Information processing systems and programs

The information processing system addresses the challenge of setting security configurations by automating the acquisition and verification of location information, ensuring compliance with local regulations and environmental settings.

JP2026136821APending Publication Date: 2026-08-26FUJIFILM BUSINESS INNOVATION CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025022583
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-26

AI Technical Summary

Technical Problem

Users and administrators of information devices face challenges in setting security-related configurations that comply with local regulations, and these settings often need to be updated when regulations change or when the device is moved to a different country or region, without automated assistance to ensure compliance.

Method used

An information processing system that includes a storage device and a processor to associate place of use information with candidate security settings, automatically acquiring location information and providing compliant settings to the user, with mechanisms to verify and update settings as needed to align with local laws and regulations.

Benefits of technology

Facilitates security settings that comply with local regulations, automates the acquisition of location information, verifies manual inputs, and supports updates to ensure ongoing compliance with changing regulations and environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026136821000001_ABST
    Figure 2026136821000001_ABST
Patent Text Reader

Abstract

Unlike situations where there is no mechanism to assist users with security settings, this system makes it easier to configure settings to comply with local security regulations. [Solution] The information processing system includes a storage device that stores usage location information, including a country or region, and candidate security settings that satisfy the laws and regulations corresponding to the usage location information, and a processor. The processor acquires first usage location information indicating the usage location where the target equipment is used, provides the acquired first usage location information to the storage device to acquire candidate settings corresponding to the first usage location information, and presents the acquired candidate settings to the operator of the target equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system and a program.

Background Art

[0002] Today, various laws and regulations (hereinafter referred to as "regulations") for the purpose of data protection are in force. For example, in the UK, there is the PSTI Act (= Product Security and Telecommunication Infrastructure Act) for information devices that can be connected to the Internet. In addition, in the EU (= European Union), there is the GDPR (= General Data Protection Regulation) regarding the protection of personal data.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Users and administrators of information devices (hereinafter referred to as "users") are required to set security-related settings according to the regulations of the place of use. However, if there is no mechanism to check the set content, the user cannot notice an error in the setting due to misunderstanding or incorrect input. In addition, when new regulations are implemented, when existing regulations are revised, or when an information device moves to another country or region, it is necessary to review the security-related settings. However, in these cases, the user has to individually judge the items that need to be changed and the new settings that meet the regulations.

[0005] This invention aims to facilitate the setting of security settings that comply with local security regulations, unlike cases where there is no mechanism to assist users in configuring security settings. [Means for solving the problem]

[0006] The invention described in claim 1 is an information processing system comprising: a storage device that stores in association place of use information including a country or region and candidate security settings that satisfy the laws and regulations corresponding to the place of use information; and a processor, wherein the processor acquires first place of use information indicating the place of use where the target device is used, provides the acquired first place of use information to the storage device to acquire candidate settings corresponding to the first place of use information, and presents the acquired candidate settings to the user of the target device. The invention described in claim 2 is an information processing system according to claim 1, wherein the processor acquires the first location information using the IP (=Internet Protocol) address of the target device. The invention described in claim 3 is an information processing system according to claim 2, wherein the processor requests the user to confirm the input second location information if the second location information input by the user is different from the first location information obtained from the IP address. The invention described in claim 4 is an information processing system according to claim 2, wherein the processor reacquires the IP address if predetermined conditions are met, and if the third location information corresponding to the reacquired IP address differs from the current location information in the settings, it requests the user to confirm the current location information. The invention described in claim 5 is an information processing system according to claim 1, wherein the processor requests the user to change the settings if the current settings do not satisfy the regulations corresponding to the first place of use information. The invention described in claim 6 is an information processing system according to claim 5, wherein the processor deems that the current setting does not satisfy the laws and regulations relating to the first place of use information if there is a history of changes to the laws and regulations relating to the first place of use information that have been enacted since the commencement of use of the current setting. The invention described in claim 7 is an information processing system according to claim 5, wherein the processor considers that the current setting does not satisfy the regulations of the first place of use information if the current setting does not match a candidate setting corresponding to the first place of use information. The invention described in claim 8 is an information processing system according to claim 1, wherein the storage device stores a combination of the location information and the environment information in association with the candidate settings relating to security, and the processor acquires the first environment information of the target device, provides the acquired first environment information and the first location information to the storage device, and acquires the candidate settings corresponding to the combination of the first environment information and the first location information. The invention described in claim 9 is the information processing system described in claim 8, wherein the first usage environment information is classified according to the scale of users who use the target equipment. The invention described in claim 10 is an information processing system according to claim 8, wherein the first usage environment information is provided in accordance with the security policy used by the user on whom the target device is used. The invention described in claim 11 is the information processing system according to claim 1, wherein the processor does not accept changes to a setting that weakens the security strength compared to the candidate setting. The invention described in claim 12 is the information processing system described in claim 1, wherein the target device is an apparatus for forming an image on paper. The invention described in claim 13 is a program for a computer that enables the following functions: acquiring first location information including the country or region in which the target device is used; providing the first location information to a storage device that stores the location information including the country or region in association with candidate security settings that satisfy the laws and regulations corresponding to the location information, thereby acquiring candidate settings corresponding to the first location information; and presenting the acquired candidate settings to the user of the target device. [Effects of the Invention]

[0007] According to the invention described in claim 1, unlike cases where there is no mechanism to assist the user in configuring security settings, it is possible to facilitate settings that comply with the laws and regulations of the place of use regarding security. According to the invention described in claim 2, the acquisition of the location where the target equipment is used can be automated. According to the invention described in claim 3, it is possible to verify the incorrect setting of the usage location due to manual input. According to the invention described in claim 4, even if the place of use changes, it is possible to support setting up the system to comply with the laws and regulations of the changed place of use. According to the invention described in claim 5, it is possible to assist in reviewing security settings to comply with the laws and regulations of the place of use. According to the invention described in claim 6, even if the regulations change after the current settings are put into use, the security settings can be helped to comply with the regulations of the place of use. According to the invention described in claim 7, it is possible to assist in reviewing security settings to comply with the laws and regulations of the place of use. According to the invention described in claim 8, it is possible to facilitate the setting of security according to the usage environment, in addition to the laws and regulations of the place of use. According to the invention described in claim 9, it is possible to support security settings that are appropriate to the scale of users using the target equipment, in addition to the laws and regulations of the place of use. According to the invention described in claim 10, it is possible to support settings that satisfy not only the laws and regulations of the place of use, but also the security guidelines of the user using the target device. According to the invention described in claim 11, it is possible to disable security settings that do not comply with the regulations of the place of use. According to the invention described in claim 12, the security of the apparatus that forms an image can be set to comply with the regulations of the place of use. According to the invention described in claim 13, unlike the case where there is no mechanism to support the user settings regarding security, it is possible to facilitate the settings that comply with the regulations of the place of use regarding security.

