Image forming apparatus

The image forming apparatus maintains security by using a controller to transmit restricted data for remote display, addressing the issue of decreased security when operation screens with high security levels are displayed remotely.

JP2026004546AActive Publication Date: 2026-01-14BROTHER KOGYO KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025169819
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-10-08
Publication Date
2026-01-14
Estimated Expiration
2040-08-24

AI Technical Summary

Technical Problem

When an operation screen with a high security level is displayed remotely on an information processing apparatus, the desired security level cannot be maintained.

Method used

An image forming apparatus with a controller that executes remote display control, transmitting data via a communication interface to display a restricted operation screen on a remote browser using restriction parameters.

Benefits of technology

The security level is maintained by restricting the display content of the remote screen, preventing a decrease in security even when the operation screen is displayed remotely.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026004546000001_ABST
    Figure 2026004546000001_ABST
Patent Text Reader

Abstract

To suppress a decrease in security level when an operation screen displayed on an image forming apparatus is displayed on a remote information processing apparatus.SOLUTION: The controller 11 in the MFP10 executes remote display control for transmitting remote information to the PC40 via the communication IF16, and the remote information is information for displaying a remote screen reproducing an operation screen displayed in the user IF17 on a browser provided in the PC40. The controller 11 acquires a limit parameter for determining the limit of the display content on the remote screen, and transmits remote information corresponding to the limit parameter to the PC40 in the remote display control, thereby displaying the remote screen with the limited display content on the browser.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for displaying an operation screen displayed on an image forming apparatus on a remote information processing apparatus. [Background technology]

[0002] Patent Document 1 describes an image forming apparatus that displays a preview screen of an image after reading on a display unit. In addition, the image forming apparatus described in Patent Document 1 increases the security level by displaying a degraded preview screen for documents with a high security level. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-258771 Summary of the Invention [Problem to be solved by the invention]

[0004] However, there is a known function that allows an operation screen displayed on an image forming apparatus to be displayed on a remote information processing apparatus. In such a function, if an operation screen including an image with a high security level is remotely displayed on the information processing apparatus, there is a concern that the desired security level cannot be maintained.

[0005] The present invention has been made in view of the above-mentioned problems, and has an object to suppress a decrease in security level when an operation screen displayed on an image forming apparatus is displayed on a remote information processing apparatus. [Means for solving the problem]

[0006] In order to solve the above problems, the present invention relates to an image forming apparatus including a communication interface, a user interface, and a controller. The controller of the image forming apparatus executes remote display control to transmit remote data to an information processing apparatus via the communication interface, the remote data being data for displaying a remote screen that reproduces an operation screen displayed on the user interface on a browser provided in the information processing apparatus, and the controller executes an acquisition process to acquire restriction parameters that determine restrictions on display content on the remote screen, and in the remote display control, transmits remote data according to the restriction parameters to the information processing apparatus, thereby displaying the remote screen with the restricted display content on the browser.

[0007] In the above configuration, the controller transmits remote data to the information processing device via the communication interface, thereby executing remote display control to display a remote screen that reproduces an operation screen displayed on the user interface on a browser of the information processing device. The remote display control executed by the controller then transmits remote data according to the acquired restriction parameters to the information processing device, thereby restricting the display content of the remote screen displayed on the browser. This restricts the display content of the remote screen even when the operation screen displayed on the image forming device is displayed on a remote information processing device, thereby preventing a decrease in security level.

[0008] The present invention can be realized in various forms, and in addition to being an invention of an image forming apparatus, it can also be realized as an invention of a control program executed by a controller. [Effects of the Invention]

[0009] According to the present invention, even when an operation screen displayed on an image forming apparatus is displayed on a remote information processing apparatus, a decrease in security level can be suppressed. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating the configuration of an image forming system. [Figure 2] 10 is a flowchart illustrating a procedure of a process executed by a controller of the MFP. [Figure 3] FIG. 1 is a diagram illustrating an SFL list. [Figure 4] 3 is a flowchart illustrating the procedure of the process executed in S16 of FIG. 2. [Figure 5] FIG. 10 is a diagram illustrating the EWS screen. [Figure 6] FIG. 10 is a diagram illustrating a remote screen. [Figure 7] 3 is a flowchart illustrating the procedure of the process executed in S18 of FIG. 2. [Figure 8] FIG. 10 is a diagram illustrating a remote screen with display restrictions. [Figure 9] FIG. 10 is a diagram illustrating a remote screen with display restrictions. [Figure 10] FIG. 10 is a diagram illustrating a remote screen according to the second embodiment. [Figure 11] 3 is a flowchart illustrating the procedure of the process executed in S18 of FIG. 2. DETAILED DESCRIPTION OF THE INVENTION

[0011] (First embodiment) An image forming system 100 according to this embodiment will be described with reference to the drawings. The image forming system 100 shown in FIG. 1 includes an MFP 10, a general user PC 30, an administrator PC 31, and a service technician PC 40. MFP is an abbreviation for multifunction peripheral. The MFP 10 and the PCs 30 and 31 are connected to a LAN 200 and are capable of communicating with each other via the LAN 200. The LAN 200 is also connected to the Internet 210, to which the service technician PC 40 is connected. In this embodiment, the MFP 100 is an example of an image forming apparatus. The PCs 30, 31, and 40 are examples of information processing apparatuses.

