Image forming apparatus, confidentiality method, and confidentiality program

The image forming apparatus maintains security by using a confidentiality unit to set and enforce execution conditions when switching between network connections, preventing information leakage.

JP2026084285APending Publication Date: 2026-05-21KONICA MINOLTA INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
KONICA MINOLTA INC
Filing Date
2024-11-11
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing image forming apparatuses with multiple communication interfaces fail to maintain security when switching between networks, leading to potential information leakage.

Method used

The apparatus includes a confidentiality unit that ensures security by setting execution conditions and performing security processes when switching between network connections, using a first and second communication unit connected to different networks.

Benefits of technology

Prevents information leakage by ensuring security conditions are met when transitioning between network connections, protecting sensitive data from unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026084285000001_ABST
    Figure 2026084285000001_ABST
Patent Text Reader

Abstract

To provide an image forming apparatus that suppresses information leakage. [Solution] The image forming apparatus comprises a first communication unit connected to a first network line, a second communication unit connected to a second network line, a condition setting unit 57 for setting execution conditions for executing a job, and a confidentiality unit 55 that performs a security securing process to ensure security when the second network line becomes communicable while the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an image forming apparatus, a confidentiality maintaining method, and a confidentiality maintaining program, and more particularly to an image forming apparatus capable of being connected to a plurality of networks, a confidentiality maintaining method executed by the image forming apparatus, and a confidentiality maintaining program for causing a computer to execute the confidentiality maintaining method.

[0002] There is known an image forming apparatus provided with a plurality of communication interfaces respectively connected to a plurality of networks. Networks may have differences in security depending on the type of information flowing through them. For example, in an image forming apparatus provided with a first communication interface and a second communication interface, assume that a first network is connected to the first communication interface. In a situation where the user of the first network is predetermined, the information output from the image forming apparatus has security ensured among limited users. In this situation, when a second network is connected to the second communication interface, a user different from the user of the first network can use the image forming apparatus. Therefore, the information output from the image forming apparatus may be known to persons other than the user of the first network.

[0003] For example, Japanese Patent Application Laid-Open No. 2016-181102 describes an information processing apparatus including a plurality of communication interfaces individually connected to respective ones of a plurality of communication networks, a first determination means for determining the communication interface through which a file passes when the file is stored in a data storage unit, a reception means for receiving a transfer request for the file stored in the data storage unit, a second determination means for determining the communication interface through which the transfer request passes when the transfer request is received by the reception means, and a transfer control means for executing or prohibiting transfer of the file based on the type of the communication interface through which the file passes determined by the first determination means and the type of the communication interface through which the transfer request for the file passes determined by the second determination means.

[0004] However, the information processing device described in Japanese Patent Publication No. 2016-181102 processes data flowing between multiple communication interfaces. Therefore, if the information processing device outputs the data flowing through multiple interfaces using an output means separate from the interfaces themselves, security cannot be maintained. [Prior art documents] [Patent Documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2016-181102 [Overview of the project] [Problems that the invention aims to solve]

[0006] This invention was made to solve the above-mentioned problems, and one of its objectives is to provide an image forming apparatus that suppresses information leakage.

[0007] Another object of this invention is to provide a confidentiality method that suppresses the leakage of information from an image forming apparatus.

[0008] Another object of this invention is to provide a confidentiality program that suppresses the leakage of information from an image forming apparatus. [Means for solving the problem]

[0009] In order to achieve the above-mentioned objective, according to one aspect of this invention, the image forming apparatus comprises: a first communication unit connected to a first network line; a second communication unit connected to a second network line; a condition setting unit for setting execution conditions for executing a job; and a confidentiality unit that performs a security ensuring process to ensure security when the second network line becomes communicable, provided that the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.

[0010] According to another aspect of this invention, the confidentiality method is a confidentiality method performed by an image forming apparatus, the image forming apparatus comprising a first communication unit connected to a first network line and a second communication unit connected to a second network line, and the image forming apparatus is made to perform a condition setting step of setting execution conditions for executing a job, and a confidentiality securing step of performing a security securing process to ensure security in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.

[0011] According to yet another aspect of this invention, the confidentiality program is a confidentiality program executed by a computer that controls an image forming apparatus, wherein the image forming apparatus comprises a first communication unit connected to a first network line and a second communication unit connected to a second network line, and the computer is made to perform a condition setting step of setting execution conditions for executing a job, and a confidentiality securing step of performing a security securing process to ensure security in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions. [Brief explanation of the drawing]

[0012] [Figure 1] This figure shows an example of an overall overview of an image forming system in an embodiment of the present invention. [Figure 2]This is a schematic cross-sectional view illustrating an example of the internal structure of an MFP. [Figure 3] This block diagram shows an overview of the hardware configuration of the MFP in this embodiment. [Figure 4] This block diagram shows an example of the functions of the MFP in this embodiment. [Figure 5] This diagram shows an example of the detailed functions of the warning unit. [Figure 6] This figure shows an example of the detailed functions of the condition change section. [Figure 7] Figure 1 shows an example of a settings screen. [Figure 8] The second figure shows an example of the settings screen. [Figure 9] This flowchart shows an example of the confidentiality process. [Figure 10] This flowchart shows an example of the process for changing conditions. [Modes for carrying out the invention]

[0013] Embodiments of the present invention will be described below with reference to the drawings. In the following description, identical parts are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions of them will not be repeated.

[0014] Figure 1 is a diagram showing an example of an overall overview of an image forming system in an embodiment of the present invention. Referring to Figure 1, the image forming system 1 includes an MFP 100, first PCs 200, 200A to 200C, first server 250, second PCs 300, 300A to 300C, and second server 350. The first PCs 200, 200A to 200C and the second PCs 300, 300A to 300C are personal computers. Their hardware and software configurations are well known, so a detailed explanation will not be repeated here. The first server 250 and the second server 350 are general-purpose computers. Their hardware and software configurations are well known, so a detailed explanation will not be repeated here.

