Communication system, information processing device, and program

The communication system addresses the risk of unintended data communication by detecting and restricting connections from unintended network devices, ensuring secure and efficient data transmission through the mobile communication network.

JP7679215B2Active Publication Date: 2025-05-19CANON KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021060817
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-31
Publication Date
2025-05-19
Estimated Expiration
2041-03-31

AI Technical Summary

Technical Problem

In communication systems where an information processing device is connected to a relay device via a local area network, there is a risk of unintended data communication when an unintended network device is connected, leading to excessive data transmission, communication speed restrictions, and security concerns.

Method used

A communication system that includes a relay device connected to a mobile communication network and an information processing device connected via a local area network, which detects connections from different information processing devices and transmits a request to change the operation settings of the relay device, restricting communication via the mobile network by shutting down the relay device.

Benefits of technology

This solution effectively suppresses the use of a mobile communication network by unintended network devices, preventing excessive data transmission, maintaining communication speed, and enhancing security by ensuring intended data communication only.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007679215000004
    Figure 0007679215000004
  • Figure 0007679215000005
    Figure 0007679215000005
  • Figure 0007679215000006
    Figure 0007679215000006
Patent Text Reader

Abstract

To provide a mechanism that prevents an unintended network device from using a mobile communication network in a communication system that is connected to the mobile communication network.SOLUTION: An information processing device of a communication system including at least a relay device connected to a mobile communication network and an information processing device connected to the relay device via a network sends a request to change an operational setting of the relay device when it is detected that an information processing device different from the relay device is connected to the network. The relay device restricts different information processing devices from communicating via the mobile communication network according to the reception of the request.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a communication system that performs data communication with an external device, Information processing apparatus and a program.

Background Art

[0002] When connecting an information processing device to an external network, a form is known in which an information communication device is connected to a relay device typified by a mobile router and a mobile phone line is used. Patent Document 1 discloses a technique for realizing end-to-end communication between information communication devices on different networks via a relay device and a mobile phone communication network (also referred to as a mobile communication network).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An information processing device such as an image forming apparatus is provided with a service that enables remote device management by transmitting device information to a device management server on the Internet. The device information transmitted by the image forming apparatus includes counter information (the number of sheets used by the image forming apparatus), the usage amount and remaining amount of consumables, and log information of the image processing apparatus.

[0005] For transmitting such device information, it is conceivable to use a relay device such as a mobile router. In this case, a communication system is constructed in which a relay device is connected to the information processing device, and communication is performed with the device management server via the relay device and the mobile communication network.

[0006] Here, an organization different from the vendor of the image forming apparatus, the sales company of the image forming apparatus, etc., and the end user who actually uses the image forming apparatus may conclude a service contract with a mobile communication network operator for the purpose of providing the above-described device management service and construct a communication system.

[0007] In this case, it is assumed that the vendor or the sales company concludes a data plan of a mobile communication network with low communication costs while satisfying the assumed data traffic, in view of both the maintenance cost of the device management service and the data traffic required for sending and receiving device information.

[0008] By the way, a general relay device such as a mobile router can connect a network device compliant with the IEEE802.3 series standard and a network device compliant with a standard such as IEEE802.11. Therefore, after constructing a communication system, if an unintended network device is connected to the relay device by a third party or the like, there is a risk that unintended data communication will be performed by the vendor or the sales company that bears the cost of the communication system.

[0009] When data transmission and reception are performed via an unintended relay device and a mobile communication network, data communication exceeding the assumption occurs, and problems such as restrictions on the communication speed of the mobile phone line and stoppage of communication occur, which may hinder the operation of the service. Also, from the security point of view, it is desirable to avoid unintended data communication by the subscriber of the mobile communication network.

[0010] The present invention has been made in view of at least one of the above problems. As one aspect of the present invention, an object is to provide a mechanism for suppressing the use of a mobile communication network of a router by an unintended network device triggered by detection of connection by an information processing device different from the router in a communication system.

