System and image forming apparatus

The system manages digital certificate expiration dates through a cloud server interface, ensuring timely updates and preventing communication blockages in image forming devices.

JP2026037558APending Publication Date: 2026-03-06BROTHER KOGYO KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024140620
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-22
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing image forming devices face issues with managing the validity period of digital certificates, leading to potential communication blockages when certificates expire.

Method used

A system comprising an image forming device and a cloud server that allows the device to store electronic certificates with expiration dates, enabling the cloud server to receive commands for transmitting expiration date information to an information processing device, which can then notify administrators of the expiration dates.

Benefits of technology

Enables appropriate management of electronic certificate expiration dates, facilitating timely updates and preventing communication disruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026037558000001_ABST
    Figure 2026037558000001_ABST
Patent Text Reader

Abstract

To provide a technique capable of appropriately managing the expiration date of an electronic certificate in an image forming apparatus capable of storing the electronic certificate.SOLUTION: In a management system 100 including an MFP1 and a cloud server 200, the MFP1 can store an electronic certificate having an expiration date in a memory 12, and the cloud server 200 can receive a command in which a destination is designated from a head office PC5. The MFP1 acquires a command in which the MFP1 is designated as a destination from the cloud server 200 via the NET-IF1 17, and in a case where the acquired command is a command for requesting transmission of an expiration date of an electronic certificate, the MFP1 passes expiration date information indicating the expiration date of the electronic certificate stored in the memory 12 to the cloud server 200 in association with the command. The cloud server 200 transfers the deadline information transferred from the MFP1 to the head office PC5 as a response to the command.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technical field disclosed in this specification relates to a system having an image forming device capable of storing a digital certificate. [Background technology]

[0002] Conventionally, a technology using digital certificates has been known as a communication technology for communicating between devices over a network. An example of a document disclosing an image forming device that stores a digital certificate is Patent Document 1. Patent Document 1 discloses a configuration in which a multifunction device that uses a digital certificate blocks communication with a PC when a request for encrypted communication is received from the PC if the digital certificate used by the device has expired. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-274060 Summary of the Invention [Problem to be solved by the invention]

[0004] As disclosed in the aforementioned Patent Document 1, if the validity period of a digital certificate expires, communication with other devices may be blocked. Therefore, it is desirable to appropriately manage the validity period of the digital certificate stored in the image forming device. [Means for solving the problem]

[0005] A system designed to solve this problem is a system having an image forming device and a cloud server, wherein the image forming device is capable of storing an electronic certificate with an expiration date in the memory of the image forming device, and the cloud server is capable of receiving a command with a specified destination from an information processing device, and the image forming device obtains the command with the image forming device specified as the destination from the cloud server via the network interface of the image forming device, and if the obtained command is a first command requesting the transmission of the expiration date of the electronic certificate, the image forming device associates first expiration date information indicating the expiration date of the electronic certificate stored in the memory with the first command and passes it to the cloud server, and the cloud server passes the first expiration date information passed from the image forming device to the information processing device as a response to the first command.

[0006] According to the system disclosed in this specification, when an image forming apparatus receives a first command addressed to itself from an information processing apparatus via a cloud server, the image forming apparatus transmits first expiration information indicating the expiration date of the electronic certificate stored in the image forming apparatus's own memory to the cloud server. The cloud server then transmits the first expiration information received from the image forming apparatus to the information processing apparatus as a response to the first command. Therefore, the information processing apparatus can notify the expiration date of the electronic certificate stored in the image forming apparatus that is the destination of the first command. This allows, for example, an administrator of the image forming apparatus to know the expiration date of the electronic certificate stored in the image forming apparatus by using the information processing apparatus. As a result, appropriate management of the expiration date of the electronic certificate, such as updating the electronic certificate within the expiration date, can be expected.

