Information processing systems and programs
The system allows users to securely execute their chosen software on untrusted devices by using volatile memory and authentication, addressing security concerns and preventing tampering.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-03
AI Technical Summary
Existing information processing systems do not allow users to execute software of their choice securely on untrusted devices, as they lack mechanisms to ensure software integrity and user authentication, leading to potential tampering and security risks.
The system employs a processor that receives and executes user-provided software and command data from volatile memory, ensuring that functional components operate only from user-controlled firmware stored in RAM, while authenticating the user and erasing the software after use to enhance security.
This approach enables users to run their desired software on untrusted devices, improving security by preventing tampering and ensuring secure operation without affecting other users' data integrity.
Smart Images

Figure 2026058167000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing system and a program.
Background Art
[0002] For example, in Patent Document 1, a plurality of public terminals installed in a plurality of printers installed in a public place, a print reception server, a storage server, and an authentication server connected to NGN function as sink clients, provide an operation screen, and receive input. It has a public terminal server, receives a print application from a user terminal of a user authenticated by the authentication server by the print reception server, temporarily stores print data in the storage server, and the public terminal server is authenticated by the authentication server. Based on the input from the public terminal of the user, the print data is transmitted from the storage server to the printers associated with the plurality of public terminals, and a print system for performing print output is disclosed.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] An object of the present disclosure is to provide an information processing system and a program that enable a user using the information processing system to execute software desired by the user and use the information processing system.
Means for Solving the Problems
[0005] The first embodiment of the information processing system comprises a functional component and a processor, wherein the processor receives from a user operating software which is software for operating the functional component and command data for the functional component, operates the functional component based on the operating software received from the user, and causes the functional component to execute the commands included in the command data.
[0006] The information processing system in the second embodiment is the information processing system described in the first embodiment, wherein the processor further receives reference data referenced by the functional component and causes the functional component to execute a command that references the reference data.
[0007] The third embodiment of the information processing system is the information processing system described in the first or second embodiment, wherein the processor stores the operating software only in volatile memory.
[0008] The information processing system of the fourth embodiment is the information processing system described in the third embodiment, wherein the processor erases the operating software when the command of the functional component is completed.
[0009] The fifth aspect of the information processing system is an information processing system according to any one of the first to fourth aspects, wherein the processor executes reception software recorded on a non-rewritable recording medium to receive the operation software.
[0010] The information processing system in the sixth embodiment is the information processing system described in the fifth embodiment, wherein other operating software for operating the functional components is recorded in memory, and the processor receives the operating software from the user while the execution of the other operating software is stopped.
[0011] The information processing system of the seventh embodiment is an information processing system according to any one of the first to sixth embodiments, wherein the processor further receives authentication information associated with the operating software and receives identification information, and operates the functional component when the identification information and the authentication information correspond.
[0012] The program of the eighth aspect causes the processor to perform the following actions: receive from the user operating software which is software for operating a functional component and command data for the functional component; operate the functional component based on the operating software received from the user; and cause the functional component to execute the commands included in the command data. [Effects of the Invention]
[0013] According to the information processing system of the first embodiment, users of the information processing system can use the system by running the software of their choice.
[0014] According to the information processing system of the second embodiment, the user can use a function based on a command in which the functional component references reference data.
[0015] According to the information processing system of the third embodiment, compared to the case in which operating software is also stored on non-volatile memory, the security of the information processing system can be improved for users of the information processing system.
[0016] According to the information processing system of the fourth embodiment, compared to the case where the operating software is stored and the operating software is then received, the security of using the information processing system can be improved for other users who use the information processing system next.
[0017] According to the information processing system of the fifth aspect, it is easier to prevent the reception software from being tampered with.
[0018] According to the information processing system according to the sixth aspect, in an information processing system in which a user without operating software can also use the information processing system, a user with operating software can execute and use the software desired by the user.
[0019] According to the information processing system according to the seventh aspect, the security when using the information processing system can be improved for the user using the information processing system as compared with the case of operating the functional component without confirming the correspondence between the identification information and the authentication information.
[0020] According to the program according to the eighth embodiment, for the user using the information processing system, the software desired by the user can be executed to use the information processing system.
Brief Description of Drawings
[0021] [Figure 1] It is a diagram showing the system configuration of the information usage environment according to the first embodiment. [Figure 2] It is a block diagram showing the configuration of the multifunction device according to the first embodiment, and is a diagram showing a state where the functional components are not operating. [Figure 3] It is a block diagram showing the configuration of the multifunction device according to the embodiment following FIG. 2, and is a diagram showing a state where the functional components are operating. [Figure 4] It is a block diagram showing the configuration of the computer according to the first embodiment. [[ID=3This sequence diagram shows an example in which a multifunction printer, a second modified version of the first execution example, communicates with a server and performs a printing function. [Figure 9] This is a sequence diagram illustrating an example in which a multifunction printer, related to the second execution example, communicates with a computer and performs a document scanning function. [Figure 10] This is a sequence diagram showing an example in which a multifunction printer, according to a modified example of the second execution example of the first embodiment, communicates with a computer and performs a duplication function. [Figure 11] This sequence diagram shows an example of a multifunction printer, the third example of its operation, performing a print function when communicating with multiple computers. [Figure 12] This sequence diagram shows an example of a multifunction printer, a modified version of the third execution example, performing a printing function when communicating with multiple computers. [Figure 13] This is a block diagram showing the configuration of a multifunction printer according to the second embodiment, and it depicts a state where the functional components are not in operation. [Figure 14] Figure 13 is a block diagram showing the configuration of the multifunction device according to the second embodiment, and it shows the functional components in operation. [Figure 15] This is a sequence diagram showing an example of a multifunction printer according to the second embodiment communicating with a computer and executing a printing function. [Figure 16] Figure 15 is followed by a flowchart showing an example of a multifunction printer according to the second embodiment performing a printing function. [Figure 17] This flowchart shows an example of a multifunction printer according to a modified version of the second embodiment communicating with a computer and determining whether the firmware has been received correctly. [Modes for carrying out the invention]
[0022] Hereinafter, an example of an embodiment of this disclosure will be described with reference to the drawings. In each drawing, the same or equivalent components and parts are given the same reference numerals. Also, the dimensional ratios in the drawings are exaggerated for illustrative purposes and may differ from the actual ratios.
[0023] [First Embodiment] (composition) (Information Usage Environment 10) Figure 1 is a diagram showing the system configuration of an information utilization environment 10 according to one embodiment of the present disclosure. As shown in Figure 1, the information utilization environment 10 has a multifunction printer 32 and multiple computers 20A and 20B installed in a shared facility 14. The multifunction printer 32 and the multiple computers 20A and 20B are connected to an internal facility network 16. The internal facility network 16 is also connected to the Internet 12. Furthermore, the information utilization environment 10 has an information management server 18 connected via the Internet 12.
[0024] Computer 20A is the device used by the first user 21A. Computer 20B is the device used by the second user 21B. Computers 20A and 20B are identical devices. In the following explanation, when computers 20A and 20B are not distinguished, they will be referred to as "computer 20." Similarly, when the first user 21A and the second user 21B are not distinguished, they will be referred to as "user 21."
[0025] Furthermore, the first user 21A and the second user 21B belong to different organizations. In other words, the shared facility 14 is a facility used by multiple people from different organizations. Also, both the first user 21A and the second user 21B belong to different organizations than the administrators of the shared facility 14. In addition, the administrators of the multifunction printer 32 and the information management server 18 belong to different organizations than both user 21 and the administrators of the shared facility 14.
[0026] (Multifunction machine 32) The multifunction printer 32 is a device known as a multifunction printer, which has multiple functions such as printing, scanning, copying, and facsimile. The multifunction printer 32 is an example of an "information processing system" in this embodiment.