Brief Description of the Drawings

[0008] [Figure 1] It is a diagram for explaining an example of a security management system. [Figure 2] It is a diagram for explaining an example of the hardware configuration of a security setting support server. [Figure 3] It is a diagram for explaining a data example of recommended setting information. [Figure 4] It is a diagram for explaining an example of parameters regarding security. [Figure 5] It is a diagram for explaining an example of the hardware configuration of an image forming apparatus. [Figure 6] It is a diagram for explaining an example of a processing sequence regarding the security setting of an image forming apparatus. [Figure 7] It is a diagram for explaining an example of an operation screen used for setting the place of use and the installation environment. [Figure 8] It is a diagram for explaining an example of a display screen of recommended security. [Figure 9] It is a flowchart for explaining an example of a processing operation executed in relation to the setting of the place of use. [Figure 10] It is a diagram for explaining the change of the place of use due to a move. [Figure 11] It is a flowchart for explaining an example of an operation for confirming the place of use. [Figure 12] It is a flowchart for explaining another example of an operation for confirming the place of use. [Figure 13]It is a flowchart for explaining an example of a processing operation that assumes a review of security according to changes in the user's business environment after setting. [Figure 14] It is a diagram for explaining an example of a security management system. [Figure 15] It is a diagram for explaining an example of the hardware configuration of a security setting support server. [Figure 16] It is a diagram for explaining an example of data of recommended setting information. [Figure 17] It is a diagram for explaining an example of the hardware configuration of a security policy server. [Figure 18] It is a diagram for explaining an example of data of security information by policy. [Figure 19] It is a diagram for explaining an example of a processing sequence related to the security setting of an image forming apparatus. [Figure 20] It is a diagram for explaining an example of a processing sequence related to the security setting of an image forming apparatus. [Figure 21] It is a diagram for explaining an example of a processing sequence related to the security setting of an image forming apparatus.

Embodiments for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0010] <Terms>[ The place of use includes a country or region. The place of use includes, for example, Japan, the United States of America, and the EP (= European Union). Laws and regulations refer to laws, rules, and standards applicable to the place of use. Examples of laws and regulations include the EU General Data Protection Regulation, the Radio Equipment Directive, PSTI (= Product Security and Telecommunications Infrastructure), and CC (= Common Criteria) certification.

[0011] Users include businesses (including individuals; hereinafter the same) that own network equipment, businesses that use network equipment under lease or rental agreements, employees of businesses (including managers and workers responsible for maintenance), and businesses that undertake the maintenance of network equipment.

[0012] The usage environment refers to the environment in which network equipment is used. This usage includes not only the use of network equipment installed in a specific location, but also usage where the location changes over time. In other words, the usage environment includes information about the place of use.

[0013] Furthermore, the usage environment also includes information about the users who configure the network equipment and the scale of their setup. Scale classifications include, for example, large corporations, small and medium-sized enterprises, and SOHO (Small Office Home Office). The usage environment is just one example of installation environment information.

[0014] Network devices refer to electronic devices connected to a LAN (Local Area Network) or the Internet. Examples of network devices include image forming machines, computers, automobiles, trains, aircraft, ships, drones, electronic toys, home appliances, and medical equipment. Computers include smartphones, laptops, tablet computers, and desktop computers. Network devices are also called IoT (Internet of Things) devices. Network devices are just one example of the types of devices covered.

[0015] <Embodiment 1> <System Configuration> Figure 1 is a diagram illustrating an example of a security management system 1. The security management system 1 includes a security setting support server 10 connected to a network N and multiple image forming machines 20. The security management system 1 described here is an example of an information processing system. However, the security setting support server 10 and the image forming apparatus 20 may also be considered as separate information processing systems.

[0016] Network N could be, for example, a LAN or the Internet. The security setting support server 10 is a server that assists with security settings for the image forming apparatus 20. In Figure 1, one security setting support server 10 is provided. However, the security setting support server 10 may consist of multiple servers that cooperate with each other.

[0017] The image forming apparatus 20 is a device equipped with the function of forming an image on paper or the like (hereinafter referred to as "printing function"). In this embodiment, the image forming apparatus 20 receives support from the security setting support server 10 for its security settings. In this sense, the image forming apparatus 20 is an example of a target device. The image forming apparatus 20 assumed in this embodiment also has functions other than printing. For example, the image forming apparatus 20 also has a scanner function, a copy function, and a facsimile function.

[0018] The scanner function refers to the function of optically reading a document. The copy function refers to the function of creating a copy of a document. The facsimile function refers to the function of sending and receiving still images using a public telephone network, etc. An image forming apparatus 20 that has functions other than printing is also called a multifunction device. However, the image forming apparatus 20 may also be a device that specializes in printing (a so-called printing device).

[0019] In Figure 1, the image forming apparatus 20 includes an image forming apparatus 20 used at site A and an image forming apparatus 20 used at site B. As mentioned above, the site of use includes countries and regions. In Figure 1, for explanatory purposes, only sites A and B are depicted. However, the number of sites of use is not limited to two.

[0020] The user of the image forming apparatus 20 may be an individual or a corporation. For example, the user may be the person who actually uses the image forming apparatus 20, or an individual or corporation that leases the image forming apparatus 20 as part of a lease or rental agreement. For example, the user may be an individual or corporation that undertakes the maintenance and management of the image forming apparatus 20.

[0021] Incidentally, one user may use multiple image forming apparatuses 20. In this case, it is not necessary for all of the multiple image forming apparatuses 20 used by one user to be used at the same location. That is, multiple image forming apparatuses 20 may be used at multiple locations. For example, one user may use two image forming apparatuses 20 at location A and three image forming apparatuses 20 at location B.

[0022] <Device Configuration> <Hardware configuration of security configuration support server 10> Figure 2 illustrates an example of the hardware configuration of the security configuration support server 10. The security configuration support server 10 includes a processor 11, semiconductor memory 12, auxiliary storage device 13, communication interface 14, and signal lines 15.

[0023] The processor 11 is a semiconductor integrated circuit that implements various functions through the execution of programs. These programs include the OS (Operating System), UEFI (Unified Extensible Firmware Interface), and application programs. The operating system (OS) is a program that controls the overall operation of a server.

[0024] UEFI is a program that controls the server startup process. The application program in this embodiment includes a program that assists in configuring the security settings of the image forming apparatus 20 according to information about the location of use and installation environment.

[0025] The semiconductor memory 12 includes, for example, ROM (=Read Only Memory) and RAM (=Random Access Memory) used as a work area for the processor 11. The auxiliary storage device 13 is composed of, for example, a hard disk drive or semiconductor storage. The auxiliary storage device 13 is an example of a storage device.

[0026] The auxiliary storage device 13 stores not only the program but also recommended configuration information 13A. The recommended configuration information 13A stores recommended security values ​​(hereinafter also referred to as "recommended security") according to the combination of location of use and configuration environment.

[0027] Figure 3 illustrates an example of the recommended configuration information 13A data. The recommended configuration information 13A includes the location of use 13A1, the installation environment 13A2, and the recommended security 13A3. The usage location 13A1 corresponds to the country or region in which the image forming apparatus 20 is used. In Figure 3, usage location 13A1 is exemplified by the United Kingdom, Italy, and Japan. Incidentally, Italy is registered as one of the constituent countries of the EU.

[0028] Installation environment 13A2 represents the classification of the environment in which the image forming apparatus 20 is installed. In the case of Figure 3, installation environment 13A2 is given as three types: large enterprise, small and medium-sized enterprise, and SOHO. However, the classification shown in Figure 3 is just one example, and classifications based on the number of users or registered users of the image forming apparatus 20, or the number of image forming apparatuses 20 managed by users, are also possible.

[0029] Recommended security 13A3 corresponds to the recommended security value (so-called default value) for the combination of usage location 13A1 and installation environment 13A2. Even if the usage location 13A1 is the same, the recommended security value will differ if the installation environment 13A2 is different. Recommended security 13A3 stores candidate security settings that meet the regulations of the usage location 13A1. However, in this embodiment, candidate settings that take into account not only the usage location 13A1 but also the installation environment 13A2 are stored.

[0030] For example, if the usage location 13A1 is "United Kingdom" and the installation environment 13A2 is "Large Enterprise," a combination of PSTI compliance, user authentication, and other parameters is recommended. These other parameters may be one or more. In Figure 3, these other parameters are represented by "α".

