Image forming device
By introducing a user interface, communication interface and controller into the image forming device, the approval process for remote screen display is realized, and the problem of difficult to balance security and operation convenience in the prior art is solved, and a remote screen display with high security and simplicity of operation is realized.
Patent Information
- Application Number
- JP2021159410
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-29
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-09-29
AI Technical Summary
Existing remote screen technology is difficult to balance between security and operational ease, especially when displaying remote screens without user interface approval, there is a risk of reduced security.
The approval process for remote screen display is realized by introducing a user interface, a communication interface and a controller in the image forming device. The specific steps include: receiving a request from the connected device, displaying an approval screen through the user interface, accepting user approval operations, and automatically approving the display of the remote screen without displaying the approval screen when the IP address that meets a specific condition.
It effectively improves the security of remote operations, while simplifies the startup process of remote operations, reducing the cumbersomeness of user operations.
Smart Images

Figure 0007673606000001 
Figure 0007673606000002 
Figure 0007673606000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a technology for an image forming apparatus that can receive remote control from an information processing apparatus. [Background technology]
[0002] Patent Document 1 describes a technology for remotely controlling an image forming device in response to operations on a remote screen by displaying a remote screen that virtually shows a user interface of the image forming device on a remote information processing device. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2020-10265 A Summary of the Invention [Problem to be solved by the invention]
[0004] In order to improve the security of the remote screen, the inventor is considering a configuration in which the information processing device is permitted to display the remote screen on the condition that an approval operation is received via a user interface of the image forming device. [Means for solving the problem]
[0005] The image forming apparatus disclosed as an embodiment for solving the above problem includes a user interface, a communication interface, and a controller, and when the controller receives a first request from a device connected via the communication interface, it displays an approval screen on the user interface, and when an approval operation on the approval screen is received via the user interface, it is capable of executing an approval process to approve the display of a remote screen, the first request being a request to display a remote screen, and the remote screen being a screen displayed on the device that requested the first request and virtually reproducing the user interface. When the display of the remote screen is approved through the approval process, the controller executes a transmission process to transmit remote screen data to the device that originated the request for the first request, the remote screen data being data for displaying a remote screen on the device that originated the request for the first request, and when the controller receives an instruction from the device that originated the request for the first request via the communication interface after the transmission process indicating that a virtual operation has been performed using the remote screen, the controller executes a predetermined process in accordance with the instruction, and in the approval process, the controller determines whether the communication address satisfies a specific condition, the communication address being an IP address used for communication with the device that originated the request for the first request, and in the approval process, if it is determined that the communication address satisfies the specific condition, the controller approves the display of the remote screen to the device that originated the request for the first request without displaying an approval screen on the user interface.
[0006] In the above configuration, when the controller of the image forming apparatus receives an instruction to display the remote screen, the controller displays an approval screen on the user interface, and when it is determined that an approval operation on the approval screen has been received, it executes an approval process to approve the display of the remote screen on the requesting apparatus. On the other hand, in the approval process, when it is determined that a communication address, which is an IP address used for communication with the requesting apparatus of the first request, satisfies a specific condition, the controller approves the display of the remote screen on the requesting apparatus of the first request without displaying the approval screen. When the display of the remote screen is approved by the approval process, the controller transmits remote screen data to the requesting apparatus of the first request, and when an instruction indicating that a virtual operation using the remote screen has been performed is received from the requesting apparatus of the first request via the communication interface after transmitting the remote screen data, the controller executes a predetermined process according to the instruction. As a result, when the IP address used for communication with the requesting apparatus of the first request satisfies a specific condition, the remote screen is displayed on the requesting apparatus of the first request without displaying the approval screen on the user interface, so that it is not necessary to perform an approval operation on the user interface of the image forming apparatus. As a result, it is possible to suppress a decrease in security for remote operation using a remote screen, while suppressing the hassle of operations when starting remote operation. [Brief description of the drawings]
[0007] [Figure 1] FIG. 1 is a configuration diagram of an image forming system. [Diagram 2] 4 is a timing chart illustrating a process related to remote screen control. [Diagram 3] FIG. 13 is a diagram illustrating an administrator screen. [Figure 4] FIG. 13 is a diagram illustrating an administrator screen. [Diagram 5] 3 is a flowchart illustrating the process of S24 in FIG. 2. [Figure 6] 11 is a flowchart illustrating a process related to updating a configuration file. [Figure 7] FIG. 13 is a diagram illustrating a setting screen. [Figure 8] FIG. 13 is a diagram illustrating an approval screen. [Figure 9] FIG. 13 is a diagram illustrating a remote screen. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0008] (First embodiment) An image forming system 100 according to the present embodiment will be described with reference to the drawings. The image forming system 100 shown in FIG. 1 includes an MFP 10 and PCs 30, 50, and 51. MFP is an abbreviation for multifunction peripheral. The MFP 10 and the PCs 30, 50, and 51 are connected to a network 200 and are capable of communicating with each other through the network 200. The network 200 is a LAN or the Internet. In this embodiment, the MFP 100 is an example of an image forming apparatus. The PCs 30, 50, and 51 are examples of information processing apparatuses. The MFP 10 and the PCs 30, 50, and 51 are connected to the same LAN.