Means for Solving the Problems

[0011] As one aspect of the present invention, in order to achieve at least one of the above objects, a communication system includes at least a relay device connected to a mobile communication network and an information processing device connected to the relay device via a local area network, wherein when the information processing device detects that a different information processing device is connected on the local area network, transmission means for transmitting a request to change the operation setting of the relay device having , and a restriction means for restricting communication of the different information processing device via the mobile communication network in accordance with receiving the request are provided. and wherein the request is a request to shut down the relay device, and the restricting means restricts communication via the mobile communication network by shutting down the relay device in accordance with receiving the request It is characterized by the above.

Effect of the Invention

[0012] As one aspect of the present invention, it becomes possible to suppress an unintended network device from using the mobile communication network of a router when a connection of a different information processing device from the router is detected.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. Note that the following embodiments do not limit the invention according to the claims, and not all combinations of features described in the embodiments are essential for the solution means of the invention.

[0015] <First Embodiment> Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. Note that the following embodiments do not limit the invention according to the claims, and not all combinations of features described in the embodiments are essential for the solution means of the invention.

[0016] <First Embodiment> First, the configuration of the communication system according to the present invention will be described with reference to FIG. 1. The communication system according to the present embodiment includes at least MFP101 and router 121. MFP101 is connected to mobile router 121 via LAN (Local Area Network) 120. In the present embodiment, it is assumed that MFP101 and router 121 are directly connected via an Ethernet (registered trademark) crossover cable to construct a two-unit LAN120, but it is not limited thereto. Router 121 provides Internet access to information processing devices connected to LAN120. MFP101 accesses servers and resources on Internet 131 via router 121 and mobile communication network 130 to transmit or receive data. In this way, router 121 functions as a relay device that provides Internet access via a mobile communication network such as CDMA, LTE, or 5G to information processing devices connected to LAN120, which is a local area network.

[0017] The MFP (Multi Function Peripheral) 101 has a scanning function of transmitting data based on an image obtained by reading using a scanner to the outside. It also has a printing function of printing an image on a sheet such as paper based on a print job received from an external device, and a copying function. In the present embodiment, as an example of an information processing apparatus constituting a communication system, the MFP 101 having a plurality of functions is illustrated, but it is not limited thereto. Devices such as a single-function scanner or printer may be used. Also, devices such as a 3D printer or 3D scanner may be used. Further, it can also be applied to a communication system including a device such as a vending machine that sells drinking water, a surveillance camera, a digital signage device, and a relay device.

[0018] The MFP 101 is provided with a device management function of transmitting device information to a device management server 132 on the Internet 131. The MFP 101 of the present embodiment transmits device information to the management server 132 via the LAN 120 and the router 121.

[0019] Also, the MFP 101 is connected to the LAN 110 and can communicate with a client computer on the LAN 110 or a client computer accessible to the LAN 110. For example, the MFP 101 can receive a print job from the client computer 111 and perform printing based on the print job.

[0020] <Hardware Configuration of MFP101> Subsequently, the hardware configuration of the MFP 101, which is an example of the information processing apparatus in the present embodiment, will be described with reference to FIG. 2. FIG. 2 is a block diagram showing the hardware configuration of the MFP 101.

[0021] The control unit 200 including the CPU (Central Processing Unit) 201 controls the operation of the entire MFP 101. The CPU 201 reads out a control program stored in the ROM (Read Only Memory) 202 or the storage 204, and performs various controls such as print control and read control. The ROM 202 stores a control program executable by the CPU 201. The RAM (Random Access Memory) 203 is a main memory accessed by the CPU 201, and is used as a work area or a temporary storage area for expanding various control programs. The storage 204 is a non-volatile storage area that stores print jobs, image data, various programs, and various setting information. The storage 204 is hardware such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive). Thus, the hardware such as the CPU 201, the ROM 202, the RAM 203, and the storage 204 constitutes a so-called computer. The storage 204 also stores connection information for communicating with the router 121 and a program for transmitting a request to the router 121.