[0031] For example, if the usage location 13A1 is "United Kingdom" and the installation environment 13A2 is "Small and Medium-sized Enterprises," a combination of PSTI compliance and user authentication is recommended. For example, if the usage location 13A1 is "United Kingdom" and the installation environment 13A2 is "SOHO", then compliance with the PSTI Act and the use of a panel lock are recommended.

[0032] If the usage location 13A1 is "Italy" and the installation environment 13A2 is "large enterprise," then compliance with GDPR, user authentication, and a combination of other parameters are recommended. For example, if the usage location 13A1 is "Italy" and the installation environment 13A2 is "Small and Medium-sized Enterprises," a combination of GDPR compliance and user authentication is recommended. For example, if the usage location 13A1 is "Italy" and the installation environment 13A2 is "SOHO", then compliance with GDPR and the use of panel locks are recommended.

[0033] If the usage location 13A1 is "Japan" and the installation environment 13A2 is "large enterprise," a combination of user authentication and other parameters is recommended. For example, if the usage location 13A1 is "Japan" and the installation environment 13A2 is "small and medium-sized enterprises," user authentication is recommended. For example, if the usage location 13A1 is "Japan" and the installation environment 13A2 is "SOHO", a panel lock is recommended. Generally, the larger the business entity, the higher the security settings recommended.

[0034] Figure 4 illustrates an example of security-related parameters. One of the parameters is a setting that determines whether to require a PIN (Personal Identification Number) code or a password to verify permission to access the device. In Figure 4, the PIN code is, for example, a 4-digit number, and the password is, for example, a 128-character string. Generally, passwords offer stronger security than PIN codes.

[0035] Another parameter is specifying the minimum number of characters required for the password. The minimum number of characters refers to the minimum number of characters a password must have. A larger number of characters results in stronger security. Another parameter is a setting regarding whether to use panel locking or device authentication (so-called user authentication). If panel locking is used, administrator operation is required to unlock it. On the other hand, if device authentication is used, operation of the image forming apparatus 20 becomes possible once the authentication operation on the image forming apparatus 20 is successful.

[0036] Another parameter is the type of encryption method used for communication. The encryption method determines the key length, or number of bits. Incidentally, there is a minimum bit limit set by law. Another parameter is the setting to turn audit logging information "on" or "off". When audit logging information is "on", the history of operations is recorded; in other words, an operation log is recorded.

[0037] Let's return to the explanation of Figure 2. The communication interface 14 is a module that enables communication with external terminals. The communication interface 14 includes a module used for connecting to a LAN, for example, via a wired or wireless connection. The communication interface 14 also includes a USB (Universal Serial Bus) module, for example. The communication interface 14 is also used for communication with the image forming apparatus 20 (see Figure 1). Each device is connected via a bus or other signal line 15.

[0038] <Hardware configuration of the image forming apparatus 20> Figure 5 is a diagram illustrating an example of the hardware configuration of the image forming apparatus 20. The image forming apparatus 20 includes a processor 21, a semiconductor memory 22, an auxiliary storage device 23, a control panel 24, a printing engine 25, a scanner 26, a communication interface 27, and a signal line 28.

[0039] The processor 21 is a semiconductor integrated circuit that implements various functions through the execution of programs. These programs include firmware, UEFI, and application programs. Firmware is a program that controls the overall operation of a device. UEFI is a program that controls the device's boot process.

[0040] The semiconductor memory 22 includes, for example, ROM and RAM used as a work area for the processor 21. The auxiliary storage device 23 is composed of, for example, a hard disk drive or semiconductor storage. In addition to the program, the auxiliary storage device 23 stores location information 23A, installation environment information 23B, and security information 23C.

[0041] Location information 23A indicates the location where the device (i.e., the image forming apparatus 20) is used. Location information 23A may be set manually or automatically based on the IP address. The installation environment information 23B is information indicating the installation environment of the device (i.e., the image forming apparatus 20). In this embodiment, the installation environment information 23B is manually set by the user of the image forming apparatus 20. However, it is also possible for the security setting support server 10 (see Figure 1) to automatically set the installation environment information 23B. Security information 23C is a set of security settings adopted by the device itself (i.e., the image forming apparatus 20).

[0042] The control panel 24 is a device that accepts user input. The control panel 24 may include, for example, a touch panel, buttons, and switches. The touch panel is a device having a structure in which a capacitive, translucent thin-film sensor is laminated on the surface of a display. The touch panel is an example of a device that combines both input and output functions. Buttons and switches are examples of mechanical controls. Hereinafter, the various screens displayed on the touch panel will also be referred to as operation screens.

[0043] The print engine 25 is a device that prints information onto paper or other media. In this embodiment, the print engine 25 also performs various processes related to printing information. For example, the print engine 25 also performs functions related to rasterization, density correction, sharpness correction, contrast correction, and background color removal. The mechanism of the print engine 25 differs depending on the printing method. For example, the mechanism of the print engine 25 differs between the photographic printing method and the inkjet printing method.

[0044] The scanner 26 is a device that optically reads information from a document. The scanner 26 supports at least one of two methods: one in which the reading unit is moved relative to a stationary document, and another in which the document is moved relative to a stationary reading unit. The communication interface 27 is a module that enables communication with external terminals. The communication interface 27 includes, for example, a module used for connecting to a LAN that is connected by wire or wirelessly.

[0045] The communication interface 27 includes, for example, a USB module or an NFC (Near Field Communication) module. The communication interface 27 is used for communication with terminals connected to the network N (e.g., smartphones). In this embodiment, the communication interface 27 is used for communication with the security setting support server 10 (see Figure 1). Each device is connected via a bus or other signal line 28.

[0046] <Processing Sequence> Figure 6 illustrates an example of a processing sequence related to the security settings of the image forming apparatus 20. In Figure 6, the symbol S represents a step. The processing operations of the security setting support server 10 proceed through the execution of a program by the processor 11 (see Figure 2). The processing operations of the image forming apparatus 20 proceed through the execution of a program by the processor 21 (see Figure 5).

[0047] In the case of Figure 6, the image forming apparatus 20 acquires an IP address at a predetermined timing (step 101). The predetermined timing includes, for example, the startup timing of the image forming apparatus 20, the timing when the elapsed time since startup exceeds a threshold (first threshold), and the timing when the elapsed time since the main power was turned off exceeds a threshold (second threshold).

[0048] Next, the image forming apparatus 20 sets the location of use (step 102). If the IP address is successfully obtained, the image forming apparatus 20 sets the location of use based on the IP address. On the other hand, if the IP address is not obtained, the image forming apparatus 20 accepts location input from the user. The location information set using the IP address is an example of first location information. On the other hand, the location information entered by the user is an example of second location information.

[0049] Next, the image forming apparatus 20 sets the installation environment (step 103). In this embodiment, the image forming apparatus 20 accepts input of the installation environment from the user. Figure 7 illustrates an example of an operation screen 300 used for setting the usage location and installation environment. The operation screen 300 includes a field for setting the usage location 301, a field for setting the installation environment 302, and an OK button 303.

[0050] In Figure 7, the location setting field 301 accepts location settings in a pull-down menu format. If the location is set by IP address, the already set location will be displayed by default. However, the user can change the location displayed by default.

[0051] In Figure 7, the installation environment settings section 302 accepts installation environment settings in the form of radio buttons. In Figure 7, the radio button corresponding to large corporations is selected. Since it is a radio button, only one button can be selected at a time. When the OK button 303 is pressed, the settings for the location of use and the installation environment are finalized. Returning to the explanation of Figure 6.

