Information processing systems and information processing programs

The system addresses firmware update decisions by considering device settings and API usage to prevent application unavailability, ensuring smooth integration and cooperation with external applications.

JP2026123661APending Publication Date: 2026-07-30FUJIFILM BUSINESS INNOVATION CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
FUJIFILM BUSINESS INNOVATION CORP
Filing Date
2025-01-17
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Conventional firmware update decisions in information processing devices rely solely on fixed information such as version numbers, ignoring current settings and API usage status, leading to potential application unavailability post-update.

Method used

An information processing system and program that acquires device and firmware information, including setting values and application links, to determine if firmware updates satisfy predetermined prohibition conditions, using update policies to prioritize function enhancement, cooperation, and administrator judgment.

Benefits of technology

Prevents firmware updates that could render applications unusable by considering device settings and API usage, ensuring seamless integration and cooperation with external applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026123661000001_ABST
    Figure 2026123661000001_ABST
Patent Text Reader

Abstract

Compared to using only fixed information, including the firmware version, when deciding whether or not to update the firmware of an information processing device, this method suppresses the occurrence of malfunctions caused by firmware updates. [Solution] The update determination server 10 is equipped with a CPU 11, which acquires device information including at least one of the setting values ​​set in the information processing device and information about applications that cooperate with the information processing device when updating the firmware of the information processing device, or at regular intervals, and acquires firmware information including the firmware version, and permits the firmware update if the combination of device information and firmware information does not satisfy predetermined prohibition conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system and an information processing program.

Background Art

[0002] For example, Patent Document 1 describes a network system including a distribution system that controls software distribution to network devices and a setting management system that manages setting values of network devices. This network system has a determination means for determining whether a cooperation flag for permitting software distribution from the distribution system in the network device to be a software distribution target in the distribution system is enabled, and in the distribution system, when it is determined that the cooperation flag is not enabled, an instruction means for instructing the setting management system to enable the cooperation flag of the network device to be the distribution target, an enabling means for enabling the cooperation flag of the network device in the setting management system in response to the instruction, a notification means for notifying the distribution system of the completion of enabling the cooperation flag of the network device in the setting management system, and a distribution control means for performing software distribution preparation in the distribution system in response to the notification. This distribution control means controls software distribution in response to a request from a network device in which the cooperation flag is enabled after the distribution preparation.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Incidentally, conventionally, when deciding whether or not to update the firmware of an information processing device, fixed information such as the firmware version is used. In this case, the current settings of the information processing device and the usage status of the API (Application Programming Interface) are not taken into consideration, so problems such as applications becoming unusable after a firmware update may occur.

[0005] This disclosure aims to provide an information processing system and an information processing program that can suppress the occurrence of malfunctions caused by firmware updates, compared to the case where only fixed information, including the firmware version, is used when determining whether or not to update the firmware of an information processing device. [Means for solving the problem]

[0006] To achieve the above objective, the information processing system according to the first embodiment includes a processor, which acquires device information, including at least one of the setting values ​​set in the information processing device and information relating to an application that is linked with the information processing device, when updating the firmware of the information processing device, or at regular intervals, and acquires firmware information, including the version of the firmware, and permits the firmware update if the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions.

[0007] Furthermore, in the information processing system according to the second embodiment, the processor in the information processing system according to the first embodiment prohibits updating the firmware if the combination satisfies the prohibition conditions.

[0008] Furthermore, in the information processing system according to the third embodiment, the combination is multiple, the processor acquires the prohibition conditions associated with each of the multiple combinations, and permits the firmware update if each of the multiple combinations does not satisfy the prohibition conditions.

[0009] Furthermore, in the information processing system according to the fourth embodiment, the processor prohibits updating the firmware if at least one of the plurality of combinations satisfies the prohibition condition.

[0010] Furthermore, the information processing system according to the fifth embodiment has an update policy used for determining whether to update the firmware in the case of a combination that satisfies the prohibition conditions in the information processing system according to the first embodiment, and the processor determines that it is possible to update the firmware if the update policy indicates a state that enables the firmware update.

[0011] Furthermore, in the information processing system according to the sixth embodiment, the update policy includes a function enhancement priority that prioritizes the functional enhancement of the information processing device, a cooperation priority that prioritizes cooperation with the application, and an administrator priority that prioritizes the judgment of the administrator managing the information processing device, and the update policy that indicates a state in which the firmware update is possible is the function enhancement priority and the administrator priority.

[0012] Furthermore, in the information processing system according to the seventh embodiment, if the processor determines that the firmware update is possible according to the update policy, it adds the applicable prohibition condition to the first list, and if the processor determines that the firmware update is not possible according to the update policy, it adds the applicable prohibition condition to a second list different from the first list.

[0013] Furthermore, in the information processing system according to the eighth aspect, the processor, in the information processing system according to the seventh aspect, creates risk information representing the risks of updating the firmware based on at least one of the first list and the second list, and notifies the administrator of the created risk information and the result of the firmware update determination.

[0014] Furthermore, in the information processing system according to the ninth embodiment, in the information processing system according to the first embodiment, the application includes at least one of an application incorporated into the information processing device and an application outside the information processing device.

[0015] Furthermore, in the information processing system according to the tenth embodiment, the device information includes option information relating to options connected to the information processing device.

[0016] To achieve the above objective, the information processing program according to the 11th embodiment acquires device information, which includes at least one of the setting values ​​set in the information processing device and information about an application that is linked with the information processing device, when updating the firmware of the information processing device, or at regular intervals, acquires firmware information including the firmware version, and causes a computer to execute a process that permits the firmware update if the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions. [Effects of the Invention]

[0017] According to the first and eleventh embodiments, compared to the case where only fixed information including the firmware version is used when determining whether or not to update the firmware of the information processing device, it is possible to suppress the occurrence of malfunctions due to firmware updates.

[0018] According to the second embodiment, compared to the case where an update decision is made without considering the prohibition conditions, it has the effect of being able to appropriately prohibit firmware updates.

[0019] According to the third embodiment, compared to the case where an update decision is made for each of the multiple combinations without considering the prohibition conditions, it has the effect of being able to appropriately permit firmware updates.