[0009] Next, a description will be given of the configuration of the MFP 10. The MFP 100 includes a controller 11, a memory 12, a printer 13, a scanner 14, a FAX-IF 15, a communication IF 16, a user IF 17, and a bus 18. IF is an abbreviation for interface.
[0010] The communication IF 16 connects the MFP 10 to the network 200 in accordance with a predetermined communication protocol. The user IF 17 is an interface between a user who directly operates the MFP 10 and the controller 11, and has a touch panel 171 and operation keys 172 which are physical keys.
[0011] The printer 13 executes a printing operation to print an image on a recording medium such as a sheet or a disk. The recording method of the printer 13 may be an inkjet method, an electrophotographic method, or the like. The scanner 14 executes a scanning operation to read an image recorded on an original and generate image data. The FAX-IF 15 executes a FAX operation to transmit and receive image data in a method conforming to a FAX protocol. The MFP 10 may also be capable of executing a composite operation that combines a plurality of operations. A copy operation that combines a print operation by the printer 13 and a scan operation by the scanner 14 is an example of a composite operation.
[0012] The controller 11 is configured with a CPU, an ASIC (abbreviation of Application Specific Integrated Circuit), etc., and controls the operations of the printer 13, the scanner 14, the FAX-IF 15, the communication IF 16, and the user IF 17. The memory 12 has a data storage area. The data storage area is an area for storing data necessary for executing programs, etc. The memory 12 is configured by combining RAM, ROM, SSD, HDD, etc. A buffer provided in the controller 11 and used when executing various programs may also be considered as part of the memory 12. The memory 12 may be a storage medium readable by the controller 11. The storage medium readable by the controller 11 is a non-transitory medium. In addition to the above examples, the non-transitory medium also includes recording media such as CD-ROM and DVD-ROM. The non-transitory medium is also a tangible medium. On the other hand, electrical signals carrying programs downloaded from a server on the Internet, for example, are computer-readable signal media, which is a type of computer-readable medium, but are not included in non-transitory computer-readable storage media.
[0013] The memory 12 stores firmware 20 as a program executable by the controller 11. In the following description, the controller 11 that executes the program may be described simply by the program name. For example, the description "the firmware" is used to mean "the controller 11 that executes the firmware 20". In this embodiment, the description mainly refers to the processing of the controller 11 according to the instructions written in the program. That is, the processing of "judging", "extracting", "selecting", "calculating", "deciding", "identifying", "obtaining", "accepting", "controlling" and the like in the following description represents the processing of the controller 11. Note that "obtaining" is used as a concept that does not require a request. In other words, the processing of the controller 11 receiving data without a request is also included in the concept of "the controller 11 obtaining data". In addition, "data" in this specification is represented by a bit string that can be read by the controller. Data that has the same substantial meaning but different formats is treated as the same data. The same applies to "information" in this specification.
[0014] The firmware 20 also functions as a Web server for displaying a predetermined Web page on the PC 30. The firmware 20 can also provide a remote screen control to the PC 30. The remote screen control is a function for remotely operating the MFP 10 by causing the PC 30 to display a remote screen that simulates the input IF 17 of the MFP 10, and performing operations on the remote screen. The firmware 20 can display the remote screen on a browser 41 (described later) of the PC 30 by transmitting Web page data for displaying the remote screen to the PC 30.
[0015] Management information 25 is stored in the data storage area of the memory 12. In the management information 25, a login name and a password, which are authentication information, are recorded in association with a PC that can access the MFP 10.
[0016] Next, a description will be given of the configuration of the PC 30. The PC 30 includes a communication IF 31, a memory 32, a controller 33, a display 34, and a user IF 35. The units 31, 32, 33, and 35 included in the PC 30 have the same configuration as the controller 11, memory 12, communication IF 16, and user IF 17 included in the MFP 30, and therefore descriptions thereof will be omitted.
[0017] The memory 32 stores an OS 40 and a browser 41. The browser 41 is a program that causes the controller 33 to display on the display 34 an image corresponding to the Web page data transmitted from the MFP 10. The PCs 50 and 51 have the same configuration as the PC 30, and therefore a description thereof will be omitted.
[0018] Next, the procedure of processing when remote screen control is executed by PC 30 will be described with reference to Fig. 2. MFP 10 displays an operation screen on user IF 17, and changes the display of the operation screen according to operations via user IF 17, the operating status of MFP 10, etc. The process of changing the operation screen is executed in parallel with the process of Fig. 2. The operation screen includes an execution screen showing that printing, scanning, etc. are being executed, an instruction screen for receiving execution instructions for copying, scanning, etc., a setting screen for changing various settings, a status screen showing the status of MFP 10, an execution instruction screen, a standby screen for waiting for an instruction to display a setting screen, etc.
