Information processing device, information processing method, and program
TLS-secured network communication in scanners prevents authentication information interception, enhancing security in scan protocols by restricting unencrypted push scans.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2026-02-19
- Publication Date
- 2026-05-13
AI Technical Summary
The risk of authentication information interception during unencrypted communication in scan protocols between client and scanner terminals poses a security threat, allowing unauthorized access to external terminals and potential data leakage.
Implementing TLS (Transport Layer Security) for network communication in scanners to ensure encrypted transmission of authentication information, and restricting push scans if communication is not encrypted, thereby preventing interception.
Prevents authentication information interception, ensuring secure transmission of scan data and reducing the risk of unauthorized access.
Smart Images

Figure 2026077852000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and a program.
Background Art
[0002] In recent years, a configuration in which a push scan request is transmitted from a client terminal to a scanner terminal and the data scanned by the scanner terminal is transmitted to an external terminal has started to spread (Patent Document 1). In such a system, first, the user sets a document on the scanner terminal, specifies settings such as the destination and storage location for storing the scan result, the scan resolution, etc. from the client terminal, and selects scan start. A specified information and an instruction at the time of scan start are transmitted from the client terminal to the scanner terminal, and the scanner terminal that has received these information performs a scan. Then, the scanner terminal connects to the specified destination terminal and transmits the scanned data.
[0003] Although various methods have been proposed for these scan protocols, protocols such as IPP Scan (PWG5100.17) and eSCL based on HTTP have become widespread. Also, as a protocol for searching and registering a scanner terminal in a client terminal, a search protocol such as mDNS (RFC676) is common.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Incidentally, the destination for saving scanned data can be various external terminals, such as a server on the same LAN, the terminal that issued the scan command, or cloud service storage. Authentication is required for the scanner terminal to connect to these external terminals, and this authentication information is also sent from the client terminal to the scanner terminal along with the scan start command request. Authentication information includes, for example, a token, username, and password. However, if the communication path from the client terminal to the scanner terminal is not encrypted, there is a risk that this authentication information will be intercepted. If the authentication information is intercepted, there is a problem that someone could impersonate that user, access the external terminal, extract confidential data stored in the storage, and potentially leak information.
[0006] The present invention aims to prevent authentication information from being intercepted when a processing terminal transmits a scan instruction that includes authentication information. [Means for solving the problem]
[0007] To achieve the objectives of the present invention, for example, a scanner according to one embodiment has the following configuration. That is, a scanner that supports communication by TLS (Transport Layer Security) over a network, and comprises a receiving means for receiving a request from an information processing device regarding the capabilities of the scanner, and a transmitting means for transmitting a response in response to the request, wherein if a predetermined TLS setting of the scanner is enabled, a response indicating that a predetermined function is available on the scanner is transmitted to the information processing device, and if the predetermined TLS setting of the scanner is disabled, a response indicating that the predetermined function is not available on the scanner is transmitted to the information processing device, and the predetermined function is a function that uses credential information transmitted from the information processing device to the scanner over the network for processing scan data obtained by scanning with the scanner, and is a function that uses the credential information after the scan. [Effects of the Invention]
[0008] When a client terminal sends a scan command that includes authentication information, it is possible to prevent the authentication information from being intercepted. [Brief explanation of the drawing]
[0009] [Figure 1] A diagram showing an example of a system including a processing terminal according to Embodiment 1. [Figure 2] A diagram showing an example of packets transmitted and received by a processing terminal according to Embodiment 1. [Figure 3] A diagram showing an example of a request and response transmitted by a processing terminal according to Embodiment 1. [Figure 4] A flowchart showing an example of the search process in the system according to Embodiment 1. [Figure 5] A flowchart showing an example of the scanning process in the system according to Embodiment 1. [Figure 6] A block diagram showing an example of the hardware configuration of a processing terminal according to Embodiment 1. [Figure 7] A diagram showing an example of the screen flow and confirmation screen of a processing terminal according to Embodiment 1. [Figure 8] A flowchart showing an example of the scanning process performed by the processing terminal according to Embodiment 1. [Figure 9] A flowchart showing an example of the verification process performed by the processing terminal according to Embodiment 1. [Figure 10] A diagram showing an example of the flow of the registration screen displayed by the processing terminal according to Embodiment 2. [Figure 11] A flowchart showing an example of the search process performed by the processing terminal according to Embodiment 2. [Figure 12] A flowchart showing an example of the registration process performed by the processing terminal according to Embodiment 2. [Figure 13] A flowchart showing an example of the scanning process performed by the processing terminal according to Embodiment 3. [Figure 14] A diagram showing an example of a screen displayed by the image processing device according to Embodiment 4. [Figure 15]Flowchart showing an example of the setting process performed by the image processing apparatus according to Embodiment 4. [Figure 16] Block diagram showing an example of the hardware configuration of the image processing apparatus according to Embodiment 4. [Figure 17] Diagram showing an example of the request transmitted by the processing terminal according to Embodiment 5 and its response.
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are given the same reference numerals, and redundant descriptions are omitted.
[0011] [Embodiment 1] FIG. 1 is a diagram showing an example of the configuration of a printing system including a processing terminal 101 which is an information processing apparatus according to the present embodiment. This printing system includes a processing terminal 101, image processing apparatuses 102 to 104 equipped with a scanning function, and a cloud storage service (service) 105. The processing terminal 101 communicates with the image processing apparatuses 102 to 104 existing within the same LAN via a network 100. The network 100 enables the transmission and reception of data between the processing terminal 101 and the image processing apparatuses 102 to 104, and any communication method of the physical layer may be adopted. The image processing apparatuses 102 to 104 have a scanning function and communicate with a service 105 on the Internet via a communication network or a cellular network. Hereinafter, when simply referred to as an image processing apparatus, any one of the image processing apparatuses 102 to 104 is used.