[0027] Figures 2 and 3 are block diagrams showing the hardware configuration of the multifunction device 32 in this embodiment. As shown in Figure 2, the multifunction device 32 comprises a control unit 40, an input / output unit 50, an image forming unit 52, a document reading unit 54, a communication unit 56, and an authentication acceptance unit 58. These components are connected to each other via an input / output interface (I / O) 46. The input / output unit 50, the image forming unit 52, the document reading unit 54, and the authentication acceptance unit 58 are examples of "functional components" in this embodiment.
[0028] The control unit 40 is a device that controls each part of the multifunction printer 32. This control unit 40 has computer-like functions and, as shown in Figure 2, includes a CPU 41 (Central Processing Unit), RAM 42 (Random Access Memory), flash memory 43 (Flash Memory), and ROM 44 (Read Only Memory). The CPU 41, RAM 42, flash memory 43, and ROM 44 are each interconnected by a control bus 45.
[0029] The CPU 41 is a central processing unit that executes various programs, including the main firmware 56F such as an information synchronization program, and controls various parts. In this embodiment, the CPU 41 is an example of a "processor" in this disclosure. The flash memory 43 temporarily stores data, etc. The flash memory 43 is an example of a "non-volatile memory" in this embodiment. That is, the flash memory 43 retains the stored information even when the current to the control unit 40 is interrupted (for example, when the power supply to the multifunction printer 32 is interrupted).
[0030] ROM44 stores various programs and data, including the main firmware 56F. Furthermore, ROM44 is an example of a "non-rewritable recording medium" in this embodiment. ROM44 can be any non-rewritable recording medium.
[0031] RAM42 temporarily stores the main firmware 56F or data as a working area. RAM42 is also an example of "volatile memory" in this embodiment. That is, if the current to the control unit 40 is interrupted (for example, if the power supply to the multifunction printer 32 is interrupted), the information stored in RAM42 is erased.
[0032] The input / output unit 50 is a device that receives instructions from the user 21 using the multifunction printer 32 and notifies the CPU 41 of the control unit 40 of the received instructions. Furthermore, the input / output unit 50 is a device that presents information to the user 21 using the multifunction printer 32 according to the instructions of the CPU 41. As the input / output unit 50, a device that performs both input reception and information display, such as a touch panel, is used. The input / output unit 50 implements the above functions based on the procedure specified in the firmware 50F for the input / output unit, as will be described later.
[0033] The image forming unit 52 is a component that forms an image on a recording medium such as paper. The image forming unit 52 forms an image on the recording medium by an electrophotographic method, for example, by performing the steps of charging, exposure, development, transfer, and fixing. The image forming unit 52 may also form an image on the recording medium by other methods such as an inkjet method. The image forming unit 52 performs the above functions based on the procedure specified in the firmware 52F for the image forming unit, as will be described later.
[0034] The document reading unit 54 is a component (for example, a scanner) that reads the image of the document. The document reading unit 54 optically reads the image of the document and converts it into a digital signal to generate image data. As will be described later, the document reading unit 54 performs the above function based on the procedure specified in the firmware 54F for the document reading unit.
[0035] The communication unit 56 is a component for communicating with other devices such as the digital shadow server 22. Specifically, the communication unit 56 communicates with other devices using communication means such as wired, wireless, the internet 12, an intranet, and public lines such as telephone lines. The communication means may also be communication means using voice, light, vibration, images, etc.
[0036] The authentication reception unit 58 is a component that receives authentication information from a user 21 using the multifunction printer 32. The authentication reception unit 58 can have any configuration as long as it is capable of identifying the user 21 using the multifunction printer 32. For example, the authentication reception unit 58 reads information from an ID card or the like held by the user 21 and identifies the user 21 by reading the information contained in the ID card. The authentication reception unit 58 implements the above function based on the procedure specified in the authentication reception unit firmware 58F, as will be described later.
[0037] The control unit 40 reads various programs, including the main firmware 56F, from the ROM 44 via the CPU 41, and executes the main firmware 56F using the RAM 42 as a working area. Furthermore, as the CPU 41 executes the main firmware 56F, the communication unit 56 of the multifunction device 32 operates as shown in Figure 2. In other words, the main firmware 47 is an example of "reception software" in this embodiment.
[0038] Here, the input / output unit 50 operates when the firmware 50F for the input / output unit is stored in the RAM 42. The image forming unit 52 operates when the firmware 52F for the image forming unit is stored in the RAM 42. The document reading unit 54 operates when the firmware 54F for the document reading unit is stored in the RAM 42. The authentication acceptance unit 58 operates when the firmware 58F for the authentication acceptance unit is stored in the RAM 42. In other words, each of the above-mentioned firmwares is an example of "operational software" in this embodiment.
[0039] Furthermore, any method may be used for the procedure from the time each of the above-mentioned firmwares is stored in RAM42 until it is activated. In this description, as an example, CPU41 transmits each of the firmwares stored in RAM42 to a RAM (not shown) of the corresponding functional component. The functional component then implements its function based on the firmware stored in RAM42. In this embodiment, RAM42 may also be able to access the data stored from each functional component.
[0040] In this embodiment, as shown in Figure 2, the ROM 44 of the multifunction device 32 does not contain firmware for operating the input / output unit 50, the image forming unit 52, the document reading unit 54, and the authentication acceptance unit 58. That is, as shown in Figure 3, in order to operate the input / output unit 50, the image forming unit 52, the document reading unit 54, or the authentication acceptance unit 58, the multifunction device 32 needs to obtain the firmware corresponding to the functional component from an external device. The method for obtaining the firmware will be described later.
[0041] (Computer 20) As shown in Figure 4, the computer 20 comprises a control unit 60, an input unit 70, an output unit 72, and a communication unit 76. Note that, among the components of the computer 20, those with the same names as those of the multifunction device 32 have the same functionality, except for performance (processing capacity).
[0042] The input unit 70 is a component that allows a user 21 using the computer 20 to input commands to the computer 20. Examples of input devices that can be included in the input unit 70 include a keyboard, mouse, trackpad, and other input devices.
[0043] The output unit 72 is a component that allows the user 21 using the computer 20 to perceive the results of the processing performed by the CPU 61. An example of the output unit 72 is a display device such as a monitor.
[0044] Furthermore, as shown in Figure 4, the control unit 60 includes a CPU 61 (Central Processing Unit), a RAM 62 (Random Access Memory), and a flash memory 63 (Flash Memory). The CPU 61, RAM 62, and ROM 64 are each interconnected by a control bus 65.
[0045] As shown in Figure 4, the flash memory 63 contains the multifunction printer driver 67, firmware 50F for the input / output unit, firmware 52F for the image forming unit, firmware 54F for the document reading unit, and firmware 58F for the authentication acceptance unit.
[0046] The multifunction printer driver 67 is software used by the computer 20 to utilize the multifunction printer 32. More specifically, when the CPU 61 loads the multifunction printer driver 67, the user 21 operating the computer 20 becomes able to use the multifunction printer 32.
[0047] As described above, the input / output unit firmware 50F is software that the CPU 41 of the multifunction printer 32 reads and operates the input / output unit 50. In other words, the computer 20 in this embodiment has firmware that operates the functional components of the multifunction printer 32 as described above. The same applies to the image forming unit firmware 52F, the document reading unit firmware 54F, and the authentication acceptance unit firmware 58F.
[0048] (Information management server 18) As shown in Figure 5, the information management server 18 comprises a control unit 80 and a communication unit 96. Note that, among the components of the information management server 18, those components with the same names as those of the multifunction printer 32 have the same functionality, except for performance (processing capacity).
[0049] Furthermore, as shown in Figure 5, the control unit 80 includes a CPU 81 (Central Processing Unit), a RAM 82 (Random Access Memory), and a flash memory 83 (Flash Memory). The CPU 81, RAM 82, and ROM 84 are each interconnected by a control bus 85.
[0050] As shown in Figure 5, the ROM 84 contains the multifunction printer driver 87, firmware 50F for the input / output unit, firmware 52F for the image forming unit, firmware 54F for the document reading unit, and firmware 58F for the authentication acceptance unit.