[0015] The MFP 100 is connected to the first network 3 via the first LAN cable 5. The first PCs 200, 200A to 200C and the first server 250 are connected to the first network 3. Therefore, the MFP 100 can communicate with the first PCs 200, 200A to 200C and the first server 250 via the first network 3. The first server 250 functions as a DNS (Domain Name System) server and assigns an IP address to each of the MFP 100 and the first PCs 200, 200A to 200C connected to the first network 3. If IP addresses are pre-assigned to the MFP 100 and the first PCs 200, 200A to 200C, the first server 250 is not necessary.

[0016] The users who use the first PCs 200, 200A to 200C can operate the first PCs 200, 200A to 200C to cause the MFP 100 to execute processing.

[0017] The second PCs 300, 300A to 300C and the second server 350 are connected to the second network 7. Therefore, the second PCs 300, 300A to 300C and the second server 350 can communicate with each other via the second network 7. The second server 350 functions as a DNS server and assigns an IP address to each of the first PCs 200, 200A to 200C connected to the second network 7.

[0018] The first network 3 and the second network 7 are local area networks (LANs). Note that the second network 7 is not limited to a LAN and may be the Internet or a wide area network (WAN).

[0019] The MFP100 has multiple communication interfaces. Therefore, the MFP100 may be connected to the second network 7 while being connected to the first network 3 via the first LAN cable 5. The MFP100 is connected to the second network 7 via the second LAN cable 9. When the MFP100 is connected to the second LAN cable 9, an IP address is assigned by the second server 350. Then, the users of the second PCs 300, 300A to 300C can use the MFP100. The users of the second PCs 300, 300A to 300C can view the information output from the MFP100.

[0020] Here, the users using the first PCs 200, 200A to 200C are referred to as the first type of users, and the users using the second PCs 300, 300A to 300C are referred to as the second type of users. When the second type of users can use the MFP100, the second type of users can view the information output from the MFP100 by the first type of users. Also, the second type of users can view the data stored in the HDD 115 of the MFP100 by the first type of users.

[0021] In the first state where the MFP100 is connected to the first network 3 and not connected to the second network 7, the second type of users cannot use the MFP100. Therefore, in the first state, the data output from the MFP100 or the data stored in the MFP100 by the first type of users cannot be viewed by the second type of users. For this reason, in the first state, the data related to the first type of users does not leak from the MFP100 to the second type of users.

[0022] When the MFP100 is connected to the second LAN cable 9, it becomes the second state where the MFP100 is connected to the first network 3 and the second network 7 respectively. The user can make the MFP100 transition from the first state to the second state by a simple operation of connecting the second LAN cable 9 to the MFP100 in the first state.

[0023] In the second state, the second type of user can use the MFP100. Therefore, in the second state, data output from or stored in the MFP100 by the first type of user can be viewed by the second type of user. Consequently, in the second state, data relating to the first type of user may be leaked from the MFP100 to the second type of user. In this embodiment, the MFP100 ensures the security of data relating to the first type of user when transitioning from the first state to the second state.

[0024] Figure 2 is a schematic cross-sectional view showing an example of the internal configuration of an MFP. Referring to Figure 2, the MFP 100 includes an automatic document transport device 120, a document reading unit 130 for reading documents, an image forming unit 140 for forming images on paper based on image data, and a paper feeding unit 150 for supplying paper to the image forming unit 140.

[0025] The automatic document transport device 120 automatically transports multiple documents placed on the document tray one by one to a predetermined document reading position set on the platen glass of the document reading unit 130. The automatic document transport device 120 then discharges the documents from which the image formed on the documents has been read by the document reading unit 130 into the document output tray.

[0026] The document scanning unit 130 exposes the image of the document placed on the document glass 11 to an exposure lamp 13 attached to a slider 12 that moves below it. The reflected light from the document is guided to the lens 16 by a mirror 14 and two reflective mirrors 15, 15A, and an image is formed on the CCD (Charge Coupled Devices) sensor 18.

[0027] The reflected light formed on the CCD sensor 18 is converted into image data as an electrical signal within the CCD sensor 18. The image data is converted into printable data for cyan (C), magenta (M), yellow (Y), and black (K), and output to the image forming unit 140.

[0028] The image forming unit 140 includes image forming units 20Y, 20M, 20C, and 20K for yellow, magenta, cyan, and black, respectively. Here, "Y", "M", "C", and "K" represent yellow, magenta, cyan, and black, respectively. An image is formed when at least one of the image forming units 20Y, 20M, 20C, and 20K is driven. A full-color image is formed when all of the image forming units 20Y, 20M, 20C, and 20K are driven. Printing data for yellow, magenta, cyan, and black are input to the image forming units 20Y, 20M, 20C, and 20K, respectively. The only difference between the image forming units 20Y, 20M, 20C, and 20K is the color of the toner they handle, so here we will describe the image forming unit 20Y for forming a yellow image.

[0029] The image forming unit 20Y comprises an exposure device 21Y, a photoreceptor drum 23Y, a charging roller 22Y, a developer 24Y, and a primary transfer roller 25Y. The charging roller 22Y, exposure device 21Y, developer 24Y, primary transfer roller 25Y, and drum cleaning blade 27Y are arranged sequentially around the photoreceptor drum 23Y along the rotational direction of the photoreceptor drum 23Y. The exposure device 21Y receives data for printing yellow. The photoreceptor drum 23Y is the image carrier. The charging roller 22Y uniformly charges the surface of the photoreceptor drum 23Y. The primary transfer roller 25Y transfers the toner image formed on the photoreceptor drum 23Y onto the intermediate transfer belt 30, which is the image carrier, by the action of an electric field force.