[0012] The network 100 may be, for example, a communication network such as a LAN or a WAN, a cellular network (such as LTE or 5G), or a wireless network compliant with IEEE 802.11, etc., and may be configured by combining a plurality of these communications. The processing terminal 101 may be any terminal capable of acquiring user input and operating, such as a desktop personal computer, a tablet, or a mobile phone terminal. The image processing device 102 is not particularly limited as long as it has a scanning function, and may be, for example, a scanner-only device or a multifunction device equipped with a printing function.
[0013] The processing terminal 101 according to the present embodiment transmits a push scan start request to the image processing device via the network 100 to cause the scanning to be executed. The image processing device that has received the push scan start request uses the authentication information included in the packet of the push scan start request to connect to the service 105 which is the specified external destination and transmits the scanned data.
[0014] [Push Scan] Subsequently, the transmission and reception of communication in general push scan will be described using FIGS. 2 to 5. In the present embodiment, the push scan instruction described below is performed by communication of the HTTP protocol using XML, and the scanner terminal search is performed by communication of the mDNS protocol. FIG. 2 is a diagram showing an example of requests and responses transmitted and received by the mDNS protocol.
[0015] FIG. 4 is a diagram showing an example of a sequence in which a user searches for an image processing device using the processing terminal 101 and registers it in the processing terminal 101. In step S401, when the user selects the "Search" button from the operation screen of the processing terminal 101, the processing following step S402 is started. In step S402, the processing terminal 101 transmits, by a multicast packet, a request (search request) as to whether there is a terminal with an effective scan service within the same link network using the mDNS protocol as shown in FIG. 2(a).
[0016] In the processing according to this embodiment, the plaintext scan service protocol uses port number 80, and the scan service protocol encrypted by TLS uses port number 443. When an image processing device receives a search request, if both plaintext and encrypted communication are enabled in communication with the processing terminal 101, it will send an mDNS response (search response) that includes both port 80 and port 443, as shown in Figure 2(b). If only one of the two is enabled, the image processing device will send a search response that includes only the service that is enabled between port 80 and port 443, as shown in Figures 2(c) and 2(d). TLS is a communication method using TCP / IP, and if TLS is enabled, communication between the processing terminal 101 and the image processing device 102 is encrypted; if it is disabled, communication is performed in plaintext.
[0017] Steps S403 to S404 are the processes in which the image processing device receives a search request from the processing terminal 101 and returns a response. In this example, in step S403, the image processing device sends an mDNS response to the processing terminal 101 as shown in Figure 2(c), and in step S404, the image processing device sends an mDNS response as shown in Figure 2(b) or Figure 2(d). Following steps S403 and S404, the process proceeds to step S405.
[0018] In step S405, the processing terminal 101, having received the search response, displays a list of image processing devices that returned the search response on its display unit. In step S406, the processing terminal 101 obtains the desired selection from the list of image processing devices based on user input.
[0019] In step S407, the processing terminal 101 can send a request (detailed request) to the image processing device selected in step S406 to obtain more detailed information in order to know what kind of scanning is possible. In step S408, the processing terminal 101 receives a response to the detailed request from the image processing device. In step S409, the processing terminal 101 registers the selected image processing device in its internal memory and stores information indicating the selected image processing device in the storage area, thereby ending the registration process. In this embodiment, the information indicating the image processing device after the registration process is completed is stored in the volatile area of the processing terminal 101. This stored state is maintained even when the processing terminal 101 is powered off, and can be accessed and operated by the user at any time.
[0020] Figure 5 shows an example of a sequence in which the processing terminal 101 issues a push scan instruction based on user operation. In this example, the following explanation assumes that the image processing device 102, which has only plaintext communication enabled, is selected in step S406 and the processing shown in Figure 5 is performed. In step S501, the user selects the scan start button from the operation screen of the processing terminal 101 with the original document for the scan image already set in the image processing device 102, thereby starting the processing that follows in step S402.
[0021] In step S502, the processing terminal 101 sends a scan start request to the image processing device 102, as shown in Figure 3(a), in response to the selection of the scan start button. In step S503, the image processing device 102 sends a response to the scan start request to the processing terminal 101, as shown in Figure 3(b). In the example in Figure 3(a), the "DestinationURI" attribute indicates the destination for the push scan, and it is indicated that the scan data will be stored at that destination using POST as shown by "HttpMethod". Also in the example in Figure 3(a), it is indicated that the attribute shown by "JobPassword" will be used as an authentication token when connecting to the destination. The destination for a (push) scan is the destination to which the scan data generated by the (push) scan is sent, and in this embodiment, service 105 is specified. The required authentication method differs depending on the authentication settings of the destination, and methods such as OAuth authentication, DIGEST authentication, or BASIC authentication are used.
[0022] In step S504, the image processing device 102 performs a scan of the document in response to receiving a scan start request. In step S505, the image processing device 102 sends a connection request to the destination specified in the scan start request (in this case, service 105). Here, the image processing device 102 sends a connection request as shown in Figure 3(c), with the necessary authentication information added. In this embodiment, the image processing device 102 sends a connection request that includes authentication information for BASIC authentication, but any authentication information depending on the authentication method, such as an OAuth authentication token, may be used. In step S506, the image processing device 102 receives a response indicating successful connection from service 105, which has been successfully authenticated.