[0007] A control method for realizing the functions of the above system, an image forming apparatus included in the system, a computer program executed by each apparatus, and a computer-readable storage medium storing the computer program are also novel and useful. [Effects of the Invention]

[0008] The technology disclosed in this specification realizes a technology that is expected to enable appropriate management of the expiration date of an electronic certificate in an image forming device that can store the electronic certificate. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is an explanatory diagram showing an overview of a management system according to an embodiment of the present invention; [Figure 2] FIG. 10 is a sequence diagram illustrating an example of a remote management procedure. [Figure 3] FIG. 10 is a sequence diagram illustrating an example of a proximity management procedure. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, a detailed description will be given of an embodiment of the system with reference to the accompanying drawings. This specification discloses a management system including a multifunction peripheral (hereinafter referred to as "MFP") capable of storing digital certificates.

[0011] 1, the management system 100 of this embodiment includes an MFP 1 to be managed, a branch PC 3 which is a personal computer (hereinafter referred to as "PC") used by an administrator who manages the MFP 1 near the MFP 1, and a head office PC 5 which is a PC used by an administrator who manages the MFP 1 from a remote location. The head office PC 5 is located, for example, at a head office, a system management company, or a management organization that manages operational organizations, and the MFP 1 and the branch office PC 3 are located, for example, at a branch office, a client company, or an operational organization that operates a business using the MFP 1. The MFP 1 is an example of an image forming device, the branch office PC 3 is an example of an external device, and the head office PC 5 is an example of an information processing device. The management system 100 is an example of a system.

[0012] 1, the MFP 1 includes a controller 10 including a CPU 11 and a memory 12. The MFP 1 also includes a user interface (hereinafter referred to as "user IF") 13, a print engine 15, a reading engine 16, a network interface (hereinafter referred to as "NET-IF") 17, and a USB interface (hereinafter referred to as "USB-IF") 18, which are electrically connected to the controller 10.

[0013] The CPU 11 of the MFP 1 executes various processes in accordance with programs read from the memory 12 and based on user operations. The memory 12 of the MFP 1 can store various programs and data, including an image processing program 21, a first digital certificate 22, a second digital certificate 23, access information 24, a device ID 25, and administrator information 26. The memory 12 is also used as a work area when various processes are executed.

[0014] The first digital certificate 22 and the second digital certificate 23 are necessary for communication with other devices, and each has an expiration date. The first digital certificate 22 and the second digital certificate 23 are, for example, certificates issued by various certification authorities (CAs). Certificates issued by certification authorities are also called CA certificates. Digital certificates include, for example, a server certificate that is presented by a server to a client to notify that the server has been authenticated by the certification authority. The MFP 1 can store one or more digital certificates. There may be an upper limit to the number of digital certificates that the MFP 1 can hold.

[0015] Image processing program 21 is a program for causing MFP 1 to perform various types of image processing. Access information 24 is information for MFP 1 to access a predetermined area of ​​cloud server 200. Access information 24 is, for example, a URL. Access information 24 may include information such as a password. Note that access information 24 does not need to be stored in memory 12 when MFP 1 is shipped from the factory. Device ID 25 is unique information for identifying MFP 1. Administrator information 26 is information indicating the administrator of MFP 1. Details of the programs and data will be described later.

[0016] Note that an example of memory 12 is not limited to a ROM, RAM, HDD, etc. built into MFP 1, but may also be a storage medium that is readable and writable by CPU 11. For example, a buffer provided in CPU 11, an external memory such as a USB memory or HDD connected to MFP 1, or a memory or HDD provided in a device connected to MFP 1 via communication IF 14 are also examples of memory.

[0017] Computer-readable storage media are non-transitory media. In addition to the above examples, non-transitory media also include recording media such as CD-ROMs and DVD-ROMs. Non-transitory media are also tangible media. On the other hand, electrical signals carrying programs downloaded from servers on the Internet are computer-readable signal media, which is a type of computer-readable medium, but are not included in non-transitory computer-readable storage media.

[0018] The user IF 13 includes, for example, a touch panel. The touch panel includes hardware for displaying a screen for notifying the user of information and hardware for accepting operations by the user. The user IF 13 may include a combination of a display and hardware buttons.

[0019] The print engine 15 includes a configuration for printing an image based on image data onto a print medium such as a sheet. The print engine 15 uses, for example, an electrophotographic method or an inkjet method. The read engine 16 includes a configuration for reading an image of an original document and generating scan data.