[0019] 2, in step 10 (hereinafter, step will be simply abbreviated as "S"), browser 41 of PC 30 transmits a request for web page data to MFP 10. The web page data requested in S10 is web page data for displaying a home screen when firmware 20 functions as a web server. For example, browser 41 transmits the request to firmware 20 when it receives input of a URL specifying firmware 20 by a user. Communication between browser 41 and firmware 20 is performed according to the http(s) protocol.
[0020] In S11, the firmware 20 transmits Web page data to the PC 30. In S12, the browser 41 receives the Web page data and displays the Web page indicated by the received Web page data on the display 34. In this embodiment, the browser 41 displays a home screen on the display 34 in response to the reception of the Web page data.
[0021] When a login operation to the MFP 10 is performed on the home screen, the browser 41 transmits a login password and the like to the firmware 20. When a response of login permission is received from the EWS, the browser 41 displays an administrator screen 300 shown in Fig. 3 on the display 34 of the PC 30. The administrator screen 300 includes an item display area 301 and a function display area 302.
[0022] When a selection operation of "Remote Screen Control" item 303 included in item display area 301 is accepted via user IF 35, browser 41 requests MFP 10 to start remote screen control in S13. When firmware 20 receives the request to start remote screen control, firmware 20 transmits Web page data for updating the Web page in S14. This Web page data includes an execution program that can be interpreted by browser 41. The execution program is a script program, for example, JavaScript.
[0023] The browser 41 executes the execution program, and in S15, requests the MFP 10 for the current usage status of the remote screen control. The usage status of the remote screen control is information indicating whether or not remote screen control targeting another device such as the PC 50 is already being executed, and in this embodiment, is information indicating either "executing" or "not executed." When information indicating the permitted status is stored in the memory 12, the firmware 20 replies with information indicating "executing", and otherwise replies with information indicating "not executed".
[0024] In S16, the firmware 20 returns the usage status of the remote screen control to the PC 30. In S17, the browser 41 judges the usage status returned from the firmware 20. Specifically, when the browser 41 judges that the usage status of the remote screen control indicates "executing" (NO in S17), it issues an error notification and ends the processing of FIG. 2. In this case, execution of the remote screen control is not permitted. For example, a text image is displayed on a Web page indicating that remote screen control of another device is currently being executed and that remote screen control of the own device cannot be executed. In this case, the browser 41 continues to display the home screen in S12.
[0025] On the other hand, when the browser 41 determines that the information indicating the usage state of the remote screen control indicates "not executed" (YES in S17), it requests the MFP 10 to issue a token in S18. The token is information for authenticating the device that executes the remote screen control, and in this embodiment, it is a one-time token created based on the authentication information. When the firmware 20 accepts the token issuance request, it requests the PC 30 for authentication information in S19. Specifically, the firmware 20 transmits data for displaying a login form that accepts input of authentication information to the browser 41. The browser 41 displays the administrator screen 300 with the login form 310 shown in FIG. 4 superimposed thereon, based on the transmitted data. The browser 41 transmits the authentication information (i.e., user name and password) input via the login form 310 to the MFP 10 in S20.
[0026] When the firmware 20 receives the authentication information, in S21, it performs authentication processing to determine whether or not the user indicated by the received authentication information is a user permitted to execute remote screen control. In the authentication processing, it is determined whether or not the authentication information of the user (e.g., administrator) stored in the management information 25 stored in the memory 12 matches the authentication information transmitted from the browser 41. If the authentication information does not match, a response is sent to the browser 41 to refuse transmission of the token, and the processing of FIG. 2 is terminated.
[0027] If the authentication is successful, the firmware 20 issues a token to the PC 30 in S22. At this time, if information indicating that a token has already been issued is stored in the memory 12, the firmware 20 determines that the token has not yet been issued, and may not transmit the token. When the browser 41 receives the token issued by the MFP 10, the firmware 20 requests display of a remote screen together with the issued token in S23. When the firmware 20 receives a request to display a remote screen from the browser 41, the firmware 20 performs an approval process in S24. In this embodiment, the request to display a remote screen transmitted by the browser 41 in S23 is an example of a first request.
[0028] 5 is a flow chart for explaining the approval process executed in S24, and the subject is the firmware 20. In S30, it is determined whether or not the token transmitted from the PC 30 together with the request to display the remote screen is correct. Specifically, the firmware 20 determines that the token is incorrect when too much time has passed since the token was issued, or when the token is a forged token. When the firmware 20 determines that the transmitted token is incorrect, it proceeds to S43 and sets the permission status to "rejected". When S43 ends, it proceeds to S25 in FIG. 2.
[0029] On the other hand, if the firmware 20 determines that the token transmitted from the PC 30 is correct, it makes an affirmative judgment in S30, proceeds to S31, and sets the permission status to "verifying".