[0052] Once the settings for the usage location and installation environment are complete, the image forming apparatus 20 accesses the security setting support server 10 and requests recommended security measures corresponding to the combination of usage location and installation environment (step 104). Meanwhile, the security setting support server 10 refers to, for example, recommended setting information 13A (see Figure 2) and notifies the user of recommended security measures corresponding to the combination of location and installation environment (step 105).

[0053] The image forming apparatus 20 displays the acquired recommended security (step 106). The recommended security is a set of recommended parameters determined according to the regulations and installation environment of the place of use. Therefore, the user is freed from the task of individually setting each and every configurable parameter. In addition, since the recommended security satisfies the regulations of the place of use, the user does not have to individually set parameters to comply with the regulations of the place of use.

[0054] Figure 8 illustrates an example of the recommended security display screen 400. The display screen 400 includes recommended parameters 401, a description 402, an edit button 403, and a settings button 404. In Figure 8, the recommended parameter 401 is set to a minimum password length of 10 characters, device authentication enabled, audit logging enabled, and the encryption method set to "AES-CBC256".

[0055] Furthermore, the device authentication process also indicates that the guest user does not have authentication privileges. Recommended parameter 401 not only complies with local regulations but also meets the security requirements appropriate for the installation environment. The explanatory text 402 may include, for example, a description of the decision required of the user. In the case of Figure 8, it says, "Is this setting OK?". The explanatory text 402 may also include a description of the actions required of the user. For example, it may include a description such as, "If this setting is OK, please operate the settings button. If changes are needed, please operate the edit button."

[0056] When the edit button 403 is pressed, for example, the recommended security settings can be edited. However, editing settings that do not comply with regulations is not permitted. To edit the recommended security settings, the display screen 400 may be used as is, or a dedicated editing screen may be used. If a dedicated editing screen is used, it may be possible to edit parameters other than the recommended parameter 401. When the setting button 404 is pressed, the settings are confirmed with the contents of the recommended parameter 401. Specifically, the contents of the recommended parameter 401 are registered in security information 23C (see Figure 5).

[0057] Returning to the explanation of Figure 6. When the display screen 400 is shown, the image forming apparatus 20 determines whether or not to use the recommended security (step 107). If the recommended security is not used (for example, if the edit button 403 (see Figure 8) is operated), a negative result is obtained in step 107. Not using the recommended security may include changes that increase security above the recommended parameters, or conversely, changes that decrease security below the recommended parameters.

[0058] If a negative result is obtained in step 107, the image forming apparatus 20 accepts the change to the security settings and then determines whether the changed content complies with the law (step 108). If the revised content does not comply with the law, a negative result will be obtained in step 108.

[0059] In this case, the image forming apparatus 20 displays that the modified content does not comply with the regulations (step 109). After that, the image forming apparatus 20 returns to step 107. In the case of Figure 6, the modified content is judged only from the perspective of regulations. Therefore, in the case of Figure 6, the modified content is not judged from the perspective of the installation environment. However, the modified content may be judged not only from the perspective of regulations but also from the perspective of the installation environment. If the revised content complies with the law, a positive result will be obtained in step 108.

[0060] Incidentally, if the setting button 404 (see Figure 8) is operated on the recommended security display screen 400 (see Figure 8), a positive result is obtained in step 107. In this case, or if a positive result is obtained in step 108, the image forming apparatus 20 confirms the security setting (step 110).

[0061] <Summary> The adoption of the security management system 1 (see Figure 1) makes it easier to configure security settings that meet the regulations and installation environment of the location where the image forming apparatus 20 is used. For example, if the location can be set from the IP address, the user can receive recommended parameters 401 (see Figure 8) simply by inputting the installation environment.

[0062] Furthermore, if a security setting operation that does not comply with the laws and regulations of the area of ​​use is received, the user will be notified accordingly. In this case, the setting operation will not be accepted as a valid operation, and the security setting will not be completed. This helps the user to avoid setting incorrect security settings that do not comply with the laws and regulations of the area of ​​use. As a result, the use of the image forming apparatus 20 in a security state that does not comply with the laws and regulations is prevented.

[0063] <Embodiment 2> In Embodiment 1, the location obtained from the IP address is displayed by default in the location setting field 301 (see Figure 7). However, the location obtained from the IP address can also be used to verify that the user has entered the location incorrectly. Figure 9 is a flowchart illustrating an example of processing operations performed in relation to setting the usage location. The flowchart shown in Figure 9 is performed, for example, in step 102 (see Figure 6).

[0064] First, the image forming apparatus 20 determines whether the user has entered the location of use (step 111). That is, the image forming apparatus 20 determines whether the location of use was entered manually. If the user's input of the location of use is confirmed, a positive result is obtained in step 111. In this case, the image forming apparatus 20 determines whether the location of use entered by the user is the same as the location of use corresponding to the IP address (step 112). The location of use entered by the user here is an example of second location information.

[0065] If the location entered by the user differs from the location corresponding to the IP address, a negative result is obtained in step 112. In this case, the image forming apparatus 20 requests confirmation of the location (step 113). For example, the image forming apparatus 20 changes the text of the location set in the location setting field 301 (see Figure 7) to red to draw the user's attention. In addition, a warning message requesting confirmation of the location, a pop-up requesting confirmation of the location, or a separate screen requesting confirmation of the location may be displayed.

[0066] The image forming apparatus 20 sets the location after detecting confirmation by the user (step 114). This confirmation includes, for example, changing the location to one obtained from an IP address, and pressing a button to indicate that the entered location is correct. On the other hand, if the location entered by the user and the location corresponding to the IP address are the same, a positive result is obtained in step 112. In this case, the image forming apparatus 20 sets the location entered by the user (step 115).

[0067] If the user does not enter a location, a negative result is obtained in step 111. In this case, the image forming apparatus 20 sets the location obtained from the IP address (step 116). By adopting the aforementioned mechanism, misconfiguration of the usage location, which is essential for recommended security settings, is prevented. As a result, security settings that comply with the laws and regulations of the usage location are achieved.

[0068] <Embodiment 3> The image forming apparatus 20 may not be used at the same location after installation, but its location may change due to business relocation or other reasons. Figure 10 illustrates the change of location due to relocation. Figure 10 includes corresponding reference numerals for parts that correspond to those in Figure 1. The image forming apparatus 20 shown in Figure 10 has been moved from location A to location B after installation.

[0069] If the laws and regulations applicable in location A and location B are the same, there is no need to change the security settings. However, if the laws and regulations applicable in location A differ from those applicable in location B, it may be necessary to consider changing the security settings.

[0070] For example, if the regulations applicable in location B are less stringent than those applicable in location A, it is possible to use the same security settings as those set in location A. However, it is also possible to change the security settings to be less stringent than those in location A, in accordance with the regulations applicable in location B. Furthermore, if the regulations applicable in location B are stricter than those applicable in location A, it will be essential to change the security settings to comply with the regulations of location B.

[0071] Thus, a change in the location where the image forming apparatus 20 is used is one of the reasons why the security settings no longer conform to the regulations of the location. However, unlike when introducing a new image forming apparatus 20, there is a possibility that changes to security settings may be overlooked. Therefore, in this embodiment, we will describe a function that periodically checks whether the current security settings comply with the laws and regulations of the place of use.