[0020] The NET-IF 17 includes hardware for communicating with the cloud server 200. The NET-IF 17 includes functions compatible with communication standards such as Wi-Fi (registered trademark) and Ethernet (registered trademark). The USB-IF 18 includes hardware for communicating with the branch PC 3 and the like based on the USB communication standard.

[0021] The branch PC 3 includes an operating system (hereinafter referred to as "OS") 31, an application program for time limit management (hereinafter referred to as "management app") 32, and a USB-IF 33. The branch PC 3 is, for example, located in the same branch as the MFP 1, and can communicate with the MFP 1 via the USB-IF 33. The branch PC 3 may or may not be able to communicate with the cloud server 200. The branch PC 3 may or may not be able to communicate with the MFP 1 via the branch LAN.

[0022] The head office PC 5 includes an OS 61, a management application 62, a NET-IF 63, and access information 64. The head office PC 5 can communicate with the cloud server 200 on the Internet via the NET-IF 63 by using the access information 64. The access information 64 is, for example, a URL. The access information 64 may also include information such as a password. The head office PC 5 is not connected to the same branch LAN as the MFP 1. The head office PC 5 cannot communicate with the MFP 1 using a USB or LAN.

[0023] Cloud server 200 is, for example, a service operated by a third party other than the company that uses MFP1 or the vendor of MFP1, and includes a group of storages accessible via the Internet. Cloud server 200 includes storage 201 that can store structured text data. Storage 201 of cloud server 200 can store a structured database having a structure including a plurality of records. For example, a system administrator of management system 100 can register information indicating the structure of the structured database, including the structure of each record, in storage 201, thereby enabling storage 201 to store the structured database.

[0024] MFP1 can use access information 24 to access cloud server 200 via the Internet, thereby uploading records to storage 201 and downloading records from storage 201. Head office PC 5 can use access information 64 to access cloud server 200 via the Internet, thereby uploading records to storage 201 and downloading records from storage 201.

[0025] Cloud server 200 may have a communication function via an Internet line and a Web server function in addition to a storage function as a data repository. For example, cloud server 200 may act as a Web server when it receives HTTPS access and return a response that can be displayed by a browser. MFP 1 may access cloud server 200 via HTTPS access to upload or download records. Head office PC 5 may also access cloud server 200 via HTTPS access to upload or download records.

[0026] Cloud server 200 may be, for example, Azure (registered trademark) storage service provided by Microsoft (registered trademark). Storage 201 may be Table storage. Also, for example, cloud server 200 is not limited to Microsoft Azure, and may be, for example, Google (registered trademark) Cloud, Amazon (registered trademark) AWS (registered trademark). Also, cloud server 200 may be, for example, a server of a service operated by the vendor of MFP1.

[0027] Next, procedures for managing digital certificates stored in the MFP1 will be described. The following processes basically refer to CPU processing in accordance with instructions written in a program. In other words, processes such as "determine," "extract," "select," "calculate," "decide," "identify," "acquire," "receive," and "control" in the following description represent CPU processing. CPU processing also includes hardware control using an OS API. In this specification, the operation of each program will be described without mentioning the OS. In other words, in the following description, a statement to the effect that "Program B controls Hardware C" may also mean that "Program B controls Hardware C using the OS API." Furthermore, CPU processing in accordance with instructions written in a program may be described in abbreviated terms. For example, it may be described as "performed by the CPU." Furthermore, CPU processing in accordance with instructions written in a program may be described in abbreviated terms, such as "performed by Program A."

[0028] In this specification, the terms "notification," "alert," "notification," "reply," "response," and "answer" are used not only to mean the transmission of information to a person, but also to mean communication or exchange of information between devices or between components within a device. Note that the components within a device include software.

[0029] Note that "obtaining" is used as a concept that does not require a request. In other words, the process of receiving data without the CPU requesting it is also included in the concept of "the CPU obtaining data." Furthermore, "data" in this specification is represented as a bit string that can be read by a computer. Data with the same substantial meaning but different formats will be treated as the same data. The same applies to "information" in this specification. Furthermore, "requesting" and "instructing" are concepts that indicate outputting information indicating a request or an instruction to the other party. Furthermore, information indicating a request or an instruction will also be simply referred to as a "request" or "instruction."