[0030] In S32, it is determined whether or not automatic determination is enabled. Automatic determination is a process for determining whether or not to permit PC 30 to display a remote screen by using an IP address used in communication between MFP 10 and PC 30. Specifically, the MFP 10 determines whether automatic determination is enabled or disabled and whether the determination content of automatic determination is enabled or disabled by referring to the setting items of setting file 26 stored in memory 12. The setting items of setting file 26 can be updated by a process for updating setting file 26, which will be described later.
[0031] The process of updating the setting file 26 in which various setting items for automatic determination are stored will be described. Fig. 6 shows the process executed by the controller 11 when a user issues an instruction to update a setting item in the approval process on an administrator screen 300, which is a Web page displayed on the PC 51. The PC 51 is a PC managed by an administrator, similar to the PC 30.
[0032] In S60, the web page data is transmitted to PC 51, thereby causing PC 51 to display setting screen 450 shown in Fig. 7. Specifically, when firmware 20 of MFP 10 receives, via communication IF 16, an instruction that a selection operation for "approval setting" included in item display area 301 on administrator screen 300 shown in Fig. 3 displayed on PC 51 has been received, firmware 20 causes PC 51 to transmit the web page data. In this case as well, authentication similar to S19 to S21 is performed between firmware 20 of MFP 10 and browser 41 of PC 51, and if authentication in S21 is successful, firmware 20 transmits web page data related to the approval setting.
[0033] The setting screen 450 included in the administrator screen 300 is a screen for accepting settings of valid / invalid, which are setting items in the automatic determination, and designation operations of valid / invalid, which are setting items for each determination content. The setting screen 450 includes check boxes 452, 453, and 454, an address form 455, and a setting reflection button 456.
[0034] When checkbox 452 is checked, an instruction to enable the automatic determination setting item for the configuration file 26 has been received. In this case, checkboxes 453 and 454 can be checked. Note that when checkbox 452 is not checked, checkboxes 453 and 454 are not accepted. When only checkbox 453 is checked, an instruction to enable the "determine by local machine's IP address" setting item for the configuration file 26 has been received. When only checkbox 454 is checked, an instruction to enable the "determine by requester's IP address" setting item for the configuration file 26 has been received.
[0035] In this embodiment, when check box 452 is checked, either check box 453 or 454 is always checked. Specifically, when only check box 453 is checked, a received operation to uncheck check box 453 is not accepted. When only check box 454 is checked, a received operation to uncheck check box 454 is not accepted. Alternatively, when either check box 453 or 454 is checked and a check uncheck operation is accepted via user IF 17, the unchecked check box 453 or 454 may be automatically checked.
[0036] When the check box 454 is checked and the setting item "determine by request source IP address" is enabled, the IP address can be input into the address form 455 by the accepted operation.
[0037] In S61, it is determined whether or not a setting reflecting request has been received from PC 51 via communication IF 16. Specifically, when setting reflect button 456 is operated on setting screen 450 displayed on PC 51, PC 51 transmits a setting reflecting request to MFP 10. At this time, PC 51 transmits, together with the setting reflecting request, an instruction for a setting item corresponding to the operation accepted on setting screen 450 to PC 10 via communication IF 16. If an affirmative determination is made in S61, the process proceeds to S62.
[0038] In S62, each setting item of the setting file 26 is updated according to the instruction for the setting item transmitted from the PC 51 together with the setting reflection request. When an instruction to enable automatic determination is received by checking the check box 452, the setting item of automatic determination stored in the setting file 26 is set to "enabled". When an instruction to enable the determination content "determine by the IP address of the own machine" is received by checking the check box 453, the setting item of "determine by the IP address of the own machine" stored in the setting file 26 is set to "enabled". When an instruction to enable "determine by the IP address of the requester" is received by checking the check box 454, the setting item of "determine by the IP address of the requester" stored in the setting file 26 is set to "enabled".
[0039] The setting items of the setting file 26 can also be updated by an operation on the user IF 17 of the MFP 10. Specifically, the controller 11 of the MFP 10 causes the user IF 17 to display the setting screen shown in Fig. 7 in accordance with the operation on the user IF 17. In this case, the firmware 20 of the MFP 10 updates the setting file 26 based on an instruction for the setting item of the automatic determination received on the setting screen. Specifically, the firmware 20 receives instructions for the setting items of the automatic determination, such as the enable / disable setting, the determination content, and the IP address to be registered.
[0040] In addition, when firmware 20 of MFP 10 receives an update instruction for a setting item of setting file 26 from PC 30, 50, 51 connected to network 200 via communication IF 16, it may update setting file 26 in accordance with the received update instruction.
[0041] Returning to FIG. 5, if automatic determination is enabled in the configuration file 26 and an affirmative judgment is made in S32, the process proceeds to S33, in which the configuration file 26 is referenced to determine whether or not to make a judgment based on the IP addresses of both the request source device, PC 30, and the request destination device, MFP 10.