[0020] According to the fourth aspect, there is an effect that firmware updates can be appropriately prohibited as compared with the case where update determination is performed without considering prohibition conditions for each of a plurality of combinations.

[0021] According to the fifth aspect, there is an effect that it is possible to appropriately determine whether or not to update firmware as compared with the case where update determination is performed without considering an update policy.

[0022] According to the sixth aspect, there is an effect that it is possible to appropriately determine whether or not to update firmware as compared with the case where update determination is performed without considering function expansion priority, cooperation priority, and administrator priority as an update policy.

[0023] According to the seventh aspect, there is an effect that even when it is determined that firmware update is possible, corresponding prohibition conditions can be added.

[0024] According to the eighth aspect, there is an effect that risk information associated with firmware update can be notified to an administrator.

[0025] According to the ninth aspect, there is an effect that cooperation can be maintained not only for built-in applications but also for external applications.

[0026] According to the tenth aspect, there is an effect that cooperation can be maintained for options connected to the information processing apparatus.

Brief Description of Drawings

[0027] [Figure 1] It is a diagram showing an example of the configuration of an information processing system according to an embodiment. [Figure 2] It is a block diagram showing an example of the electrical configuration of an update determination server according to an embodiment. [Figure 3] It is a block diagram showing an example of the functional configuration of an update determination server according to an embodiment. [Figure 4]This figure shows an example of device information acquired from an image processing device. [Figure 5A] This figure shows an example of firmware information obtained from the distribution server. [Figure 5B] This figure shows an example of firmware information obtained from the distribution server. [Figure 6] This figure shows an example of a prohibited conditions table used for updating the firmware according to the embodiment. [Figure 7] This figure shows examples of update feasibility determination lists, warning lists, and vulnerability lists according to the embodiment. [Figure 8] This diagram schematically shows the processing flow by the information processing system according to the embodiment. [Figure 9] This is a sequence diagram showing an example of firmware update determination processing by the information processing system according to the embodiment. [Figure 10] This flowchart shows an example of the firmware update determination process flow by the information processing program according to the embodiment. [Figure 11] This diagram illustrates an example of executing a firmware update determination process that does not affect the integration process, prioritizing either feature enhancements or integration. [Figure 12] This diagram illustrates an example of a case where firmware update detection processing, which does not affect the integration, is executed with priority given to the administrator. [Figure 13] This diagram illustrates an example of how firmware update detection processing that affects integration can be executed with integration priority / administrator priority. [Figure 14] This diagram illustrates an example of how firmware update detection processing, which affects the integration process, is executed with priority given to feature enhancements. [Modes for carrying out the invention]

[0028] Hereinafter, an example of an embodiment for carrying out the technology of this disclosure will be described in detail with reference to the drawings. Components and processes that perform the same operation, action, or function are given the same reference numerals throughout the drawings, and redundant explanations may be omitted as appropriate. Each drawing is only a schematic representation to the extent that the technology of this disclosure can be fully understood. Therefore, the technology of this disclosure is not limited to the illustrated examples. Furthermore, in this embodiment, explanations of configurations not directly related to the technology of this disclosure or well-known configurations may be omitted.

[0029] Figure 1 shows an example of the configuration of the information processing system 100 according to this embodiment. As shown in Figure 1, the information processing system 100 according to this embodiment includes an update determination server 10, a distribution server 20, an image processing device 30, and a terminal device 50. In the example in Figure 1, one image processing device 30 and one terminal device 50 are shown, but the number is arbitrary. Note that the image processing device 30 according to this embodiment is an example of an information processing device.

[0030] The update judgment server 10, distribution server 20, image processing device 30, and terminal device 50 are connected to each other via network N. Network N can be the Internet, LAN (Local Area Network), WAN (Wide Area Network), etc. There are no restrictions on the connection method of network N; it may be wired, wireless, or a combination of wired and wireless.

[0031] The update determination server 10 is a server computer for determining whether or not to update the firmware FW of the image processing device 30. The distribution server 20 is a server computer for distributing the firmware FW to the image processing device 30. In this embodiment, the update determination server 10 and the distribution server 20 are shown as separate entities, but they may be configured as an integrated unit. Here, firmware FW is software for controlling the computer system (hardware) incorporated into the image processing device 30, and is updated periodically or at arbitrary times.

[0032] The image processing device 30, as an example, has a scanning function that reads an image written on a recording medium such as paper as image data, a printing function that forms an image represented by the image data on a recording medium, and a copying function that forms an image identical to the image formed on the recording medium on another recording medium. The copying function, printing function, and scanning function are examples of image processing in the image processing device 30. The image processing device 30 is also connected via network N to an application provision server 60 that provides external applications to the image processing device 30, and can provide various functions in cooperation with external applications. Furthermore, the image processing device 30 is also connected via network N to an image processing device 70, which is an older model chronologically than the image processing device 30, and can provide various functions in cooperation with the image processing device 70. To explicitly distinguish between the image processing device 30 and the image processing device 70, the image processing device 70 is referred to as the older model 70.

[0033] The terminal device 50 is a terminal device used by the administrator of the image processing device 30, and various devices such as personal computers (PCs), smartphones, and tablet devices are applicable.

[0034] Figure 2 is a block diagram showing an example of the electrical configuration of the update determination server 10 according to this embodiment. As shown in Figure 2, the update determination server 10 according to this embodiment includes a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, an input / output interface (I / O) 14, a storage unit 15, a display unit 16, an operation unit 17, and a communication unit 18.

[0035] The CPU 11, ROM 12, RAM 13, and I / O 14 are connected to each other via a bus. The I / O 14 is connected to various functional units, including a storage unit 15, a display unit 16, an operation unit 17, and a communication unit 18. These functional units are capable of communicating with the CPU 11 via the I / O 14.