[0030] Furthermore, the process by a CPU to determine whether information A indicates event B is sometimes conceptually described as "determining whether event B is true from information A." The process by a CPU to determine whether information A indicates event B or event C is sometimes conceptually described as "determining whether event B or event C is true from information A."

[0031] In addition, in this specification, a setting item may be simply referred to as a "setting." A setting value may be simply referred to as a "setting." A setting value may also be referred to as a "parameter." Furthermore, storing a setting value in a memory or the like may be simply referred to as a "setting." An operation for setting or an input for setting may be simply referred to as a "setting."

[0032] First, a remote management procedure for obtaining the expiration date of the digital certificate stored in the MFP1 using the head office PC5, which is not connected to the same branch LAN as the MFP1, will be described with reference to the sequence diagram of FIG.

[0033] An administrator using the head office PC 5 starts up the management application 62 on the head office PC 5, specifies the MFP 1 that is a device to be managed, and inputs an instruction to obtain expiration information (A01). Note that the management application 62 may be executable when the administrator is logged in to the head office PC 5. The management application 62 generates instruction data based on the instruction in A01, and uploads the generated instruction data to the cloud server 200 using the access information 64 (A02). The head office PC 5 transmits the instruction data to the cloud server 200 via the NET-IF 63.

[0034] The instruction data includes a device ID indicating the MFP 1 designated as the destination, transmission instruction information instructing the transmission of the expiration date of the digital certificate, and authentication information for authenticating the administrator of the MFP 1. The transmission instruction information is an example of a command. When the management application 62 receives an instruction to obtain expiration date information for the MFP 1, it may further request authentication information indicating the administrator of the MFP 1 and generate instruction data including the received authentication information, for example.

[0035] Cloud server 200 is capable of receiving instruction data transmitted from head office PC 5. When instruction data is uploaded from head office PC 5 in A02, cloud server 200 stores a record including transmission instruction information, a device ID, and authentication information included in the instruction data in storage 201 (A03). Cloud server 200 stores the received instruction data as one record in storage 201 specified by access information 64. Note that cloud server 200 may also store classification information indicating the type of instruction and time information indicating the time of upload in the record.

[0036] While the management application 62 is operating, it periodically accesses the cloud server 200 using the access information 64 and monitors the records stored in the storage 201. Then, in the periodic access (A05) performed after the upload of A02, the management application 62 can check whether the response data has been updated for the record that stores the information of the instruction data uploaded by A02, among the records stored in the storage 201.

[0037] Meanwhile, while the MFP 1 is powered on, it periodically accesses the cloud server 200 using the access information 24 stored in the memory 12 (A11) and checks whether a record including an instruction addressed to the MFP 1 is stored in the storage 201. The MFP 1 checks, for example, whether there is a record including the device ID of the MFP 1.

[0038] When a new record including the device ID of the MFP1 is stored in the storage 201 in A03 based on the instruction data uploaded from the head office PC 5, the MFP1 can download the new record (A12) by a subsequent access (A11). Furthermore, the MFP1 obtains the content of the instruction from the downloaded record.

[0039] Cloud server 200 may store the instruction data uploaded in A02 in multiple records associated with each other in A03. In this case, MFP 1 may download the multiple records in A12 and acquire the content of the instruction.

[0040] If the downloaded record is a record that stores information about the instruction data uploaded in A02, the instruction included in that record is a transmission instruction to transmit the expiration date of the electronic certificate. When this record is downloaded, the MFP1 can obtain transmission instruction information indicating that transmission instruction (A13). This allows the MFP1 to accept the transmission instruction for the expiration date of the electronic certificate. The transmission instruction information indicating the transmission instruction for the expiration date of the electronic certificate is an example of a first command.

[0041] Then, when the transmission instruction information is acquired, the MFP 1 executes administrator authentication (A15). Specifically, the MFP 1 determines whether the authentication information included in the downloaded record matches the administrator information 26 (see FIG. 1) stored in the memory 12.