[0072] <Processing Action 1> Figure 11 is a flowchart illustrating an example of the process for verifying the usage site. Figure 11 includes corresponding reference numerals for parts that correspond to those in Figure 6. In the case of Figure 11, the image forming apparatus 20 (see Figure 1) determines whether the elapsed time since the last startup has exceeded a threshold (step 121). Startup here is not limited to startup immediately after the main power is turned on, but may also include recovery from sleep mode.

[0073] The criteria used here are just one example of predetermined conditions. Other criteria include whether the elapsed time since the last check has exceeded a threshold, whether the current date and time match a pre-set month and day of the week, and whether the timing is pre-scheduled. If the elapsed time since the last startup does not exceed the threshold, a negative result is obtained in step 121. In this case, the image forming apparatus 20 repeats the determination in step 121.

[0074] On the other hand, if the elapsed time since the last startup exceeds a threshold, a positive result is obtained in step 121. In this case, the image forming apparatus 20 reacquires an IP address (step 122). Next, the image forming apparatus 20 obtains the location of use corresponding to the IP address (step 123). This reveals the location of use of the image forming apparatus 20 at the current time.

[0075] Next, the image forming apparatus 20 determines whether the configured location of use and the location of use corresponding to the reacquired IP address are the same (step 124). Incidentally, the configured location of use is stored in the auxiliary storage device 23 (see Figure 5) as location information 23A (see Figure 5). If the configured location and the location corresponding to the reacquired IP address are the same, a positive result is obtained in step 124. In this case, there is no need to change the security settings. Therefore, the image forming apparatus 20 terminates the current processing operation without issuing any notification.

[0076] On the other hand, if the configured location of use differs from the location of use corresponding to the reacquired IP address, a negative result is obtained in step 124. In this case, the image forming apparatus 20 requests confirmation of the location of use (step 125). For example, the image forming apparatus 20 sends an email or message to its administrator. In addition, the image forming apparatus 20 may display a message requesting confirmation of the location of use on the control panel 24 (see Figure 5).

[0077] Next, the image forming apparatus 20 sets the location after detecting confirmation by the user (step 126). This confirmation can be either to confirm a change in the location or to confirm the maintenance of the current location. Changes to the location include changing to a location obtained from the IP address or changing to a location entered by an administrator or the like. Next, the image forming apparatus 20 determines whether or not the usage location has been changed (step 127).

[0078] If the current location is to be used as is, a negative result is obtained in step 127. In this case, the image forming apparatus 20 terminates the current processing operation without issuing any notification. On the other hand, if the location of use is changed, a positive result is obtained in step 127. In this case, the image forming apparatus 20 proceeds to the security reset process according to the current location of use. That is, it executes the processing operations in steps 104 to 110 (see Figure 6).

[0079] <Processing operation 2> Figure 12 is a flowchart illustrating another example of the site verification process. Figure 12 includes corresponding reference numerals for parts that correspond to those in Figure 11. In the processing operation shown in Figure 12, the image forming apparatus 20 also determines whether the elapsed time since the last startup has exceeded a threshold (step 121). If the elapsed time since the last startup does not exceed the threshold, a negative result is obtained in step 121. In this case, the image forming apparatus 20 repeats the determination in step 121.

[0080] On the other hand, if the elapsed time since the last startup exceeds a threshold, the image forming apparatus 20 requests confirmation of the usage location (step 131). Confirmation of the usage location can be performed, for example, by the same method as in step 125 (see Figure 11). In this usage operation, the image forming apparatus 20 performs the operation up to the point of requesting confirmation, but thereafter it is left to the user's judgment. For example, the user may confirm or set the usage location. If the user sets the usage location, steps 104 to 110 (see Figure 6) are performed.

[0081] <Processing operation 3> In the aforementioned processing operations 1 and 2, the criterion for determining whether a predetermined condition is met was whether the elapsed time since the last startup exceeded a threshold. However, the criterion may also be whether the elapsed time since the main power was turned off exceeds a threshold. For example, in the case of an office relocation, the power cable of the image forming apparatus 20 is disconnected from the power outlet or power strip. In this case, the main power supply of the image forming apparatus 20 is turned off.

[0082] However, the main power supply may be turned off for a short period due to power outages, etc. But, except in cases of disasters, the duration of the power outage is shorter than that of an office relocation, etc. On the other hand, in the case of an office relocation, the main power may be off for several hours to several days. The duration of the main power off depends on the amount of belongings being moved to the new location and the distance of the move. For example, if the location is close to a national border, the regulations of the new location may change within just a few hours.

[0083] Therefore, in this example, the threshold is set to, for example, 3 hours, and the main power off state exceeding the threshold is considered to be the occurrence of an event involving a change in regulations. If the criteria are met, you may either reacquire an IP address as in step 122 (see Figure 11), or request the administrator to verify the location of use as in step 131 (see Figure 12).

[0084] <Embodiment 4> The embodiments 1 to 3 described above assume that the installation environment set by the user is correct or does not change. However, users may make mistakes in the settings, or the scale of the users may change during use. For example, the number of image forming machines 20 used by the user may increase or decrease, or the number of employees registered with the image forming machines 20 may increase or decrease. If such an event occurs, the security settings that were in place when the image forming apparatus 20 was installed may no longer be suitable for the current situation.

[0085] Figure 13 is a flowchart illustrating an example of a processing sequence that anticipates a review of security measures in response to changes in the user's business environment after installation. Figure 13 includes corresponding reference numerals for parts that correspond to those in Figure 6. In this embodiment, the security setting support server 10 serves as the starting point for processing operations. The security setting support server 10 starts processing operations at a predetermined timing for each user who uses the image forming apparatus 20 or the security setting support service. The predetermined timing includes, for example, a predetermined period of time after the start of using the security setting support service, and a predetermined period of time after the previous operation.

[0086] First, the security setting support server 10 determines whether the number of registered users is 100 or more (step 141). The number of registered users here includes, for example, the number of people registered with the image forming apparatus 20 that is the target of processing, and the total number of users registered who use the image forming apparatus 20 that is the target of processing.

[0087] 100 people is one example of a threshold used to distinguish between large corporations and other companies. Furthermore, as in the embodiment described above, when distinguishing between large corporations, small and medium-sized enterprises (SMEs), and SOHOs, the corresponding number of people is used as the threshold. If the number of registered users is 100 or more, a positive result is obtained in step 141. In this case, the security setting support server 10 notifies the image forming apparatus 20 of this fact.

[0088] On the other hand, if the number of registered users is less than 100, a negative result is obtained in step 141. In this case, the security setting support server 10 determines whether or not there are registrations for other image forming devices 20 that cooperate (step 142). Other image forming devices 20 that cooperate include, for example, other image forming devices 20 that have the same user of management information. Also, other image forming devices 20 that cooperate include, for example, other image forming devices 20 used on the same floor.

[0089] In Figure 13, it is assumed that large companies use multiple image forming machines 20, while other companies use only one image forming machine 20. Furthermore, as in the embodiment described above, when distinguishing between large corporations, small and medium-sized enterprises, and SOHOs, the corresponding number of units can be used as a threshold.

[0090] If there are other image forming apparatuses 20 that cooperate, a positive result is obtained in step 142. In this case, the security setting support server 10 notifies the image forming apparatuses 20 of this fact. If there are no other image forming apparatuses 20 to cooperate with, a negative result will be obtained in step 142. In this case, the security setting support server 10 will terminate this operation.

[0091] If a positive result is obtained in step 141 or step 142 (i.e., if the security setting support server 10 notifies that it is a large company), the image forming apparatus 20 determines whether the settings of its installation environment are those of a large company (step 143). If the installation environment of the device is set up in a large company, a positive result is obtained in step 143. In this case, since there is no change in the settings, the image forming apparatus 20 terminates the current processing operation.

