Image forming apparatus

The image forming apparatus addresses the issue of unauthorized programs by rewriting and restarting with original programs, maintaining operation safety and functionality.

JP2026002163APending Publication Date: 2026-01-08TOSHIBA TEC KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024099935
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Conventional image forming devices stop operation when they detect a program with a mismatched hash value, posing a risk of unauthorized installation or rewriting of malicious programs.

Method used

An image forming apparatus with a first memory storing programs and a second memory storing a whitelist that registers unique information for each legitimate program, allowing the processor to rewrite detected malicious programs with an original program and restart the device.

Benefits of technology

Enables safe operation without stopping the device when program fraud is detected, ensuring continued functionality by restoring programs to their original state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026002163000001_ABST
    Figure 2026002163000001_ABST
Patent Text Reader

Abstract

To provide an image forming apparatus which is safely operated without stopping the operation when detecting the illegality of a program.SOLUTION: The image forming device MFP11 has a storage 24 including a first memory and a second memory, and a processor 21. The first memory stores an updatable program. The second memory stores a whitelist in which information including unique information for each authorized program is registered. The second memory is a secure storage area in which falsification by a third party is difficult. When the program requested to be executed does not match the unique information registered in the white list, the processor rewrites the program requested to be executed with the original program and restarts the image forming apparatus.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD An embodiment of the present invention relates to an image forming apparatus. [Background technology]

[0002] Image forming devices such as digital multifunction peripherals are configured to perform various processes by executing various programs through a processor. In recent years, as the functionality of image forming devices such as digital multifunction peripherals has become more diverse, a large number of programs have been installed. Such image forming devices are at risk of unauthorized installation of malicious programs or unauthorized rewriting of legitimate programs.

[0003] To combat malicious programs, some conventional image forming devices are equipped with a whitelist-based anti-malware function that controls program execution based on a whitelist. When executing a program or loading a library, the image forming device checks whether the hash value matches a value in the whitelist. If a conventional image forming device detects a program with a mismatched hash value, it controls the entire image forming device to stop. This poses a problem: conventional image forming devices stop operation when they detect a program with a mismatched hash value. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-191698 Summary of the Invention [Problem to be solved by the invention]

[0005] In order to solve the above-mentioned problems, an object of the present invention is to provide an image forming apparatus that can operate safely without stopping operation when program fraud is detected. [Means for solving the problem]

[0006] According to an embodiment, an image forming apparatus includes a first memory, a second memory, and a processor. The first memory stores a program. The second memory stores a whitelist that registers information including unique information for each legitimate program. If a program requested to be executed does not match the unique information registered in the whitelist, the processor rewrites the program requested to be executed with an original program and restarts the image forming apparatus. [Brief explanation of the drawings]

[0007] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of an image forming system including a digital multifunction peripheral as an image forming apparatus according to an embodiment. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of a digital multifunction peripheral as an image forming apparatus according to the embodiment. [Figure 3] FIG. 3 is a diagram showing an example of a whitelist related to legitimate programs held by a digital multifunction peripheral as an image forming apparatus according to the embodiment. [Figure 4] FIG. 4 is a flowchart for explaining an example of the operation of the validity check process by the digital multifunction peripheral as the image forming apparatus according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] Hereinafter, this embodiment will be described with reference to the drawings. FIG. 1 is a diagram showing an example of the configuration of an image forming system 1 including a digital multifunction peripheral (MFP) 11 as an image forming apparatus according to an embodiment. The image forming system 1 has a configuration in which a digital multi-functional peripheral (MFP) 11 serving as an image forming apparatus is connected to a service center 13 and a cloud 14 via a network 12.

[0009] The service center 13 has a server that communicates with the digital multifunction peripheral 11. The service center 13 maintains and manages the digital multifunction peripheral 11 that can communicate via the network 12. For example, the service center 13 has a server that notifies a serviceman who maintains the digital multifunction peripheral 11 of information indicating the status of the digital multifunction peripheral 11. The cloud 14 may also include a server that securely stores the original programs of the programs installed in the digital multifunction peripheral 11.

[0010] The cloud 14 has various servers with which the digital multifunction peripheral 11 can communicate. The cloud 14 includes a server that stores data used by the digital multifunction peripheral 11. For example, the cloud 14 includes a server used by a cloud service application installed on the digital multifunction peripheral 11. Cloud services available to the digital multifunction peripheral 11 include the provision of processes such as scan data processing and printer data management. The cloud 14 may also include a server that securely stores the original programs of the programs installed on the digital multifunction peripheral 11.