[0051] The multifunction printer driver 87 is software used by the information management server 18 to utilize the multifunction printer 32. More specifically, when the CPU 81 loads the multifunction printer driver 87, the user 21 can use the multifunction printer 32 via the information management server 18.
[0052] Furthermore, the information management server 18 in this embodiment, like the computer 20, has firmware that operates the functional components of the multifunction printer 32 described above.
[0053] (Regarding User 21's untrusted software) Incidentally, the first user 21A and the second user 21B belong to different organizations, but they each use computer 20 in the shared facility 14. In other words, for each user 21, the software run by the multifunction printer 32 located in the shared facility 14 is not necessarily trustworthy. In other words, for user 21, the multifunction printer 32 is located in an untrustworthy location.
[0054] One specific reason why it cannot be trusted is that even if the software of the multifunction printer 32 located in the shared facility 14 is tampered with by a malicious attacker, it is difficult for the user 21 to become aware of the fact that the software has been tampered with.
[0055] Next, the procedure for the operation of CPU 41, CPU 61, or CPU 81 when user 21 uses the multifunction printer 32 is shown below. In the following explanation, one of the configurations may be referred to as "starting up" or "operating." In the following explanation, "starting up" refers to the transition of the configuration to a state in which it can perform functions based on a command. "Operating" refers to the execution of the operation desired by user 21 by the configuration performing functions based on a command.
[0056] [First example of execution] The first example shows a case where user 21, using computer 20, prints image data using multifunction printer 32. The procedure for this example is shown with reference to Figures 6 and 7.
[0057] (Operating procedures for information utilization environment 10 and multifunction printer 32) Figure 6 is a sequence diagram showing an example in which the multifunction device 32 in this example communicates with the computer 20 and executes a printing function. Figure 7 is a flowchart showing an example in which the multifunction device 32 in this example executes a printing function. In the following steps, although not specifically explained, the command data for operating the functional components of the multifunction device 32, excluding the firmware, is assumed to be generated in a timely manner by the computer 20 executing the multifunction device driver 67.
[0058] First, as shown in Figure 7, the CPU 41 activates the communication unit 56 and waits for communication to be received from an external device (S100). More specifically, the CPU 41 obtains the main firmware 47 from the ROM 44 and stores it in the RAM 42. Then, the CPU 41 activates the communication unit 56 based on the main firmware 47 stored in the RAM 42, thereby receiving communication from an external device.
[0059] Note that the procedure in S100 shown in Figure 7 is not shown in Figure 6, but this indicates that the CPU 41 has already activated the communication unit 56 and is preparing to receive the communication in S104, which will be explained next. If the user 21 operates the computer 20 to use the printing function based on image data, the procedure shown in Figure 6 will be executed.
[0060] More specifically, as shown in Figure 6, user 21 first inputs a print instruction to the computer 20 based on image data (S102). The CPU 61 of the computer 20 then transmits the image data to be printed, command data including the instruction to print the image data, and firmware 52F for the image forming unit to the multifunction printer 32 (S104). The CPU 41 of the multifunction printer 32, upon receiving the data from the computer 20, stores the received data in the RAM 42.
[0061] Next, the CPU 41 of the multifunction printer 32 loads the image forming unit firmware 52F, which is included in the received data, into the RAM 42 (S108). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0062] Next, the CPU 41 of the multifunction printer 32 starts the image forming unit 52 using the image forming unit firmware 52F deployed in the RAM 42 (S110). In other words, the CPU 41 starts the image forming unit 52 based on the procedure specified in the image forming unit firmware 52F deployed in the RAM 42. Furthermore, when the CPU 41 determines that the startup of the image forming unit 52 is complete, it executes the procedure in S112.
[0063] Next, the CPU 41 of the multifunction printer 32 prints image data based on the command data contained in the data received from the computer 20 (S112). More specifically, the CPU 41 reads the command data stored in the RAM 42 and instructs the image forming unit 52 to print the image data. Furthermore, when the CPU 41 determines that the procedure contained in the command data has been completed, that is, when it determines that printing is complete, it executes the next procedure S114.
[0064] Next, the CPU 41 of the multifunction printer 32 restarts the multifunction printer 32 (S114). More specifically, the CPU 41 terminates the software running on the multifunction printer 32 based on the main firmware 47 running on the multifunction printer 32 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 32 executes a boot loader (not shown) to load the main firmware 47 and completes the series of procedures.
[0065] Here, the CPU 41 of the multifunction printer 32 starts the communication unit 56 in order to execute the main firmware 47. In other words, after executing the procedure in S114, the CPU 41 executes the procedure in S100 again. In other words, the CPU 41 waits again for communication to be received.
[0066] In the procedure described above, the communication in S104 received by the CPU 41 of the multifunction printer 32 is based on the print instruction in S102 from the user 21. Therefore, in this embodiment, it can be said that the CPU 41 receives firmware and command data from the user 21.
[0067] Furthermore, in the procedure described above, the CPU 41 receives image data during the communication in S104. Since this image data is referenced by the image forming unit 52 in the procedure in S112, it can be said to be an example of "reference data referenced by the functional component" in this embodiment.
[0068] Next, the operation and effects of the computer 20 and the multifunction device 32 in this embodiment operating according to the procedure described above will be explained.
[0069] (Mechanism of Action and Effects) The CPU 41 of the multifunction printer 32 in this example receives firmware 52F for the image forming unit and command data, which is data that commands the image forming unit 52, from the user 21. The CPU 41 also executes the firmware 52F for the image forming unit received from the user 21, and performs the following actions: operating the image forming unit 52 and instructing the image forming unit 52 to print image data as a command included in the command data. Therefore, with the multifunction printer 32 in this example, for a user 21 using the multifunction printer 32 located in a location untrusted to the user 21, the firmware 52F for the image forming unit provided by the user's own computer 20 is executed. In other words, the user 21 can use the multifunction printer 32 by running the software of their choice.
[0070] Furthermore, the multifunction printer 32 in this example also receives image data that the image forming unit 52 references and executes a command to print the image in the image forming unit 52. Therefore, with the multifunction printer 32 in this example, the user can utilize the function in which the image forming unit 52 prints image data, which is an example of a command in which the functional configuration unit references reference data.
[0071] Furthermore, the CPU 41 in this example stores the image forming unit firmware 52F only in volatile memory. Therefore, with the multifunction printer 32 in this example, compared to the case where the image forming unit firmware 52F is also stored in non-volatile memory, restarting the multifunction printer 32 will not affect other data stored in non-volatile memory. This improves security for the user 21 using the multifunction printer 32.
[0072] Furthermore, the CPU 41 in this example erases the firmware 52F for the image forming unit when the command from the image forming unit 52 is completed. Therefore, with the multifunction printer 32 in this example, compared to the case where the firmware 52F for the image forming unit is stored in the RAM 42 and further firmware is accepted, the security of using the multifunction printer 32 can be improved for other users 21 who will use the multifunction printer 32 next.
[0073] Furthermore, the CPU 41 in this example executes the main firmware 47 recorded in the ROM 44 to accept the firmware 52F for the image forming unit. Therefore, with the multifunction device 32 in this example, it is easier to prevent the main firmware 47 from being tampered with.
[0074] Furthermore, the main firmware 56F in this example causes the CPU 41 to receive image forming unit firmware 52F, which is software for operating the image forming unit 52, from the user 21. The main firmware 47 also causes the CPU 41 to receive command data, which is data that commands the image forming unit 52, and to execute the image forming unit firmware 52F received from the user 21 to operate the image forming unit 52. The main firmware 47 also causes the CPU 41 to print image data as a command included in the command data for the image forming unit 52. Therefore, according to the program in this example, a user 21 who uses a multifunction printer 32 located in a location untrustworthy to the user 21 can use the multifunction printer 32 by executing the software desired by the user 21.
[0075] Next, we will explain the first modified example of the first implementation.