[0022] In the MFP 101 of the present embodiment, it is assumed that one CPU 201 uses one memory (RAM 203) to execute each process illustrated in the flowchart described later, but other modes may be used. For example, a plurality of processors, memories, and storages may cooperate to execute each process described later. Also, some processes may be executed using a hardware circuit.

[0023] The printer I / F (interface) 206 connects the printer 220 (printer engine) and the control 200. The MFP 101 generates a print image and a print control command to be transferred to the printer 220 based on a print job received from a client computer via the LAN 110 or the like. The printer 220 prints an image on a sheet fed from a paper feed cassette (not shown) based on the print image and the print control command input via the printer I / F 206. The printing method may be an electrophotographic method in which toner is transferred to paper and fixed, or an inkjet method in which ink is ejected onto paper for printing.

[0024] The scanner I / F 207 connects the scanner 230 and the control unit 200. The scanner 230 reads a document placed on a document table (not shown) and generates image data. The image data generated by the scanner 230 can be printed by the printer 220, stored in the storage 204, or transmitted to a client computer via a network interface.

[0025] The operation unit I / F 205 connects the operation unit 210 and the control unit 200. The operation unit 210 is provided with a liquid crystal display unit having a touch panel function and various hard keys. The operation unit 210 functions as a display unit for displaying information to the user and a reception unit for receiving the user's instructions. The CPU 201 cooperates with the operation unit 210 to perform display control of information and reception control of user operations.

[0026] The network I / F 208 is an interface for connecting to a LAN. In this embodiment, the case where the MFP 101 is connected to the LAN 120 via the network I / F 208 is illustrated.

[0027] One end of a network cable is connected to the network I / F 208. The other end of the network cable is connected to the router 121, and a LAN 120 consisting of two devices, the MFP 101 and the router 121, is constructed. The MFP 101 can communicate with the router 121 on the LAN 120 via the network I / F 208. Also, the MFP 101 can communicate with a server on the Internet 131 via the router 121. In this embodiment, it is assumed that the network I / F 209 is a communication interface that connects a wired cable in the form of an RJ45 connector or a GG (GigaGate) 45 connector and performs communication compliant with Ethernet (registered trademark). However, it is not limited to this. The communication method at the physical layer for transmitting data to and from the router 121 may be a wireless communication method compliant with the IEEE802.11 series, etc.

[0028] A network cable is connected to the network I / F 209. The MFP 101 transmits image data and information to a client computer on the LAN 110 via the network I / F 209, or receives data such as a print job from a client computer on the LAN 110. Similarly for the network I / F 209, it is assumed that wired communication compliant with Ethernet is performed, but it is not limited to this. The communication method at the physical layer may be a wireless communication method.

[0029] Also, in this embodiment, as an example, the case where the MFP 101 has two network I / Fs is illustrated, but it is not limited to this. The MFP 101 only needs to have a network I / F for communicating with the router 121. Also, the MFP 101 may have three or more network I / Fs.

[0030] <Hardware Configuration of Router 121> Subsequently, the hardware configuration of the router 121, which is an example of the relay device in this embodiment, will be described with reference to FIG. 3. FIG. 3 is a block diagram showing the hardware configuration of the router 121.

[0031] The control unit 300 including the CPU 301 controls the operation of the entire router 121. The CPU 301 reads out the control program stored in the ROM 302 and executes various control processes. The RAM 303 is used as a temporary storage area such as the main memory and work area of the CPU 301.