[0023] In step S507, the image processing device 102 sends the scanned data of the scanned document to the service 105, and in step S508, it receives a response indicating that the scan data has been received. The processing terminal 101 also periodically sends a request to the image processing device 102 to inquire about the scan job status, as shown in Figure 3(e). Upon receiving the inquiry request, the image processing device 102 sends a response to the processing device 101 indicating the scan job status, as shown in Figure 3(f), and if the job has been successfully saved to the destination, it sends a response to the processing device 101 indicating that the saving is complete.
[0024] In this example, since the image processing device 102 only supports plaintext communication, the exchange shown in Figures 3(a) and 3(b) is performed in plaintext over HTTP port 80. As a result, the authentication token and other information mentioned above are transmitted in plaintext, creating a problem where packets may be intercepted and authentication information may be leaked. However, if encrypted communication over HTTPS port 443 is used for sending and receiving data, eavesdropping is much easier to prevent.
[0025] Therefore, the processing terminal 101 determines whether the communication mode, connection conditions, or authorization level with the image processing device 102 meets predetermined conditions, and if they do not, it controls the system so as not to allow the image processing device 102 to perform a push scan. In this embodiment, if the predetermined conditions regarding the communication mode are not met, the processing terminal 101 restricts the image processing device 102 from starting a push scan if the communication with the image processing device 102 is not encrypted. If the communication with the image processing device 102 is encrypted, the processing terminal 101 does not restrict the start of the push scan and can send the credentials to be sent to the service 105 during the push scan to the image processing device 102. Credentials are authentication information required during user authentication such as BASIC authentication or DIGEST authentication, and are sent by the image processing device 102 in step S505 described above. Hereinafter, it will be explained that a username and password are used as this authentication information.
[0026] Furthermore, the processing terminal 101 does not restrict the initiation of a push scan if it meets predetermined conditions regarding connection conditions, such as when the communication path with the image processing device 102 is a wireless LAN P2P connection like WiFi Direct. This is because, in a wireless LAN P2P connection, other terminals cannot join the connection, and since the wireless LAN layer is used, there is little risk of eavesdropping even when using plain text HTTP communication.
[0027] Figure 6 is a block diagram showing an example of the hardware configuration of the processing terminal 101. The processing terminal 101 comprises a CPU 601, ROM 602, RAM 603, storage unit 604, operation unit 605, and communication unit 606. The CPU 601 directly or indirectly controls each device (such as ROM and RAM) connected via internal devices and executes a program to realize the present invention. The ROM 602 is a read-only storage device that stores the program executed by the CPU 601 and stores the BIOS as firmware. The RAM 603 functions as the main memory or work memory of the CPU 601 and is used to load software modules to realize the present invention. The storage unit 604 is a storage area, such as a hard disk drive (HDD) or solid-state drive (SSD) that stores the OS, which is the basic software, and software modules. The operation unit 605 functions as a display unit that displays information to the user and a reception unit that receives user instructions. The operation unit 605 is, for example, a liquid crystal display unit with touch panel functionality or a display equipped with various hard keys.
[0028] The CPU 601 works in cooperation with the operation unit 605 to control the display of information and to control the reception of user operations. The communication unit 606 is an interface for the processing terminal 101 to connect to a network. In this embodiment, the communication unit 606 is assumed to be a communication interface that performs wired communication compliant with Ethernet®, but is not particularly limited to this as long as it enables communication. The communication unit 606 may be a wireless communication interface compliant with, for example, the IEEE 802.11 series. The communication unit 606 may also perform communication as a wireless communication interface. Furthermore, for example, the communication unit 606 may perform communication via a 3G line such as CDMA, a 4G line such as LTE, or mobile communication such as 5G NR. In this embodiment, each process performed by the CPU 601 is described as being implemented by the processing terminal 101, which is dedicated hardware, but some or all of the processing may be performed by a separate computer.
[0029] Next, using Figures 7 to 9, we will explain the control process by the processing terminal 101 according to this embodiment that restricts the initiation of a push scan in the mode of unencrypted plaintext communication. Figure 7 shows an example of the screen flow of the operation unit 605 displayed by the processing terminal 101 according to this embodiment. Screen 701 is an example of a screen that displays a list of image processing devices registered in the processing terminal 101. When the user selects any terminal to scan from the image processing devices displayed on screen 701, the screen transitions to screen 702. Screen 702 is the main menu screen for the selected image processing device and displays the status of the image processing device (e.g., idling state or busy state) or buttons for making detailed scan settings. In this example, when the user presses the button labeled "Open Scan Setting", screen 703, which is a screen for making detailed settings, is displayed. In the example in Figure 7, screen 703 is a screen for setting the size, resolution, or format of the scan, but any setting used for scanning may be made, such as the position of the starting point of the scan or the feed direction of the document.
[0030] When a user selects an item on screen 703, the operation unit 605 displays a screen for detailed settings related to the selected item. Screens 704 to 708 are examples of setting screens corresponding to each item selected on screen 703. Screen 704 is for setting the destination for push scans. On screen 704, it is possible to set whether the destination for storing scan data is the local terminal or an external terminal, the path for storing scan data, and the authentication information required to connect to the destination. Screen 704 displays the item "Destination," where the setting of whether the destination is the local terminal or an external terminal and the details (URL) of the destination if it is an external terminal are entered. Screen 704 displays a form for entering authentication information in response to a user authentication request from the destination terminal that requires a username and password, such as BASIC authentication or DIGEST authentication. This authentication information may be set in advance, or when the image processing device 102 sends a user authentication request to the processing terminal 101, a screen prompting the user to enter authentication information may be displayed as a pop-up on the operation screen of the processing terminal 101. Furthermore, if user authentication with service 105 using this authentication information has already been completed, an item may be provided on screen 703 to set whether or not to send the token stored in processing terminal 101 to image processing device 102. In this embodiment, various protocols such as HTTP, FTP, or SMB may be used as the protocol setting for connecting to service 105, and the parameters required for setting the destination (in this case, service 105) can be arbitrarily changed.