[0092] On the other hand, if the installation environment of the device is not that of a large corporation, a negative result is obtained in step 143. In this case, the image forming apparatus 20 requests the user (e.g., administrator) to confirm the installation environment (step 144). Information for contacting the administrator (e.g., email address, phone number) is stored in the image forming apparatus 20. Alternatively, a message or screen requesting confirmation of the installation environment can be displayed on the control panel 24 (see Figure 5), and the administrator can be contacted via an employee.

[0093] Next, the image forming apparatus 20 determines whether or not there is an error in the current installation environment (step 145). The administrator makes the determination of whether or not there is an error in the settings. In other words, the image forming apparatus 20 determines whether the administrator's input or selection is "incorrect" or "correct" in the settings of the current installation environment. If there are no errors in the current installation environment, a negative result is obtained in step 145. This includes cases where, for example, the user does not want to change the current security settings for some reason. In this case, the image forming apparatus 20 terminates its processing operation without executing the sequence for changing the security settings.

[0094] On the other hand, if there is an error in the current installation environment, a positive result is obtained in step 145. In this case, the image forming apparatus 20 proceeds to the security reset process according to the current installation environment. That is, it executes the processing operations of steps 104 to 110 in Figure 6. As a result, the security level of the image forming apparatus 20 can be adjusted according to changes in the installation environment. However, compliance with the laws and regulations of the place of use is a prerequisite.

[0095] In this embodiment, the description assumes a change in the classification of the installation environment from small and medium-sized enterprises (SMEs) to large enterprises, but it also includes a change in the classification of the installation environment from SOHO to SMEs. Furthermore, it also includes a change in the classification of the installation environment from large enterprises to SMEs, and a change in the classification of the installation environment from SMEs to SOHO. In these cases, the image forming apparatus 20 may be notified if a negative result is obtained in steps 141 and 142. Furthermore, in step 143, the image forming apparatus 20 may determine whether the current installation environment is a small or medium-sized enterprise or a SOHO (small office / home office).

[0096] <Embodiment 5> In the aforementioned embodiment, the installation environment is managed on a company-wide scale, and recommended parameters prepared according to the company size are recommended to the image forming apparatus 20. However, even if companies are classified by size, for example, some users may be satisfied with the recommended parameters, others may prefer stronger settings, and still others may prefer settings weaker than the recommended parameters.

[0097] In this embodiment, it is possible to set the desired intensity parameters regardless of the size of the company. Figure 14 illustrates an example of a security management system 1A. Figure 14 includes corresponding reference numerals for parts that correspond to those in Figure 1.

[0098] The security management system 1A shown in Figure 14 has a security policy server 30 added to it. The security policy server 30 is a server that manages recommended parameters according to security policies. A security policy refers to the user's security guidelines. These guidelines include, for example, whether to adopt standard security, higher-than-standard security, or lower-than-standard security.

[0099] In this embodiment, only one security policy server 30 is installed within the security management system 1A, and it centrally manages the security policies of multiple users. However, a security policy server 30 may be provided for each user who utilizes the security configuration support service. The security policy server 30 may also be considered an information processing system in itself. In this embodiment, the security setting support server 10A stores only the recommended security settings that comply with the laws and regulations of the area of ​​use.

[0100] <Device Configuration> <Hardware configuration of security configuration support server 10A> Figure 15 illustrates an example of the hardware configuration of the security configuration support server 10A. Figure 15 uses corresponding reference numerals to indicate parts that correspond to those in Figure 2. The security setting support server 10A shown in Figure 15 includes a processor 11, semiconductor memory 12, auxiliary storage device 13, communication interface 14, and signal lines 15. However, the auxiliary storage device 13 stores recommended setting information 13B.

[0101] Figure 16 illustrates an example of the recommended configuration information 13B data. The recommended configuration information 13B shown in Figure 16 includes the usage location 13B1 and the recommended security 13B2. The usage location 13B1 corresponds to the country or region in which the image forming apparatus 20 is used. In the case of Figure 16, the usage location 13B1 is exemplified by the United Kingdom, Italy, and Japan. Recommended security 13B2 corresponds to the recommended security value (so-called default value) that complies with the regulations applicable to usage location 13B1.

[0102] <Hardware configuration of security policy server 30> Figure 17 is a diagram illustrating an example of the hardware configuration of the security policy server 30. The security policy server 30 includes a processor 31, semiconductor memory 32, auxiliary storage device 33, communication interface 34, and signal lines 35.

[0103] The processor 31 is a semiconductor integrated circuit that performs various functions through the execution of programs. These programs include the OS, UEFI, and application programs. The OS is a program that controls the overall operation of the server. UEFI is a program that controls the server's boot process.

[0104] The semiconductor memory 32 includes, for example, ROM and RAM used as a work area for the processor 31. The auxiliary storage device 33 is composed of, for example, a hard disk drive or semiconductor storage. In addition to programs, policy-specific security information 33A is stored in the auxiliary storage device 33.

[0105] Figure 18 illustrates an example of security information data for policy-specific security information 33A. The security information data for policy-specific security information 33A shown in Figure 18 includes policy 33A1 and recommended parameters 33A2. Figure 18 illustrates three types of policies, A, B, and C.

[0106] For example, let's say the security strength of policy A is "high," the security strength of policy B is "medium," and the security strength of policy C is "low." Here, "medium" means standard security, "high" means a higher level of security than standard, and "low" means a lower level of security than standard.

[0107] It should be noted that this classification is for explanatory purposes only, and in reality, it can be defined from various perspectives. Recommended parameter 33A2 stores a recommended set of parameters according to the policy. For example, policy A stores parameter set A, policy B stores parameter set B, and policy C stores parameter set C.

[0108] The communication interface 34 (see Figure 17) is a module that enables communication with an external terminal. The communication interface 34 includes a module used for connecting to a LAN, for example, a wired or wireless LAN. In this embodiment, the communication interface 34 is used for communication with the image forming apparatus 20 (see Figure 1). Each device is connected via a bus or other signal line 35 (see Figure 17).

[0109] <Processing Sequence> Figure 19 illustrates an example of a processing sequence related to the security settings of the image forming apparatus 20. Note that parts of Figure 19 are denoted by corresponding reference numerals in Figure 6. In this embodiment as well, the image forming apparatus 20 acquires an IP address at a predetermined timing (step 101).

[0110] Next, the image forming apparatus 20 sets the usage area (step 102). Next, the image forming apparatus 20 sets a security policy (step 151). The security policy is an example of installation environment information. The security policy is set through the control panel 24 (see Figure 5). For example, candidate security policies are displayed in the installation environment settings section 302 (see Figure 7).

[0111] Next, the image forming apparatus 20 requests the security policy server 30 to provide recommended parameters corresponding to the configured security policy (step 152). Meanwhile, the security policy server 30 refers to the policy-specific security information 33A (see Figure 18) and sends recommended parameters corresponding to the notified policy (step 153).

[0112] Next, the image forming apparatus 20 requests the security setting support server 10A to provide recommended security settings corresponding to the location of use (step 154). Meanwhile, the security setting support server 10A refers to, for example, the recommended setting information 13B (see Figure 16) and notifies the user of the recommended security settings corresponding to the location of use (step 155).

[0113] The image forming apparatus 20 displays the acquired recommended security and recommended parameters (step 156). However, the parameter with the higher security level takes precedence. Subsequently, the image forming apparatus 20 determines whether or not to use the displayed parameter settings (step 157).