[0011] The digital multifunction peripheral 11 is an example of an image forming apparatus. The digital multifunction peripheral 11 includes not only a printer but also a scanner and an operation panel. The digital multifunction peripheral 11 according to this embodiment executes various programs to perform various processes. The programs installed in the digital multifunction peripheral 11 are not only stored in a read-only memory, but also in a rewritable storage device (storage). For example, the storage of the digital multifunction peripheral 11 may store an application program for performing special processing on image data.

[0012] Next, the configuration of the digital multifunction peripheral 11 as the image forming apparatus according to the embodiment will be described. FIG. 2 is a block diagram showing an example of the configuration of a digital multifunction peripheral (MFP) 11 as an image forming apparatus according to the embodiment. As shown in FIG. 2, the digital multifunction peripheral 11 includes a processor 21, a ROM (read-only memory) 22, a RAM (random access memory) 23, storage 24, a communication interface (I / F) 25, a scanner 26, a printer 27, and an operation panel 28.

[0013] The processor 21, ROM 22, RAM 23, storage 24, and communication interface 25 constitute a system controller of the digital multifunction peripheral 11. The system controller is connected to a scanner 26, a printer 27, and an operation panel 28. The system controller is a computer that performs overall operational control of each part of the digital multifunction peripheral 11 and executes various data processing operations.

[0014] The processor 21 controls the digital multifunction peripheral 11. The processor 21 also executes data processing such as various types of arithmetic operations. The processor 21 executes programs to control each unit and execute data processing. The processor 21 is, for example, a CPU. The processor 21 is connected to each unit in the digital multifunction peripheral 11 via an internal interface. For example, the processor 21 executes various processes by using the RAM 23 to execute programs stored in the ROM 22 or storage 24.

[0015] The ROM 22 is a read-only memory. The ROM 22 is a non-volatile memory that does not allow data to be rewritten. The ROM 22 stores preset original programs, control data, and the like. There may be multiple ROMs 22, or the ROM 22 may include a PROM that can be written to using a specific procedure. For example, the ROM 22 may include a ROM that stores programs and control data for system operation and a dedicated ROM (read-only memory) that stores original programs.

[0016] The RAM 23 is a volatile memory. The RAM 23 functions as a working memory or a buffer memory. For example, the RAM 23 loads programs to be executed by the processor 21 and temporarily stores data being processed.

[0017] The storage 24 is configured with a rewritable nonvolatile memory. For example, the storage 24 is configured with an HDD (hard disk drive), an SSD (solid state drive), a flash memory, or the like. The storage 24 stores data such as programs, control data, and setting information. The storage 24 includes a storage area (first memory) for storing updatable programs and a storage area (second memory) for storing setting information such as a whitelist. For example, the storage area for storing the whitelist is a secure storage area that is difficult for a third party to tamper with.

[0018] The communication interface 25 is an interface for communicating with an external device. For example, the communication interface 25 is a network interface for communicating with the service center 13 or the cloud 14 via the network 12. The communication interface 25 may include an interface for wired communication or an interface for wireless communication.

[0019] The scanner 26 is a device that optically reads an image of a document. The scanner 26 reads an image of a document set on a platen glass. The scanner 26 may also be equipped with an automatic document feeder (ADF). The scanner 26 equipped with an ADF reads an image of a document transported by the ADF.

[0020] Printer 27 forms an image on a medium such as paper. For example, printer 27 forms an image on paper taken out of a paper feed cassette that stores paper. Printer 27 may be equipped with an image forming mechanism of any image forming method. For example, if printer 27 is equipped with an electrophotographic image forming mechanism, it forms a developer image on an image carrier such as a photosensitive drum and transfers the developer image on the image carrier to paper. If printer 27 is equipped with an inkjet image forming mechanism, it forms an image on paper using ink ejected from an inkjet head.

[0021] The operation panel 28 is a user interface. The operation panel 28 has a display unit 281 and an operation unit 282. The display unit 281 is composed of a display. The display unit 281 displays operation guides and the like. The operation unit 282 has a touch panel and a plurality of operation buttons. The touch panel serving as the operation unit 282 detects a location on the display screen of the display that is touched by the user. The touch panel is provided, for example, on the display screen of the display unit 281. The operation buttons serving as the operation unit 282 are buttons for inputting specific operation instructions.

[0022] Next, a whitelist held by the digital multifunction peripheral 11 as the image forming apparatus according to the embodiment will be described. FIG. 3 is a diagram showing an example of a whitelist held by the digital multifunction peripheral 11 as the image forming apparatus according to the embodiment. A whitelist is information that registers information for verifying the legitimacy of a program. A whitelist is information that lists individual programs that are subject to legitimacy checks. The whitelist registers information about each program as a legitimate program.