[0030] The photoreceptor drum 23Y is charged by the charging roller 22Y, and then irradiated with laser light emitted by the exposure device 21Y. The exposure device 21Y exposes the image-corresponding portion of the surface of the photoreceptor drum 23Y. This forms an electrostatic latent image on the photoreceptor drum 23Y. Subsequently, the developer 24Y develops the electrostatic latent image formed on the photoreceptor drum 23Y with charged toner. Specifically, toner is placed on the electrostatic latent image formed on the photoreceptor drum 23Y by the action of an electric field force, thereby forming a toner image on the photoreceptor drum 23Y. The toner image formed on the photoreceptor drum 23Y is transferred onto the intermediate transfer belt 30, which is an image carrier, by the action of an electric field force using the primary transfer roller 25Y. Toner that remains on the photoreceptor drum 23Y without being transferred is removed from the photoreceptor drum 23Y by the drum cleaning blade 27Y.

[0031] The intermediate transfer belt 30 is suspended by a drive roller 33 and a driven roller 34 to prevent slack. When the drive roller 33 rotates counterclockwise in the figure, the intermediate transfer belt 30 rotates counterclockwise in the figure at a predetermined speed. As the intermediate transfer belt 30 rotates, the driven roller 34 rotates counterclockwise.

[0032] As a result, the image forming units 20Y, 20M, 20C, and 20K sequentially transfer toner images onto the intermediate transfer belt 30. The timing at which each of the image forming units 20Y, 20M, 20C, and 20K transfers toner images onto the intermediate transfer belt 30 is adjusted based on the detection of reference marks attached to the intermediate transfer belt 30. As a result, yellow, magenta, cyan, and black toner images are superimposed onto the intermediate transfer belt 30.

[0033] Paper cassettes 35 and 35A are each loaded with paper of different sizes. The paper stored in paper cassettes 35 and 35A is supplied to the transport path by the ejection rollers 36 and 36A attached to paper cassettes 35 and 35A, respectively, and then sent to the timing roller 31 by the paper feed roller 37.

[0034] The paper, transported by the timing roller 31, is carried to the nip section where the intermediate transfer belt 30 and the secondary transfer belt 26 meet. The toner image formed on the intermediate transfer belt 30 is transferred to the paper by the action of an electric field by the secondary transfer belt 26, which is a transfer member. The paper with the transferred toner image is transported to the fuser roller 32, where it is heated and pressurized. This melts the toner and fixes it to the paper. After that, the paper is transported to the output tray 39.

[0035] When forming a full-color image, the MFP100 drives all four image forming units 20Y, 20M, 20C, and 20K. However, when forming a monochrome image, it drives only one of the four image forming units 20Y, 20M, 20C, and 20K. It is also possible to form an image by combining two or more of the two image forming units 20Y, 20M, 20C, and 20K. Here, we will describe an example in which the MFP100 employs a tandem system equipped with image forming units 20Y, 20M, 20C, and 20K that form each of the four toners on the paper. However, the MFP100 may also form an image using a four-cycle system in which a single photosensitive drum transfers the four toners sequentially onto the paper.

[0036] Figure 3 is a block diagram illustrating the hardware configuration of the MFP in this embodiment. Referring to Figure 3, the MFP 100 includes a main circuit 110, a document reading unit 130, an automatic document transport device 120, an image forming unit 140, a paper feeding unit 150, and an operation panel 160. The operation panel 160 is the user interface.

[0037] The main circuit 110 includes a CPU 111, a ROM 113, a RAM 114, an HDD 115, a facsimile unit 116, an external storage device 117, a first communication unit 118, and a second communication unit 119. The HDD 115 is a high-capacity storage device. A solid-state drive (SSD) may be used instead of the HDD 115. The CPU 111 is connected to the automatic document transport device 120, the document reading unit 130, the image forming unit 140, the paper feeding unit 150, and the operation panel 160, and controls the entire MFP 100.

[0038] The facsimile unit 116 is connected to the Public Switched Telephone Network (PSTN) and transmits facsimile data to the PSTN, and also receives facsimile data from the PSTN. The facsimile unit 116 converts the facsimile data into printable data for the image forming unit 140 and outputs it to the image forming unit 140. As a result, the image forming unit 140 forms an image on paper from the facsimile data received by the facsimile unit 116. The facsimile unit 116 stores the received facsimile data in the HDD 115. The facsimile unit 116 transmits the facsimile data to a facsimile device connected to the PSTN. The facsimile data transmitted by the facsimile unit 116 includes the data stored in the HDD 115 and image data output by the document reading unit 130 after reading the document.

[0039] The first communication unit 118 and the second communication unit 119 are communication interfaces. The first communication unit 118 and the second communication unit 119 communicate using communication protocols such as TCP (Transmission Control Protocol) or FTP (File Transfer Protocol). Here, the first communication unit 118 has a first network port, to which the first LAN cable 5 is connected. As a result, the first communication unit 118 is connected to the first network 3 via the first LAN cable 5. The first communication unit 118 is a communication interface for connecting the MFP 100 to the first network 3. The second communication unit 119 has a second network port, to which the second LAN cable 9 is connected. As a result, the second communication unit 119 is connected to the second network 7 via the second LAN cable 9. The second communication unit 119 is a communication interface for connecting the MFP 100 to the second network 7.

[0040] ROM 113 stores the program executed by CPU 111, or the data necessary to execute that program. RAM 114 is used as a workspace when CPU 111 executes the program. RAM 114 also temporarily stores scanned images that are continuously sent from document reading unit 130.