[0012] PCs 30, 31, and 40 each include a CPU, memory, a user IF, a display, and a network IF (not shown). IF is an abbreviation for interface. The memory of PC 40 stores an OS and a browser program. The browser program connects to a web server via the Internet 210 and displays web page data managed by the web server on the display.

[0013] Of the PCs 30, 31, and 40, the general user PC 30 is a PC used by a user who uses the MFP 10 via the LAN 200. Specifically, the MFP 10 can be used by logging in to the MFP 10 through an operation on any of the PCs 30, 31, and 40. The administrator PC 31 is a PC used by an administrator who has the authority to manage the MFP 10 on the LAN 200. The service technician PC 40 is a PC used by a service technician who provides services such as maintenance and operational support for the MFP 10.

[0014] Next, a description will be given of the configuration of the MFP 10. The MFP 100 includes a controller 11, a memory 12, a printer unit 13, a scanner unit 14, a FAX unit 15, a communication IF 16, a user IF 17, and a bus 18.

[0015] The communication IF 16 connects the MFP 10 to the LAN 200 and the Internet 210 in accordance with a predetermined communication protocol. The user IF 17 is an interface that is interposed between the user who directly operates the MFP 10 and the controller 11, and is, for example, a touch panel or operation keys.

[0016] The printer unit 13 performs a printing operation to print an image on a recording medium such as a sheet or a disk. The recording method of the printer unit 13 can be an inkjet method, an electrophotographic method, or the like. The scanner unit 14 performs a scanning operation to read an image recorded on an original and generate image data. The FAX unit 15 performs a FAX operation to send and receive image data in a method compliant with the FAX protocol. The MFP 10 may also be capable of performing a composite operation that combines multiple operations. A copy operation that combines a print operation by the printer unit 13 and a scan operation by the scanner unit 14 is an example of a composite operation.

[0017] The controller 11 is configured with a CPU, an ASIC (application specific integrated circuit), etc., and controls the operation of the printer unit 13, the scanner unit 14, the FAX unit 15, the communication IF 16, and the user IF 17 that configure the MFP 10. The memory 12 has a data storage area. The data storage area is an area for storing data necessary for executing programs, etc. The memory 12 is configured by combining RAM, ROM, SSD, HDD, etc. A buffer provided in the controller 11 and used when executing various programs may also be considered part of the memory 12. The memory 12 may be a storage medium readable by the controller 11. A storage medium readable by the controller 11 is a non-transitory medium. In addition to the above examples, non-transitory media also include recording media such as CD-ROMs and DVD-ROMs. A non-transitory medium is also a tangible medium. On the other hand, electrical signals carrying programs downloaded from a server on the Internet 210, etc., are computer-readable signal media, which is a type of computer-readable medium, but are not included in non-transitory computer-readable storage media.

[0018] The memory 12 stores a control program 20 as a program executable by the controller 11. In the following description, the controller 11 executing the program may be referred to simply by the program name. For example, the phrase "the control program 20" is used to mean "the controller 11 executing the control program 20." In this embodiment, the term primarily refers to the processing of the controller 11 in accordance with instructions written in the program. In other words, processes such as "determine," "extract," "select," "calculate," "decide," "identify," "acquire," "receive," and "control" in the following description represent the processing of the controller 11. Note that "acquire" is used as a concept that does not necessarily require a request. In other words, the process of the controller 11 receiving data without a request is also included in the concept of "the controller 11 acquiring data." Furthermore, "data" in this specification refers to a bit string that can be read by the controller. Data with essentially the same meaning but different formats are treated as the same data. The same applies to "information" in this specification.

[0019] The control program 20 controls printer operations using the printer unit 13, scanner operations using the scanner unit 14, and fax operations using the fax unit 15. The control program 20 also functions as an EWS (Embedded Web Server), which is a Web server. By functioning as an EWS, the control program 20 can display a browser screen on the browser provided in each of the PCs 30, 31, and 40. Specifically, when a user starts the browser on the PC and enters a URL specifying the control program 20 (i.e., the EWS), the Web page data created by the control program 20 can be downloaded and the EWS screen, which is a browser screen, can be displayed on the browser. In this embodiment, the Web page data is an example of remote data.

[0020] An SFL (an abbreviation for Secure Function Lock) list L1 is stored in the memory 12. The SFL list L1 sets whether or not there are restrictions on the execution of various operations and functions of the MFP 10. The SFL list L1 will be described in detail later.

[0021] Next, the processing executed by the controller 11 will be described with reference to the drawings. Fig. 2 is a flowchart showing the procedure of the processing executed by the control program 20 of the MFC 10, and the subject of the processing will be omitted.

[0022] In S10, a standby screen is displayed on the user IF 17. The standby screen includes shortcut icons and unregistered icons as operation icons for specifying each operation of the MFP 10. For example, the standby screen includes a shortcut icon for specifying a "FAX operation," a shortcut icon for specifying a "copy operation," a shortcut icon for specifying a "scan operation," a shortcut icon for specifying a "2-in-1 copy," and a shortcut icon for specifying a "specific paper copy." In this embodiment, the specific paper copy is a function for copying invoices. The specific paper copy may also be a function for copying high-security items such as driver's licenses, passports, and insurance cards, in addition to invoices. Each shortcut icon is not basically an icon that is pre-arranged when the MFP 10 is shipped, but is an icon that is arranged in place of an unregistered icon when the user performs a registration operation on the unregistered icon.