[0042] If it is determined that administrator authentication was successful (alt:[Authentication successful]), the MFP1 reads out the expiration dates of all digital certificates stored in memory 12 based on the transmission instruction information in the downloaded record (A21). If, for example, first digital certificate 22 and second digital certificate 23 (see FIG. 1) are stored in memory 12 of the MFP1, the MFP1 acquires the expiration date of first digital certificate 22 and the expiration date of second digital certificate 23. Note that if there is only one digital certificate stored in memory 12, the MFP1 acquires only the expiration date of that digital certificate.

[0043] Then, for each digital certificate, the MFP 1 creates expiration information by combining information for identifying the digital certificate with information indicating the expiration date of the digital certificate (A22). The MFP 1 then uploads the created expiration information to the cloud server 200 using the access information 24 (A23). The expiration information uploaded in A23 is an example of first expiration information. The information for identifying the digital certificate is, for example, the name, ID, and type information of the digital certificate.

[0044] On the other hand, if it is determined that administrator authentication has failed (alt:[Authentication failed]), the MFP1 does not acquire the expiration information of the digital certificate, and uploads failure information indicating that the procedure based on the transmission instruction has failed to the cloud server 200 (A25). Note that if no digital certificates are stored in the memory 12, the MFP1 may upload expiration information indicating that no digital certificates are stored, or may upload failure information.

[0045] The MFP 1 specifies the downloaded record in A12, and uploads the deadline information in A23 and failure information in A25 as response data to the cloud server 200. The cloud server 200 stores the response data uploaded from the MFP 1 in the specified record in the storage 201. This updates the response data in the record.

[0046] As described above, after A02, the management application 62 periodically accesses the cloud server 200 (A05). Then, in A05 after A22 or A25, the response data has been updated, so the management application 62 can download the record and acquire the response data (A31). Based on the acquired response data, the management application 62 displays a result screen on the user interface of the head office PC 5 (A32). This allows the administrator using the head office PC 5 to check the result.

[0047] For example, if multiple digital certificates are stored in the MFP 1, the management application 62 can obtain, for each digital certificate, information identifying the digital certificate and expiration information indicating the expiration date of the digital certificate from the cloud server 200. This allows the management application 62 of the head office PC 5 to display a result screen indicating the expiration date of each digital certificate. Therefore, the user of the head office PC 5 can know the expiration date of each digital certificate stored in the MFP 1. Note that the result screen may also display information indicating the MFP 1 that sent the expiration date information and the date and time when the expiration date information was obtained.

[0048] If the expiration information cannot be acquired, the management application 62 displays a result screen including a message indicating that acquisition of the expiration information has failed. In this case, the result screen may further display information indicating the reason for the failure, such as that the password is incorrect or that the digital certificate is not stored in the MFP 1.

[0049] The transmission instruction information may include designation information that specifies the electronic certificate for which the expiration date is to be transmitted. When the transmission instruction information includes designation information that specifies the electronic certificate for which the expiration date is to be transmitted, the MFP1 creates expiration date information that includes the expiration date of only the electronic certificate designated by the designation information. The MFP1 does not need to obtain the expiration date of electronic certificates that are not designated.

[0050] If the transmission instruction information includes designation information, the MFP 1 creates and uploads expiration information including information on the expiration date of only the designated digital certificate. If the digital certificate designated by the designation information is not stored in the memory 12, the MFP 1 may upload information indicating that the corresponding digital certificate does not exist, or failure information.

[0051] This reduces the need to transfer unnecessary information compared to transferring expiration information indicating the expiration dates of all electronic certificates. The designation information may be information that designates only one electronic certificate, or information that designates multiple electronic certificates. The designation information is not limited to information that designates an individual electronic certificate, but may also be information that designates the type of electronic certificate, or information that designates an electronic certificate whose expiration date is within a predetermined period.

[0052] On the other hand, if no designation information is associated, MFP1 passes expiration information indicating the expiration dates of all electronic certificates stored in memory 12 to cloud server 200. Therefore, if you want to check the expiration dates of all electronic certificates or if you do not know which electronic certificates are stored, the user does not have to go through the trouble of designating an electronic certificate when inputting an information acquisition instruction in A01.