[0041] The control panel 160 is provided on the top surface of the MFP 100. The control panel 160 includes a display unit 161 and an operation unit 163. The display unit 161 is, for example, a liquid crystal display (LCD) and displays instruction menus for the user, information about acquired image data, etc. Instead of an LCD, any device that can display images, such as an organic EL display, may be used.

[0042] The operating unit 163 includes a touch panel 165 and a hard key unit 167. The touch panel 165 is capacitive. However, the touch panel 165 is not limited to the capacitive type; other types such as resistive, surface acoustic wave, infrared, and electromagnetic induction can be used. The hard key unit 167 includes a plurality of hard keys. The hard keys are, for example, contact switches.

[0043] The external storage device 117 is controlled by the CPU 111 and has a CD-ROM 112 installed in it. In this embodiment, an example is described in which the CPU 111 executes a program stored in ROM 113. Alternatively, the CPU 111 may control the external storage device 117 to read a program for execution from CD-ROM 112, store the read program in RAM 102, and then execute it.

[0044] Furthermore, the recording medium for storing the program to be executed by the CPU 111 is not limited to the CD-ROM 112, but may also be a flexible disk, cassette tape, optical disk, semiconductor memory, or other media. Optical disks include MO (Magnetic Optical Disc), MD (MiniDisc), and DVD (Digital Versatile Disc). Semiconductor memory includes IC cards, optical cards, mask ROM, and EPROM (Erasable Programmable ROM).

[0045] Furthermore, the CPU 111 may load programs stored in the HDD 115 into the RAM 114 and execute them on the CPU 111. Programs stored in the HDD 115 include programs downloaded by the CPU 111 from a computer connected to the Internet, or programs written to the HDD 115 by a computer connected to the Internet. The term "program" here includes not only programs that can be directly executed by the CPU 111, but also source programs, compressed programs, encrypted programs, and the like.

[0046] Figure 4 is a block diagram showing an example of the functions of the MFP in this embodiment. The functions shown in Figure 4 are realized by the CPU 201, which causes the CPU 111 of the MFP 100 to execute a confidentiality program stored in the ROM 113, HDD 115, or CD-ROM 112. Alternatively, these functions may be implemented in hardware.

[0047] Referring to Figure 4, the CPU 111 of the MFP 100 includes a first communication control unit 51, a second communication control unit 53, a confidentiality unit 55, a condition setting unit 57, and a setting reception unit 59.

[0048] The first communication control unit 51 controls the first communication unit 118. The first communication control unit 51 detects when the first LAN cable 5 is connected to the first communication unit 118. In response to detecting the connection of the first LAN cable 5, the first communication control unit 51 outputs a first connection detection signal to the confidentiality unit 55.

[0049] The second communication control unit 53 controls the second communication unit 119. The second communication control unit 53 detects when the second LAN cable 9 is connected to the second communication unit 119. In response to detecting the connection of the second LAN cable 9, the second communication control unit 53 outputs a second connection detection signal to the confidentiality unit 55.

[0050] The setting reception unit 59 receives operations input by the user from an external source. The setting reception unit 59 controls the operation panel 160 and receives operations input by the user to the operation panel 160. In addition, if the setting reception unit 59 is remotely controlled from a computer connected to the network, it receives remote operations received via the network. For example, the setting reception unit 59 functions as a web server. The setting reception unit 59 sends an operation screen to the first PC 200 connected to the first network 3 and receives remote operations from the first PC 200. The operations that the setting reception unit 59 receives from an external source are, for example, operations to set setting values ​​corresponding to setting items. The setting reception unit 59 outputs the operations received from an external source to the condition setting unit 57.

[0051] The condition setting unit 57 sets the execution conditions for the MFP100 to execute the process. The execution conditions define setting values ​​corresponding to multiple setting items. The condition setting unit 57 sets the setting values ​​corresponding to multiple setting items. The condition setting unit 57 outputs the execution conditions to the confidentiality unit 55.

[0052] The processes performed by the MFP100 include printing, facsimile transmission / reception, and data management. Printing is the process of forming an image on a recording medium. Facsimile processing is the process of sending and receiving facsimile data. Scanning is the process of reading a document and outputting image data. Data management is the process of saving and inputting / outputting data. The data that data management processes is the data stored in the HDD115. The data stored in the HDD115 includes an address book that defines the destinations of facsimile data used in facsimile transmission processing.

[0053] The condition setting unit 57 sets execution conditions related to security. The execution conditions related to security for print processing are determined by the setting value set in the setting item that defines the method of outputting print data received from an external source. The setting item that defines the method of outputting print data can be set to one of the following: a setting value that forms an image of the print data, a setting value that temporarily stores the print data in the HDD 115 without forming an image of the print data, or a setting value that transfers the print data to another predetermined device without forming an image of the print data. For the setting item that defines the method of outputting print data, the setting value that forms an image of the print data is an execution condition in which security is not ensured. For the setting item that defines the method of outputting print data, the setting value that temporarily stores the print data in the HDD 115 without forming an image of the print data, and the setting value that transfers the print data to another predetermined device without forming an image of the print data are execution conditions in which security is ensured. The print data temporarily stored in the HDD 115 is converted into an image on the recording medium when the user operates the operation panel 160.