[0076] <First Variation> In the first example, the multifunction printer 32 received communication from the computer 20 in step S104. In the first modified example, instead of step S104, the printer receives image data to be printed from the removable media, command data including a command to print the image data, and firmware 52F for the image forming unit.
[0077] In other words, in this modified example, user 21 uses computer 20 to record image data to be printed on removable media, command data including a command to print the image data, and firmware 52F for the image forming unit. Then, when the multifunction printer 32 reads the recorded removable media, CPU 41 performs the same procedure as in the first example.
[0078] Any type of removable media may be used. Examples include CD-RW (Compact Disk ReWritable), DVD-RW (Digital Versatile Disk ReWritable), and USB (Universal Serial Bus) memory.
[0079] Furthermore, in this modified example, if the procedure is the same as in the first example, the same action and effect as in the first example can be obtained.
[0080] Next, we will explain a second variation of the first implementation example.
[0081] <Second variation> Figure 8 shows the operating procedures of the information utilization environment 10 and the multifunction printer 32 in this modified example. In Figure 8, it is assumed that the multifunction printer 32 has already performed the procedure in S100, as in the first example.
[0082] (Operating procedures for information utilization environment 10 and multifunction printer 32) As shown in Figure 8, user 21 first inputs a print command to computer 20 based on image data (S162). The CPU 61 of computer 20 then sends the image data to be printed to information management server 18 (S164).
[0083] Next, the CPU 81 of the information management server 18, which received data from the computer 20, transmits the image data, command data including a command to print the image data, and firmware 52F for the image forming unit to the multifunction printer 32 (S166). The CPU 41 of the multifunction printer 32, which received data from the computer 20, stores the received data in the RAM 42.
[0084] Next, the CPU 41 of the multifunction printer 32 loads the image forming unit firmware 52F, which is included in the received data, into the RAM 42 (S168). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0085] Subsequently, CPU 41 executes procedures equivalent to those in S108 to S114 as part of the procedures in S168 to S174.
[0086] In the procedure described above, the communication in S166 received by the CPU 41 of the multifunction printer 32 is based on the print instruction in S162 from the user 21. Therefore, in this embodiment, it can be said that the CPU 41 receives firmware and command data from the user 21.
[0087] Furthermore, in this modified example, if the procedure is the same as in the first example, the same action and effect as in the first example can be obtained.
[0088] Next, a second example of this embodiment will be described with reference to Figure 9.
[0089] [Second example of execution] The first example shows a case where a user 21 using computer 20 scans a document using multifunction printer 32 and creates image data. The procedure for this example is shown with reference to Figure 9.
[0090] (Operating procedures for information utilization environment 10 and multifunction printer 32) Figure 9 is a sequence diagram showing an example in which the multifunction device 32 in this example communicates with the computer 20 and executes the document scanning function. In Figure 9, it is assumed that the multifunction device 32 has already performed the procedure in S100, as in the first execution example. That is, when the user 21 operates the computer 20 to use the document scanning function based on image data, the procedure shown in Figure 9 will be executed.
[0091] As shown in Figure 9, user 21 first inputs an instruction to the computer 20 to read the document based on image data (S202). The CPU 61 of the computer 20 then sends command data, including the command to read and transmit the document, and destination data, including the destination of the image data, to the multifunction device 32 (S204). The CPU 61 of the computer 20 also sends firmware 50F for the input / output unit and firmware 54F for the document scanning unit to the multifunction device 32 (S204). The CPU 41 of the multifunction device 32, upon receiving the data from the computer 20, stores the received data in RAM 42.
[0092] Next, the CPU 41 of the multifunction device 32 loads the firmware 54F for the document scanning unit, which is included in the received data, into the RAM 42 (S208). In other words, the CPU 41 makes the firmware 54F for the document scanning unit available by referring to the RAM 42.
[0093] Furthermore, the CPU 41 of the multifunction printer 32 loads the input / output firmware 50F contained in the received data into the RAM 42 (S208). In other words, the CPU 41 makes the input / output firmware 50F available by referencing the RAM 42.
[0094] Next, the CPU 41 of the multifunction printer 32 starts the document scanning unit 54 using the firmware 54F for the document scanning unit that has been deployed in the RAM 42 (S210). In other words, the CPU 41 starts the document scanning unit 54 based on the procedure specified in the firmware 54F for the document scanning unit that has been deployed in the RAM 42.
[0095] Furthermore, the CPU 41 of the multifunction printer 32 uses the I / O firmware 50F deployed in the RAM 42 to start the I / O unit 50 (S210). In other words, the CPU 41 starts the I / O unit 50 based on the procedure specified in the I / O firmware 50F deployed in the RAM 42.
[0096] Furthermore, when the CPU 41 determines that the input / output unit 50 and the document reading unit 54 have finished starting up, it permits the user 21 to accept input instructions.
[0097] Then, user 21 inputs an instruction to the input / output unit 50 to scan the document (S214). The CPU 41 of the multifunction printer 32 then scans the document and creates image data (S216).
[0098] Next, the CPU 41 refers to the destination data and transmits the image data (S218). More specifically, the CPU refers to the destination data and transmits the image data to the destination specified in the destination data. Furthermore, when the CPU 41 determines that the procedure for transmitting the image data is complete, that is, when it determines that the scanning of the document is complete, it executes the next procedure in S220.
[0099] Next, the CPU 41 of the multifunction printer 32 restarts the multifunction printer 32 (S220). More specifically, the CPU 41 terminates the software running on the multifunction printer 32 based on the main firmware 47 running on the multifunction printer 32 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 32 executes a boot loader (not shown) to load the main firmware 47 and completes the series of procedures.
[0100] Here, the CPU 41 of the multifunction printer 32 starts the communication unit 56 in order to execute the main firmware 47. In other words, after executing the procedure in S220, the CPU 41 executes the procedure in S200 again. In other words, the CPU 41 waits again for communication to be received.
[0101] In the procedure described above, the communication S204 received by the CPU 41 of the multifunction printer 32 is based on the document scanning instruction S202 from the user 21. Therefore, in this embodiment, it can be said that the CPU 41 receives firmware and command data from the user 21.
[0102] Next, the operation and effects of the computer 20 and the multifunction device 32 in this embodiment operating according to the procedure described above will be explained.
[0103] (Mechanism of Action and Effects) In this example, the CPU 41 of the multifunction device 32 receives command data from the user 21, which is data that commands the firmware 54F for the document scanning unit and the document scanning unit 54. The CPU 41 also receives command data from the user 21, which is data that commands the firmware 50F for the input / output unit and the input / output unit 50. The CPU 41 also receives input operations to the input / output unit 50 from the user 21. The CPU 41 then executes the firmware 54F for the document scanning unit received from the user 21, which activates the document scanning unit 54, and also performs the function of scanning the document as a command included in the command data.
[0104] Therefore, with the multifunction device 32 in this example, for a user 21 using the multifunction device 32 located in a location untrusted to the user 21, the firmware 50F for the input / output unit and the firmware 54F for the document scanning unit provided by the user's computer 20 are executed. In other words, the user 21 can use the multifunction device 32 by running the software of their choice.
[0105] Furthermore, according to this example, other effects and benefits can be obtained in the same way as in the second example.
[0106] Next, we will explain a modified version of the second example.
[0107] <Variations> Figure 10 shows the operating procedures of the information utilization environment 10 and the multifunction printer 32 in this modified example. In Figure 10, it is assumed that the multifunction printer 32 has already performed the procedure in S100, as in the second example.
[0108] (Operating procedures for information utilization environment 10 and multifunction printer 32) As shown in Figure 10, user 21 first inputs an instruction to the computer 20 to duplicate the document based on image data (S232). The CPU 61 of the computer 20 then sends command data, including a command to read and transmit the document, to the multifunction device 32 (S234). The CPU 61 of the computer 20 also sends firmware 50F for the input / output unit, firmware 52F for the image forming unit, and firmware 54F for the document reading unit to the multifunction device 32 (S234). The CPU 41 of the multifunction device 32, upon receiving the data from the computer 20, stores the received data in RAM 42.