[0023] In S11, it is determined whether a user operation on the user IF 17 has been detected. If it is determined that an operation on the user IF 17 has been detected, the process proceeds to S19. In S19, it is determined whether the operation on the user IF 17 is a login operation for the MFP 10. If an affirmative decision is made in S19, the process proceeds to S20, where the standby screen is updated to a screen corresponding to the login operation.

[0024] In S21, the login ID input via the user IF 17 is acquired. In S22, the SFL list L1 corresponding to the login ID acquired in S21 is read. In the SFL list L1, restriction parameters are set for each “login ID” that identifies the login user of the MFP 10, indicating whether or not there are restrictions on the “print operation,” “copy operation,” and “fax operation” that are operations of the MFP 10, and whether or not there is a display restriction on the “remote display control” function of the MFP 10. In the SFL list L1 shown in FIG. 3, check boxes are checked for items indicating operations or functions for which restrictions are set, and check boxes are not checked for items indicating operations or functions for which restrictions are not set. Because a restriction is set on the “copy operation” for the login user “User A” in the SFL list L1, when “User A” is logged in to the MFP 10, the MFP 10 cannot perform a copy operation. The restriction parameters read from the SFL list L1 are temporarily stored. Note that the values ​​of the SFL list L1 can be set on the EWS screen described later. In this embodiment, the process executed by the controller 11 in S22 is an example of an acquisition process.

[0025] The controller 11 may execute the acquisition process in response to an operation received via the user IF 17 of the MFP 10. In this case, the controller 11 causes the user IF 17 to display a setting screen for setting the contents of the SFL list L1 in response to the user operation received via the user IF 17. Then, the controller 11 executes the acquisition process for setting the contents of the SFL list L1 in response to the user operation received on this setting screen.

[0026] When S22 is completed or a negative judgment is made in S19, the process proceeds to S23. In S23, it is determined whether the operation on the user IF 17 is an operation on a shortcut icon. When a positive judgment is made in S23, the process proceeds to S24, where the screen displayed on the user IF 17 is updated in accordance with the operated shortcut icon. For example, if the user operates a shortcut icon instructing a "copy operation," the copy operation is executed by the MFP 10. When a negative judgment is made in S23, the process proceeds to S28, where it is determined whether or not updating of the screen is necessary due to the operation on the user IF 17. When a positive judgment is made in S28, the process proceeds to S29, where the screen is updated in accordance with the operation accepted via the user IF 17. When a negative judgment is made in S28, or when the processing of S29 is completed, the process returns to S11.

[0027] In S25, it is determined whether the operation on the user IF 17 corresponds to a service request. A service request is a request to a service technician to perform remote display control for remote support of the MFP 10. Specifically, the remote display control is a control for displaying a remote screen, which is a virtual screen that virtually creates and displays the display of the user IF 17 of the MFP 10, on a browser of the PC. In the remote display control, when a user performs an operation input on the remote screen displayed on the PC, the result is the same as if the same operation input had been performed on the user IF 17 of the MFP 10. If a negative determination is made in S25, the process returns to S11. In this embodiment, a service request is an example of a support request.

[0028] If an affirmative decision is made in S25, the process proceeds to S26, where a request transmission process is performed to make a service request. In this embodiment, as the service request, a command for requesting the start of remote display control for remote support is transmitted to the service technician PC 40 via the communication IF 16. If the controller 11 has stored the service technician's email address in the memory 12, the controller 11 may transmit the support request by email to this email address. Alternatively, if the controller 11 has stored the service technician's telephone number in the memory 12, the controller 11 may display the service technician's telephone number on the user IF 17 in S26. In this case, the user of the MFP 10 makes a support request to the service technician by calling the telephone number displayed on the user IF 17.

[0029] In S27, the fact that a service request has been sent to a service technician is stored.

[0030] Returning to S11, if no user operation is detected, proceed to S12 and determine whether or not an http(s) communication, i.e., data communication according to the http(s) protocol, has been received. If it is determined that an http(s) communication has not been received, return to S11.

[0031] If it is determined in S12 that an http(s) communication has been received, the process proceeds to S13, where it is determined whether the http(s) communication is a display request for displaying an EWS screen. An EWS screen is a browser screen displayed by a browser using web page data created by the control program 20. A request to display an EWS screen is sent to the control program by entering a URL specifying the control program 20 in the browser. If the http(s) communication is a display request for an EWS screen, in S14 web page data for displaying the home screen of the EWS screen is sent to the PC that sent the display request. If S14 is completed, the process returns to S11.

[0032] By the process of S14, for example, when the home screen of the EWS screen is displayed on the service technician PC 40, the user can receive various functions provided by the control program 20 by entering a password in a login password input field on a screen displayed on any of the PCs 30, 31, and 40 and clicking the login button. Functions that can be provided from the EWS screen include remote display control for remotely operating the MFP 10 using a remote screen displayed on each of the PCs 30, 31, and 40, and processing for updating items recorded in the SFL list L1. For example, when a user selects remote display control on the EWS screen after logging in, a request to start remote display control is sent to the MFP 10 via HTTP(S) communication.