[0023] The programs to be registered on the whitelist and checked for legitimacy are, for example, programs stored in storage 24. The programs to be registered on the whitelist are, for example, firmware and application programs. The programs to be registered on the whitelist include, for example, application programs for providing services using cloud 14. The programs to be registered on the whitelist may be programs that can be updated through regular procedures.

[0024] In the example shown in FIG. 3, the whitelist registers information such as the file path name, hash value, and original program information for each program. 3 is stored in a storage area (second memory) that is difficult to tamper with. For example, a whitelist of programs whose file path names or hash values ​​may be changed by legitimate updates is stored in a secure memory provided in the storage 24. Furthermore, a whitelist of programs whose file path names or hash values ​​are not changed may be stored in the ROM 22.

[0025] 3, the file path name is information indicating the legitimate storage location of a file in which legitimate program data is stored. For example, a path name indicating the location where program data is stored by the legitimate mechanism of the digital multifunction peripheral 11 is registered as the file path name. Whether the program to be executed is an unauthorized program (malware) is determined depending on whether the file path of the program to be executed is registered in the whitelist.

[0026] In the whitelist shown in Figure 3, the hash value is calculated using a hash function from the legitimate program data of a program identified by the file path name. The authenticity of a program is checked by checking whether the hash value calculated from the data of the program to be executed matches the hash value in the whitelist.

[0027] That is, the digital multifunction peripheral 11 performs a hash check process using a hash value to detect whether a program has been tampered with. For example, if the hash value of a program to be executed does not match the hash value in the whitelist, the program to be executed is determined to have been tampered with. Note that when a program is properly updated, the hash value registered in the whitelist is updated to the hash value of the data of the updated program.

[0028] In the whitelist illustrated in Fig. 3, the original program information is information indicating the original program for a program identified by a file path name. The original program information includes, for example, information indicating the storage location of the data of the original program. The data of the original program is stored in the ROM 22, which is a read-only memory.

[0029] However, the data of the original program may be stored in a server that can communicate via the network 12. In this case, the original program information may indicate access information for accessing the server that stores the original program. The server that stores the original program may be capable of securely storing data and securely communicating with the digital multifunction peripheral 11. For example, the server that stores the original program may be a server provided in the service center 13 or a server provided in the cloud 14.

[0030] Next, a program validity check process using a whitelist in the digital multifunction peripheral 11 as the image forming apparatus according to the embodiment will be described. FIG. 4 is a flowchart for explaining an example of a program validity check process in the digital multifunction peripheral 11 as the image forming apparatus according to the embodiment. In the digital multifunction peripheral 11, the processor 21 receives a request to execute a program to be checked by a user operation or processing by a specific program (ACT11). When the processor 21 receives the program execution request, it checks the validity of the program requested to be executed.

[0031] When the processor 21 receives a request to execute a program (ACT11, YES), it compares the program requested to be executed with information registered in the whitelist (ACT12). First, the processor 21 determines whether the program requested to be executed exists in the whitelist by comparing it with the whitelist (ACT13). For example, the processor 21 compares the path of the program requested to be executed with the path name of a file registered in the whitelist. The processor 21 determines whether the program requested to be executed exists based on whether the path name of a file that matches the path of the program whose execution request was detected exists in the whitelist.

[0032] If the program requested to be executed does not exist in the whitelist (ACT13, NO), the processor 21 detects the program as an unauthorized program (malware). If the processor 21 detects the program requested to be executed as malware, the processor 21 saves the detection of malware as log (history) data (ACT14). For example, the processor 21 stores information about the program detected as malware in the storage 24 as a malware detection log.

[0033] Furthermore, if the processor 21 detects the program whose execution has been requested as malware, it executes a process to delete the program detected as malware (ACT 15). For example, the processor 21 deletes data of the program detected as malware from the storage.

[0034] When the processor 21 deletes the program detected as malware, it determines whether or not to stop the operation of the digital multifunction peripheral 11 (ACT 16). For example, it is assumed that the operation to be performed after the program detected as malware is deleted is set in advance. The processor 21 determines the operation to be performed after the program detected as malware is deleted based on the set in advance.

[0035] Here, it is assumed that the digital multifunction peripheral 11 is set in advance to either stop operation and notify the service center (call for service) or continue operation after removing the malware. In this case, the processor 21 determines based on the preset setting whether to call for service or to allow operation after removing the malware.