[0109] Next, the CPU 41 of the multifunction device 32 loads the firmware 54F for the document scanning unit, which is included in the received data, into the RAM 42 (S238). In other words, the CPU 41 makes the firmware 54F for the document scanning unit available by referring to the RAM 42.
[0110] Furthermore, the CPU 41 of the multifunction printer 32 loads the image forming unit firmware 52F, which is included in the received data, into the RAM 42 (S238). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0111] Furthermore, the CPU 41 of the multifunction device 32 loads the input / output firmware 50F contained in the received data into the RAM 42 (S238). In other words, the CPU 41 makes the input / output firmware 50F available by referencing the RAM 42.
[0112] Next, the CPU 41 of the multifunction printer 32 starts the document scanning unit 54 using the firmware 54F for the document scanning unit that has been deployed in the RAM 42 (S240). In other words, the CPU 41 starts the document scanning unit 54 based on the procedure specified in the firmware 54F for the document scanning unit that has been deployed in the RAM 42.
[0113] Furthermore, the CPU 41 of the multifunction printer 32 uses the image forming unit firmware 52F deployed in the RAM 42 to start the image forming unit 52 (S240). In other words, the CPU 41 starts the image forming unit 52 based on the procedure specified in the image forming unit firmware 52F deployed in the RAM 42.
[0114] Furthermore, the CPU 41 of the multifunction printer 32 uses the I / O firmware 50F deployed in the RAM 42 to start the I / O unit 50 (S240). In other words, the CPU 41 starts the I / O unit 50 based on the procedure specified in the I / O firmware 50F deployed in the RAM 42.
[0115] Furthermore, when the CPU 41 determines that the input / output unit 50, the image forming unit 52, and the document reading unit 54 have finished starting up, it permits the acceptance of input instructions from the user 21.
[0116] Then, user 21 inputs an instruction to the input / output unit 50 to scan the document (S244). The CPU 41 of the multifunction printer 32 then scans the document and creates image data (S246).
[0117] Next, the CPU 41 refers to the created image data and prints the image data (S248). More specifically, the CPU 41 reads the command data stored in the RAM 42 and instructs the image forming unit 52 to print the image data. Furthermore, when the CPU 41 determines that the procedure included in the command data has been completed, that is, when it determines that printing has been completed, it executes the procedure in S250.
[0118] Subsequently, CPU41 executes a procedure equivalent to the procedure for S220 as part of the procedure for S250.
[0119] Furthermore, in this modified example, if the procedure is the same as in the second example, the same effects and benefits as in the second example can be obtained.
[0120] Next, a third implementation example of this embodiment will be described with reference to Figure 11.
[0121] [Third example of execution] The first example shows a case where a user 21 using computer 20 scans a document using multifunction printer 32 and creates image data. The procedure for this example is shown with reference to Figure 11.
[0122] (Operating procedures for information utilization environment 10 and multifunction printer 32) Figure 11 is a sequence diagram showing an example in which the multifunction device 32 in this example communicates with the computer 20 and executes the document scanning function. In Figure 11, it is assumed that the multifunction device 32 has already performed the procedure in S100, as in the first execution example. That is, when the user 21 operates the computer 20 to use the document scanning function based on image data, the procedure shown in Figure 11 will be executed.
[0123] As shown in Figure 11, the second user 21B first inputs a print instruction to the computer 20B based on image data (S301). The CPU 61 of the computer 20B then transmits the image data to be printed, command data including the command to print the image data, and identification information data identifying the second user 21B to the multifunction printer 32. The CPU 61 of the computer 20B also transmits the firmware 52F for the image forming unit and the firmware 58F for the authentication acceptance unit to the multifunction printer 32 (S303). The CPU 41 of the multifunction printer 32, having received the data from the computer 20B, stores the received data in the flash memory 43 (S303).
[0124] Furthermore, the CPU 41 of the multifunction printer 32 loads the authentication acceptance unit firmware 58F, which is included in the received data, into the RAM 42 (S305). In other words, the CPU 41 makes the authentication acceptance unit firmware 58F available by referring to the RAM 42.
[0125] Next, the CPU 41 of the multifunction printer 32 starts the authentication acceptance unit 58 using the authentication acceptance unit firmware 58F deployed in the RAM 42 (S307). In other words, the CPU 41 starts the authentication acceptance unit 58 based on the procedure specified in the authentication acceptance unit firmware 58F deployed in the RAM 42.
[0126] As shown in Figure 11, the first user 21A inputs a print instruction to the computer 20A based on the image data (S308). The CPU 61 of the computer 20A then transmits the image data to be printed, command data including the command to print the image data, and identification information data identifying the first user 21A to the multifunction printer 32. The CPU 61 of the computer 20A also transmits the firmware 52F for the image forming unit and the firmware 58F for the authentication reception unit to the multifunction printer 32 (S310). The CPU 41 of the multifunction printer 32, having received the data from the computer 20A, stores the received data in the flash memory 43 (S310).
[0127] Here, the CPU 41 of the multifunction printer 32 accepts authentication from the first user 21A (S312). More specifically, the CPU 41 obtains the authentication information of the first user 21A who will be using the multifunction printer 32 from the authentication acceptance unit 58. Then, the CPU 41 compares the authentication information of the first user 21A with the identification information data received together with the authentication acceptance unit firmware 58F which is deployed in the RAM 42 (S316).
[0128] However, in the example shown in Figure 11, the execution of step S307 activates the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F transmitted by the second user 21B. Therefore, the CPU 41 makes a negative determination in step S316.
[0129] Then, the CPU 41 restarts the multifunction printer 32 (S318). More specifically, the CPU 41 terminates the software running on the multifunction printer 32 based on the main firmware 47 running on the multifunction printer 32 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 32 executes a boot loader (not shown) and loads the main firmware 47.
[0130] Next, the CPU 41 restarts the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F stored in the flash memory 43 (S320). More specifically, the CPU 41 restarts the authentication acceptance unit 58 based on a different authentication acceptance unit firmware 58F, rather than the one used immediately before (in the procedure of S318). In this example, the CPU 41 restarts the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F transmitted by the first user 21A in S308.
[0131] Next, the CPU 41 accepts authentication from the first user 21A (S322). More specifically, the CPU 41 obtains the authentication information of the first user 21A who will be using the multifunction printer 32 from the authentication acceptance unit 58. Then, the CPU 41 compares the authentication information of the first user 21A with the identification information data received together with the authentication acceptance unit firmware 58F which is deployed in the RAM 42 (S324).
[0132] In the example shown in Figure 11, the execution of step S320 activates the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F transmitted by the first user 21A. Therefore, the CPU 41 makes an affirmative determination in step S324.
[0133] Next, the CPU 41 of the multifunction device 32 loads the image forming unit firmware 52F transmitted from the first user 21A into the RAM 42 (S326). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0134] Next, the CPU 41 of the multifunction printer 32 starts the image forming unit 52 using the image forming unit firmware 52F deployed in the RAM 42 (S328). In other words, the CPU 41 starts the image forming unit 52 based on the procedure specified in the image forming unit firmware 52F deployed in the RAM 42. Furthermore, when the CPU 41 determines that the startup of the image forming unit 52 is complete, it executes the procedure in S330.
[0135] Next, the CPU 41 of the multifunction printer 32 prints image data based on the command data contained in the data received from the computer 20 (S330). More specifically, the CPU 41 reads the command data stored in the RAM 42 and instructs the image forming unit 52 to print the image data. Furthermore, when the CPU 41 determines that the procedure contained in the command data has been completed, that is, when it determines that printing is complete, it executes the procedure in S332.
[0136] Then, the CPU 41 restarts the multifunction printer 32 (S332). More specifically, the CPU 41 terminates the software running on the multifunction printer 32 based on the main firmware 47 running on the multifunction printer 32 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 32 executes a boot loader (not shown) and loads the main firmware 47.