[0033] On the other hand, if a negative judgment is made in S13, the process proceeds to S15, where it is determined whether the http(s) communication is a request in response to an operation on the EWS screen. If the EWS screen is already displayed on the PC that sent the display request in S14 and the user performs an operation on the EWS screen, an http(s) request in response to the operation on the EWS screen is sent to the MFP10. Therefore, if a positive judgment is made in S15, the process proceeds to S16, where processing in response to the operation accepted on the EWS screen is executed. Note that if a negative judgment is made in S15, the process proceeds to S17.

[0034] Figure 4 is a flowchart explaining the detailed processing executed in S16. In S30, it is determined whether the http(s) request corresponds to a login operation on the EWS screen. If the determination in S30 is affirmative, the process proceeds to S31, where web page data for displaying the updated EWS screen is sent to the requesting PC as login processing.

[0035] In S32, the login user who performed the login operation on the EWS screen is temporarily stored in memory 12. Specifically, the user who performed the login operation is stored in memory 12 based on the "user name" included in the http(s) request received in conjunction with the login operation on the EWS screen.

[0036] If the process of S32 is terminated or a negative judgment is made in S30, the process proceeds to S33. In S33, it is determined whether the http(s) request is a request to start remote display control. If a positive judgment is made in S33, the process proceeds to S34, where it is determined whether the logged-in user stored in S32 is a service technician. If the logged-in user is a service technician and a positive judgment is made in S34, the process proceeds to S35, where it is determined whether a service request has already been sent to the service technician. If a service request has not already been sent to the service technician, the received request to start remote display control may have been sent in error, and the process of FIG. 4 is temporarily terminated. In this case, remote display control is not started. On the other hand, if a positive judgment is made in S35, the received request to start remote display control is valid, and the process proceeds to S36, where a flag indicating the start of remote display control is set to valid. Then, the process proceeds to S17 of FIG. 2. The flag set in S36 is changed from valid to invalid when an operation icon indicating the end of remote display control is operated on the remote screen.

[0037] In S34, if the logged-in user is not a service person, i.e., an administrator or a general user logged in to MFP10, the process proceeds to S36, where a flag indicating that remote display control is to be started is set to valid. In other words, if the logged-in user is an administrator or a general user, it can be determined that the remote display control is not intended for remote support, and therefore, whether or not a service request has been sent is not determined. When the process of S36 ends, the process proceeds to S17 in FIG. 2.

[0038] If, in S33, the http(s) communication is not a request to start remote display, the process proceeds to S37, where it is determined whether remote display control is currently being executed. If the flag indicating the start of remote display control has already been set to enabled by the processing of S36, an affirmative decision is made in S37, and the process proceeds to S17 in FIG. 2. On the other hand, if the flag indicating the start of remote display control is set to disabled, an affirmative decision is made in S37, and the process proceeds to S38. In S38, it is determined whether an update of the EWS screen is necessary. If, in S38, it is determined that an update of the EWS screen is necessary, the process proceeds to S39, and web page data for displaying the updated EWS screen in the browser is sent to the PC that originated the http(s) communication. If S39 has ended, or if a negative decision is made in S38, the process proceeds to S17 in FIG. 2.

[0039] 2, in S17, it is determined whether or not remote display control is currently being executed. Specifically, if the process proceeds to S17 via S36 in FIG. 4 or after making a positive determination in S37, the flag indicating that remote display control has started is set to enabled, so the process makes a positive determination in S17 and proceeds to S18. On the other hand, if the process proceeds to S17 via S38 and S39 after making a negative determination in S37, the flag indicating that remote display control has started is set to disabled, so the process makes a negative determination in S17 and returns to S11.

[0040] In S18, remote display control is executed. Figure 5 shows a browser screen 300 that is displayed on one of the PCs 30, 31, and 40 as a result of remote display control being executed when the standby screen is displayed on the user IF 17. The browser screen 300 includes an item display area 301 that displays Web page data provided by the control program 20, and a details display area 302. The item display area 301 is an area that displays items that indicate functions that can be selected on the EWS screen. In Figure 5, because remote display control has been selected on the EWS screen, the item "Remote Display Control" that indicates remote display control is displayed as activated.

[0041] The detail display area 302 is an area where a screen corresponding to a selected function is displayed. In Fig. 5, the detail display area 302 displays a remote screen 310, which is an image that reproduces the user IF 17. Specifically, the remote screen 310 includes a panel display image 311 that corresponds to the standby screen and virtual key icons 312 that correspond to the operation keys. Therefore, the remote screen 310 includes shortcut icons that are the same as the shortcut icons displayed on the standby screen.

[0042] 6 is a remote screen 310 that is displayed on any of PCs 30, 31, and 40 when a user causes MFP 10 to execute a copy operation and causes user IF 17 to display a preview screen of the scanned document. Remote screen 310 includes a preview screen 315 and operation icons 316. Preview screen 315 is a screen that displays a document scanned by the scanning operation of MFP 10. Operation icon 316 is an icon that accepts instructions for processing such as enlarging / reducing the document displayed on preview screen 315 and inverting it.