[0054] The execution conditions related to security in the facsimile transmission and reception process are determined by the setting value set in the setting item that defines the output method of facsimile data received from an external source. The setting item that defines the output method of facsimile data received from an external source can be set to one of the following: a setting value that forms an image of the facsimile data, a setting value that temporarily stores the facsimile data in the HDD 115 without forming an image of the facsimile data, or a setting value that transfers the facsimile data to another predetermined device without forming an image of the facsimile data. For the setting item that defines the output method of facsimile data, the setting value that temporarily stores the facsimile data in the HDD 115 without forming an image of the facsimile data, and the setting value that transfers the facsimile data to another predetermined device without forming an image of the facsimile data are execution conditions that ensure security. The facsimile data temporarily stored in the HDD 115 can be imaged on the recording medium by the user operating the operation panel 160.

[0055] The execution conditions related to security in data management processing are determined by the setting value set in the setting item that defines access rights to the data stored on HDD115. The setting item that defines access rights to the data stored on HDD115 can be set to either a setting value that defines access rights to the data or a setting value that does not define access rights to the data. For the setting item that defines access rights to the data, setting a value that defines access rights to the data is an execution condition in which security is ensured. For the setting item that defines access rights to the data, setting a value that does not define access rights to the data is an execution condition in which security is not ensured. The setting value that defines access rights to the data includes, for example, a password. The data stored on HDD115 includes image data and an address book.

[0056] The confidentiality unit 55 may receive a second connection signal from the second communication control unit 53 while a first connection signal is being input from the first communication control unit 51. In response to the input of the second connection signal, the confidentiality unit 55 determines whether the security-related conditions among the execution conditions satisfy predetermined conditions. The predetermined conditions are that the setting value that ensures security is an execution condition set in the setting item.

[0057] The confidentiality unit 55 includes a warning unit 61 and a condition modification unit 63. The warning display unit 71 issues a warning if there is an execution condition among the execution conditions in which the security condition does not meet the predetermined conditions. The condition modification unit 63 changes the execution condition set by the condition setting unit 57 to an execution condition that meets the predetermined conditions.

[0058] Figure 5 shows an example of the detailed functions of the warning unit. Referring to Figure 5, the warning unit 61 includes a warning display unit 71, a warning information transmission unit 73, and a re-warning unit 75. The warning display unit 71 displays warning information on the display unit 161. The warning information includes a message notifying that the execution conditions are in a state where security cannot be ensured. The warning information may also include a settings screen for setting the values ​​of the execution conditions where security cannot be ensured. The user can immediately change the execution conditions to ensure security.

[0059] The warning information transmission unit 73 transmits warning information. The warning information transmission unit 73 includes a default transmission unit 77 and an access transmission unit 79. The default transmission unit 77 transmits the warning information to a predetermined destination. The predetermined destination is, for example, the address of a predetermined administrator of the MFP 100. The predetermined destination is stored in the HDD 115 in advance. The predetermined destination may be multiple addresses. For example, the addresses of multiple users who use the first PCs 200, 200A to 200C connected to the first network 3 may be stored in the HDD 115. The addresses are, for example, email addresses or message addresses.

[0060] The access transmission unit 79 detects access from a device connected to the first network 3 and sends warning information to the accessing device. The devices connected to the first network 3 are, for example, the first PC200, 200A, and 200C. For example, when the printer driver for controlling the MFP100 is started on the first PC200, the first PC200 may access the MFP100. The access transmission unit 79 sends warning information to the first PC200 in response to the access from the first PC200. The printer driver on the first PC200 displays the warning information on its display unit. The warning information is transmitted using a protocol such as SNMP (Simple Network Management Protocol). The access transmission unit 79 may also send warning information to the accessing device when it detects access from a device connected to the second network 7.

[0061] Figure 6 shows an example of the detailed functions of the condition change unit. The condition change unit 63 includes a job hold unit 81, a job transfer unit 83, an output prohibition unit 85, a setting screen display unit 87, and a change notification unit 89. The job hold unit 81 holds the execution of jobs received via the first network 3. For example, the job hold unit 81 holds the execution of a print job that defines print processing. The job hold unit 81 changes the setting item that defines the output method of the print data included in the print job to a setting value that temporarily stores the print data in the HDD 115 without forming an image. The job hold unit 81 also holds the execution of a facsimile reception job that defines facsimile reception processing. The job hold unit 81 holds the execution of a facsimile reception job that receives facsimile data. The job hold unit 81 changes the setting item that defines the output method of the facsimile data included in the facsimile reception job to a setting value that temporarily stores the facsimile data in the HDD 115 without forming an image.

[0062] The job transfer unit 83 transfers jobs received via the first network 3 to another device without executing them. For example, the job holding unit 81 changes a setting item that determines how to output the print data included in a print job to a setting value that transfers the print data to another device without forming an image. The job transfer unit 83 also transfers facsimile data included in a facsimile reception job to another device without executing the facsimile reception job received from an external source. For example, the job transfer unit 83 changes a setting item that determines how to output the facsimile data to a setting value that transfers the facsimile data to another device without forming an image.

[0063] The output prohibition unit 85 prohibits the output of data stored on the HDD 115. The output prohibition unit 85 changes the setting item that defines the access rights to the data stored on the HDD 115 to a setting value that proves access rights to the data. For example, the setting value is a password.

[0064] The settings screen display unit 87 displays a settings screen for setting execution conditions on the display unit 161. The settings screen display unit 87 displays a settings screen for setting execution conditions related to security. This allows the user to change the execution conditions to secure settings on the operation unit 163 according to the settings screen displayed on the display unit 161. The settings screen display unit 87 displays the settings screen when the execution conditions are not changed by the job hold unit 81, the job transfer unit 83, or the output prohibition unit 85.

[0065] Figure 7 is the first diagram showing an example of the settings screen. The settings screen shown in Figure 7 includes settings that define how print data is output. In Figure 7, the setting value for the "Authentication Specification" setting is set to "Print without authentication." This execution condition indicates that print data received from an external source will be formed into an image. By setting the "Authentication Specification" setting value to "Print with authentication," the execution condition is set to temporarily store print data received from an external source on HDD115 without forming an image.