[0137] Next, the CPU 41 restarts the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F stored in the flash memory 43 (S333). More specifically, the CPU 41 restarts the authentication acceptance unit 58 based on a different authentication acceptance unit firmware 58F, rather than the one used immediately before (in the procedure in S332). In this example, the CPU 41 restarts the authentication acceptance unit 58 based on the authentication acceptance unit firmware 58F transmitted by the second user 21B in S303.
[0138] The subsequent steps are the same as those in steps S322 through S332.
[0139] Furthermore, in the procedure described above, the CPU 41 receives image data during the communication in S308. Since this image data is referenced by the image forming unit 52 in the procedure in S330, it can be said to be an example of "reference data referenced by a functional component" in this embodiment. Also, in the procedure described above, the CPU 41 receives authentication information data during the communication in S308. Since this authentication information data is associated with the image data referenced by the image forming unit 52 in the procedure in S330, it can be said to be an example of "authentication information associated with operating software" in this embodiment.
[0140] Next, the operation and effects of the computer 20 and the multifunction device 32 in this embodiment operating according to the procedure described above will be explained.
[0141] (Mechanism of Action and Effects) The multifunction device 32 in this example further receives authentication information data associated with the image forming unit firmware 52F and receives identification information. The multifunction device 32 also operates the image forming unit 52 when the identification information and authentication information data correspond. Therefore, the multifunction device 32 in this example improves security for the first user 21A and the second user 21B when using the multifunction device 32 compared to the case where the image forming unit 52 is operated without confirming the correspondence between the identification information and authentication information data.
[0142] Furthermore, according to this example, other effects and benefits can be obtained in the same way as in the second example.
[0143] In the above explanation, the same reference numeral was used to denote the firmware, but these firmwares do not need to have the same software version or publisher. In other words, it is sufficient that each user 21 can operate the functional components based on the software transmitted from their own computer 20.
[0144] Next, we will explain a modified version of the third example.
[0145] <Variations> Figure 12 shows the operating procedures for the information utilization environment 10 and the multifunction printer 32 in this modified example. In Figure 12, it is assumed that the multifunction printer 32 has already performed the procedure in S100, as in the third example.
[0146] (Operating procedures for information utilization environment 10 and multifunction printer 32) As shown in Figure 12, first, the first user 21A inputs a print instruction to the computer 20A based on image data (S362). The CPU 61 of the computer 20A then transmits command data, including the image data to be printed and the command to print the image data, to the multifunction printer 32. The CPU 61 of the computer 20A also transmits the firmware 52F for the image forming unit and the firmware 58F for the authentication acceptance unit to the multifunction printer 32 (S364). The CPU 41 of the multifunction printer 32, having received the data from the computer 20A, stores the received data in the RAM 42 (S364).
[0147] Next, the CPU 41 of the multifunction device 32 loads the image forming unit firmware 52F transmitted from the first user 21A into the RAM 42 (S370). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0148] Next, the CPU 41 of the multifunction printer 32 starts the image forming unit 52 using the image forming unit firmware 52F deployed in the RAM 42 (S372). In other words, the CPU 41 starts the image forming unit 52 based on the procedure specified in the image forming unit firmware 52F deployed in the RAM 42.
[0149] Here, the second user 21B inputs an instruction to the computer 20B to print based on the image data (S375). The CPU 61 of the computer 20B then sends the image data to be printed and command data including the command to print the image data to the multifunction device 32. The CPU 61 of the computer 20B also sends the firmware 52F for the image forming unit and the firmware 58F for the authentication acceptance unit to the multifunction device 32 (S377).
[0150] However, as shown in Figure 12, the CPU 41 of the multifunction printer 32 has already deployed the firmware for the image forming unit to the RAM 42. In this case, as shown in Figure 12, the CPU 41 sends a prohibition message to the computer 20B indicating that data communication is not permitted (S379). In other words, as shown in Figure 12, the CPU 41 restricts the acceptance of firmware that operates the components from multiple users 21 at the same time.
[0151] Furthermore, if the CPU 61 of computer 20B receives a forbidden message, it will display a message on the output unit 72 indicating that printing is restricted.
[0152] Furthermore, when the CPU 41 determines that the image forming unit 52 has finished starting up, it prints the image data based on the command data contained in the data received from the computer 20 (S380). More specifically, the CPU 41 reads the command data stored in the RAM 42 and instructs the image forming unit 52 to print the image data. Also, when the CPU 41 determines that the procedure contained in the command data has been completed, that is, when it determines that printing has been completed, it executes the procedure in S382.
[0153] Then, the CPU 41 restarts the multifunction printer 32 (S382). More specifically, the CPU 41 terminates the software running on the multifunction printer 32 based on the main firmware 47 running on the multifunction printer 32 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 32 executes a boot loader (not shown) and loads the main firmware 47. Here, the CPU 41 of the multifunction printer 32 starts the communication unit 56 in order to execute the main firmware 47. In other words, after executing the procedure in S114, the CPU 41 executes the procedure in S100 again. In other words, the CPU 41 waits again for communication to be received.
[0154] Furthermore, in this modified example, if the procedure is the same as in the third example, the same action and effect as in the second example can be obtained.
[0155] <Other examples of implementation> In the above explanation, user 21 does not send firmware again after sending the command data. The CPU 61 of computer 20 has already sent firmware along with command data, and if it sends further command data to operate the same functional component before the command based on that command data is executed, it may choose not to send firmware again. In other words, if the CPU 61 has already sent firmware, it does not need to send the same firmware again until the command data is executed.
[0156] Next, the configuration and operation of the multifunction device 132 according to the second embodiment of this disclosure will be described with reference to Figures 13 to 15. In Figures 13 and 14, components similar to those in the first embodiment are denoted by the same reference numerals as in the first embodiment, and their descriptions are omitted.
[0157] [composition] Figures 13 and 14 show the hardware configuration of the multifunction printer 132 in this embodiment. As shown in Figures 13 and 14, the multifunction printer 132 has a control unit 140 that is further equipped with a switch SW in addition to the control unit 40 in the first embodiment.
[0158] As shown in Figures 13 and 14, the switch SW is located on the control bus 45 that connects the flash memory 43 to the other components. In other words, the switch SW switches between a state in which the flash memory 43 can be connected to the other components and a state in which it is disconnected.
[0159] Furthermore, as shown in Figures 13 and 14, the flash memory 43 stores firmware 50F for the input / output unit, firmware 52F for the image forming unit, firmware 54F for the document reading unit, and firmware 58F for the authentication acceptance unit.
[0160] Therefore, as shown in Figure 14, in the multifunction printer 132 of this embodiment, when the switch SW is in the ON position, each firmware recorded in the flash memory 43 can be stored in the RAM 42. In other words, when the switch SW is in the ON position, the multifunction printer 132 of this embodiment is capable of operating its functional components without the use of external devices.
[0161] In other words, as shown in Figure 13, when the switch SW is in the off position, the firmware recorded in the flash memory 43 cannot be transferred to the RAM 42. In this case, the operation is the same as that of the multifunction device 32 in the first embodiment.
[0162] The switch SW can be any type as long as it can switch the connection between the flash memory 43 and other components. Examples of the switch SW include relays and solid-state relays, which are operated by the control operation of the CPU 41. Alternatively, examples of the switch SW include toggle switches and DIP switches, which are manually operated by the user 21 from outside the multifunction device 132. It is preferable that the switch SW, when opened, directly disconnects the connection to the control bus 45.
[0163] Next, the procedure performed by the CPU 41 of the multifunction printer 132 in this embodiment to operate the functional components will be explained with reference to Figures 15 and 16. This procedure is initiated when the CPU 41 executes the main firmware 47. The switch SW is operated by the control operation of the CPU 41. At the start of the procedure shown in Figure 15, the switch SW of the multifunction printer 132 is in the closed state (state shown in Figure 14).