[0031] Figure 8 is a flowchart showing an example of a process performed by the CPU 601 of the processing terminal 101 according to this embodiment to restrict the start of a push scan by displaying a warning screen. When the "Scan" button is pressed on screen 703, the CPU 601 of the processing terminal 101 starts the process in step S801 and proceeds to step S802.
[0032] In step S802, the CPU 601 determines whether the scan can be started. Here, the CPU 601 first determines whether the scan process by the image processing device 102 is a push scan or a pull scan. If it is a pull scan, the exchange of authentication information as described above is not necessary, so the process proceeds to step S805, assuming that the scan can be started. If it is a push scan, the process proceeds to step S803 to avoid leakage of authentication information.
[0033] In step S803, the CPU 601 determines whether the communication path between the processing terminal 101 and the image processing device 102 is a P2P connection via a wireless LAN such as WiFi Direct. If it is a P2P connection, the scan can be started, and the process proceeds to step S805. On the other hand, if it is not a P2P connection, such as in an environment where communication is done via a general LAN connection, the process proceeds to step S804.
[0034] In step S804, the processing terminal 101 determines whether or not the communication with the image processing device 102 is encrypted. If the communication is not encrypted, such as with the image processing device 102 which only supports HTTP communication on port 80, the process proceeds to step S806. If the communication is encrypted, the process proceeds to step S805.
[0035] In step S805, the processing terminal 101 determines that communication with the image processing device 102 is encrypted, sends a request to the image processing device 102 to start a push scan as shown in Figure 3(a), and terminates the process. On the other hand, in step S806, the processing terminal 101 determines that communication with the image processing device 102 is not encrypted, presents a warning screen as shown in screen 707 to the user, and terminates the process. The processing terminal 101 may also periodically check the scan job status, and if the saving of scan data is completed after step S805, it may present a completion display as shown in screen 705 or screen 706 to the user. Screen 705 is a completion display when the cloud 105 is an external device separate from the processing terminal 101, and screen 706 is a completion display when the destination of the scan process is the processing terminal 101.
[0036] This type of processing prevents information leakage by controlling whether or not to send a push scan start request packet containing authentication information, depending on whether the communication mode, connection status, or authorization level between the processing terminal and the image processing device (scanner) meets predetermined conditions. In particular, if it is determined that the communication path between the processing terminal and the image processing device is encrypted, the leakage of authentication information can be prevented by controlling the system so as not to send the scan start request packet.
[0037] Furthermore, the processing terminal 101 may not restrict the initiation of a push scan even if the user has given consent to the transmission of authentication information to service 105. That is, the push scan initiation process may continue in response to the user's approval that it is acceptable to transmit authentication information in plain text, for example, if the processing terminal 101 and the image processing device 102 are connected within a completely closed LAN. To this end, the processing terminal 101 can present the user with a screen to confirm whether or not to continue the push scan process (for example, when communication with the image processing device 102 is not encrypted) and obtain the user's selection. This process is, for example, step S906 in Figure 9 (Figure 7(b)) described later, and if the user approves to continue the scan process, the communication approval level is considered to have met the predetermined conditions described above, and the initiation of the push scan is not restricted. If the user approves to continue the scan process, the communication approval level is considered to have not met the predetermined conditions described above, and the initiation of the push scan is restricted.
[0038] Figure 9 is a flowchart showing an example of a process performed by the CPU 601 of the processing terminal 101 according to this embodiment, which displays a confirmation screen to determine whether to continue the push scan initiation process instead of the warning screen shown in Figure 8, thereby restricting the initiation of a push scan. In the process shown in Figure 9, the same processing as shown in Figure 8 is performed, except that steps S901 and S902 are performed instead of step S806, so redundant explanations are omitted.
[0039] In step S901, which is performed when it is determined in step S804 that the communication is not encrypted, the processing terminal 101 presents the user with a confirmation screen asking whether to continue the push scan initiation process. In this example, a confirmation screen like the one shown in screen 708 of Figure 7(b) is displayed, and the user's selection to continue or cancel the process is obtained. In step S902, the processing terminal 101 determines whether the user's selection on the confirmation screen displayed in step S901 is to approve the continuation of the process or to cancel it. If the user selects to continue the process, the process moves to step S805, and the push scan initiation command is issued. If the user selects to cancel the process, the process ends.
[0040] Furthermore, if the processing terminal 101 restricts the initiation of a push scan, it may instead suggest to the user that they perform a pull scan. With a pull scan, as mentioned above, the exchange of authentication information is not required, so the risk of authentication information leakage can be avoided even with plaintext communication. In this example, instead of displaying the warning screen in step S806, the processing terminal 101 presents the user with a screen allowing them to choose whether or not to perform a pull scan.
[0041] [Embodiment 2] The processing terminal 101, which is an information processing device according to Embodiment 2, controls the image processing device to prevent push scanning by an image processing device by restricting the display of an image processing device whose communication is not encrypted in the list of search results, as performed in steps S401 to S405 of Embodiment 1. Except for this series of processes, the processing terminal 101 according to this embodiment performs basically the same processing as in Embodiment 1, so redundant explanations are omitted.