[0053] Next, the proximity management procedure for obtaining the expiration date of the digital certificate stored in the MFP 1 using the branch PC 3 will be described with reference to the sequence diagram in Fig. 3. In this procedure, the MFP 1 is connected to the branch PC 3 via the USB-IF 18.

[0054] An administrator using the branch PC 3 starts the management application 32 on the branch PC 3, specifies the MFP 1, which is a device to be managed, and inputs an instruction to acquire expiration information indicating the expiration date of the digital certificate stored in the memory 12 (B01). The management application 32 generates a PJL command indicating an information acquisition instruction based on the instruction of B01, and transmits the generated PJL command to the MFP 1 via the USB-IF 33 (B02). The PJL command is an example of a command and an example of a second command. The PJL command includes authentication information indicating the administrator of the MFP 1.

[0055] The MFP1 uses the authentication information included in the received PJL command to authenticate the administrator (B15). B15 is the same process as A15 in Figure 2.

[0056] If it is determined that administrator authentication was successful (alt:[Authentication successful]), the MFP1 reads the expiration dates of all electronic certificates stored in memory 12 based on the received PJL command (B21). If the PJL command includes information specifying an electronic certificate, the MFP1 reads the expiration dates of the specified electronic certificates. The MFP1 then creates information indicating the read expiration dates as expiration information (B22). Steps B21 to B22 are the same as steps A21 to A22 in FIG. 2. The expiration information created in step B22 may be the same as the expiration information created in step A22. The MFP1 then transmits the created expiration information to the branch PC 3 via the USB-IF 18 (B23). The expiration information transmitted in step B23 is an example of second expiration information.

[0057] On the other hand, if it is determined that the administrator authentication has failed (alt:[Authentication failed]), the MFP1 sends failure information indicating that it has failed to obtain the expiration information of the digital certificate to the branch PC 3 via the USB-IF 18 (B25). The failure information sent in B25 may be the same information as the failure information uploaded in A25.

[0058] The management application 32 of the branch PC 3 displays a result screen showing the result based on the received information (B32). B32 is the same process as A32 in Figure 2. This allows the administrator using the branch PC 3 to know the expiration date of the digital certificate stored in the MFP 1.

[0059] When the MFP1 receives a PJL command requesting expiration information from the branch PC 3 connected via USB, it transmits the expiration information to the branch PC 3 via the USB-IF 18. This enables the branch PC 3 to notify the expiration date of the digital certificate held by the MFP1.

[0060] The deadline information sent to the branch PC 3 in B23 may be in the same format as or a different format from the deadline information uploaded to the cloud server 200 in A23 of Fig. 2. Also, instead of sending the PJL command to the MFP 1 using USB communication, the branch PC 3 may send the PJL command using LAN communication, or may pass the PJL command via a USB memory in which the PJL command is stored.

[0061] As described above in detail, according to management system 100, when MFP 1 receives information including an instruction addressed to itself from head office PC 5 via cloud server 200, it transmits expiration information indicating the expiration dates of the electronic certificates (e.g., first electronic certificate 22 and second electronic certificate 23 (see FIG. 1 )) stored in memory 12 of MFP 1 to cloud server 200. Then, cloud server 200 transmits the expiration information transmitted from MFP 1 to head office PC 5 as a response to the instruction data. Therefore, head office PC 5 can notify the expiration date of the electronic certificate stored in MFP 1. This allows an administrator using head office PC 5 to know the expiration date of the electronic certificate stored in MFP 1. In particular, even an administrator using head office PC 5 that is not connected to MFP 1 via a LAN can know the expiration date of the electronic certificate stored in MFP 1 by passing through cloud server 200. As a result, appropriate management of the expiration date of the electronic certificate, such as renewal of the electronic certificate within the expiration date, can be expected.

[0062] Note that this embodiment is merely an example and does not limit the present invention in any way. Therefore, the technology disclosed in this specification can naturally be improved and modified in various ways without departing from the spirit and scope of the present invention. For example, the device to be managed may be not only an MFP but also a single-function printer, copier, scanner, fax machine, or machine tool capable of image-based processing, as long as it has NET-IF 17 and can connect to cloud server 200. Furthermore, management system 100 may include one or more managed devices and devices used by the administrator, and the number and arrangement of these devices are not limited to the illustrated example.