[0164] (Operating procedures for information utilization environment 10 and multifunction printer 132) In this embodiment, a user 21 who wishes to use their own firmware first inputs a print command to the computer 20 based on image data, as shown in Figure 15 (S502). The CPU 61 of the computer 20 then notifies the multifunction printer 132 to switch to high security mode (S504).
[0165] Next, the CPU 41 of the multifunction printer 132 determines whether the received notification includes a notification to switch to high security mode (S505). More specifically, the CPU 41 of the multifunction printer 132 makes a positive determination in the procedure of S505. Then, having received a notification to switch to high security mode, the CPU 41 of the multifunction printer 132 operates the switch SW to the open state (state shown in Figure 13) (S506). As a result, the flash memory 43 of the multifunction printer 132 is disconnected from other components.
[0166] Next, the CPU 41 of the multifunction printer 132 restarts the multifunction printer 132 (S508), as shown in Figures 15 and 16. More specifically, the CPU 41 terminates the software running on the multifunction printer 132 based on the main firmware 47 running on the multifunction printer 132 and frees the memory area used by the RAM 42. After that, the CPU 41 of the multifunction printer 132 executes a boot loader (not shown) to read the main firmware 47 and activates the communication unit 56 to accept communication from an external device.
[0167] Next, the CPU 61 of the computer 20 transmits the image data to be printed, command data including the command to print the image data, and firmware 52F for the image forming unit to the multifunction printer 132 (S510). The CPU 41 of the multifunction printer 132, upon receiving the data from the computer 20, stores the received data in the RAM 42.
[0168] Next, the CPU 41 of the multifunction printer 132 loads the image forming unit firmware 52F, which is included in the received data, into the RAM 42 (S512). In other words, the CPU 41 makes the image forming unit firmware 52F available by referencing the RAM 42.
[0169] Next, the CPU 41 of the multifunction printer 132 starts the image forming unit 52 using the image forming unit firmware 52F deployed in the RAM 42 (S514). In other words, the CPU 41 starts the image forming unit 52 based on the procedure specified in the image forming unit firmware 52F deployed in the RAM 42. Furthermore, when the CPU 41 determines that the startup of the image forming unit 52 is complete, it executes the procedure in S112.
[0170] Next, the CPU 41 of the multifunction printer 132 prints image data based on the command data contained in the data received from the computer 20 (S516). More specifically, the CPU 41 reads the command data stored in the RAM 42 and instructs the image forming unit 52 to print the image data. Furthermore, when the CPU 41 determines that the procedure contained in the command data has been completed, that is, when it determines that printing is complete, it executes the procedure in S518.
[0171] Next, the CPU 41 of the multifunction printer 132 closes the switch SW (S518). In other words, the CPU 41 connects the flash memory 43 of the multifunction printer 132 to the other components.
[0172] Next, the CPU 41 of the multifunction printer 132 restarts the multifunction printer 132 (S520). More specifically, the CPU 41 terminates the software running on the multifunction printer 132 based on the main firmware 47 running on the multifunction printer 132 and frees up the memory area used by RAM 42. After that, the CPU 41 of the multifunction printer 132 executes a boot loader (not shown) to load the main firmware 47, transitions to the state shown in Figure 14, and then terminates the series of procedures.
[0173] In this embodiment, if user 21 does not wish to use their own firmware, the multifunction device 132 will not be notified of the transition to high security mode. In other words, if user 21, who does not have firmware on computer 20, uses the multifunction device 132, they will not be notified of the transition to high security mode.
[0174] In this case, the computer 20 used by user 21 transmits only image data and command data to the multifunction printer 132. Therefore, in the procedure shown in S505 of Figure 16, the CPU 41 of the multifunction printer 132 makes a negative determination. In this case, the CPU 41 of the multifunction printer 132 prints the image data based on the command data contained in the data received from the computer 20 (S523). After that, the CPU 41 of the multifunction printer 130 terminates the series of procedures.
[0175] Thus, in this embodiment, the multifunction printer 132 operates in the same manner as conventional models if it is not notified to switch to high-security mode. In other words, the multifunction printer 132 in this embodiment can be used by both users 21 using a computer 20 with firmware and users 21 using a computer 20 without firmware.
[0176] Next, the operation and effects of the multifunction device 132 in this embodiment will be explained.
[0177] (Mechanism of Action and Effects) In this embodiment, the multifunction printer 132 has other operating software that operates the functional components stored in the flash memory 43, and accepts firmware from the user 21 when the execution of the other operating software is stopped. Therefore, according to this embodiment, even users 21 who do not have firmware can use the multifunction printer 132. In addition, users 21 who have firmware can use the multifunction printer 132 in a manner that enhances security.
[0178] Furthermore, in this embodiment as well, if the procedure is the same as in the first embodiment, the same effects and benefits as in the first embodiment can be obtained.
[0179] Next, a modified example of the second embodiment will be described. In the second modified example, the switch SW is configured to be operated manually by the user 21.
[0180] <Variations> Figure 8 shows the operating procedures of the information utilization environment 10 and the multifunction printer 32 in this modified example. In Figure 8, it is assumed that the multifunction printer 32 has already performed the procedure in S100, as in the first example.
[0181] (Procedure for activating the functional components) First, the CPU 41 determines whether the switch SW is in the closed state (S542). In other words, the CPU 41 determines whether the flash memory 43 is disconnected from other components as shown in Figure 13. The CPU 41 then makes a positive determination if the switch SW is in the closed state (the state shown in Figure 14). On the other hand, the CPU 41 makes a negative determination if the switch SW is in the off state (the state shown in Figure 13). If the CPU 41 makes a positive determination, it proceeds to the procedure in S544; if it makes a negative determination, it proceeds to the procedure in S546.
[0182] Next, the CPU 41 receives command data (S544). More specifically, the CPU 41 receives command data to operate the input / output unit 50, the image forming unit 52, the document reading unit 54, and the authentication reception unit 58. In other words, as shown in the first embodiment, the CPU 41 receives data such as image data, command data, and authentication information.
[0183] The CPU 41 then activates the functional components based on the received data. In other words, the CPU 41 activates the functional components based on the command data contained in the received data. The CPU 41 then completes the procedure for activating the functional components.
[0184] If the procedure in S542 is denied, the CPU 41 further determines whether the functional components excluding the communication unit 56 are in a stopped state (S546). More specifically, the CPU 41 determines whether the firmware that operates the functional components excluding the communication unit 56 is stored in the RAM 42. In other words, the CPU 41 determines whether firmware other than the main firmware 47 is stored in the RAM 42. The CPU 41 then makes an affirmative determination if firmware other than the main firmware 47 is stored in the RAM 42. On the other hand, the CPU 41 makes a negative determination if firmware other than the main firmware 47 is not stored in the RAM 42. If the CPU 41 makes an affirmative determination, it proceeds to the procedure in S544; if it makes a negative determination, it proceeds to the procedure in S548.
[0185] The CPU 41 then receives firmware to operate the functional components excluding the communication unit 56 (S548). More specifically, the CPU 41 receives data including firmware 50F for the input / output unit, firmware 52F for the image forming unit, firmware 54F for the document reading unit, and firmware 58F for the authentication acceptance unit. The CPU 41 also receives command data (S548). More specifically, as shown in the first embodiment, the CPU 41 receives data such as image data, command data, and authentication information.
[0186] The procedure in S548 described above corresponds to the procedure in S100 executed by the CPU 41 in the multifunction device 32 of the first embodiment. In other words, the procedure in S548 is as shown in the first embodiment. After executing the procedure in S548, the CPU 41 completes the procedure for activating the functional components.