[0036] When the processor 21 determines that the operation of the digital multifunction peripheral 11 should be stopped and a service call should be made when the malware is removed (ACT16, YES), the processor 21 stops the operation of the digital multifunction peripheral 11. In the stopped state, the processor 21 executes a service call to notify the service center 13 of information about the program detected as malware (the deleted program) (ACT17). The service center 13 can confirm from the service call that the digital multifunction peripheral 11 has deleted the program detected as malware and has stopped operation. When the service center 13 receives the service call, it carries out a procedure to resume the operation of the digital multifunction peripheral 11.

[0037] Furthermore, if the processor 21 determines that the operation of the device should continue after the malware has been deleted (ACT16, NO), it ends the series of processes in response to the execution request for the program that was deleted as malware. However, the processor 21 may continue operation by restarting the digital multifunction peripheral 11 after detecting and deleting malware. Furthermore, the processor 21 may not only continue operation, but also notify the user or notify the service center 13 that the program detected as malware has been deleted.

[0038] Furthermore, if the program requested to be executed exists on the whitelist (ACT13, YES), the processor 21 performs a hash check of the program (ACT18). As the hash check, the processor 21 calculates a hash value of the data of the program requested to be executed. For example, the processor 21 loads the data of the program requested to be executed into the RAM 23. The processor 21 applies a hash function to the data of the program loaded into the RAM 23 to calculate a hash value.

[0039] The processor 21 identifies the hash value of a program in the whitelist whose file path name matches the program whose execution has been requested, and determines whether the hash value of the program whose execution has been requested matches the hash value registered in the whitelist.

[0040] If the hash value of the program requested to be executed matches the hash value in the whitelist (ACT18, YES), the processor 21 determines that the legitimacy of the program has been confirmed. If the legitimacy of the program requested to be executed has been confirmed, the processor 21 executes the program (ACT24).

[0041] If the hash value of the program requested to be executed does not match the hash value in the whitelist (ACT18, NO), the processor 21 determines that program tampering has been detected. When the processor 21 detects tampering of the program requested to be executed, it stores abnormality log data indicating that program tampering has been detected in the storage 24 (ACT19).

[0042] Furthermore, when the processor 21 detects tampering of a program whose execution has been requested, the processor 21 displays a notice (warning) on ​​the display unit 281 of the operation panel 28 to the effect that tampering of the program has been detected (ACT20). Furthermore, when the processor 21 detects tampering of a program whose execution has been requested, the processor 21 notifies a predetermined contact point that tampering of the program has been detected (ACT21). For example, the processor 21 notifies a pre-set administrator of the digital multifunction peripheral 11 by email or the like that program tampering has been detected. The processor 21 may also notify the service center 13 via the communication interface 25 that program tampering has been detected.

[0043] When the processor 21 detects tampering of a program requested to be executed, the processor 21 restores the program with the original program without executing the program (ACT22). For example, the processor 21 reads original program information indicating the original program of the program whose tampering has been detected from the whitelist.

[0044] The processor 21 identifies a storage location for the data of the original program indicated by the original program information. The data of the original program is stored in a memory that can safely store the data without it being rewritten. For example, the data of the original program is stored in the ROM 22, which is a read-only memory provided in the digital multifunction peripheral 11.

[0045] The original program data may be stored in an external device (service center 13 or cloud 14) with which the digital multifunction peripheral 11 can communicate via the network 12. In this case, the original program information indicates information for accessing the external device that stores the original program data.

[0046] For example, if the data of the original program is stored in a server of the service center 13, the original program information indicates access information to the server of the service center 13. The processor 21 accesses the server of the service center 13 using the access information indicated in the original program information to obtain the data of the original program.

[0047] Furthermore, when the data of the original program is stored in a server in the cloud 14, the original program information indicates access information to the server that stores the data of the original program in the cloud 14. The processor 21 acquires the data of the original program from the server in the cloud 14 using the access information indicated in the original program information.

[0048] After identifying the storage location of the original program data, processor 21 acquires the original program data from the storage location. After acquiring the original program data, processor 21 rewrites the data of the program in which tampering was detected with the data of the original program. As a result, the program in which tampering was detected is restored by the original program indicated by the original program information.

[0049] When the processor 21 rewrites the program for which tampering was detected with the original program, it restarts the digital multifunction peripheral 11 (ACT23). When the processor 21 restarts the digital multifunction peripheral 11 with the program restored, it executes the restored program with the original program (ACT24). Here, the processor 21 may display on the display unit 281 that the program for which tampering was detected has been restored with the original program. Furthermore, the processor 21 may notify the service center 13 that the program for which tampering was detected has been restored with the original program.