[0043] In the above-described remote display control, when a remote screen 310 including an image with a high security level, such as a certificate or an ID card, is displayed on the serviceman PC 40, there is a concern that a desired security level for the image cannot be maintained. For example, in the example of Fig. 6, the remote screen 310 includes an original image M corresponding to an ID card, and there is a concern that displaying the remote screen 310 on the serviceman PC 40 will lower the security level. Therefore, in the present embodiment, a restriction is placed on the display of the remote screen 310 in the remote display control, thereby suppressing a decrease in the security level for the original.

[0044] Next, the procedure of the process relating to the remote display control executed in S18 of FIG. 2 will be described with reference to FIG.

[0045] In S40, it is determined whether the http(s) communication is an http(s) request with operation coordinates. The operation coordinates are generated in response to an operation on an icon on the remote screen 310, and are information indicating the coordinates operated on the remote screen 310. If a negative decision is made in S40, the process proceeds to S41, where raster data corresponding to the operation screen currently displayed on the user IF 17 is created. Note that if the remote screen 310 is not displayed on the PC that requested remote display control, the user cannot operate icons on the remote screen 310, so a negative decision is made in S40 and the process proceeds to S41.

[0046] In S46, it is determined whether the user currently logged in on the EWS screen is a service technician. In this embodiment, if a service technician is logged in, it is determined that the remote display control is for the purpose of remote support. This is because, when the operation of the MFP 10 is supported via the remote screen 310 displayed by the remote service technician PC 40, the service technician PC 40 is used by an unspecified number of users, which increases the possibility of a lower security level. In such cases, the display content of the remote screen 310 is restricted. Specifically, if the logged-in user stored in S32 of FIG. 4 is a service technician, a positive determination is made in S46. However, if the logged-in user stored in S32 is an administrator or a general user, a negative determination is made in S46.

[0047] Alternatively, in S46, if the IP address of the sender of the http(s) request is the serviceman PC 40, it may be determined that the remote screen display is for remote support, and if the IP address is the general user PC 30 or the administrator PC 31, it may be determined that the remote screen display is not for remote support. In this embodiment, the login ID indicating the serviceman and the IP address of the serviceman PC 40 are examples of purpose information.

[0048] If the result of S46 is affirmative, the process proceeds to S47, where it is determined whether the screen currently displayed on the user IF 17 is a preview screen for scanner operation. If it is determined that the screen currently displayed on the user IF 17 is a preview screen, the process proceeds to S48. In S48, the raster data created in S41 is modified by adding restrictions based on the restriction parameters read from the SFL list L1, and Web page data including the modified raster data is created. That is, in this embodiment, the display restriction is limited to the preview screen. The restriction parameters read at this time are the restriction parameters read in S21 of FIG. 2 according to the logged-in user of the MPF 10.

[0049] In this embodiment, the presence or absence of display restrictions on the remote screen 310 can be set in three modes using the restriction parameters recorded in the SFL list L1. As shown in FIG. 3 , the "Off mode" is a mode in which the original image M is displayed as is, i.e., without any restrictions, when the preview screen 315 is displayed on the remote screen 310. The "On mode" and "blur mode" are modes in which the original image M is displayed with restrictions when the preview screen 315 is displayed on the remote screen 310. Of these, the "On mode" is a mode in which the original image M is not displayed when the preview screen 315 is displayed on the remote screen 310. Specifically, as shown in FIG. 8 , in the "On mode," the original image M is displayed grayed out on the preview screen 315, thereby hiding the original image M. On the other hand, the "blur mode" is a mode in which the original image M is displayed with a blurring process applied when the preview screen 315 is displayed on the remote screen 310. Specifically, as shown in FIG. 9, in the "blur mode," the original image M is blurred on the preview screen 315, so that the original image M is not displayed.

[0050] For example, the method for recognizing the original image M from the raster data may be performed using well-known image processing such as pattern detection, etc. Furthermore, the method for graying out or blurring the original image M may be performed using image processing using well-known filters, for example.

[0051] Note that if it is determined in S46 that a service technician is not logged in, the process proceeds to S49. As described above, in this embodiment, if an administrator or general user is logged in on the EWS screen, it is determined that remote display control for the purpose of remote support is not being executed, and therefore the display of the remote screen 310 is not restricted. Therefore, in S49, web page data is created that includes the created raster data as is. In other words, the web page data created in S49 is web page data for displaying the remote screen 310 corresponding to the preview screen as is in the browser. Note that even if it is determined in S47 that the preview screen is not being displayed, the process proceeds to S49, and web page data is created that does not restrict the display of the remote screen 310.

[0052] After S48 or S49 is completed, the process proceeds to S50. If the process proceeds to S50 via S48, the web page data including the raster data with display restrictions is sent to the service technician PC 40 along with the http(s) response. Upon receiving the web page data along with the http(s) response, the service technician PC 40 analyzes the web page data. Depending on the analysis results, the raster data included in the web page data is displayed in the browser. If the process proceeds to S50 via S49, the web page data including the raster data without display restrictions is sent to one of the destination PCs 30, 31, 40 along with the http(s) response.

[0053] If the remote screen 310 has already been displayed on the PC that requested the remote display control by the processing of S50, a request with operation coordinates is sent to the MFP 10 when the user operates an icon on the remote screen 310 displayed on the PC. Therefore, if the http(s) request is a request with operation coordinates in S40, the process proceeds to S42. In S42, it is analyzed whether the operation coordinates are within the area of ​​the operation icon on the remote screen 310. For example, a table that records the correspondence between the operation coordinates and the area of ​​the operation icon included in the remote screen 310 may be stored in the memory 12, and the relationship between the operation coordinates and the area of ​​the operation icon may be analyzed by referring to this table.