[0187] As described above, the CPU 41 in this embodiment determines whether the I / O unit firmware 50F, the image forming unit firmware 52F, the document reading unit firmware 54F, and the authentication acceptance unit firmware 58F are stored in the RAM 42. The CPU 41 then accepts each firmware if the I / O unit firmware 50F, the image forming unit firmware 52F, the document reading unit firmware 54F, and the authentication acceptance unit firmware 58F are not stored in the RAM 42. In other words, if the I / O unit firmware 50F, the image forming unit firmware 52F, the document reading unit firmware 54F, or the authentication acceptance unit firmware 58F are stored in the RAM 42, that firmware can be said to be an example of "other operating software" in this embodiment.
[0188] Furthermore, in this modified example, the same functions and effects as those of the multifunction device 132 of the second embodiment can be obtained.
[0189] In the above description, restarting meant terminating the software running on the multifunction printer 32 and then running the boot loader again. However, "restarting" in this embodiment is not limited to this; for example, it may also mean cutting off and then turning on the power to the multifunction printer 32 (a so-called cold reboot).
[0190] Furthermore, in the above explanation, "what User 21 wishes" is not limited to what User 21 himself wishes. "What User 21 wishes" also includes cases where "what the organization to which User 21 belongs wishes."
[0191] In the above embodiment, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (for example, the aforementioned CPU41, CPU61, and CPU81, etc.) and dedicated processors (for example, GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.).
[0192] Furthermore, the operation of the processor in the above embodiment may not be performed by a single processor, but may be performed by multiple processors located in physically separate locations working together. Also, the order of the processor operations is not limited to the order described in the above embodiment, but may be changed as appropriate.
[0193] In addition, the processing that the CPU 41 reads and executes in each of the above embodiments may be executed by various processors other than the CPU. Examples of such processors include PLDs (Programmable Logic Devices) such as FPGAs (Field-Programmable Gate Arrays) whose circuit configuration can be changed after manufacturing, and dedicated electrical circuits that are processors with circuit configurations specifically designed to execute specific processing, such as ASICs (Application Specific Integrated Circuits). Furthermore, the processing may be executed by one of these various processors, or by a combination of two or more processors of the same or different types (for example, multiple FPGAs, and a combination of a CPU and an FPGA). More specifically, the hardware structure of these various processors is an electrical circuit that combines circuit elements such as semiconductor elements.
[0194] Furthermore, while the above embodiments describe a configuration in which the processing program is pre-stored (installed) on storage, the invention is not limited to this. The program may be provided in a form stored on a non-transitory storage medium such as a CD-ROM (Compact Disk Read Only Memory), DVD-ROM (Digital Versatile Disk Read Only Memory), or USB memory. Alternatively, the program may be downloaded from an external device via a network.
[0195] While embodiments of this disclosure have been described above with reference to the attached drawings, it is clear that any person with ordinary skill in the art to which this disclosure belongs could conceive of various modifications or applications within the scope of the technical idea described in the claims, and these too are naturally understood to fall within the technical scope of this disclosure.
[0196] Further preferred embodiments of this disclosure are shown below.
[0197] (((1))) Functional components and, Processor and Equipped with, The aforementioned processor, The system receives from the user the operating software which is the software that operates the functional component, and command data for the functional component, The operation of the functional components based on the operating software received from the user, To cause the aforementioned functional component to execute the commands included in the command data, An information processing system that performs [this action].
[0198] (((2))) The processor further receives reference data that the functional component refers to, The command to refer to the aforementioned reference data is to be executed by the functional component, An information processing system that executes (((1)))
[0199] (((3))) The processor stores the operating software only in volatile memory. An information processing system as described in (((1))) or (((2))).
[0200] (((4))) The processor erases the operating software when the command of the functional component is completed. The information processing system described in (((3))).
[0201] (((5))) The processor executes reception software recorded on a non-rewritable recording medium to receive the operation software. An information processing system as described in any one of the items (((1))) through (((4))).
[0202] (((6))) Other operating software that operates the aforementioned functional components is recorded in memory. The processor accepts the operating software from the user while the execution of the other operating software is stopped. The information processing system described in (((5))).
[0203] (((7))) The processor further receives authentication information associated with the operating software, Accepting identification information, The process is executed, and the functional component is activated if the identification information and the authentication information correspond. An information processing system as described in any one of the items (((1))) through (((6))).
[0204] (((8))) The system receives operating software, which is software that operates the functional components, and command data for the functional components from the user. The operation of the functional components based on the operating software received from the user, To cause the aforementioned functional component to execute the commands included in the command data, A program that causes the processor to execute.
[0205] According to the information processing system described in (((1))), users of the information processing system can use the system by running the software of their choice. According to the information processing system related to (((2))), the user can use functions based on a command in which the functional component references reference data. According to the information processing system described in (((3))), compared to the case where operating software is also stored on non-volatile memory, the security of using the information processing system can be further improved for users of the information processing system. According to the information processing system described in (((4))), compared to the case where the operating software is stored and the operating software is then received, the security of using the information processing system can be improved for other users who use the information processing system next. According to the information processing system related to (((5))), it is easier to prevent the reception software from being tampered with. According to the information processing system described in (((6))), in an information processing system that can be used by users who do not have operating software, a user who has operating software can run and use the software of their choice. According to the information processing system described in (((7))), compared to the case where the functional components are operated without confirming the correspondence between identification information and authentication information, the security of the information processing system can be improved for users of the information processing system. According to the program described in (((8))), users of the information processing system can use the information processing system by running the software of their choice. [Explanation of Symbols]
[0206] 10 Information usage environment 12 Internet 14. Shared facilities 16. In-facility network 18. Information Management Server 20 Computers 32. Multifunction printer (an example of an information processing system) 40 Control Unit 41 CPU (Example of a processor) 42 RAM 43 Flash memory 44 ROM 45 Control bus 46 Input / Output Interfaces 47 Main Firmware (Example Program) 50 Input / output section 52 Image forming unit (an example of a functional component) 54. Document reading unit (an example of a functional configuration) 56 Communications Department 58 Authentication Reception Unit (An example of a functional configuration unit) 60 Control Unit 61 CPU 62 RAM 63 Flash Memory 65 Control bus 66 Input / Output Interfaces 67 Multifunction printer driver 70 Input section 72 Output section 76 Communications Department 80 Control Unit 81 CPU 82 RAM 83 Flash Memory 85 Control bus 86 Input / Output Interfaces 87 Multifunction printer driver 90 Input section 92 Output section 96 Communications Department 132. Multifunction printer (an example of an information processing system) Firmware for the 50F Input / Output Section (an example of software that operates the functional components) 52F Image Forming Unit Firmware (An example of software that operates the functional components) 54F Firmware for Document Scanning Unit (An example of software that operates the functional components) 58F Firmware for the Authentication Acceptance Unit (An example of software that operates the functional configuration unit)
Claims
1. Functional components and, Processor and Equipped with, The aforementioned processor, The system receives from the user the operating software which is the software that operates the functional component, and command data for the functional component, The operation of the functional components based on the operating software received from the user, To cause the aforementioned functional component to execute the commands included in the command data, An information processing system that performs [this action].
2. The processor further receives reference data that the functional component refers to, The command to refer to the aforementioned reference data is to be executed by the functional component, The information processing system according to claim 1, which performs the following.
3. The processor stores the operating software only in volatile memory. The information processing system according to claim 1.
4. The processor erases the operating software when the command of the functional component is completed. The information processing system according to claim 3.
5. The processor executes reception software recorded on a non-rewritable recording medium to receive the operation software. The information processing system according to claim 1.
6. Other operating software that operates the aforementioned functional components is recorded in memory. The processor accepts the operating software from the user while the execution of the other operating software is stopped. The information processing system according to claim 5.
7. The processor further receives authentication information associated with the operating software, Accepting identification information, The process is executed, and the functional component is activated if the identification information and the authentication information correspond. An information processing system according to any one of claims 1 to 6.
8. The system receives operating software, which is software that operates the functional components, and command data for the functional components from the user. The operation of the functional components based on the operating software received from the user, To cause the aforementioned functional component to execute the commands included in the command data, A program that causes the processor to execute.
Citation Information
Patent Citations
Print system and printing method
JP2012064063A