[0042] If S33 is judged as positive, the process proceeds to S34, where it is judged whether the IP address of the own machine is a private IP address. The IP address of the own machine is specifically the IP address of MFP 10 used as the destination address of the request from the request source device. The IP address of MFP 10 used as the destination address of the request from the request source device is an example of an IP address used for communication. If the address of the own machine is a private IP address, the access is within the LAN, so even if the display of the remote screen is permitted, there is a low possibility that security will be reduced. In this embodiment, an example of the specific condition is that the IP address of the own machine is a private IP address.
[0043] If the determination in S34 is affirmative, the process proceeds to S35, where it is determined whether the IP address of the requesting device is a registered address. The IP address of the requesting device is an IP address used as a requesting device's address when the requesting device transmits data to the MFP 10. The IP address of the requesting device is an IP address used as a destination when the MFP 10 transmits data to the requesting device. That is, the IP address of the requesting device is an example of an IP address used for communication. The registered address is an IP address registered in advance in the setting file 26 stored in the memory 12. If the IP address is registered in advance in the setting file 26, there is a low possibility that security will be reduced even if the display of the remote screen is permitted. In this embodiment, an example of the specific condition is that the IP address of the requesting device is a registered address.
[0044] If an affirmative judgment is made in S35, the process proceeds to S42, where the permission status is set to "permitted." Specifically, the firmware 20 stores information indicating the permission status in the memory 12. The information indicating the permission status is information indicating either "permitted" or "denied." On the other hand, if a negative judgment is made in S34 or S35, the process proceeds to S43, where the permission status is set to "denied." Note that the firmware 20 erases the information indicating the permission status (permitted, denied) stored in the memory 12 when the remote screen control ends.
[0045] In S33, if the determination content of the automatic determination is not set to "determine based on both addresses" in the setting file 26, the process proceeds to S36, where it is determined whether or not "determine based on the IP address of the own machine" is set as the determination content of the automatic determination in the setting file 26. If "determine based on the IP address of the own machine" is set in the setting file 26, an affirmative determination is made in S36.
[0046] If the result of S36 is affirmative, the process proceeds to S37, where the same determination as in S34 is made. If the result of S37 is affirmative, the process proceeds to S42, where the permission status is set to "permitted." On the other hand, if the result of S37 is negative, the process proceeds to S44, where the permission status is set to "denied."
[0047] If "determine by IP address of own machine" is not set in the configuration file 26 as the determination content of the automatic determination and a negative judgment is made in S36, the process proceeds to S38. In S38, it is determined whether or not "determine by IP address of request source device" is set in the configuration file 26 as the determination content of the automatic determination. If a positive judgment is made in S38, the process proceeds to S39, where a judgment similar to that in S35 is made. If a positive judgment is made in S39, the process proceeds to S42, where the permission status is set to "permitted". On the other hand, if a negative judgment is made in S38 or S39, the process proceeds to S43, where the permission status is set to "rejected". The approval performed by the firmware 20 using the IP address for communication in S31 to S39 and S42, S43 is an example of a first approval process.
[0048] In S32, if automatic determination is set to be disabled in the setting file 26, the process proceeds to S40. In S40, approval is performed using the approval screen 400. Approval using the approval screen 400 is a process of approving the display of a remote screen when an approval operation on the approval screen displayed on the user IF 17 is accepted.
[0049] 8, approval screen 400 includes a text image 401, an allow button 402, and a deny button 403. Text image 401 is an image that displays text prompting an approval operation because a user near MFP 10 has requested to display a remote screen.
[0050] If a user near the MFP 10 operates the permission button 402 as an approval operation, an affirmative judgment is made in S41, and the process proceeds to S42. In S42, the permission status is set to "permitted." On the other hand, if a user near the MFP 10 operates the reject button 403 as an approval operation, an affirmative judgment is made in S41, and the process proceeds to S43. In S43, the permission status is set to "rejected." Note that if an approval operation is not performed even after a predetermined period of time has elapsed after the approval screen 400 is displayed in S40, the process proceeds to S43, and the permission status may be set to "rejected." In this embodiment, the approval performed by the firmware 20 using the approval screen in S40 to S43 is an example of a second approval process.
[0051] Returning to FIG. 2, if the permission status is set to "rejected", the firmware 20 responds to the PC 30 in S25 that the transmission of the remote screen is rejected. When the browser 41 receives the rejection response from the MFP 10, the browser 41 may display a prohibition screen on the administrator screen 300. This allows the user of the PC 30 to determine that the transmission of the remote screen is prohibited by the MFP 10 by viewing the text image displayed on the display 34.
[0052] When the permission state is set to "permitted", the firmware 20 responds to the PC 30 in S26 to permit transmission of the remote screen. The firmware 20 transmits remote screen data for displaying the remote screen on the browser 41 to the PC 30 in S27. In this embodiment, the remote screen data is data including data indicating the operation screen currently displayed on the user IF 17. Specifically, the remote screen data includes data indicating operation keys that are physical keys of the user IF 17 and data indicating an end button (reference numeral 333 in FIG. 4) described later, in addition to data indicating the operation screen. The firmware 20 creates remote screen data and transmits the created remote screen data to the browser 41. In the browser 41, an execution program included in the remote screen data interprets the remote screen data and causes the display 34 to display the remote screen. In this embodiment, the process executed by the firmware 20 in S27 is an example of a transmission process. It should be noted that, upon receiving the display permission response in S26, the browser 41 may again request the remote screen data from the MFP 10, and upon receiving this request, the firmware 20 may transmit the remote screen data to the PC 30 in S27.