[0042] The processing terminal 101 according to this embodiment restricts the display of an image processing device in the search results list by either preventing the display of an image processing device whose communication is not encrypted in the search results list, or by confirming whether the user is actually going to register the device when it is selected from the list. Figure 11, described later, shows a flowchart for preventing the display of an image processing device in the search results list, and Figure 12 shows a flowchart for confirming whether the user is actually going to register the device.
[0043] In this embodiment, the processing terminal 101 searches for the image processing device by sending a search request in a multicast packet, for example, in the same manner as in step S402. Here, the processing terminal 101 refers to the mDNS response of the image processing device to the search request and determines whether or not communication with each searched image processing device is encrypted. This is determined, for example, by referring to the port number from the response shown in Figures 2(b) to 2(d). In the following example, the processing terminal determines whether a push scan is possible based on whether or not the communication is encrypted, but this may be a condition based on the connection type or a condition based on the authorization level.
[0044] The processing terminal 101 can control the display of image processing devices that are determined to have unencrypted communication during a search, preventing them from being displayed in the search results list. Alternatively, the processing terminal 101 may display all search results in a list, and when an image processing device to be registered is selected by the user, it may indicate that communication with that image processing device is unencrypted and obtain the user's option on whether to proceed with registration (for example, screen 1005). In that case, if communication with the selected image processing device is encrypted, the selected image processing device will be registered in the list as a registered device.
[0045] Figures 10 to 12 illustrate an example of the processing performed by the processing terminal 101 according to this embodiment when searching for an image processing device. Figure 10 shows an example of the screen flow of the operation unit 605 displayed by the processing terminal 101 according to this embodiment when searching for an image processing device. Figure 11 is a flowchart showing an example of the processing performed by the CPU 601 of the processing terminal 101 when searching for an image processing device, as shown in Figure 10, which restricts the display.
[0046] Screen 1001 displays a list of image processing devices registered with the processing terminal 101. The operation unit 605 can search for and register new image processing devices by obtaining user input on screen 1001. In step S1101, the processing terminal 101 sends a search request via multicast packet. Here, if the user selects the "Search" button on screen 1001, the CPU 601 sends an mDNS search packet to the image processing device as shown in Figure 2(a), and the operation unit 605 displays an indication that a search is in progress as shown on screen 1002.
[0047] In step S1102, the processing terminal 101 receives mDNS responses from each image processing device that performed the search. In step S1103, the processing terminal 101 determines whether the service for scanning the response packets uses encrypted communication. For image processing devices that use encrypted communication, the process in step S1104 is performed, and for image processing devices that do not use encrypted communication, the process in step S1105 is performed. In step S1104, the processing terminal 101 adds image processing devices that use encrypted communication via HTTPS communication with TLS using port 443, as shown in Figures 2(b) and 2(d), to the list of search results as devices whose communication is encrypted. On the other hand, in step S1105, the processing terminal 101 does not add image processing devices that perform the service of scanning HTTP communication using port 80, as shown in Figure 2(c), to the list of search results as devices whose communication is not encrypted. If the processing in step S1104 or step S1105 is completed, the process proceeds to step S1106, and the processing in steps S1103 to S1105 is repeated until the mDNS lookup response is completed, after which the process proceeds to step S1107. In step S1107, the processing terminal 101 displays a list of search results from the image processing devices on the display screen. The processing terminal 101 displays the image processing devices 103 and 104 in the list, excluding, for example, the image processing device 102 which only supports plaintext communication.
[0048] This process allows for the determination of whether or not the communication path to the processing terminal is encrypted when searching for image processing devices for registration. Therefore, by excluding image processing devices with unencrypted communication from the search results, the risk of leakage of authentication information can be reduced.
[0049] On the other hand, Figure 12 is a flowchart showing an example of the process performed by the CPU 601 of the processing terminal 101 in the process shown in Figure 10, which involves restricting the image processing device after it has been registered in the list of searched image processing devices. In step S1201, the processing terminal 101 sends a search request in a multicast packet in the same manner as in step S1101. In step S1102, the processing terminal 101 receives mDNS responses from each image processing device that has been searched in the same manner as in step S1102.
[0050] In step S1203, the processing terminal 101 adds each image processing device that returned an mDNS response to the list of search results. In step S1204, the processing terminal 101 determines whether the process in step S1203 was performed for all image processing devices that returned an mDNS response. If it was performed for all image processing devices, the process proceeds to step S1205; otherwise, the process returns to step S1203. After receiving all responses in step S1205, the processing terminal 101 generates and displays a list of search results for image processing devices as shown on screen 1003.
[0051] In step S1206, the processing terminal 101 obtains the user's selection of an image processing device to be registered from the list. In step S1207, the processing terminal 101 determines, in the same manner as in step S1103, whether the communication between the image processing device selected in step S1206 and the processing terminal 101 is encrypted. If the communication with the selected image processing device includes an encrypted scan service, the process proceeds to step S1208, and the processing terminal 101 adds the image processing device to the registered list and the process ends. On the other hand, if the selected image processing device does not include an encrypted scan service, the process proceeds to step S1209.
[0052] In step S1209, the processing terminal 101 displays a screen, as shown in screen 1005, to obtain a user selection regarding whether to continue the registration process even though it does not involve encrypted communication. In step S1210, the processing terminal 101 determines whether the user selected to continue the registration process in step S1209. If the user selects to continue, the process proceeds to step S1208, where the processing terminal 101 adds the image processing device to the list of registered devices and displays a completion message, as shown in screen 1006, before the process ends. If the user does not select to continue, the registration process is canceled and the process ends.