[0036] The control unit is comprised of a CPU 11, ROM 12, RAM 13, and I / O 14. The control unit may be configured as a sub-control unit that controls some of the operations of the update determination server 10, or as part of a main control unit that controls the overall operation of the update determination server 10. Some or all of the blocks in the control unit may use integrated circuits such as LSIs (Large Scale Integration) or ICs (Integrated Circuit) chipsets. Individual circuits may be used for each of the above blocks, or some or all of them may be integrated into a single circuit. The above blocks may be provided as a single unit, or some of the blocks may be provided separately. Furthermore, parts of each of the above blocks may be provided separately. For the integration of the control unit, dedicated circuits or general-purpose processors may be used, not just LSIs.

[0037] For example, the storage unit 15 can be an HDD (Hard Disk Drive), an SSD (Solid State Drive), or flash memory. The storage unit 15 stores the information processing program 15A and the update policy 15B described later according to this embodiment. The information processing program 15A may also be stored in the ROM 12.

[0038] The information processing program 15A may, for example, be pre-installed on the update determination server 10. The information processing program 15A may also be implemented by storing it on a non-volatile storage medium or distributing it via the network N and installing it on the update determination server 10 as appropriate. Examples of non-volatile storage mediums include CD-ROMs (Compact Disc Read Only Memory), magneto-optical disks, HDDs, DVD-ROMs (Digital Versatile Disc Read Only Memory), flash memory, and memory cards.

[0039] The display unit 16 may include, for example, a liquid crystal display (LCD), an electroluminescent (EL) display, or the like. The display unit 16 may also have an integrated touch panel. The operation unit 17 is equipped with, for example, a keyboard, mouse, or other device for operation input. The display unit 16 and the operation unit 17 receive various instructions from the user of the update judgment server 10. The display unit 16 displays various information such as the results of processing performed in response to instructions received from the user, and notifications regarding the processing.

[0040] The communication unit 18 is connected to a network N, such as the Internet, LAN, or WAN, and can communicate with the distribution server 20, the image processing device 30, and the terminal device 50 via the network N.

[0041] By the way, as mentioned above, when determining whether or not to update the firmware FW of the image processing device 30, if fixed information such as the firmware FW version is used, the current settings of the image processing device 30 and the usage status of the API are not taken into consideration. As a result, problems such as the application becoming unusable after updating the firmware FW may occur.

[0042] Therefore, the CPU 11 of the update determination server 10 according to this embodiment functions as the various parts shown in Figure 3 by writing the information processing program 15A stored in the memory unit 15 to the RAM 13 and executing it. Note that the CPU 11 is an example of a processor.

[0043] Figure 3 is a block diagram showing an example of the functional configuration of the update determination server 10 according to this embodiment. As shown in Figure 3, the CPU 11 of the update determination server 10 according to this embodiment functions as a first acquisition unit 11A, a second acquisition unit 11B, a determination unit 11C, an addition unit 11D, and a notification unit 11E. Note that the first acquisition unit 11A and the second acquisition unit 11B may be configured as a single acquisition unit.

[0044] The first acquisition unit 11A acquires device information when updating the firmware FW of the image processing device 30, or at regular intervals. The device information includes at least one of the setting values ​​set in the image processing device 30 and information about applications that cooperate with the image processing device 30. Here, the application includes at least one of the applications built into the image processing device 30 and external applications of the image processing device 30. An external application is, for example, an application that can cooperate by connecting to an application provision server 60. The application is not particularly limited, but specifically, examples include an MPS (Managed Print Service) that provides an efficient print service using the print function of the image processing device 30, and a scan form service that provides form services using the scan function of the image processing device 30. In addition, the device information may also include option information regarding options connected to the image processing device 30 (for example, a post-processing device). The device information is acquired from, for example, the distribution server 20, the image processing device 30, etc.

[0045] The second acquisition unit 11B acquires firmware information, including the firmware version (FW). The firmware information is acquired, for example, from the distribution server 20.

[0046] The determination unit 11C permits the firmware update if the combination of device information acquired by the first acquisition unit 11A and firmware information acquired by the second acquisition unit 11B does not satisfy predetermined prohibition conditions. Conversely, the determination unit 11C prohibits the firmware update if the combination of device information and firmware information satisfies the prohibition conditions.

[0047] Furthermore, there may be multiple combinations of device information and firmware information. In this case, the determination unit 11C acquires the prohibition conditions associated with each of the multiple combinations, and permits the firmware update if none of the multiple combinations satisfy the prohibition conditions. Alternatively, the determination unit 11C may prohibit the firmware update if at least one of the multiple combinations satisfies the prohibition conditions.

[0048] Furthermore, in the case of combinations that satisfy the prohibited conditions, the update policy 15B may be used to determine whether to update the firmware FW. In this case, the determination unit 11C determines that the firmware FW can be updated if the update policy 15B indicates a state in which the firmware FW can be updated. The update policy 15B includes, for example, a function enhancement priority that prioritizes the functional enhancement of the image processing device 30, a cooperation priority that prioritizes cooperation with applications, and an administrator priority that prioritizes the judgment of the administrator managing the image processing device 30. In this case, the update policy 15B that indicates a state in which the firmware FW can be updated is, for example, a function enhancement priority and an administrator priority. However, with a function enhancement priority, the firmware FW can always be updated, but with an administrator priority, it is up to the administrator to decide whether or not to allow the firmware FW to be updated.

[0049] If update policy 15B determines that firmware FW can be updated, the additional unit 11D adds the relevant prohibition conditions to the first list. If update policy 15B determines that firmware FW cannot be updated, the additional unit 11D adds the relevant prohibition conditions to a second list, which is different from the first list. These first and second lists will be described later.

[0050] The notification unit 11E creates risk information representing the risks associated with firmware updates based on at least one of the first list and the second list, and notifies the administrator's terminal device 50 of the created risk information and the result of the firmware update determination. This risk information will also be described later.

[0051] Figure 4 shows an example of device information obtained from the image processing device 30. In Figure 4, "DATA_ID" indicates the setting value ID (Identification), which is the identification information of the setting value; "VALUE" indicates the currently set setting value (current value); and "Description" indicates a description of the setting value. However, "Description" is not used for determining whether to update the firmware FW. For example, the setting value with setting value ID "DATA_1" indicates that the current value is "HTTP only". The same applies to other setting values ​​"DATA_2", "DATA_3", "DATA_4", etc.