[0066] Figure 8 is the second diagram showing an example of the settings screen. The settings screen shown in Figure 8 includes settings that define how facsimile data is output. In Figure 8, the setting value for the "Received Data Processing Settings" is set to "None". This execution condition indicates that the execution condition is set to form an image from facsimile data received from an external source. By setting the setting value for the "Received Data Processing Settings" to "Forced Memory Reception Settings", the execution condition is set to temporarily store print data received from an external source in the HDD115 without forming an image. In addition, by setting the setting value for the "Received Data Processing Settings" to "Transfer Fax Settings", the execution condition is set to transfer facsimile data received from an external source to another device without forming an image.

[0067] Returning to Figure 6, the change notification unit 89, after the execution conditions have been changed to secure ones, detects access from a device connected to the first network 3 and transmits the changes to the accessing device. The changes are information indicating that the execution conditions have been changed. This information includes the setting item whose setting value has been changed, and the setting value before and after the change. The devices connected to the first network 3 are, for example, the first PC200, 200A to 200C. For example, when the printer driver for controlling the MFP100 is started on the first PC200, the first PC200 may access the MFP100. The change notification unit 89 transmits the changes to the first PC200 in response to the access from the first PC200. The printer driver on the first PC200 displays the changes on the display unit. This allows the user to know that the execution conditions have been changed.

[0068] The condition change unit 63 may accept a change operation to change the execution conditions to conditions that ensure security after the execution conditions have been changed to conditions that do not ensure security while the first network 3 and the second network 7 are able to communicate.

[0069] The re-warning unit 75 shown in Figure 5, upon receiving a change operation, prohibits and warns against changing the execution conditions based on that change operation. When a change operation is input to the operation unit 163, the re-warning unit 75 displays re-warning information on the display unit 161. The re-warning information includes a message indicating that changes to the execution conditions are restricted. When the first communication control unit 51 or the second communication control unit 53 receives the change operation, the re-warning unit 75 transmits the re-warning information to the device that transmitted the change operation. The device that transmitted the change operation displays the re-warning information on the display unit.

[0070] Figure 9 is a flowchart illustrating an example of the confidentiality processing flow. Confidentiality processing is a process executed by the CPU 201 when the CPU 111 of the MFP 100 executes a confidentiality program stored in the ROM 113, HDD 115, or CD-ROM 112. Referring to Figure 9, the CPU 111 of the MFP 100 determines whether the line flag is set to 1. If the line flag is set to 1, the process proceeds to step S02; otherwise, the process proceeds to step S07. The line flag indicates the number of network lines connected to the MFP 100. Here, we will explain using the example where the MFP 100 is connected to the first network 3 via the first LAN cable 5, and the second LAN cable 9 is not connected to the second network 7. In this case, the line flag is set to 1, so the process proceeds to step S02.

[0071] In step S02, it is determined whether the number of connected lines is 2 or not. The system waits until the number of connected lines becomes 2 (NO in step S02), and if the number of connected lines is 2 (YES in step S02), the process proceeds to step S03. The case where MFP100 is connected to the first network 3 via the first LAN cable 5 and MFP100 is connected to the second network 7 via the second LAN cable 9 is detected.

[0072] In step S03, the line flag is set to 2, and the process proceeds to step S04. In step S04, it is determined whether the execution condition satisfies a predetermined condition. The predetermined condition is that security is ensured. If the execution condition does not satisfy the predetermined condition, the process proceeds to step S05, but if the execution condition satisfies the predetermined condition, the process terminates.

[0073] In step S05, a warning process is executed, and the process proceeds to step S06. The CPU 111 displays the warning information on the display unit 161. The CPU 111 also sends the warning information to a predetermined address. In step S06, a condition change process is executed, and the process terminates. Details of the condition change process will be described later.

[0074] The process proceeds to step S07 if the line flag is set to 2. If the line flag is set to 0, the MFP100 is not connected to either the first network 3 or the second network 7, and is therefore not subject to processing at this stage. At the stage when step S03 is executed, the line flag is set to 2. Therefore, if the process proceeds to step S07, the MFP100 is connected to both the first network 3 and the second network 7. In this case, the execution conditions satisfy the predetermined conditions. After determining NO in step S04, step S05 or step S06 is executed, and the execution conditions are changed to execution conditions that satisfy the predetermined conditions. Alternatively, if it is determined YES in step S04, the execution conditions satisfy the predetermined conditions.

[0075] In step S07, the CPU 111 determines whether or not it has accepted an operation to change the execution conditions. If it has accepted an operation to change the execution conditions, the process proceeds to step S08; otherwise, the process returns to step S01.

[0076] In step S08, it is determined whether the execution condition to be changed by the operation to change the execution condition satisfies predetermined conditions. If the changed execution condition does not satisfy the predetermined conditions, the process proceeds to step S09; otherwise, the process proceeds to step S11. In step S11, the execution condition is changed according to the change operation accepted in step S07, and the process ends.

[0077] In step S09, the CPU 111 issues another warning and proceeds to step S10. The CPU 111 displays a re-warning on the display unit 161 indicating that the execution conditions cannot be changed. It also transmits the re-warning information to the device that sent the operation to change the execution conditions.

[0078] In step S10, the CPU 111 prohibits any changes to the execution conditions and terminates the process. The CPU 111 discards the operation to change the execution conditions that was accepted in step S07 and does not change the execution conditions.

[0079] In addition, in steps S09 and S10, the settings may be changed based on the modification operation. In this case, a warning will be issued that the execution conditions have been changed to conditions under which security cannot be ensured.