[0054] If the operation coordinates are not within the area of ​​any of the operation icons, the operation on the remote screen 310 is not an operation for updating the remote screen 310, so a negative decision is made in S43 and the processing in Fig. 7 is temporarily terminated. On the other hand, if a positive decision is made in S43, the processing proceeds to S44, where the operation screen displayed on the user IF 17 is updated in accordance with the operation of the operation icon corresponding to the operation coordinates. That is, the operation screen displayed on the user IF 17 of the MFP 10 is updated in accordance with the operation of the operation icon on the remote screen 310.

[0055] In S45, raster data corresponding to the operation screen updated in S44 is created. Proceeding to S46, it is determined whether the person logged in to the EWS screen is a service technician. If an affirmative judgment is made in S46, it proceeds to S47, where it is determined whether the screen currently displayed on the user IF 17 is a preview screen. If an affirmative judgment is made in S47, it proceeds to S48, where the raster data created in S45 is modified using restriction parameters to restrict its display, and web page data including the modified raster data is created. If an affirmative judgment is made in S46 or S47, it proceeds to S49, where web page data including the raster data created in S45 is created as is. In S50, the web page data created in S48 or S49 is sent to one of the destination PCs 30, 31, 40 together with an http(s) response.

[0056] The above-described embodiment can achieve the following effects. The controller 11 executes remote display control, which transmits web page data to the serviceman PC 40 via the communication IF 16, thereby causing a remote screen 310, which reproduces the operation screen displayed on the user IF 17, to be displayed on the browser of the serviceman PC 40. The remote display control executed by the controller 11 restricts the display content of the remote screen 310 displayed on the browser by transmitting web page data according to the acquired restriction parameters to the serviceman PC 40. As a result, even when the operation screen displayed on the MFP 10 is displayed on a remote PC, the display content of the remote screen is restricted, thereby preventing a decrease in the security level.

[0057] In the remote display control, the controller 11 creates raster data including a plurality of operation icons for displaying the remote screen 310 on the browser of the serviceman PC 40, transmits Web page data including the raster data to the serviceman PC 40, and upon receiving information indicating that an operation icon has been operated from the serviceman PC 40 that has received the Web page data via the communication IF 16, updates the operation screen displayed on the user IF 17 in accordance with the received information. The controller 11 creates raster data corresponding to the updated operation screen, and transmits Web page data including the created raster data to the serviceman PC 40. As a result, the Web page data transmitted to the serviceman PC 40 includes raster data whose display content is restricted according to the restriction parameters. Therefore, even in a configuration in which the operation screen displayed on the MFP 10 is updated in accordance with operations on the remote screen 310 on the serviceman PC 40, it is possible to restrict the display content of the remote screen 310 displayed on the serviceman PC 40.

[0058] Controller 11 accepts input of restriction parameters from an administrator of MFP 10, does not accept input of restriction parameters from anyone other than the administrator, and in remote display control, transmits web page data according to the accepted input of restriction parameters to serviceman PC 40. As a result, since the restriction parameters are obtained by operations limited to the administrator of MFP 10, it is possible to prevent a decrease in security level compared to when restriction parameters are changed by an unspecified number of people.

[0059] The restriction parameters are set in association with identification information that identifies a predetermined user of the serviceman PC 40. In remote display control, the controller 11 acquires the identification information together with a request for remote display control from the serviceman PC 40, and if a restriction parameter is set in the acquired identification information, it transmits web page data according to the set restriction parameter to the serviceman PC 40. This allows the restriction parameters to be set only for a predetermined user, making it possible to set different security levels for each user who views the remote screen.

[0060] When the login ID indicates that the user is a logged-in user of MFP 10, controller 11 transmits web page data for displaying remote screen 310, the display content of which is not restricted, on a browser to general user PC 30. As a result, remote screen 310, the display content of which is not restricted, is displayed on serviceman PC 40 for the logged-in user of MFP 10. Therefore, for example, in a situation where a user who is logged in to MFP 10 wants remote screen 310 to be displayed on PC 30, remote screen 310 can be displayed on PC 30 without any restrictions on the display content.

[0061] The restriction parameters are set in association with purpose information indicating the purpose of the remote display control, and in the remote display control, the controller 11 acquires the purpose information together with a request for remote display control from the serviceman PC 40, and if a restriction parameter is set in the acquired purpose information, transmits web page data according to the set restriction parameter to the serviceman PC 40. This allows switching whether or not to restrict display of the remote screen depending on the purpose of the remote display control, making it possible to vary the security level for each purpose of the remote display control.

[0062] The purpose information includes purpose information indicating that the operation of MFP 10 is to be supported via the remote screen, and the restriction parameter is set in association with the purpose information indicating the support. As a result, when remote display control is performed for the purpose of supporting the operation of MFP 10 on a remote PC, the display content of remote screen 310 is restricted, so that a decrease in security level can be suppressed in situations where security is particularly required.