[0052] Figures 5A and 5B show examples of firmware information obtained from the distribution server 20. Figure 5A shows an overview of the firmware FW. In Figure 5A, "FW_ID" indicates the firmware ID, which is the identification information of the firmware FW; "Version" indicates the version of the firmware FW; "Region" indicates the region in which the firmware FW is provided; "Providing Customer" indicates the customer to whom the firmware FW is provided; and "Supported Options" indicates the options that support the firmware FW. For example, firmware FW with firmware ID "1" indicates that the version is "1.2.10", the region is "JP (Japan)", and the providing customer is "General". The same applies to other firmware IDs "2" and "3". Figure 5B shows the firmware FW correction information. In Figure 5B, "FW_ID" indicates the firmware ID; "Urgency" indicates the urgency of the correction; and "Correction Details" indicates the correction details of the firmware FW. Here, a lower value for "Urgency" (5, 1, 2, 5 in the example of Figure 5B) indicates a higher urgency and a correction that should be addressed quickly. Furthermore, instead of determining whether or not to update based solely on the update policy 15B described above, it may be possible to weight the updates based on urgency. For example, firmware updates with high urgency (FW) could be given a greater weight to ensure they are updated as quickly as possible.

[0053] Figure 6 shows an example of a prohibition condition table used for updating the firmware FW according to this embodiment. This prohibition condition table may be obtained from the distribution server 20, an external site, or the image processing device 30, or it may be created by the device itself (update determination server 10). The prohibition condition table obtained from an external source or created by the device itself is stored, for example, in the storage unit 15. In Figure 6, "Prohibition Condition_ID" indicates the prohibition condition ID, which is the identification information of the prohibition condition; "FW_ID" indicates the firmware ID; "DATA_ID" indicates the setting value ID; "Condition" indicates the prohibition condition; "VALUE" indicates the setting value corresponding to the prohibition condition; and "Warning" indicates the risk if the firmware FW update is permitted while the prohibition condition is met. For example, the prohibition condition ID "RESTRICTION_1" is a prohibition condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_1". In this case, the prohibition condition is "HTTP only" and "same value", so if the current value of setting value ID "DATA_1" is "HTTP only", the firmware FW update is determined to be prohibited. Furthermore, the prohibition condition ID "RESTRICTION_2" is a prohibition condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_2". In this case, the prohibition conditions are "no encryption" and "equivalent value", so if the current value of setting value ID "DATA_2" is "no encryption", the firmware update will be determined to be prohibited.

[0054] Figure 7 shows an example of the update feasibility determination list 15C, warning list 15D, and vulnerability list 15E according to this embodiment. These update feasibility determination list 15C, warning list 15D, and vulnerability list 15E are stored, for example, in the storage unit 15.

[0055] The update feasibility determination list 15C is a list for adding whether or not firmware (FW) updates are possible for each prohibition condition (i.e., each prohibition condition ID). If an update is deemed possible, "OK" is added to the determination result; if an update is deemed impossible, "NG" is added to the determination result.

[0056] Warning List 15D is a list to which the applicable prohibition conditions are added when the update policy 15B determines that the firmware FW can be updated, and is an example of the first list described above. Specifically, if the firmware FW update is prohibited as a result of the determination using the prohibition condition table shown in Figure 6, but the update policy 15B determines that the firmware FW can be updated, the applicable prohibition condition is added to Warning List 15D. For example, if the firmware FW update is prohibited for the combination of firmware ID "2" and setting value ID "DATA_1", but the update policy 15B determines that the firmware FW can be updated, the applicable prohibition condition ID "RESTRICTION_1" is added.

[0057] Vulnerability List 15E is a list to which the relevant prohibited conditions are added when the firmware (FW) is determined to be unupdatable by Update Policy 15B, and is an example of the second list described above. Specifically, if the firmware (FW) update is prohibited as a result of the determination using the prohibited conditions table shown in Figure 6, and the firmware (FW) is also determined to be unupdatable by Update Policy 15B, the relevant prohibited condition is added to Vulnerability List 15E. For example, if the firmware (FW) update is prohibited for the combination of firmware ID "2" and setting value ID "DATA_1", and the firmware (FW) is also determined to be unupdatable by Update Policy 15B, the relevant prohibited condition ID "RESTRICTION_1" is added.

[0058] Here, as described above, the notification unit 11E creates risk information based on at least one of the warning list 15D and the vulnerability list 15E in order to notify the administrator's terminal device 50 of the risk information representing the risks caused by the firmware update. For example, if the prohibition condition ID "RESTRICTION_1" is added to at least one of the warning list 15D and the vulnerability list 15E, a message such as "There is a risk that communication with SW (software) that does not support HTTPS may be hindered" is created.

[0059] In this embodiment, when the update determination server 10 distributes a new version of firmware FW, it permits the firmware update to image processing devices 30 that do not meet the prohibition conditions and notifies the image processing devices 30 of the firmware update. In response to this notification, the image processing devices 30 download the firmware FW from the distribution server 20. Alternatively, when the update determination server 10 receives a request from the image processing devices 30 to distribute a new version of firmware FW, it may permit the firmware update to image processing devices 30 that do not meet the prohibition conditions and notify the image processing devices 30 of the firmware update. In this case as well, the image processing devices 30 download the firmware FW from the distribution server 20 in response to this notification.

[0060] Figure 8 is a schematic diagram showing the processing flow by the information processing system 100 according to this embodiment.

[0061] In Figure 8 (S1), the update determination server 10 acquires, as an example, the device information shown in Figure 4 above from the image processing device 30. Specifically, device information is synchronized between the update determination server 10 and the image processing device 30 during firmware updates or at regular intervals, and the same device information is maintained between the two devices.

[0062] In (S2), the update determination server 10 requests the distribution server 20 to send, as an example, the firmware information shown in Figures 5A and 5B above, and the prohibited conditions table shown in Figure 6.

[0063] In (S3), the distribution server 20 sends firmware information and a prohibited conditions table to the update determination server 10 in response to a transmission request from the update determination server 10.