[0053] FIG. 9 is a diagram showing an example in which a standby screen is displayed in a remote screen when the standby screen is displayed in the user IF 17. The remote screen 330 is displayed in the function display area 302 in the administrator screen 300. The remote screen 330 includes a screen display area 331 and an operation key display area 332. The screen display area 331 displays the same screen as the operation screen currently displayed in the user IF 17 of the MFP 10. In FIG. 7, as an example, the standby screen is displayed in the screen display area 331. The operation key display area 332 displays icon images imitating operation keys that are physical keys provided in the user IF 17. Information indicating that a virtual operation has been performed on the user IF 17 on the remote screen 330 is interpreted by an execution program included in the remote screen data and is notified to the MFP 10. The MFP 10 that has received the information indicating that a virtual operation has been performed executes a process according to the operation in the same manner as when the operation screen displayed in the user IF 17 is operated. For example, when the MFP 10 receives information indicating an operation on the Copy button, the MFP 10 executes copy processing including displaying a screen indicating that copy is in progress. For example, when the MFP 10 receives information indicating an operation on the Setting button, the MFP 10 executes processing for setting parameters of the MFP 10 including displaying a Setting screen.
[0054] The data indicating the operation screen, the operation keys, and the end button included in the remote screen data for displaying the remote screen 330 may be in the same data format, such as raster data, or in other data formats. The data indicating the operation screen, the operation keys, and the end button may be in different data formats. The firmware 20 may transmit only the data indicating the operation screen to the browser 41 as the remote screen data, and the browser 41 may interpret the execution program to display the remote screen by superimposing the data indicating the operation keys and the end button on the remote screen data. In addition to the above, the firmware 20 may transmit data indicating the operation screen and the operation keys to the browser 41 as the remote screen data, and the browser 41 may interpret the execution program to superimpose the data indicating the end button on the remote screen data. Furthermore, instead of transmitting the remote screen data to the browser 41, the firmware 20 may transmit Web page data for displaying the entire administrator screen including the remote screen data to the browser 41.
[0055] The browser 41 executes the execution program to periodically request the firmware 20 to send remote screen data for displaying a remote screen, and reflects the screen currently displayed on the user IF 17 on the remote screen. For example, when the browser 41 receives an operation input on the remote screen 330 via the user IF 35, the browser 41 executes the execution program to transmit a request corresponding to the received operation input to the firmware 20. At this time, the browser 41 transmits a token issued by the firmware 20 together with the request corresponding to the operation input. For example, when the operation input on the remote screen 330 is an operation related to updating the screen, the browser 41 requests the firmware 20 to send remote screen data for displaying the updated remote screen together with the token. When the firmware 20 receives the request for remote screen data, it creates remote screen data for displaying the updated remote screen 330 on condition that the token is correct, and transmits the remote screen data to the browser 41.
[0056] The remote screen 330 displayed on the display 34 of the PC 30 is also updated when the user IF 17 of the MFP 10 is operated. In this case, when the firmware 20 receives an operation to change the screen via the user IF 17, the firmware 20 may transmit remote screen data relating to the updated remote screen to the browser 41 without waiting for a request from the execution program.
[0057] The remote screen 330 also includes an end button 333. When the firmware 20 receives an operation input to the end button 333 by the user, the firmware 20 requests the firmware 20 to end the remote screen control together with the token. When the firmware 20 receives the end request from the PC, the firmware 20 ends the remote screen control on condition that the token is correct. The firmware 20 ends the remote screen control. The process of ending the remote screen control includes deleting various information such as information indicating the use state of the remote screen control stored in the memory 12, information indicating that the token has been issued, and information indicating the permission state of the remote screen control. The firmware 20 may end the remote screen control after deleting the information, or another program may delete the information triggered by the end of the remote screen control. The firmware 20 also ends the remote screen control in the same manner as when the end button is pressed if there is no access from the browser 41 that executes the execution program for a certain period of time after the start of the remote screen control.
[0058] The present embodiment described above can provide the following advantages. In the approval process, when the controller 11 of the MFP 10 determines that the IP address satisfies a specific condition, it approves the display of the remote screen 330 on the PC 30 without displaying an approval screen on the user IF 17. This makes it possible to start remote display control without performing an approval operation on the user IF 17. As a result, it is possible to suppress the deterioration of security for remote operation using the remote screen 330 while suppressing the cumbersome operation when starting remote operation.
[0059] If the IP address of the MFP 10 used for communication with the requesting device is a private address, the controller 11 can approve the remote screen data without approval using the approval screen. Since communication using a private address is communication with a device in the LAN to which the MFP 10 is connected and security is expected to be ensured by the administrator of the LAN, operation may be performed without approval using the approval screen.