[0063] (Modification of the first embodiment) Display restrictions on the remote screen 310 may be implemented by processing on the service technician PC 40 side. In this case, instead of creating restricted Web page data in S48 of Fig. 7, the controller 11 transmits information for restricting the display content of the raster data in accordance with the restriction parameters together with the raster data to the service technician PC 40. The browser on the service technician PC 40 analyzes the information in accordance with the restriction parameters and performs processing to restrict the display of the raster data in accordance with the analysis results.

[0064] (Second embodiment) In the second embodiment, the configuration different from the first embodiment will be mainly described. Note that the same reference numerals as in the first embodiment denote the same parts, and the description thereof will not be repeated.

[0065] In this embodiment, the restriction parameters are set in association with the operation screen displayed on the user IF 17. FIG. 10 shows a remote screen 310 corresponding to the standby screen among the remote screens 310. The remote screen 310 includes a shortcut icon 330 for specifying a "FAX operation," a shortcut icon 331 for specifying a "copy operation," a shortcut icon 332 for specifying a "scan operation," a shortcut icon 334 for specifying a "2-in-1 copy," and a shortcut icon 335 for specifying a "specific paper copy." In this embodiment, the specific paper copy is a function for copying invoices. The specific paper copy may also be a function for copying paper or cards with a high security level, such as a driver's license, passport, or insurance card, in addition to invoices. The remote screen 310 also includes unregistered icons 333 and 336.

[0066] In this embodiment, when remote display control is performed, display restriction of the remote screen 310 is performed when a shortcut icon 335 is operated on the standby screen displayed on the user IF 17. In this embodiment, the shortcut icon is an example of a shortcut image.

[0067] 11 shows detailed steps of the display permission process executed in S18 of FIG. 2 in this embodiment. In S41 or S45, raster data corresponding to the operation screen displayed on the user IF 17 is created. In S46, it is determined whether the logged-in user for the EWS screen is a service technician, and if so, the process proceeds to S60. In this embodiment as well, if the logged-in user is an administrator or a general user, the process proceeds to S49.

[0068] In S60, it is determined whether the screen updated by operating the shortcut icon on the user IF 17 is subject to display restrictions on the remote screen 310. In this embodiment, if the shortcut icon 335 specifying a specific paper copy is operated, a positive determination is made in S60 and the process proceeds to S48. In S48, the created raster data is modified to restrict display in accordance with the restriction parameters, and web page data is created that includes the modified raster data. On the other hand, if a negative determination is made in S60, the process proceeds to S49. In S49, web page data is created that includes the created raster data as is.

[0069] In this embodiment, the SFL list stored in memory 12 stores restriction parameters in association with each shortcut icon to be operated. Therefore, in S48, the SFL list stored in memory 12 is referenced to read out the restriction parameters associated with the shortcut icon operated on the remote screen 310. Alternatively, the restriction parameters may be read out from the items in the SFL list referenced in accordance with the login user of MFP 10 in S21 of Fig. 2. In this case, it is sufficient that the SFL list stored in memory 12 stores the shortcut icons to be subject to display restriction and the control parameters in association with each other for each login user of MFP 10.

[0070] The above-described embodiment can achieve the following effects. The restriction parameters are set in association with the operation screen displayed on the user IF 17, and when the restriction parameters are set for the operation screen after switching during remote display control, the controller 11 transmits remote data corresponding to the set restriction parameters to the service technician PC 40. This makes it possible to restrict the display content to only a specific operation screen among the operation screens after switching.

[0071] (Third embodiment) In the third embodiment, the configuration different from the first embodiment will be mainly described. Note that the same reference numerals as in the first embodiment denote the same parts, and the description thereof will not be repeated.

[0072] In the first and second embodiments described above, display restrictions are imposed on the remote screen 310 according to the restriction parameters. Instead, the area to be restricted from displaying on the remote screen 310 is varied according to the restriction parameters. Specifically, the SFL list L1 has areas to be restricted from displaying on the remote screen 310 set in association with login IDs. In this embodiment, when an address book is displayed on the remote screen 310, display restrictions are imposed on the address display area included in the address book.

[0073] 7, if the address book is displayed as the remote screen 310, the process proceeds to S48. Then, the web page data in which the display of a specific area is restricted according to the restriction parameters set for the logged-in user of the MFP 10 is transmitted to the service technician PC 40. For example, the area in the address book where addresses are supposed to be displayed is grayed out or blurred.

[0074] In the embodiment described above, an area on the remote screen 310 where display is restricted can be set for each user, and therefore an area on the remote screen 310 where security is strengthened can be set for each user.

[0075] (Other embodiments) The present invention is not limited to the above-described embodiment, and various modifications are possible without departing from the spirit of the present invention. In the above-described embodiments, when the purpose of the remote display control is remote support, the display of the remote screen 310 is restricted. Alternatively, the display of the remote screen 310 may be restricted uniformly regardless of the purpose of the remote display control. In this case, the process of S46 in FIG. 7 may be deleted.

[0076] In the above-described embodiments, the MFP 10 has been taken as an example of an image forming apparatus, but the image forming apparatus is not limited to the MFP 10 and may be a standalone printer, scanner, or copier. [Explanation of symbols]

[0077] 10...MFC, 11...controller, 12...memory, 16...communication IF, 17...user IF, 30...general user PC, 31...administrator PC, 40...service technician PC, 100...image forming system

Claims

1. a communication interface, a user interface, and a controller; The controller executes remote display control to transmit remote data to an information processing device via the communication interface, the remote data being data for displaying a remote screen that reproduces an operation screen displayed on the user interface on a browser provided in the information processing device; The controller an acquisition process for acquiring restriction parameters that define restrictions on the display content on the remote screen; Run In the remote display control, the image forming apparatus transmits the remote data according to the restriction parameters to the information processing apparatus, thereby displaying the remote screen with restricted display content on the browser.

