated by the external device in response to an operation by a user who has authority to erase the data.

6. the data erasure information includes designation information that designates erasure of all or part of the data stored in the storage unit, 3. The image forming apparatus according to claim 2, wherein the erasing unit erases data designated by the designation information.

7. 3. The image forming apparatus according to claim 2, wherein the output unit encrypts the notification information before outputting it to the external device.

8. the data erasure information includes an erasure password for erasing the data; 3. The image forming apparatus according to claim 2, wherein the erasing unit erases the data when the password for erasure received from the external device matches the password entered by the user.

9. The image forming apparatus according to claim 1, further comprising a printing means for printing a two-dimensional code image provided by an external device and having embedded therein transition information for transitioning to a page having access restrictions for restricting access to the notification information.

10. 2. The image forming apparatus according to claim 1, further comprising a transmitting unit that transmits all data stored in the storage unit to an external device before the data is erased by the erasing unit.

11. The data erasure information includes a shutdown command to turn off the power, 3. The image forming apparatus according to claim 2, further comprising a control unit that controls the power supply to be turned off and the apparatus to transition to a soft-off state after the output unit has performed the output.

12. The image forming apparatus according to claim 11, wherein the control unit, when transitioning to the soft-off state based on the shutdown command, starts up based on a specific startup operation on an operation unit provided on the outer periphery, and controls the transition to the soft-on state.

13. 2. The image forming apparatus according to claim 1, wherein the output unit outputs the notification information by sending it by email or by printing it.

14. an erasing step of erasing data stored in the storage unit; an output step of encrypting and outputting notification information indicating that the data has been erased when the data has been erased in the erasure step; 10. A method for controlling an image forming apparatus, comprising:

15. A program for causing a computer to function as each of the means of the image forming apparatus according to claim 1.

16. a receiving unit for receiving data erasure information for erasing data stored in a storage unit of the image forming apparatus; a transmitting means for transmitting the data erasure information to the image forming apparatus; a storage means for storing notification information indicating that the data has been erased, which is received by the receiving means from the image forming apparatus from which the data has been erased; An information processing device comprising:

17. 17. The information processing apparatus according to claim 16, wherein said transmission means encrypts the password for erasing the data and transmits the encrypted password to a host device that notifies the user of the password.

18. 18. The information processing apparatus according to claim 17, wherein, when the notification information is not received by the receiving means, the transmitting means transmits to the host device a message indicating that the notification information has not been received.

19. 18. The information processing apparatus according to claim 17, wherein said transmission means transmits, together with said password, a password different from said password for removing the access restriction that restricts access to said password to said host device.

Citation Information

Patent Citations

  • Image processor

    JP2004159046A