[0060] The controller 11 determines that the specific condition is satisfied if the IP address of the PC 30 matches an IP address registered in the MFP 10. An operation may be performed in which the transmission of remote screen data is automatically approved if the request is from a requesting device having a reliable IP address that has been registered in advance in the MFP 10 by an administrator.
[0061] The controller 11 can accept the designation of the IP address to be permitted for approval via the user IF 17. That is, the ease of use of the approval process can be improved.
[0062] If the IP address of MFP10 and the IP address of PC30 are on the same LAN, the controller can approve the transmission of remote screen data without approval using an approval screen. If MFP10 and PC30 are connected to the same LAN and are devices managed by the same administrator who manages the LAN, it is expected that security will be ensured by the administrator, so approval using the approval screen may be omitted.
[0063] The controller 11 performs a setting for enabling approval processing using automatic determination on the MFP 10 based on an operation received via the user IF 17. This allows the user to change whether or not approval processing using automatic determination is enabled by an operation via the user IF 17. In other words, it is possible to execute a suitable approval processing depending on the situation in which the MFP 10 is used.
[0064] (Modification of the first embodiment) In the first embodiment, if the automatic determination is invalid in S32 of Fig. 5, the process proceeds to S40 and approval is performed using the approval screen 400. Alternatively, if the automatic determination is invalid, the process proceeds to S43 and the permission status may be set to "rejected." That is, in this embodiment, if the firmware 20 determines that the IP address used for communication satisfies a specific condition, it approves the PC 30 to display the remote screen, and if it determines that the IP address used for communication does not satisfy the specific condition, it does not approve the PC 30 to display the remote screen. In this case, the processes of S40 and S41 are omitted.
[0065] In the first embodiment, when the firmware 20 determines in the automatic determination that both IP addresses used in the communication are private IP addresses (YES in S34) and the IP address of the requesting device is a registered address (YES in S35), the firmware 20 proceeds to S42 and sets the permission state to "permitted". Alternatively, when both IP addresses used in the communication are private addresses (YES in S34), the controller 11 may proceed to S42 and set the permission state to "permitted". That is, after the process of S34, the controller 11 does not determine whether the addresses are registered addresses. In this case, the process of S35 is omitted. When both IP addresses used in the communication are not private IP addresses (NO in S34), the firmware 20 may proceed to S35 and determine whether both IP addresses are registered addresses. In this case, if the IP address of the requesting device is a registered address, the firmware 20 makes an affirmative determination in S35, proceeds to S42, and sets the permission state to "permitted". On the other hand, if the IP address of the requesting device is not a registered address, the firmware 20 makes a negative determination in S35, proceeds to S43, and sets the permission state to "rejected". Also, the order of the determination in S34 of whether it is a private IP address and the determination in S35 of whether it is a registered address may be reversed. In this case, if the IP address of the requesting device is a registered address in S35 (YES in S35), proceed to S34 to determine whether the IP address of the requesting device is a private IP address. If the determination in S34 is affirmative, proceed to S42, and if the determination in S34 is negative, proceed to S43. If the determination in S34 and the determination in S35 are reversed, if the determination in S35 is affirmative, proceed to S42, and if the determination in S35 is negative, proceed to S43. In this case, the process of S34 may be omitted.
[0066] (Other embodiments) The image forming apparatus is not limited to the above-described embodiment, and various modifications are possible without departing from the spirit thereof. Although the MFP 10 has been described as an example of the image forming apparatus, the image forming apparatus may be a printer, a scanner, or a copier. Although the PC has been described as an example of the information processing apparatus, the image forming apparatus may be a mobile terminal such as a smartphone. [Explanation of symbols]
[0067] 10...MFC, 11...controller, 16...communication IF, 17...user IF, 30, 50, 51...PC, 100...image forming system
Claims
1. A user interface; A communication interface; A controller, The controller: when a first request is received from an apparatus connected via the communication interface, an approval screen is displayed on the user interface, and when an approval operation on the approval screen is received via the user interface, approval processing is executed to approve display of a remote screen, the first request is a request to display the remote screen, the remote screen is a screen that is displayed on the apparatus that has made the request for the first request and is a screen that virtually reproduces the user interface, The controller: executing a transmission process to transmit remote screen data to the request source device of the first request when the display of the remote screen by the approval process is approved, the remote screen data being data for displaying the remote screen on the request source device of the first request; when the controller receives, after the transmission process, an instruction indicating that a virtual operation using the remote screen has been performed from the request source device of the first request via the communication interface, the controller executes a predetermined process in response to the instruction; the approval process determines whether a communication address satisfies a specific condition, the communication address being an IP address used for communication with the request source device of the first request, and when it is determined that the communication address satisfies the specific condition, the approval process approves the display of the remote screen for the request source device of the first request without displaying the approval screen on the user interface. Image forming device.