[0064] In (S4), the update determination server 10 determines whether the combination of the device information obtained in (S1) and the firmware information obtained in (S3) satisfies the prohibition conditions defined in the prohibition conditions table. If the combination of device information and firmware information does not satisfy the prohibition conditions, the firmware update is permitted. If the prohibition conditions are met, the update policy 15B may be used to further determine whether the firmware update is permitted.

[0065] In (S5), the update determination server 10 notifies the distribution server 20 of the determination result in (S4), as well as the image processing device 30 and the administrator's terminal device 50.

[0066] In (S6), if the judgment result notified in (S5) is that the update is permitted, the distribution server 20 distributes the update permission and the permitted firmware FW to the image processing device 30. If the judgment result notified in (S5) is that the update is prohibited, the distribution server 20 does not distribute the firmware FW. However, even if the judgment result notified in (S5) is that the update is prohibited, the distribution server 20 may distribute the firmware FW in advance and have the image processing device 30 wait for the distributed firmware FW to be installed. In this case, for example, if the administrator later grants permission for the update, the image processing device 30 will install the distributed firmware FW.

[0067] In (S7), the image processing device 30 updates the existing firmware FW with the firmware FW distributed from the distribution server 20 in accordance with the update permission sent in (S6). However, if the image processing device 30 does not receive update permission or distribution of the approved firmware FW from the distribution server 20, it will not perform the update of the existing firmware FW.

[0068] In the conventional system, the current settings of the image processing device 30 and the usage status of the API are not taken into consideration, so a firmware update may render linked applications unusable. For example, if a new encryption method is adopted with a firmware update, communication with external applications that cannot keep up with the new encryption method or with older models 70 will become impossible. Also, if a vulnerable API is disabled with a firmware update, all software that uses that vulnerable API will become unusable.

[0069] In contrast, the information processing system 100 according to this embodiment determines whether or not to update the firmware FW by considering the current settings of the image processing device 30 and the usage status of the API, thereby maintaining cooperation with external applications and the old model 70 that have been used in the past.

[0070] Next, the operation of the information processing system 100 according to this embodiment will be described with reference to Figures 9 and 10.

[0071] Figure 9 is a sequence diagram showing an example of the firmware update determination process by the information processing system 100 according to this embodiment.

[0072] In (S11) of Figure 9, the image processing device 30 transmits the latest device information regarding the image processing device 30 to the update determination server 10. Specifically, as described above, device information is synchronized between the update determination server 10 and the image processing device 30 during firmware updates or at regular intervals, and the same device information is maintained between the two devices.

[0073] In (S12), the update determination server 10 updates the old device information regarding the image processing device 30 based on the latest device information regarding the image processing device 30.

[0074] In (S13), the update determination server 10 notifies the image processing device 30 that the device information update is complete.

[0075] In (S14), the image processing device 30 queries the update determination server 10 for available firmware updates (FW).

[0076] In (S15), the update determination server 10 requests the distribution server 20 to list firmware FWs that are newer than the current firmware FW.

[0077] In (S16), the distribution server 20 sends a list of new firmware FW to the update determination server 10 in response to a request from the update determination server 10.

[0078] In (S17), the update determination server 10 determines whether or not to update the firmware based on static information such as the firmware version from the firmware information obtained from the list of new firmware FWs.

[0079] In (S18), the update determination server 10 requests the distribution server 20 to provide, as an example, the prohibition condition table shown in Figure 6 above.

[0080] In (S19), the distribution server 20 sends the prohibition condition table shown in Figure 6 above as an example to the update determination server 10.

[0081] In (S20), the update determination server 10 determines whether the combination of the updated device information and the firmware information obtained from the list of new firmware FWs satisfies the prohibition conditions defined in the prohibition condition table shown in Figure 6 above, as an example. The update determination server 10 also creates risk information associated with the firmware FW update based on the warning list 15D and vulnerability list 15E shown in Figure 7 above, as an example. The process from (S17) to (S20) is looped for the number of new firmware FWs.

[0082] In (S21), the update determination server 10 notifies the administrator's terminal device 50 of the firmware update determination result and risk information.

[0083] In (S22), the update determination server 10 notifies the image processing device 30 of the firmware update determination result and risk information.

[0084] Figure 10 is a flowchart showing an example of the firmware update determination process flow by the information processing program 15A according to this embodiment. When the update determination server 10 is instructed to execute the update determination process by the information processing program 15A, the CPU 11 reads the information processing program 15A stored in the storage unit 15 and executes it.

[0085] In step S101 of Figure 10, the CPU determines, for example, whether or not there is a prohibited condition in the prohibited condition table shown in Figure 6 above. If it determines that there is a prohibited condition (positive determination), it proceeds to step S102; if it determines that there is no prohibited condition (negative determination), it proceeds to step S112.

[0086] In step S102, the CPU 11 determines whether the acquired combination of device information and firmware information satisfies the prohibited conditions defined in the prohibited conditions table shown in Figure 6 above, as an example. If it determines that the prohibited conditions are not met (negative determination), the process proceeds to step S103. If it determines that the prohibited conditions are met (positive determination), the process proceeds to step S104.

[0087] In step S103, the CPU 11 adds the judgment result "OK" to the update feasibility judgment list 15C shown in Figure 7 above, as an example, and proceeds to step S108.

[0088] On the other hand, in step S104, the CPU 11 determines, for example, whether the update policy 15B shown in Figure 3 above prioritizes feature enhancements. If it determines that the update policy 15B prioritizes feature enhancements (positive determination), the process proceeds to step S105. If it determines that the update policy 15B does not prioritize feature enhancements (negative determination), the process proceeds to step S107.

[0089] In step S105, the CPU 11 adds the judgment result "OK" to the update feasibility judgment list 15C shown in Figure 7 above, as an example.

[0090] In step S106, the CPU 11 adds a prohibition condition corresponding to the warning list 15D shown in Figure 7 above, as an example, and then proceeds to step S108.

[0091] On the other hand, in step S107, the CPU 11 adds the judgment result "NG" to the update feasibility judgment list 15C shown in Figure 7 above, as an example, and proceeds to step S108.