[0053] This process allows for the determination of whether or not the communication path to the processing terminal is encrypted when searching for an image processing device for registration. Subsequently, for image processing devices whose communication is not encrypted, the risk of registration can be reduced by confirming whether or not registration is actually to be performed when selecting one from the list.
[0054] [Embodiment 3] In the printing system 100 according to the embodiment, a push scan was performed in which service 105 was used as the destination for the scan by the image processing device 102. On the other hand, when the image processing device 102 performs a pull scan with the processing terminal 101 as the destination for the scanned data, it is not necessary to include authentication information in the scan start instruction. From this viewpoint, the processing terminal 101, which is an information processing device according to Embodiment 3, determines whether or not the image processing device 102 can perform a pull scan. Then, if the image processing device 102 can perform a pull scan, the processing terminal 101 issues an instruction to start a pull scan, and if a pull scan is not possible, it issues an instruction to start a push scan.
[0055] The processing terminal 101 according to this embodiment has the same configuration as the processing terminal 101 of Embodiment 1 and performs the same processing, except that it transmits a pull scan start instruction when the image processing device 102 is capable of pull scanning. Therefore, redundant explanations will be omitted. In this embodiment, pull scanning will be described as a scan performed by the image processing device 102 in response to a scan start instruction from the processing terminal 101, with the processing terminal 101 as the storage destination for the scan data.
[0056] Figure 13 is a flowchart showing an example of the process of sending a pull scan start request performed by the processing terminal 101 according to this embodiment. The process shown in Figure 13 is initiated when a scan start instruction is given to the image processing device 102, for example, when the user presses the "Scan" button on screen 703 in Figure 7.
[0057] In step S1301, the processing terminal 101 detects that the user has issued a scan start command to the image processing device 102. In step S1302, the processing terminal 101 determines whether the destination (storage location) of the data scanned by the image processing device 102 is its own terminal, i.e., the processing terminal 101, or an external terminal such as the service 105. Here, the processing terminal 101 makes the above determination by referring to the item "Destination" entered by the user on screen 704 in Figure 7. If the destination is its own terminal, the process proceeds to step S1303; otherwise, the process proceeds to step S803 in Figure 8 to perform subsequent processing related to the push scan.
[0058] In step S1303, the processing terminal 101 determines whether or not it is capable of pull scanning. Here, it is determined whether or not the processing terminal 101 has a pull scan function, and if so, whether or not the setting to enable / disable the pull scan function is enabled. If the processing terminal 101 is capable of pull scanning, the process proceeds to step S1304; otherwise, the process proceeds to step S803 in Figure 8 to perform subsequent processing related to push scanning. In step S1304, the processing terminal 101 sends a start instruction to the image processing device 102 to start the scan as a pull scan, and the process ends.
[0059] This process allows the system to initiate a pull scan if it is possible. Since the scan initiation request does not include authentication information, there is no problem with sending and receiving data via plain text HTTP communication. Therefore, the leakage of authentication information can be prevented.
[0060] [Embodiment 4] As shown in Figure 2(a), the processing terminal 101 in Embodiment 1 performed a search for terminals where a scan service exists without distinguishing between push scans and pull scans. On the other hand, the processing terminal in this embodiment performs a search process assuming that, in addition to the conventional "scan service," "pull scan services" and "push scan services" also exist.
[0061] Figure 17 shows an example of service lookup and response packets by the mDNS service when "pull scan service" and "push scan service" are also present in addition to the "scan service". Compared to the example in Figure 2, the pull scan and push scan services have been added to both the packets from the processing terminal and the response packets from the image processing device, and an image processing device that only supports the conventional scan service can return the same response as in the example in Figure 2. Figure 17(b) is an example of a packet response from an image processing device (port number 80) that supports the pull scan service and performs plaintext communication. Figure 17(c) is an example of a packet response from an image processing device (port number 443) that supports both the pull scan service and the push scan service and performs encrypted communication.
[0062] In this embodiment, search requests are made using pull scans and push scans, and responses are made for each. Therefore, even in an image processing device where "Use of TLS" is disabled and "Push" is enabled, such as in Embodiment 5 described later, if a pull scan is possible, a response can be returned with information indicating that it is possible.
[0063] In this system, the image processing device sends a response to a search request from the processing terminal 101 that includes information including whether or not push scanning is possible. However, considering the need to prevent the leakage of authentication information, it is not necessary to indicate to the processing terminal 101 that push scanning is possible when plaintext communication is performed. From this perspective, the image processing device according to this embodiment does not send information to the processing terminal 101 indicating that push scanning is possible when the communication with the processing terminal 101 is plaintext communication in response to a search request from the processing terminal 101. In other words, the response sent is information indicating that push scanning is not possible.
[0064] This process allows the image processing device to provide service responses for both push scans and pull scans, enabling it to provide appropriate service responses using pull scans as well.
[0065] [Embodiment 5] The image processing device 1600 according to Embodiment 4 performs a push scan in response to a push scan start instruction from the processing terminal 101, similar to the image processing device 102 in Embodiment 1. In addition, the image processing device 1600 sets whether or not to perform encrypted communication (enabled / disabled), and sets whether or not to perform a push scan (enabled / disabled) according to that setting. Here, the image processing device 1600 is set not to perform a push scan if encrypted communication is disabled. In other words, the setting for encrypted communication and the setting for whether or not to enable push scans are linked, and the leakage of authentication information is prevented by not performing a push scan when encrypted communication is not performed.