[0063] Furthermore, in the embodiment, an example has been given of MFP 1 storing two types of digital certificates, first digital certificate 22 and second digital certificate 23 (see FIG. 1), but the number of digital certificates stored in MFP 1 is not limited to two. Furthermore, an example has been given of MFP 1 including both NET-IF 17 and USB-IF 18, but MFP 1 only needs to include at least NET-IF 17, and does not need to include USB-IF 18.

[0064] Furthermore, the device for managing MFP1 using cloud server 200 is not limited to a PC such as head office PC 5, but may be a mobile terminal such as a smartphone or tablet computer. The device for managing MFP1 using a USB connection is not limited to a PC such as branch office PC 3, but may be a mobile terminal such as a smartphone or tablet computer. Furthermore, branch office PC 3 and head office PC 5 may be the same device.

[0065] In the embodiment, the MFP 1 performs administrator authentication when it receives an instruction to transmit the expiration date of the digital certificate (A15 in FIG. 2, B15 in FIG. 3), but this does not have to be done. In that case, the head office PC 5 can simply upload instruction data that does not include authentication information. The branch office PC 3 can also simply send a PJL command that does not include authentication information.

[0066] Furthermore, although the MFP 1 creates expiration information that combines information identifying a digital certificate and information indicating the expiration date of that digital certificate, the information does not need to include information identifying the digital certificate. By displaying only a list of expiration dates, the administrator can check whether any digital certificates are about to expire. Furthermore, the transmission instruction information does not need to include information specifying the digital certificates whose expiration dates are to be transmitted. In other words, the transmission instruction information may always instruct the transmission of the expiration dates of all digital certificates.

[0067] Furthermore, the electronic certificate whose expiration information is to be managed by the management system 100 is not limited to a server certificate, but may also be a client certificate that a client presents to a server.

[0068] Furthermore, in the embodiment, the procedure for acquiring the expiration date of a digital certificate has been described, but the instruction data that can be uploaded to cloud server 200 is not limited to an instruction to acquire the expiration date of a digital certificate. MFP 1 can operate based on instructions contained in a record downloaded from cloud server 200. The instruction data may be, for example, an instruction to execute a specified image process or an instruction to display a specified display screen.

[0069] Furthermore, in any flowchart or sequence diagram disclosed in the embodiments, the execution order of multiple processes in any multiple steps can be changed or executed in parallel as desired, as long as no contradictions occur in the processing content.

[0070] The processes disclosed in the embodiments may be executed by hardware such as a single CPU, multiple CPUs, or ASIC, or a combination thereof. The processes disclosed in the embodiments may be realized in various ways, such as a recording medium on which a program for executing the processes is recorded, or a method. [Explanation of symbols]

[0071] 1 MFP 3 Branch PC 5 Head office PC 12 Memory 13 User Interface 17 NET-IF 18 USB-IF 100 Management Systems 200 cloud servers 201 Storage

Claims

1. an image forming apparatus; A cloud server; A system having: the image forming apparatus, The image forming apparatus is capable of storing an electronic certificate having an expiration date in a memory thereof, The cloud server A command specifying a destination can be received from the information processing device; the image forming apparatus, acquiring the command specifying the image forming device as a destination from the cloud server via a network interface of the image forming device; If the acquired command is a first command requesting transmission of the expiration date of the electronic certificate, first expiration date information indicating the expiration date of the electronic certificate stored in the memory is associated with the first command and passed to the cloud server; The cloud server the first time limit information received from the image forming apparatus is passed to the information processing apparatus as a response to the first command. A system configured as follows:

2. 2. The system of claim 1, The cloud server a storage device, the command received from the information processing device being stored in the storage device; the image forming apparatus, periodically accessing the storage of the cloud server via the network interface of the image forming device, and acquiring, by downloading, the commands that are stored in the storage and that are designated as destinations for the image forming device; If the command downloaded from the storage is the first command, the first time limit information is associated with the first command and uploaded to the storage of the cloud server, thereby transferring the first time limit information to the cloud server; The cloud server reading, from the storage, the first time limit information uploaded to the storage by the image forming apparatus, and transferring the first time limit information read from the storage to the information processing apparatus as a response to the first command; A system configured as follows:

3. 2. The system of claim 1, the image forming apparatus, A plurality of the digital certificates can be stored in the memory of the image forming device, If the command acquired from the cloud server is the first command, the first expiration information indicating expiration dates of all the digital certificates stored in the memory is associated with the first command and passed to the cloud server. A system configured as follows:

4. 2. The system of claim 1, The first command may specify the electronic certificate for which the expiration date is to be transmitted, or may not specify the electronic certificate, the image forming apparatus, A plurality of the digital certificates can be stored in the memory of the image forming device, If the command acquired from the cloud server is the first command specifying an electronic certificate for which an expiration date is to be transmitted, the first expiration date information indicating the expiration date of the specified electronic certificate among the electronic certificates stored in the memory is associated with the first command and passed to the cloud server; If the command obtained from the cloud server is the first command that does not specify a digital certificate for which an expiration date is to be transmitted, the first expiration date information indicating the expiration date of each digital certificate for all digital certificates stored in the memory is associated with the first command and transmitted to the cloud server. A system configured as follows:

5. 2. The system of claim 1, the image forming apparatus, Equipped with a USB interface, receiving an input of a command from an external device via the USB interface; If the command input from the external device via the USB interface is a second command requesting transmission of the expiration date of the electronic certificate, second expiration date information indicating the expiration date of the electronic certificate stored in the memory is output to the external device as a response to the second command. A system configured as follows:

6. A network interface; Memory and An image forming apparatus comprising: The memory includes: The electronic certificate can be stored with an expiration date. the image forming apparatus, a command specifying the image forming apparatus as a destination is acquired from the information processing apparatus via the network interface via a cloud server; If the acquired command is a first command requesting transmission of the expiration date of the electronic certificate, first expiration date information indicating the expiration date of the electronic certificate stored in the memory is associated with the first command and passed to the information processing device via the cloud server. The image forming apparatus is configured as follows.

7. 7. The image forming apparatus according to claim 6, the image forming apparatus, periodically accessing, via the network interface, a storage included in the cloud server, in which the commands received by the cloud server from the information processing device are stored, and acquiring, by downloading, the commands for which the image forming device is designated as a destination from among the commands stored in the storage; If the command downloaded from the storage is the first command, the first deadline information is associated with the first command and uploaded to the storage of the cloud server, and the first deadline information uploaded to the storage is passed from the cloud server to the information processing device. The image forming apparatus is configured as follows.

8. 7. The image forming apparatus according to claim 6, The memory is capable of storing a plurality of the digital certificates; the image forming apparatus, If the command acquired from the cloud server is the first command, the first expiration information indicating expiration dates of all the electronic certificates stored in the memory is associated with the first command and passed to the information processing device via the cloud server. The image forming apparatus is configured as follows.

9. 7. The image forming apparatus according to claim 6, The first command may specify the electronic certificate for which the expiration date is to be transmitted, or may not specify the electronic certificate, the image forming apparatus, A plurality of the digital certificates can be stored in the memory of the image forming device, when the command acquired from the cloud server is the first command specifying an electronic certificate for which an expiration date is to be transmitted, the first expiration date information indicating the expiration date of the specified electronic certificate among the electronic certificates stored in the memory is associated with the first command and passed to the information processing device via the cloud server; If the command acquired from the cloud server is the first command that does not specify an electronic certificate for which an expiration date is to be transmitted, the first expiration date information indicating the expiration date of each of the electronic certificates stored in the memory is associated with the first command and passed to the information processing device via the cloud server. The image forming apparatus is configured as follows.

10. 7. The image forming apparatus according to claim 6, the image forming apparatus, Equipped with a USB interface, receiving an input of a command from an external device via the USB interface; If the command input from the external device via the USB interface is a second command requesting transmission of the expiration date of the electronic certificate, second expiration date information indicating the expiration date of the electronic certificate stored in the memory is output to the external device as a response to the second command. The image forming apparatus is configured as follows.

Citation Information

Patent Citations

  • Communication apparatus and program

    JP2007274060A