[0092] In step S108, the CPU 11 determines whether or not it is the last prohibited condition. If it is determined to be the last prohibited condition (positive determination), the process proceeds to step S109. If it is determined not to be the last prohibited condition (negative determination), the process returns to step S102 and is repeated.

[0093] In step S109, the CPU 11 determines, for example, whether there is an "NG" judgment in the update feasibility determination list 15C shown in Figure 7 above. If it determines that there is an "NG" judgment (positive judgment), it proceeds to step S110; if it determines that there is no "NG" judgment (negative judgment), it proceeds to step S112.

[0094] In step S110, CPU11 disables the firmware update.

[0095] In step S111, the CPU 11 adds a prohibited condition corresponding to the vulnerability list 15E shown in Figure 7 above, as an example, creates risk information based on at least one of the warning list 15D and the vulnerability list 15E, and terminates the series of processes by the information processing program 15A.

[0096] In step S112, the CPU 11 determines, for example, whether the update policy 15B shown in Figure 3 above has priority over coordination. If it determines that the update policy 15B has priority over coordination (positive determination), it proceeds to step S110. If it determines that the update policy 15B does not have priority over coordination (negative determination), it proceeds to step S113. Here, the update policy 15B is set to prioritize coordination, but it may also be set to prioritize administrators. In this case, firmware updates are initially prohibited, but the administrator may later decide to allow updates.

[0097] In step S113, the CPU 11 authorizes the firmware update and terminates the series of processes performed by the information processing program 15A.

[0098] Next, an example of the update determination process according to this embodiment will be described with reference to Figures 11 to 14.

[0099] Figure 11 illustrates an example of executing a firmware update determination process that does not affect the integration process, prioritizing either feature enhancements or integration. In the example in Figure 11, the update policy 15B is set to prioritize feature enhancements or integration.

[0100] In (S31) of Figure 11, the update determination server 10 obtains the device information shown in Figure 4 above from the image processing device 30, as an example. In this example, the current value of "DATA_1" is "HTTPS only" and the current value of "DATA_2" is "RSA_SHA1".

[0101] In (S32), the update determination server 10 requests the distribution server 20 to send, as an example, the firmware information shown in Figures 5A and 5B above, and the prohibited conditions table shown in Figure 6.

[0102] In (S33), the distribution server 20 sends firmware information and a table of prohibited conditions to the update determination server 10 in response to a transmission request from the update determination server 10. In this example, the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_1" is "HTTP only," and the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_2" is "No encryption."

[0103] In (S34), the update determination server 10 determines whether the combination of the device information obtained in (S31) and the firmware information obtained in (S33) satisfies the prohibition conditions defined in the prohibition conditions table. In this example, since neither the combination of device information nor firmware information satisfies the prohibition conditions, the update is permitted.

[0104] In (S35), the update determination server 10 notifies the distribution server 20 of the determination result in (S34) (update permission in this example) and also notifies the image processing device 30.

[0105] In (S36), since the judgment result notified in (S35) is an update permission, the distribution server 20 distributes the update permission and the permitted firmware FW to the image processing device 30.

[0106] In (S37), the image processing device 30 updates the existing firmware FW with the firmware FW distributed from the distribution server 20 in response to the update permission sent in (S36).

[0107] Figure 12 illustrates an example of a case where firmware update determination processing, which does not affect the integration, is executed with administrator priority. In the example in Figure 12, update policy 15B is set to administrator priority.

[0108] In (S41) of Figure 12, the update determination server 10 obtains the device information shown in Figure 4 above from the image processing device 30, as an example. In this example, the current value of "DATA_1" is "HTTPS only" and the current value of "DATA_2" is "RSA_SHA1".

[0109] In (S42), the update determination server 10 requests the distribution server 20 to send, as an example, the firmware information shown in Figures 5A and 5B above, and the prohibited conditions table shown in Figure 6.

[0110] In (S43), the distribution server 20 sends firmware information and a table of prohibited conditions to the update determination server 10 in response to a transmission request from the update determination server 10. In this example, the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_1" is "HTTP only," and the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_2" is "No encryption."

[0111] In (S44), the update determination server 10 determines whether the combination of the device information obtained in (S41) and the firmware information obtained in (S43) satisfies the prohibition conditions defined in the prohibition conditions table. In this example, neither the combination of device information nor firmware information satisfies the prohibition conditions, but the update is prohibited due to administrator priority.

[0112] In (S45), the update determination server 10 notifies the distribution server 20 of the determination result in (S44) (update prohibited in this example), as well as the image processing device 30 and the administrator's terminal device 50. The administrator is also notified of the existence of the firmware FW to be updated and the risks associated with the update, and the final decision on whether to update is left to the administrator.

[0113] In (S46), since the judgment result notified in (S45) is that the update is prohibited, the distribution server 20 distributes the firmware FW to the image processing device 30, indicating that the update is prohibited.

[0114] In (S47), the image processing device 30 suspends the firmware update FW distributed from the distribution server 20 in response to the update prohibition transmitted in (S46).

[0115] In (S48), the administrator's terminal device 50 sends an update permission based on the final administrator's decision to the image processing device 30.

[0116] In (S49), the image processing device 30 updates the existing firmware FW with the pending firmware FW in response to the update permission transmitted in (S48). Alternatively, instead of distributing the firmware FW to be updated in the process of (S46) above, the update determination server 10 may retain the administrator's final decision and perform a re-determination.

[0117] Figure 13 illustrates an example of how firmware update determination processing, which affects collaboration, can be executed with either collaboration priority or administrator priority. In the example in Figure 13, update policy 15B is set to either collaboration priority or administrator priority.

[0118] In (S51) of Figure 13, the update determination server 10 obtains the device information shown in Figure 4 above from the image processing device 30, as an example. In this example, the current value of "DATA_1" is "HTTP only" and the current value of "DATA_2" is "RSA_SHA1".

[0119] In (S52), the update determination server 10 requests the distribution server 20 to send, as an example, the firmware information shown in Figures 5A and 5B above, and the prohibited conditions table shown in Figure 6.

[0120] In (S53), the distribution server 20 sends firmware information and a table of prohibited conditions to the update determination server 10 in response to a transmission request from the update determination server 10. In this example, the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_1" is "HTTP only," and the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_2" is "No encryption."