[0114] The subsequent processing steps are the same as in Embodiment 1. That is, steps 108 to 110 are executed. As mentioned above, adopting this mechanism makes it easier to set up security that satisfies the security policies of the user of the image forming apparatus 20 while also complying with the laws and regulations of the place of use.

[0115] <Embodiment 6> After the image forming apparatus 20 is put into use, the location of use may change, or the number of users of the image forming apparatus 20 may change. In these cases, the mechanism for adapting the security settings of the image forming apparatus 20 to the current situation was explained in the above-described embodiment. Incidentally, factors that may necessitate changes to the security settings applied after the image forming apparatus 20 is put into use include the enforcement or revision of new laws and regulations. However, the mechanism of the embodiment described above does not anticipate changes in laws and regulations.

[0116] <Processing Action 1> Figure 20 illustrates an example of a processing sequence related to the security settings of the image forming apparatus 20. Note that parts of Figure 20 are denoted by corresponding reference numerals in Figure 6. The security setting support server 10 shown in Figure 20 acquires the update history of the laws and regulations for each usage location (step 161). In this embodiment, step 161 is executed at a predetermined time, for example. The predetermined time is, for example, the 1st of each month. However, the acquisition process of step 161 may be executed at any time.

[0117] Next, the security setting support server 10 determines whether there are any laws or regulations that have come into effect or been amended since the start of use (step 162). Amendments to laws and regulations prior to the start of use were addressed when the image forming apparatus 20 was installed. Therefore, the determination in step 162 is performed for each image forming apparatus 20 that is subject to management. If no applicable regulations exist, a negative result is obtained in step 162. If a negative result is obtained in step 162 for all image forming apparatuses 20, the security setting support server 10 returns to step 161.

[0118] On the other hand, if there are laws and regulations that have come into effect or been amended after the start of use, a positive result is obtained in step 162. In this case, the security setting support server 10 requests the corresponding image forming apparatus 20 to confirm the security settings (step 163). However, this request may be made in conjunction with a firmware update notification. Upon receiving the notification, the image forming apparatus 20 accesses the security setting support server 10 and requests recommended security measures corresponding to the location of use and installation environment (step 104).

[0119] Meanwhile, the security setting support server 10 refers to, for example, recommended setting information 13A (see Figure 2) and notifies the user of recommended security settings corresponding to the location of use and installation environment (step 105). Upon receiving the notification, the image forming apparatus 20 determines whether the current security settings comply with the latest regulations (step 164). Specifically, the image forming apparatus 20 determines whether the security parameter settings include settings lower than the recommended parameters that were notified.

[0120] If the current security settings comply with the latest regulations, a positive result is obtained in step 164. In this case, the image forming apparatus 20 terminates the process. On the other hand, if the current security settings do not comply with the latest regulations, a negative result is obtained in step 164. In this case, the image forming apparatus 20 notifies the user (step 165).

[0121] Notifications to users will be sent, for example, via email or message. Alternatively, a message indicating that security settings need to be reviewed may be displayed on Control Panel 24 (see Figure 5). Incidentally, if the current security settings do not comply with the latest regulations, a mechanism may be adopted that automatically sets the acquired recommended security without requiring user confirmation.

[0122] <Processing operation 2> The aforementioned processing operation 1 monitors for the enforcement of new laws and amendments to existing laws, but the enforcement of new laws does not necessarily mean that the recommended parameters will change. Figure 21 illustrates an example of a processing sequence related to the security settings of the image forming apparatus 20. Note that Figure 21 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 6 and 20. In the processing operation shown in Figure 21, a firmware update triggers a review of the security settings of the image forming apparatus 20.

[0123] In the case of Figure 21, when the image forming apparatus 20 updates its firmware (step 171), it requests the security setting support server 10 to provide recommended security measures corresponding to the location of use and installation environment (step 104). The notification that a firmware update is necessary may be issued by the security setting support server 10, or by another server. Alternatively, the firmware update may be performed at the instruction of the administrator of the image forming apparatus 20.

[0124] In any case, the processing operation shown in Figure 21 is triggered by the execution of the firmware, which in turn triggers a query to the security setting support server 10 for recommended security measures. The security configuration support server 10 updates its recommended security settings for each location in accordance with the effective dates of new laws and amendments. In other words, the recommended security settings managed by the security configuration support server 10 are updated to comply with the latest laws and regulations.

[0125] After this, the security configuration support server 10 notifies the user of recommended security measures corresponding to the location and installation environment (step 105). Upon receiving the recommended security settings, the image forming apparatus 20 determines whether the current security settings comply with the latest regulations (step 164). If the current security settings comply with the latest regulations, a positive result is obtained in step 164. In this case, the image forming apparatus 20 terminates the process.

[0126] On the other hand, if the current security settings do not comply with the latest regulations, a negative result is obtained in step 164. In this case, the image forming apparatus 20 notifies the user (step 165). As a result, even if new laws and regulations apply to the area of ​​use and existing laws and regulations are amended, the security settings can be operated to comply with the latest regulations.

[0127] <Other Embodiments> (1) Although embodiments of the present invention have been described above, the technical scope of the present invention is not limited to the embodiments described above. It is clear from the claims that various modifications or improvements made to the embodiments described above are also included in the technical scope of the present invention.

[0128] (2) In Embodiment 1, the recommended security setting to be presented to the image forming apparatus 20 is determined according to the combination of the site of use and the installation environment. However, the recommended security setting may be determined based solely on the information of the site of use.

[0129] (3) In embodiments 2 and 3, the image forming apparatus 20 (see Figure 1) was described as the entity that executes the processing operations. However, the security setting support server 10 (see Figure 1) may also be the entity that executes the processing operations. In that case, the security setting support server 10 may acquire relevant information from each image forming apparatus 20 that is the subject of management and support the setting of security according to the location of use.

[0130] (4) In Embodiment 5, a security policy server 30 is provided separately from the security setting support server 10A. However, the security setting support server 10A and the security policy server 30 may be operated on a single server.

[0131] (5) In the above-described embodiment, the case of supporting the security settings of an image forming apparatus 20 (see Figure 1) as an example of network equipment was explained. However, the target of security setting support can be any network equipment.

[0132] (6) In the embodiments described above, each process is performed on any computer. Furthermore, any computer may perform these processes using a processor as hardware, a program as software, or a combination thereof. In that case, the processor is configured to work with the program to perform various processes in the embodiment, and can function as a unit or means in the embodiment.

[0133] Furthermore, the order in which the processor executes the processes is not limited to the order described and may be changed as appropriate. Any computer may be a general-purpose computer, a computer designed for a specific purpose, a workstation, or any other system capable of performing each process. A processor may consist of one or more pieces of hardware, and the type of hardware is not limited. For example, a processor may consist of a CPU (=Central Processing Unit), an MPU (=Micro Processing Unit), a programmable logic device such as an FPGA (=Field Programmable Gate Array), a dedicated circuit for performing specific processing such as an ASIC (=Application Specific Integrated Circuit), a GPU (=Graphic Processing Unit), or an NPU (=Neural Processing Unit).

[0134] Furthermore, the hardware may be a combination of different types of hardware. When multiple hardware components are configured to execute one or more processes of a processor, these components may reside in physically separate devices or in the same device. Also, in any embodiment, the order of each process performed by the processor is not limited to the order described above and may be changed as appropriate. The hardware is composed of electrical circuits, etc., which are made up of circuit elements such as semiconductor elements.

[0135] Furthermore, the program may be firmware or software such as microcode. Alternatively, the program may be, for example, a group of program modules, each of which may be implemented by a processor configured to perform its respective function. The program may also be program code or multiple code segments stored in one or more non-temporary computer-readable media (e.g., storage media or other storage devices).