[0066] The image processing device 1600 according to this embodiment implements "pull scan service" and "push scan service" in addition to the "scan service" according to Embodiment 4, according to existing standards. Therefore, the image processing device 1600 responds to a search request from the processing device 101 based on the setting of whether or not to perform the above-mentioned encrypted communication (enabled / disabled) and the setting of whether or not to perform a push scan (enabled / disabled), which is determined according to that setting. However, the image processing device 1600 is not particularly limited to implementation according to this standard, and may also perform a response generated according to a conventional standard, as shown in Figure 2 of Embodiment 1.
[0067] Figure 16 is a block diagram showing an example of the hardware configuration of the image processing apparatus 1600 according to this embodiment. The image processing apparatus 1600 comprises a CPU 1601, ROM 1602, RAM 1603, storage unit 1604, printer processing unit 1605, scanner processing unit 1606, communication unit 1607, and operation unit 1608. The CPU 1601 directly or indirectly controls each device (such as ROM and RAM) connected via internal devices and executes a program to realize the present invention. The ROM 1602 is a read-only storage device that stores the program executed by the CPU 1601 and stores the BIOS as firmware. The RAM 1603 functions as the main memory or work memory of the CPU 1601 and is used to load software modules to realize the present invention. The storage unit 1604 is a storage area, such as a hard disk drive (HDD) or solid-state drive (SSD) that stores the OS, which is the basic software, and software modules. The scanner processing unit 1606 reads and digitizes image files scanned by a plate press or feeder. The printer processing unit 1605 controls copying or prints an image to a specified image file in response to a print command from an external terminal, and then ejects the printed image. The operation unit 1608 functions as a display unit that shows information to the user and a reception unit that receives user instructions. The operation unit 1608 is, for example, a liquid crystal display unit with touch panel functionality or a display equipped with various hard keys.
[0068] The CPU 1601 works in cooperation with the operation unit 1608 to control the display of information and to control the reception of user operations. The communication unit 1607 is an interface for the image processing device 1600 to connect to a network. In this embodiment, the communication unit 1607 is assumed to be a communication interface that performs wired communication compliant with Ethernet (registered trademark), but it is not particularly limited to this as long as it enables communication. The communication unit 1607 can perform communication in the same way as the communication unit 606 in Embodiment 1.
[0069] Figure 14 shows an example of the scan setting screen displayed on the operation unit 1608 of the image processing device 1600. The user makes the desired scan settings via the screen 1400 shown in Figure 14. On screen 1400, there is an item called "Use Network Scan" which determines whether or not to use the network scan function. Depending on whether the use of network scan is enabled or disabled, the transmission and reception of data over the network by application functions such as IPP scan or eSCL scan is enabled or disabled. Also, when the "Use TLS" setting on screen 1400 is enabled or disabled, the transmission and reception of data via plaintext communication using HTTP port 80 is enabled or disabled. In other words, when "Use TLS" is enabled, data is transmitted and received via plaintext communication. Furthermore, on screen 1400, "Pull" and "Push" are individually enabled or disabled as transmission type types. Here, when "Pull" is enabled, the pull scan function of the image processing device 1600 is enabled, and when "Push" is enabled, the push scan function of the image processing device 1600 is enabled. Either the "Pull" setting or the "Push" setting may be enabled, or both may be enabled. After the user selects these various scan settings, pressing the "SAVE" button causes the CPU 1601 to retrieve the selected settings and store them in the memory unit 1604.
[0070] Figure 15 is a flowchart showing an example of the process performed by the image processing device 1600 to prohibit push scan settings when encrypted communication is disabled. The following explanation assumes that each process proceeds based on user selections on the screen 1400, but the expression is not limited to this if similar settings are made. The process shown in Figure 15 starts from step S1501 when a command to save scan settings is received, such as when the "SAVE" button on the screen 1400 is pressed. In step S1501, the CPU 1601 detects that the user has pressed the "SAVE" button and processes the settings acquired and stored by that press. In step S1502, the CPU 1601 determines whether the "Use network scan" item is enabled or disabled. If the "Use network scan" item is enabled, the process proceeds to step S1503; otherwise, the process proceeds to step S1506.
[0071] In step S1503, CPU1601 determines whether the "Push" setting is enabled or disabled. If the "Push" setting is enabled, the process proceeds to step S1504; otherwise, the process proceeds to step S1506. In step S1504, CPU1601 determines whether the "Use TLS" setting is enabled or disabled. If the "Use TLS" setting is disabled, the process proceeds to step S1505; otherwise, the process proceeds to step S1506.
[0072] If the "Push" setting is enabled and "Use TLS" is enabled, the authentication information included in the push scan communication will be transmitted in plain text. Therefore, in step S1505, the CPU 1601 controls the system so that it does not perform a push scan based on the scan settings obtained in S1501. Here, a warning message indicating that this combination of settings is not possible is displayed on the display unit, and the process is terminated without saving the obtained settings. In step S1606, where the setting is not "Push" enabled and "Use TLS" is not enabled, the CPU 1601 stores the obtained settings, assuming there are no security issues.
[0073] In other words, the image processing device 1600 according to this embodiment does not require the simultaneous implementation of push scanning and plaintext communication, and the method of implementation is not particularly limited. For example, the image processing device 1600 may display a warning message when the "SAVE" button is pressed, as shown in the flow chart of Figure 15, and may also enable the "Use TLS" setting in conjunction with the "Push" setting. Furthermore, if "Use TLS" is disabled, the image processing device 1600 may automatically disable the "Push" setting and, for example, display it grayed out so that it cannot be selected.