[0121] In (S54), the update determination server 10 determines whether the combination of the device information obtained in (S51) and the firmware information obtained in (S53) satisfies the prohibition conditions defined in the prohibition conditions table. In this example, one of the combinations of device information and firmware information satisfies the prohibition condition ("HTTP only"), so the update is prohibited.

[0122] In (S55), the update determination server 10 notifies the distribution server 20 of the determination result in (S54) (update prohibited in this example), as well as the image processing device 30 and the administrator's terminal device 50. The administrator is also notified of the existence of the firmware FW to be updated and the risks associated with the update, and the final decision on whether to update is left to the administrator.

[0123] In (S56), since the judgment result notified in (S55) is that the update is prohibited, the distribution server 20 distributes the firmware FW to the image processing device 30, indicating that the update is prohibited.

[0124] In (S57), the image processing device 30 suspends the firmware update FW distributed from the distribution server 20 in response to the update prohibition transmitted in (S56).

[0125] In (S58), the administrator's terminal device 50 sends an update permission based on the final administrator's decision to the image processing device 30.

[0126] In (S59), the image processing device 30 updates the existing firmware FW with the pending firmware FW in response to the update permission transmitted in (S58). Alternatively, instead of distributing the firmware FW to be updated in the process of (S56) above, the update determination server 10 may retain the administrator's final decision and perform a re-determination.

[0127] Figure 14 illustrates an example of a case where the firmware update determination process affecting the integration is executed with priority given to feature enhancements. In the example in Figure 14, update policy 15B is set to prioritize feature enhancements.

[0128] In (S61) of Figure 14, the update determination server 10 obtains the device information shown in Figure 4 above from the image processing device 30, as an example. In this example, the current value of "DATA_1" is "HTTP only" and the current value of "DATA_2" is "RSA_SHA1".

[0129] In (S62), the update determination server 10 requests the distribution server 20 to send, as an example, the firmware information shown in Figures 5A and 5B above, and the prohibited conditions table shown in Figure 6.

[0130] In (S63), the distribution server 20 sends firmware information and a table of prohibited conditions to the update determination server 10 in response to a transmission request from the update determination server 10. In this example, the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_1" is "HTTP only," and the prohibited condition corresponding to the combination of firmware ID "2" and setting value ID "DATA_2" is "No encryption."

[0131] In (S64), the update determination server 10 determines whether the combination of the device information obtained in (S61) and the firmware information obtained in (S63) satisfies the prohibition conditions defined in the prohibition conditions table. In this example, one of the combinations of device information and firmware information satisfies the prohibition condition ("HTTP only"), but the update is permitted due to the priority given to the functional enhancement.

[0132] In (S65), the update determination server 10 notifies the distribution server 20 of the determination result in (S64) (update permission in this example), as well as the image processing device 30 and the administrator's terminal device 50. The administrator is notified that the firmware update is permitted and that there is risk information associated with the update, but the final decision on whether to update is not left to the administrator.

[0133] In (S66), since the judgment result notified in (S65) is an update permission, the distribution server 20 distributes the update permission and the permitted firmware FW to the image processing device 30.

[0134] In (S67), the image processing device 30 updates the existing firmware FW with the firmware FW distributed from the distribution server 20 in response to the update permission transmitted in (S66).

[0135] Thus, according to this embodiment, the decision on whether or not to update the firmware is made by considering the current settings of the image processing device and the usage status of the API, thus maintaining cooperation with external applications and older models that have been used in the past. Compared to cases where only fixed information, including the firmware version, is used when deciding whether or not to update the firmware of the image processing device, the occurrence of malfunctions due to firmware updates is suppressed.

[0136] In this embodiment, each process is executed on any computer. Furthermore, any computer may execute these processes using a processor as hardware, a program as software, or a combination thereof. In that case, the processor is configured to work in cooperation with the program to execute the various processes in this embodiment, and can function as a unit or means in this embodiment. Also, the execution order of the processes by the processor is not limited to the order described and may be changed as appropriate. Any computer may be a general-purpose computer, a computer designed for a specific purpose, a workstation, or any other system capable of executing each process.

[0137] A processor may consist of one or more hardware components, and the type of hardware is not limited. For example, a processor may consist of a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a programmable logic device such as an FPGA (Field Programmable Gate Array), a dedicated circuit for executing a specific process such as an ASIC (Application Specific Integrated Circuit), a GPU (Graphic Processing Unit), or an NPU (Neural Processing Unit). Furthermore, the type of hardware may be a combination of different types of hardware. When multiple hardware components are configured to execute one or more processes of a given processor, these components may reside in physically separate devices or in the same device. Also, in any embodiment, the order of each process performed by the processor is not limited to the order described above and may be changed as appropriate. Hardware is composed of electrical circuits (circuitry) that combine circuit elements such as semiconductor elements.

[0138] Furthermore, the program may be firmware or software such as microcode. Alternatively, the program may be, for example, a group of program modules, each function of which may be implemented by a processor configured to perform its respective function. The program may be program code or multiple code segments stored on one or more non-temporary computer-readable media (e.g., storage media or other storage). The program may be divided and stored on multiple non-temporary computer-readable media located in physically separate devices. The program code or code segments may represent any combination of procedures, functions, subprograms, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. The program code or code segments may be connected to other code segments or hardware circuits by sending and receiving information, data, arguments, parameters, or memory contents. Furthermore, the program according to the embodiment may be provided as a program product.

[0139] The following additional information is disclosed regarding the embodiments described above.