[0136] A program may be divided and stored on multiple non-temporary computer-readable media located on devices that are physically separated from each other. Program code or code segments may represent any combination of procedures, functions, subprograms, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. Program code or code segments may be connected to other code segments or hardware circuits by sending and receiving information, data, arguments, parameters, or memory contents.

[0137] (7) The present invention can also be applied to programs and program products.

[0138] <Note> (((1))) An information processing system comprising: a storage device that stores in association location information including a country or region and candidate security settings that satisfy the laws and regulations corresponding to the location information; and a processor, wherein the processor acquires first location information indicating the location where the target device is used, provides the acquired first location information to the storage device, acquires candidate settings corresponding to the first location information, and presents the acquired candidate settings to the user of the target device. (((2))) The information processing system described in (((1))) wherein the processor obtains the first location information using the IP (=Internet Protocol) address of the target device. (((3))) The information processing system described in (((2))), wherein the processor requests the user to confirm the entered second location information if the second location information entered by the user differs from the first location information obtained from the IP address. (((4))) The information processing system described in (((2))), wherein the processor reacquires the IP address if predetermined conditions are met, and if the third location information corresponding to the reacquired IP address differs from the current location information in the settings, it requests the user to confirm the current location information. (((5))) The information processing system according to any one of (((1))) to (((4))), wherein the processor requests the user to change the settings if the current settings do not meet the regulations corresponding to the first place of use information. (((6))) The information processing system described in (((5))) wherein the processor determines that the current settings do not comply with the laws and regulations relating to the first place of use information if there is a history of changes to the laws and regulations relating to the first place of use information that have come into effect since the commencement of use of the current settings. (((7))) The information processing system according to (((5))), wherein the processor considers that the current setting does not satisfy the regulations of the first place of use information if the current setting does not match a candidate setting corresponding to the first place of use information. (((8))) The information processing system according to any one of (((1))) to (((7))), wherein the storage device stores a combination of the location information and the environment information and a candidate for the security setting in association with each other, and the processor acquires the first environment information of the target device, provides the acquired first environment information and the first location information to the storage device, and acquires a candidate for the setting corresponding to the combination of the first environment information and the first location information. (((9))) The first usage environment information is classified according to the scale of users who use the target equipment, as described in (((8))) information processing system. (((10))) The first usage environment information is provided in accordance with the security policy used by the user of the target device, as described in (((8))) information processing system. (((11))) The information processing system described in any one of (((1))) to (((10))) wherein the processor does not accept changes to settings that weaken the security strength compared to the candidate settings. (((12))) The aforementioned target device is an information processing system described in any one of (((1))) to (((11))), which is a device for forming an image on paper. (((13))) A program for a computer to implement the following functions: a function to acquire first location information including the country or region in which the target device is used; a function to provide the first location information to a storage device that stores the location information including the country or region in association with candidate security settings that satisfy the laws and regulations corresponding to the location information, in order to acquire candidate settings corresponding to the first location information; and a function to present the acquired candidate settings to the user of the target device.

[0139] According to the information processing system described in (((1))), unlike cases where there is no mechanism to support the user's security settings, it is possible to make settings that comply with the laws and regulations of the place of use regarding security. According to the information processing system related to (((2))), the acquisition of the location of use of the target equipment can be automated. According to the information processing system related to (((3))), it is possible to verify the setting of the usage location due to manual input. According to the information processing system related to (((4))), even if the place of use changes, it is possible to support the setting that complies with the laws and regulations of the changed place of use. According to the information processing system related to (((5))), it is possible to support the review of security settings to comply with the laws and regulations of the place of use. According to the information processing system related to (((6))), even if the regulations change after the current settings are put into use, it is possible to help ensure that the security settings comply with the regulations of the place of use. According to the information processing system related to (((7))), it is possible to support the review of security settings to comply with the laws and regulations of the place of use. According to the information processing system related to (((8))), it is possible to easily configure security settings according to the usage environment, in addition to the laws and regulations of the place of use. According to the information processing system related to (((9))), it is possible to support security settings according to the scale of users using the target equipment, in addition to the laws and regulations of the place of use. According to the information processing system related to (((10))), it is possible to support settings that meet not only the laws and regulations of the place of use, but also the security guidelines of the user using the target equipment. According to the information processing system related to (((11))), it is possible to disable security settings that do not comply with the laws and regulations of the place of use. According to the information processing system related to (((12))), the security of the image forming device can be set to comply with the laws and regulations of the place of use. According to the program described in (((13))), unlike cases where there is no mechanism to assist users in configuring security settings, it is possible to make settings that comply with the laws and regulations of the place of use regarding security. [Explanation of Symbols]

[0140] 1…Security management system, 10…Security configuration support server, 20…Image forming apparatus, 30…Security policy server

Claims

1. A storage device that stores location information, including a country or region, and candidate security settings that satisfy the laws and regulations corresponding to the location information, It has a processor, The aforementioned processor, We obtain location information indicating the place where the target equipment is being used. The acquired location information is provided to the storage device to obtain candidate settings corresponding to the location information. The acquired candidate settings are presented to the user of the target device. Information processing system.

2. The aforementioned processor, The first location information is obtained using the IP (Internet Protocol) address of the aforementioned target device. The information processing system according to claim 1.

3. The aforementioned processor, If the second location information entered by the user differs from the first location information obtained from the IP address, the system will request the user to confirm the entered second location information. The information processing system according to claim 2.

4. The aforementioned processor, If the predetermined conditions are met, the aforementioned IP address will be reacquired. If the third location information corresponding to the reacquired IP address differs from the current location information in the settings, the user will be asked to confirm the current location information. The information processing system according to claim 2.

5. The aforementioned processor, If the current settings do not comply with the regulations corresponding to the usage location information, the user will be required to change the settings. The information processing system according to claim 1.

6. The aforementioned processor, If there is a change history in the laws and regulations relating to the land use information that have come into effect since the commencement of use of the current settings, the current settings shall be deemed not to comply with the laws and regulations corresponding to the land use information. The information processing system according to claim 5.

7. The aforementioned processor, If the current setting does not match a candidate setting corresponding to the usage location information, the current setting is deemed not to satisfy the regulations corresponding to the usage location information. The information processing system according to claim 5.

8. The storage device stores the combination of the location information and the installation environment information in association with the candidate security settings. The aforementioned processor, The first installation environment information for the aforementioned target equipment is acquired, The acquired first installation environment information and the usage location information are provided to the storage device, and candidates for the settings corresponding to the combination of the first installation environment information and the usage location information are acquired. The information processing system according to claim 1.

9. The first installation environment information is categorized according to the number of users who will be using the target equipment. The information processing system according to claim 8.

10. The first installation environment information is provided according to the security policy used by the user of the target equipment. The information processing system according to claim 8.

11. The aforementioned processor, Changes to settings that weaken security compared to the aforementioned suggested settings will not be accepted. The information processing system according to claim 1.

12. The aforementioned device is a device that forms an image on paper. The information processing system according to claim 1.

13. On the computer, A function to acquire first place of use information, including the country or region in which the target equipment is used, A storage device that stores location information including a country or region and candidate security settings that satisfy the laws and regulations corresponding to the location information, has a function to obtain candidate settings corresponding to the first location information by providing the first location information to the storage device, A function to present the acquired candidate settings to the user of the target device, A program to achieve this.

Citation Information

Patent Citations

  • Electronic apparatus and image formation device

    JP2020154462A