2. A user interface; A communication interface; A controller, The controller: when a first request is received from an apparatus connected via the communication interface, an approval process can be executed to approve display of a remote screen on the apparatus that has issued the first request, the first request being a request to display the remote screen, the remote screen being a screen that is displayed on the apparatus that has issued the first request and that virtually reproduces the user interface; the controller executes a transmission process to transmit remote screen data when the display of the remote screen is approved by the approval process, the remote screen data being data for displaying the remote screen on a request source device of the first request; when the controller receives, after the transmission process, an instruction indicating that a virtual operation using the remote screen has been performed from the request source device of the first request via the communication interface, the controller executes a predetermined process in response to the instruction; In the approval process, it is determined whether or not a communication address satisfies a specific condition, and if it is determined that the communication address satisfies the specific condition, the display of the remote screen is approved for the device that originated the request of the first request, and if it is determined that the communication address does not satisfy the specific condition, the display of the remote screen is not approved for the device that originated the request of the first request, and the communication address is an IP address used for communication with the device that originated the request of the first request. Image forming device.
3. Equipped with a web server, when the controller receives a display request for a web page related to the image forming apparatus, the controller causes the web server to transmit web page data to the apparatus that has made the display request for the web page, the web page data being data for displaying the web page on the apparatus that has made the display request for the web page; The image forming apparatus according to claim 1 or 2, wherein after transmitting the web page data, when the controller receives the first request via the web page from the device to which the web page data is to be transmitted, the controller executes the approval processing using an IP address used for communication with the device that requested the first request.
4. An image forming device according to any one of claims 1 to 3, wherein in the approval process, an IP address of the image forming device is used as the communication address, and if the IP address of the image forming device is a private IP address, it is determined that the specific condition is satisfied.
5. The image forming apparatus is capable of registering IP addresses that are to be approved, An image forming device as described in any one of claims 1 to 4, wherein in the approval process, the IP address of the requesting device of the first request is used as the communication address, and if the communication address matches an IP address registered in the image forming device, it is determined that the specific condition is met.
6. The image forming device according to claim 5, wherein when the controller receives an operation via the user interface to specify an IP address to be permitted for approval, the controller registers the IP address received via the user interface in the image forming device as an IP address to be permitted for approval.
7. Equipped with a web server, when a request to display a registration page is received from a device connected via the communication interface, the controller transmits Web page data for displaying the registration page to the device that has made the request to display the registration page, the registration page being a Web page that accepts a registration operation of an IP address that is to be permitted for the approval; The image forming apparatus of claim 5, wherein when the controller receives an instruction to register an IP address to be permitted for approval from a device to which the Web page data is to be sent via the communication interface, the controller registers the IP address in response to the registration instruction, and administrator authentication is required to register the IP address.
8. An image forming device as described in any one of claims 1 to 7, wherein the approval process uses an IP address of the image forming device and an IP address of the device that made the request of the first request as the communication addresses, and if the IP address of the image forming device and the IP address of the device that made the request of the first request are addresses on the same LAN, it is determined that the specific condition is satisfied.
9. when the first approval process is set in the image forming apparatus to be invalid and the controller receives the first request from the requesting apparatus of the first request, the controller executes a second approval process as the approval process, the first approval process being a process for approving the requesting apparatus of the first request to display the remote screen without displaying the approval screen on the user interface when it is determined that the communication address satisfies the specific condition, and the second approval process being a process for approving the display of the remote screen when an approval operation on the approval screen is received via the user interface, The image forming apparatus according to claim 1 , wherein the controller performs a setting relating to validity of the first approval process on the image forming apparatus based on an operation accepted via the user interface.
10. Equipped with a web server, when the first approval process is set in the image forming apparatus to be invalid and an instruction to display the remote screen is received from the requesting apparatus of the first request, the controller executes a second approval process as the approval process, the first approval process being a process for approving the display of the remote screen for the requesting apparatus of the first request without displaying the approval screen on the user interface when it is determined that the communication address satisfies the specific condition, and the second approval process being a process for approving the display of the remote screen when an approval operation on the approval screen is received via the user interface, when the controller receives a request to display a Web page related to the approval process from a device connected via the communication interface, the controller causes the Web server to transmit Web page data to the device that has made the request to display the Web page, the Web page data being data for displaying a Web page indicating a screen for accepting a setting operation related to validity of the first approval process in the device to which the data of the Web page is transmitted; The image forming apparatus of claim 1, wherein after transmitting the Web page data, the controller sets the image forming apparatus to enable the first approval process based on a setting instruction regarding the enablement of the first approval process from the apparatus to which the Web page data is transmitted.
Citation Information
Patent Citations
Image processing apparatus, information processing apparatus, remote control method, and program
JP2006042309A
Information processing apparatus, method for controlling the same, and control program
JP2013117834A
Image forming apparatus, control method of remote control, computer program, and storage medium
JP2016045867A
Authentication system, electronic device, authentication method and authentication program
JP2016218521A
Printer and computer program
JP2017121761A