[0140] (Note) (((1))) Equipped with a processor, The aforementioned processor, When updating the firmware of the information processing device, or at regular intervals, device information including at least one of the setting values ​​set in the information processing device and information regarding applications that are linked with the information processing device is acquired. Obtain firmware information including the firmware version, If the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions, the firmware update is permitted. Information processing system. (((2))) The processor prohibits the firmware update if the combination satisfies the prohibition conditions. The information processing system described in (((1))). (((3))) The aforementioned combinations are numerous, The processor acquires the prohibition conditions associated with each of the plurality of combinations, If each of the aforementioned combinations does not satisfy the prohibition conditions, the firmware update is permitted. The information processing system described in (((1))) or (((2))). (((4))) The processor prohibits the firmware update if at least one of the plurality of combinations satisfies the prohibition condition. The information processing system described in (((3))). (((5))) In the case of a combination that satisfies the aforementioned prohibition conditions, the update policy used for determining whether to update the firmware is available, The processor determines that it is possible to update the firmware if the update policy indicates a state that enables the firmware update. An information processing system described in any one of (((1))) to (((4))). (((6))) The update policy includes a function enhancement priority that prioritizes the functional enhancement of the information processing device, a collaboration priority that prioritizes collaboration with the application, and an administrator priority that prioritizes the judgment of the administrator managing the information processing device. The update policy, which represents the state that enables the firmware update, is the priority of feature enhancements and the priority of administrators. The information processing system described in (((5))). (((7))) If the processor determines that the firmware update is possible according to the update policy, it adds the applicable prohibition condition to the first list; if the processor determines that the firmware update is not possible according to the update policy, it adds the applicable prohibition condition to a second list different from the first list. The information processing system described in (((5))) or (((6))). (((8))) The processor creates risk information representing the risks associated with the firmware update based on at least one of the first list and the second list, and notifies the administrator of the created risk information and the result of the firmware update determination. The information processing system described in (((7))). (((9))) The application includes at least one of an application incorporated into the information processing device and an application outside the information processing device. An information processing system described in any one of (((1))) to (((8))). (((10))) The device information includes option information relating to options connected to the information processing device. An information processing system described in any one of (((1))) to (((9))). (((11))) When updating the firmware of the information processing device, or at regular intervals, device information including at least one of the setting values ​​set in the information processing device and information regarding applications that are linked with the information processing device is acquired. Obtain firmware information including the firmware version, If the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions, the process of permitting the firmware update is performed. An information processing program designed to be executed by a computer.

[0141] According to (((1))) and (((11))), compared to using only fixed information including the firmware version when deciding whether or not to update the firmware of an information processing device, this method has the effect of suppressing the occurrence of malfunctions caused by firmware updates. According to (((2))), this has the effect of being able to appropriately prohibit firmware updates compared to when the update decision is made without considering the prohibition conditions. According to (((3))), this has the effect of allowing firmware updates to be appropriately permitted compared to the case where an update decision is made for each of the multiple combinations without considering the prohibition conditions. According to (((4))), this has the effect of being able to appropriately prohibit firmware updates compared to making an update decision for each of the multiple combinations without considering the prohibition conditions. According to (((5))), this has the effect of being able to appropriately determine whether or not to update the firmware, compared to when the update decision is made without considering the update policy. According to (((6))), compared to the case where the update decision is made without considering the priority of feature enhancements, integration, and administrator priority as update policies, it has the effect of being able to appropriately determine whether or not to update the firmware. According to (((7))), even if it is determined that a firmware update is possible, the relevant prohibition conditions can be added. According to (((8))), this has the effect of notifying administrators of risk information associated with firmware updates. According to (((9))), this has the effect of maintaining cooperation not only with embedded applications but also with external applications. According to (((10))), this has the effect of maintaining cooperation with options connected to the information processing device. [Explanation of Symbols]

[0142] 10 Update Judgment Server 11 CPU 12 ROM 13 RAM 14 I / O 15 Storage section 15A Information Processing Program 15B Renewal Policy 15C Renewal Feasibility Determination List 15D Warning List 15E Vulnerability List 16 Display section 17 Control section 18 Communications Department 20 distribution servers 30 Image Processing Device 50 Terminal devices 60 Application Delivery Servers 70 Image Processing Unit (Older Model) 100 Information Processing Systems

Claims

1. Equipped with a processor, The aforementioned processor, When updating the firmware of the information processing device, or at regular intervals, device information including at least one of the setting values ​​set in the information processing device and information regarding applications that are linked with the information processing device is acquired. Obtain firmware information including the firmware version, If the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions, the firmware update is permitted. Information processing system.

2. The processor prohibits the firmware update if the combination satisfies the prohibition conditions. The information processing system according to claim 1.

3. The aforementioned combinations are numerous, The processor acquires the prohibition conditions associated with each of the plurality of combinations, If each of the aforementioned combinations does not satisfy the prohibition conditions, the firmware update is permitted. The information processing system according to claim 1.

4. The processor prohibits the firmware update if at least one of the plurality of combinations satisfies the prohibition condition. The information processing system according to claim 3.

5. In the case of a combination that satisfies the aforementioned prohibition conditions, the update policy used for determining whether to update the firmware is available, The processor determines that it is possible to update the firmware if the update policy indicates a state that enables the firmware update. The information processing system according to claim 1.

6. The update policy includes a function enhancement priority that prioritizes the functional enhancement of the information processing device, a collaboration priority that prioritizes collaboration with the application, and an administrator priority that prioritizes the judgment of the administrator managing the information processing device. The update policy, which represents the state that enables the firmware update, is the priority of feature enhancements and the priority of administrators. The information processing system according to claim 5.

7. If the processor determines that the firmware update is possible according to the update policy, it adds the applicable prohibition condition to the first list; if the processor determines that the firmware update is not possible according to the update policy, it adds the applicable prohibition condition to a second list different from the first list. The information processing system according to claim 5.

8. The processor creates risk information representing the risks associated with the firmware update based on at least one of the first list and the second list, and notifies the administrator of the created risk information and the result of the firmware update determination. The information processing system according to claim 7.

9. The application includes at least one of an application incorporated into the information processing device and an application outside the information processing device. The information processing system according to claim 1.

10. The device information includes option information relating to options connected to the information processing device. The information processing system according to claim 1.

11. When updating the firmware of the information processing device, or at regular intervals, device information including at least one of the setting values ​​set in the information processing device and information regarding applications that are linked with the information processing device is acquired. Obtain firmware information including the firmware version, If the combination of the device information and the firmware information does not satisfy predetermined prohibition conditions, the process of permitting the firmware update is performed. An information processing program designed to be executed by a computer.