[0074] This process ensures that encrypted communication is always performed when the push scan setting on the image processing device is enabled. Therefore, by implementing linked and prohibited setting processes so that the encrypted communication setting is always enabled when the push scan setting on the scanning device is enabled, the communication path containing authentication information is always encrypted, thus preventing eavesdropping on the authentication information.
[0075] In this embodiment, the settings shown in Figure 14 have been described as being performed on the image processing device 1600. However, these settings may be entered on a different device; for example, the image processing device 1600 may perform the processing from step S1502 onward for scan settings entered on an external device such as a processing terminal 101 and for which the "SAVE" button has been pressed.
[0076] (Other examples) The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.
[0077] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of symbols]
[0078] 101: Processing terminal, 601: CPU, 602: ROM, 603: RAM, 604: Storage unit, 605: Operation unit, 606: Communication unit
Claims
1. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, It includes a transmission means for transmitting a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. If the predetermined TLS settings of the scanner are invalid, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. A scanner characterized by the following features.
2. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, It includes a transmission means for transmitting a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, the predetermined functions can be used in the scan command from the information processing device. If the predetermined TLS setting of the scanner is disabled, the predetermined function will not be used in the scan command from the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. A scanner characterized by the following features.
3. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, The system includes a transmission means that transmits a response to the information processing device indicating that a predetermined function is available on the scanner in response to the aforementioned request, The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by scanning with the scanner, and is a function that utilizes the credential information after the scan. When TLS communication is performed between the information processing device and the scanner, the predetermined function can be used in the scan command from the information processing device. If TLS communication is not performed between the information processing device and the scanner, the predetermined function will not be used in the scan command from the information processing device. A scanner characterized by the following features.
4. The aforementioned credential information is a password. A scanner according to any one of claims 1 to 3.
5. The image data obtained by the scan performed by the scanner, which is subject to the predetermined function, is transmitted from the scanner via the network. The scanner according to feature 1.
6. The scanner according to any one of claims 1 to 3, characterized in that the predetermined function includes the transmission of an image scanned by the scanner.
7. The scanner according to claim 1 or 2, further comprising setting means for enabling or disabling the predetermined TLS settings.
8. The scanner according to any one of claims 1 to 7, characterized in that the scanner is an image forming apparatus having scanning and printing functions.
9. A method for processing information performed by a scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving step of receiving a request regarding the capabilities of the scanner from the information processing device, The process includes a transmission step of sending a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. If the predetermined TLS settings of the scanner are invalid, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. An information processing method characterized by the following:
10. A method for processing information performed by a scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving step of receiving a request regarding the capabilities of the scanner from the information processing device, The process includes a transmission step of sending a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, the predetermined functions can be used in the scan command from the information processing device. If the predetermined TLS setting of the scanner is disabled, the predetermined function will not be used in the scan command from the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. An information processing method characterized by the following:
11. A method for processing information performed by a scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving step of receiving a request regarding the capabilities of the scanner from the information processing device, The process includes a transmission step of sending a response to the information processing device indicating that a predetermined function is available on the scanner in response to the aforementioned request, The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by scanning with the scanner, and is a function that utilizes the credential information after the scan. When TLS communication is performed between the information processing device and the scanner, the predetermined function can be used in the scan command from the information processing device. If TLS communication is not performed between the information processing device and the scanner, the predetermined function will not be used in the scan command from the information processing device. An information processing method characterized by the following:
12. The aforementioned credential information is a password. The information processing method according to any one of claims 9 to 11, characterized by the features described herein.
13. The image data obtained by the scan performed by the scanner, which is subject to the predetermined function, is transmitted from the scanner via the network. The information processing method according to feature 9.
14. The information processing method according to any one of claims 9 to 11, characterized in that the predetermined function includes the transmission of an image scanned by the scanner.
15. The information processing method according to claim 9 or 10, further comprising a setting step of enabling or disabling the predetermined TLS settings.
16. The information processing method according to any one of claims 9 to 15, characterized in that the scanner is an image forming apparatus having scanning and printing functions.
17. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, A program to function as a transmission means for sending a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. If the predetermined TLS settings of the scanner are invalid, a response indicating that the predetermined function is available on the scanner is sent to the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. A program characterized by the following features.
18. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, A program to function as a transmission means for sending a response in response to the aforementioned request, If the predetermined TLS settings of the scanner are enabled, the predetermined functions can be used in the scan command from the information processing device. If the predetermined TLS setting of the scanner is disabled, the predetermined function will not be used in the scan command from the information processing device. The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by the scanner, and is a function that utilizes the credential information after the scan. A program characterized by the following features.
19. A scanner that supports communication via TLS (Transport Layer Security) over a network, A receiving means for receiving a request regarding the capabilities of the scanner from an information processing device, A program for causing the information processing device to function as a transmission means for sending a response indicating that a predetermined function is available on the scanner in response to the aforementioned request, The predetermined function is a function that utilizes the credential information transmitted from the information processing device to the scanner via the network for processing the scan data obtained by scanning with the scanner, and is a function that utilizes the credential information after the scan. When TLS communication is performed between the information processing device and the scanner, the predetermined function can be used in the scan command from the information processing device. If TLS communication is not performed between the information processing device and the scanner, the predetermined function will not be used in the scan command from the information processing device. A program characterized by the following features.