[0080] Figure 10 is a flowchart showing an example of the flow of the condition change process. The condition change process is executed in step S06 of the confidentiality process. Referring to Figure 10, the CPU 111 branches the process depending on the change mode (step S31). The change mode is predetermined by the user to either automatic mode or manual mode. If the change mode is set to automatic mode, the process proceeds to step S32, but if the change mode is set to manual mode, the process proceeds to step S34.

[0081] In step S32, the CPU 111 changes the execution conditions to a setting to hold or transfer the job and proceeds to step S33. In step S33, the CPU 111 sets the permission to output the address book and returns the process to confidentiality processing. For example, the CPU 111 changes the execution conditions to a setting that requires a password to be entered in order to display the address book.

[0082] In step S34, the settings screen is displayed on the display unit 161. In step S35, the settings entered by the user are accepted, and the process proceeds to step S36. In step S36, the settings accepted in step S35 are set, and the process returns to the confidentiality process. This allows the user to change the execution conditions to ensure security.

[0083] <Variation> The execution conditions for ensuring security over print jobs may include setting the output storage media for print jobs received via the first network 3 and the output storage media for print jobs received via the second network 7 to be output to different output trays. This prevents a second user using the second network 7 from mistakenly acquiring the output storage media for print jobs received via the first network 3. It also prevents a second user using the second network 7 from viewing the output storage media for print jobs received via the first network 3.

[0084] <Summary of Embodiments>

[0085] (Item 1) A first communication unit connected to a first network line, A second communication unit connected to a second network line, A condition setting unit for setting the execution conditions for executing a job, An image forming apparatus comprising: a confidentiality unit that performs a security assurance process to ensure security when the second network line becomes communicable, provided that the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.

[0086] In this scenario, when the second network line becomes communicable while communication is possible on the first network line and the security conditions among the execution conditions for executing a job are not met, security processing is performed to ensure security. When the image forming apparatus becomes communicable on the second network line, users using the second network line can use the image forming apparatus. Therefore, users using the second network line can view the output results of a job executed by the image forming apparatus in accordance with the instructions of the user using the first network line, while the security conditions were not met. As a result, there is a risk of confidential information being leaked if the job output results contain confidential information. Since security processing is performed to ensure security, an image forming apparatus with a reduced risk of confidential information leakage can be provided.

[0087] (Item 2) The image forming apparatus according to Item 1, wherein the confidentiality unit warns that the security conditions among the execution conditions do not satisfy the predetermined conditions.

[0088] Following this procedure, a warning will be issued if the security conditions do not meet the specified requirements. Therefore, users of the first network line can be notified that there is a risk of confidential information being leaked.

[0089] (Item 3) The image forming apparatus according to Item 2, wherein the confidentiality unit displays warning information on the display unit.

[0090] If this procedure is followed, a warning message will be displayed on the display unit. This allows the user operating the image forming apparatus to be notified that there is a risk of confidential information being leaked.

[0091] (Item 4) The image forming apparatus according to Item 2, wherein the confidentiality unit transmits warning information to a predetermined destination.

[0092] Following this procedure, a warning message will be sent to a predetermined recipient. This allows the user managing the image forming apparatus to be notified that there is a risk of confidential information being leaked.

[0093] (Item 5) The image forming apparatus according to Item 2, wherein the confidentiality unit transmits warning information to the information processing device in response to detecting access from the information processing device via the first network line.

[0094] In this scenario, a warning message is sent to the information processing device connected to the first network line. This allows users attempting to use the first network line to be notified that there is a risk of confidential information being leaked.

[0095] (Item 6) The image forming apparatus according to Item 1, wherein the confidentiality unit changes the execution conditions set by the condition setting unit to conditions that satisfy the predetermined conditions.

[0096] Following this procedure, the execution conditions are changed to those that satisfy the predetermined conditions. Therefore, since the execution conditions are automatically changed, the leakage of confidential information can be prevented.

[0097] (Item 7) The image forming apparatus according to item 6, wherein the confidentiality unit suspends the execution of jobs received from the first network line.

[0098] Following this procedure, the execution of jobs received from the first network line will be suspended. As a result, jobs received from the first network line will not be executed, thus preventing the leakage of confidential information.

[0099] (Clause 8) The image forming apparatus according to Clause 6, wherein the confidentiality unit transfers jobs received from the first network line to another device without executing them.

[0100] In this scenario, jobs received from the first network line are transferred to another device. As a result, jobs received from the first network line are not executed in the image forming apparatus, thus preventing the leakage of confidential information.

[0101] (Item 9) The image forming apparatus according to Item 6, wherein the confidentiality unit prohibits the output of information stored in the memory unit.

[0102] Following this procedure, the output of information stored in the memory unit is prohibited. Since the information stored in the memory unit is not output, the leakage of confidential information can be prevented.

[0103] (Item 10) The confidentiality unit is the image forming apparatus according to Item 6, which displays a setting screen for setting the execution conditions.

[0104] Following this step will display a settings screen for configuring the execution conditions. This allows the user operating the image forming apparatus to be prompted to change the execution conditions.

[0105] (Item 11) The image forming apparatus according to any one of items 6 to 10, wherein the confidentiality unit transmits information to the information processing device indicating that the execution conditions have been changed, in response to detecting access from the information processing device via the first network line after the execution conditions have been changed to conditions that satisfy the predetermined conditions.

[0106] In this scenario, after the execution conditions are changed to conditions that satisfy predetermined conditions, information indicating that the execution conditions have been changed is transmitted to the information processing device in response to the detection of access from the information processing device via the first network line. Therefore, it is possible to notify users using the information processing device connected to the first network line that the execution conditions have been changed.