2. In the remote display control, the controller creating raster data for displaying the remote screen on the browser, the raster data including a plurality of operation icons; transmitting web page data including the raster data as the remote data to the information processing device; when receiving information indicating that the operation icon has been operated from the information processing device that has received the web page data via the communication interface, updating the operation screen displayed on the user interface in accordance with the received information; creating raster data corresponding to the updated operation screen; transmitting the web page data including the created raster data to the information processing device; 2. The image forming apparatus according to claim 1, wherein the Web page data includes information for restricting display content of the raster data in accordance with the restriction parameters, or the raster data whose display content is restricted in accordance with the restriction parameters.

3. The controller In the acquisition process, an input of the limiting parameters is accepted from an administrator of the image forming apparatus, and an input of the limiting parameters is not accepted from anyone other than the administrator; 3. The image forming apparatus according to claim 1, wherein the remote display control comprises transmitting the remote data corresponding to the restriction parameter whose input has been accepted to the information processing apparatus.

4. the restriction parameter is set in association with identification information for identifying a predetermined user of the information processing device, In the remote display control, the controller acquiring the identification information together with the request for remote display control from the information processing device; An image forming device described in any one of claims 1 to 3, wherein when the restriction parameters are set in the acquired identification information, the remote data corresponding to the set restriction parameters is transmitted to the information processing device.

5. The controller The user is placed in a logged-in state in response to an operation received via the user interface, In the remote display control, when the identification information indicates that the user is a logged-in user of the image forming apparatus, the remote screen with no display content restriction is displayed on the browser.

5. The image forming apparatus according to claim 4, wherein the remote data to be displayed on the information processing device is transmitted to the information processing device.

6. the limiting parameter is set in association with purpose information indicating a purpose of the remote display control, An image forming apparatus according to any one of claims 1 to 3, wherein the controller, in the remote display control, acquires the target information from the information processing device along with a request for the remote display control, and if the restriction parameter is set in the acquired target information, transmits the remote data corresponding to the set restriction parameter to the information processing device.

7. the purpose information includes the purpose information indicating that operation of the image forming apparatus is supported via the remote screen, 7. The image forming apparatus according to claim 6, wherein the restriction parameter is set in association with the purpose information indicating support.

8. In the remote display control, the controller transmitting a support request to the information processing device via the communication interface; The image forming device according to claim 7, wherein when a request for remote display control accompanying the support request is received from the information processing device, the image forming device transmits to the information processing device the remote screen that reproduces the currently displayed operation screen and the remote data corresponding to the restriction parameters.

9. the restriction parameters are set in association with the operation screen, The controller The operation screen can be switched in response to an operation via the user interface, An image forming device described in any one of claims 1 to 3, wherein, in the remote display control, when the restriction parameters are set on the operation screen after switching, the remote data corresponding to the set restriction parameters is transmitted to the information processing device.

10. The controller A shortcut image for accepting a designation operation for switching the operation screen can be set on the operation screen, the restriction parameters are set in association with the shortcut image, The image forming apparatus according to claim 9, wherein, in the remote display control, when the restriction parameters are set for the specified shortcut image, the remote data corresponding to the set restriction parameters is transmitted to the information processing device.

11. 11. The image forming apparatus according to claim 10, wherein the controller sets the shortcut image on the operation screen for each predetermined purpose in response to an operation received via the user interface.

12. The controller The user is placed in a logged-in state in response to an operation received via the user interface, In the acquisition process, the restriction parameters are set in association with a login user of the image forming apparatus; An image forming device described in any one of claims 1 to 3, wherein, in the remote display control, when the restriction parameters are set for the logged-in user, the remote data corresponding to the set restriction parameters is transmitted to the information processing device.

13. In the acquisition process, an area in which display on the remote screen is restricted can be set for each of the login users using the restriction parameters; The image forming apparatus according to claim 12, wherein the remote display control transmits the remote data corresponding to the restriction parameters to the information processing device, thereby displaying the remote screen on the browser with the display of the area indicated by the restriction parameters restricted.

14. A control program readable by a controller of an image forming apparatus including a user interface, a communication interface, and a controller, the image forming apparatus is capable of communicating with an information processing apparatus having a browser via the communication interface; The controller, executes a remote display control for transmitting remote data to the information processing device via the communication interface, the remote data being data for displaying on the browser a remote screen that reproduces an operation screen displayed on the user interface; The controller, an acquisition process for acquiring restriction parameters that define restrictions on the display content on the remote screen; Execute In the remote display control, the control program transmits the remote data according to the restriction parameters to the information processing device, thereby displaying the remote screen with restricted display content on the browser.

Citation Information

Patent Citations

  • Image display device and image forming device

    JP2010258771A

  • Information processing device, method for controlling information processing device, and program

    JP2016091132A

  • Electronic apparatus and program

    JP2018067815A

  • Communication system, communication device and control method therefor, and program

    JP2019016223A