[0050] However, when the processor 21 recovers the program and restarts, it may execute the recovered program in response to a user instruction. For example, when the digital multifunction peripheral 11 restarts, the processor 21 displays a selection guide screen on the display unit 281 for prompting the user to select whether or not to execute the recovered program, and accepts the user's instruction. In this case, the processor 21 may execute the program when the user instructs execution of the recovered program.

[0051] As described above, the digital multifunction peripheral as an image forming apparatus according to the embodiment stores a whitelist that indicates hash values ​​of legitimate programs. The digital multifunction peripheral checks whether the hash value of a program requested to be executed matches a hash value registered in the whitelist. If the hash value of the program requested to be executed does not match a hash value registered in the whitelist, the digital multifunction peripheral rewrites the program requested to be executed with the original program and restarts.

[0052] This allows the digital multifunction peripheral to restore a program with its original program when the hash value of the program does not match the hash value in the whitelist. Also, the digital multifunction peripheral can continue to operate a program with its hash value not matching the hash value in the whitelist restored with the original program.

[0053] Furthermore, the digital multifunction peripheral as an image forming apparatus according to the embodiment stores a whitelist indicating file path names and hash values ​​of legitimate programs. If the whitelist does not contain a file path name matching the file path of the program requested to be executed, the digital multifunction peripheral deletes the program requested to be executed. The digital multifunction peripheral identifies from the whitelist the hash value of the program matching the file path of the program requested to be executed. If the hash value identified from the whitelist does not match the hash value of the program requested to be executed, the digital multifunction peripheral restores the program using the original program.

[0054] As a result, if the file path of a program requested to be executed does not exist in the whitelist, the digital multifunction peripheral can delete the program as malware. Also, if the file path of a program requested to be executed exists in the whitelist, the digital multifunction peripheral can perform a hash check. As a result, the digital multifunction peripheral can delete programs suspected to be malware and restore programs suspected of being tampered with with the original program, allowing it to continue operating.

[0055] Furthermore, the digital multifunction peripheral as the image forming apparatus according to the embodiment has a read-only memory for storing an original program. The digital multifunction peripheral recovers a program whose hash value does not match the hash value in the whitelist using the original program stored in the read-only memory. As a result, the digital multifunction peripheral can recover a program that does not match a hash value in the whitelist using the original program stored in the read-only memory and continue operation.

[0056] Furthermore, the digital multifunction peripheral as the image forming apparatus according to the embodiment has a communication interface for communicating with an external device that stores original programs. The digital multifunction peripheral acquires original program data for a program whose hash value does not match a hash value in the whitelist from the external device. The digital multifunction peripheral restores the program whose hash value does not match a hash value in the whitelist using the original program acquired from the external device. This allows the digital multifunction peripheral to restore a program that does not match a hash value in the whitelist using data from an external device and continue operation.

[0057] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]

[0058] 11...digital multifunction peripheral (image forming apparatus), 12...network, 13...service center (external device), 14...cloud (external device), 21...processor, 22...ROM (read-only memory), 23...RAM, 24...storage, 25...communication interface (communication unit), 26...scanner, 27...printer, 28...operation panel, 281...display unit, 282...operation unit.

Claims

1. An image forming apparatus, a first memory for storing a program; a second memory that stores a whitelist in which information including unique information for each legitimate program is registered; a processor that, if the program requested to be executed does not match the unique information registered in the whitelist, rewrites the program requested to be executed with an original program and restarts the image forming apparatus; An image forming apparatus having the same.

2. the unique information is a hash value of a legitimate program, When a hash value of a program requested to be executed does not match a hash value registered in the whitelist, the processor rewrites the program requested to be executed with an original program. The image forming apparatus according to claim 1 .

3. Further, a read-only memory for storing the original program is provided, the processor overwrites the program requested to be executed with the original program stored in the read-only memory; The image forming apparatus according to claim 1 .

4. further comprising a communication interface for communicating with an external device that stores the original program; the processor rewrites the program requested to be executed with an original program acquired from the external device communicating via the communication interface; The image forming apparatus according to claim 1 .

5. The whitelist is information indicating a file path name and the unique information for each legitimate program, The processor deletes the program requested to be executed if the file path of the program requested to be executed does not match the path name of a file present in the whitelist; If the file path of the program requested to be executed matches a path name of a file existing in the whitelist, and if the hash value of the program whose file path matches in the whitelist does not match the hash value of the program requested to be executed, rewrite the program requested to be executed with an original program. The image forming apparatus according to claim 1 .

Citation Information

Patent Citations

  • Information processing apparatus, control method, and program thereof

    JP2019191698A