[0107] (Clause 12) The image forming apparatus according to Clause 11, wherein the confidentiality unit, in response to receiving an operation to change the execution conditions to conditions that do not satisfy the predetermined conditions, when the execution conditions satisfy the predetermined conditions and the first network line and the second network line are able to communicate, prohibits and / or warns of the change based on the operation.

[0108] In this scenario, if the execution conditions satisfy the predetermined conditions and the first and second network lines are able to communicate, and an operation to change the execution conditions to conditions that do not satisfy the predetermined conditions is accepted, the change will be prohibited and / or a warning will be issued. Therefore, the execution conditions that previously satisfied the predetermined conditions can be maintained in a state where they no longer satisfy the predetermined conditions. In addition, the user will be notified that the execution conditions that previously satisfied the predetermined conditions no longer satisfy them, and the user can be prompted to reset the execution conditions to satisfy the predetermined conditions.

[0109] (Item 13) A confidentiality method performed in an image forming apparatus, The image forming apparatus includes a first communication unit connected to a first network line, It comprises a second communication unit connected to a second network line, A condition setting step to set the execution conditions for running the job, A confidentiality method that causes the image forming apparatus to perform a confidentiality assurance step in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions, and the second network line becomes communicable, by performing a security assurance process to ensure security.

[0110] Following this approach, it is possible to provide a confidentiality method that reduces the risk of confidential information being leaked.

[0111] (Item 14) A confidential program executed on a computer that controls an image forming apparatus, The image forming apparatus includes a first communication unit connected to a first network line, It comprises a second communication unit connected to a second network line, A condition setting step to set the execution conditions for running the job, A confidentiality program that causes the computer to execute a confidentiality step, which involves executing a security process to ensure security in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.

[0112] Following this approach, we can offer a confidentiality program that reduces the risk of confidential information being leaked.

[0113] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than by the foregoing description, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]

[0114] 1 Image forming system, 3 First network, 5 First LAN cable, 7 Second network, 9 Second LAN cable, 100 MFP100, 200, 200A~200C First PC, 300, 300A~300C; Second PC, 250 First server, 350 Second server, 102 RAM, 111 CPU, 112 CD-ROM, 113 ROM, 114 RAM, 115 HDD, 116 Facsimile unit, 117 External storage device, 118 First communication unit, 119 Second communication unit, 120 Automatic document transport device, 130 Document reading unit, 140 Image forming unit, 150 Paper feeding unit, 160 Operation panel, 161 Display unit, 163 Operation unit, 51 First communication control unit, 53 Second communication control unit, 55 Confidentiality unit, 57 Condition setting unit, 59 Setting reception unit, 61 Warning unit, 63 Condition change unit, 71 Warning display unit, 73 Warning information transmission unit, 75 Re-warning unit, 77 Default transmission unit, 79 Access transmission unit, 81 Job hold unit, 83 Job transfer unit, 85 Output prohibition unit, 87 Settings screen display unit, 89 Change notification unit.

Claims

1. A first communication unit connected to a first network line, A second communication unit connected to a second network line, A condition setting unit for setting the execution conditions for executing a job, An image forming apparatus comprising: a confidentiality unit that performs a security assurance process to ensure security when the second network line becomes communicable, provided that the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.

2. The image forming apparatus according to claim 1, wherein the confidentiality unit warns that the security conditions among the execution conditions do not satisfy the predetermined conditions.

3. The image forming apparatus according to claim 2, wherein the confidentiality unit displays warning information on the display unit.

4. The image forming apparatus according to claim 2, wherein the confidentiality unit transmits warning information to a predetermined destination.

5. The image forming apparatus according to claim 2, wherein the confidentiality unit transmits warning information to the information processing device in response to detecting access from the information processing device via the first network line.

6. The image forming apparatus according to claim 1, wherein the confidentiality unit changes the execution conditions set by the condition setting unit to conditions that satisfy the predetermined conditions.

7. The image forming apparatus according to claim 6, wherein the confidentiality unit suspends the execution of jobs received from the first network line.

8. The image forming apparatus according to claim 6, wherein the confidentiality unit transfers the job received from the first network line to another device without executing it.

9. The image forming apparatus according to claim 6, wherein the confidentiality unit prohibits the output of information stored in the storage unit.

10. The image forming apparatus according to claim 6, wherein the confidentiality unit displays a setting screen for setting the execution conditions.

11. The image forming apparatus according to claim 6, wherein the confidentiality unit transmits information to the information processing device indicating that the execution conditions have been changed, in response to detecting access from the information processing device via the first network line after the execution conditions have been changed to conditions that satisfy the predetermined conditions.

12. The image forming apparatus according to claim 11, wherein the confidentiality unit, when the execution conditions satisfy the predetermined conditions and the first network line and the second network line are able to communicate, receives an operation to change the execution conditions to conditions that do not satisfy the predetermined conditions, prohibits and / or warns of the change based on the operation.

13. A confidentiality method performed in an image forming apparatus, The image forming apparatus includes a first communication unit connected to a first network line, It comprises a second communication unit connected to a second network line, A condition setting step to set the execution conditions for running the job, A confidentiality method that causes the image forming apparatus to perform a confidentiality assurance step in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions, and the second network line becomes communicable, by performing a security assurance process to ensure security.

14. A confidentiality program executed on a computer that controls an image forming apparatus, The image forming apparatus includes a first communication unit connected to a first network line, It comprises a second communication unit connected to a second network line, A condition setting step to set the execution conditions for running the job, A confidentiality program that causes the computer to execute a confidentiality step, which involves executing a security process to ensure security in response to the second network line becoming communicable when the first network line is in a state where communication is possible and the security conditions among the execution conditions do not satisfy predetermined conditions.