[0032] One end of a network cable is connected to the network I / F 304. As described above, the other end of the network cable is connected to the MFP 101, and a LAN 120 consisting of two devices is constructed. The network I / F 304 is an interface to which an information processing device to be provided with Internet access is connected. In the present embodiment, it is assumed that the network I / F 304 is a communication interface that connects a wired cable in the form of an RJ45 connector or a GG45 connector and performs wired communication compliant with Ethernet (registered trademark), but it is not limited thereto. The communication method at the physical layer may be a wireless communication method. When using a wireless communication method, network parameters may be shared between the MFP 101 and the router 121 by a setup method such as WPS (Wi-Fi Protected Setup), and a wireless connection may be established. When the wireless connection is established, the router 121 functions as a DHCP server and assigns an IP address to the MFP 101. When the assignment is completed, a LAN 120 in which the router 121 and the MFP 101 participate is formed, and the MFP 101 can access the Internet via the LAN 120. Note that the IP address may be manually assigned as the operation setting of each of the router 121 and the MFP 101 without using a DHCP server.

[0033] The cellular modem 305 is a modem for performing data communication with a base station of the mobile communication network 130. The CPU 301 cooperates with the cellular modem 305 to control communication via the mobile communication network 130. Specifically described below. The router 121 has a SIM card (Subscriber Identity Module Card), not shown, installed. The SIM card is a card that stores an ID number (also called subscriber identification information) for identifying a subscriber lent by a carrier that provides a mobile communication service using the mobile communication network. The CPU 301 cooperates with the modem 305 to identify the mobile communication network to be connected based on the information stored in the SIM card, and performs processing for connecting to the mobile communication network. When the connection is completed, the router 121 enters a normal operating state in which it can provide Internet access via the mobile communication network 130 to the devices connected to the LAN 120. Note that the subscriber identification information required for the connection may be stored in an eSIM (embedded-SIM) incorporated in the router 121.

[0034] The communication system illustrated in FIG. 1 is constructed, for example, by the sales company of the MFP 101 or the vendor of the MFP 101 in order to use the router 121 for transmitting the device information of the MFP 101. A service engineer or an installer of the MFP 101 constructs the communication system. In this case, it is assumed that the sales company or the vendor of the MFP 101 often concludes a service contract with a carrier of a mobile communication service using the mobile communication network and constructs the communication system. The vendor or the sales company is assumed to contract a data plan of a mobile communication network with low communication costs while satisfying the assumed data traffic, in view of both the maintenance cost of the device management service and the data traffic required for transmitting and receiving device information. On the other hand, the router 121 can connect to a network device compliant with the IEEE802.3 series standard or a network device compliant with a standard such as IEEE802.11. Therefore, after constructing the communication system, if a network device not intended by a third party or the like is connected to the relay device, there may be a case where unintended data communication is performed by the vendor or the sales company that constructed the communication system and bears the cost.

[0035] Specifically, it will be described with reference to FIG. 6. FIG. 6 is a schematic diagram showing an example of a communication system to which a new network device is connected by a third party.

[0036] The difference from FIG. 2 is that a switch 600 and a client computer 601 are newly connected to the LAN 120. The switch 600 is a switching hub having a network distribution function. FIG. 6 illustrates the case where the switch 600 is inserted between the MFP 101 and the mobile router 121. Also, FIG. 6 illustrates the case where the client computer 601 is connected to the LAN 120 via the switch 600. The client computer 601 is an example of a newly connected network device that is not intended at the time of constructing the communication system. The client computer 601 connected to the LAN 120 via the switch 600 can perform Internet access via the path indicated by the broken line. When the physical layer of the LAN 120 is a wireless communication method, the client computer 601 is connected to the LAN 120 by a mechanism such as WPS described above.

[0037] When the connection illustrated in FIG. 6 is made, there may be a case where data transmission and reception are performed via an unintended relay device and a mobile communication network. In this case, data communication exceeding the assumption of the sales company or vendor of the MFP 101 may occur, and there is a risk of exceeding the upper limit of the data communication volume defined by the data plan agreed with the provider of the mobile communication service. In this case, problems such as limitation of the communication speed or stoppage of the communication itself may occur, which may hinder the operation of the service. Also, from the security perspective, it is desirable to avoid data communication that is not intended by the subscriber of the mobile communication network.

[0038] In view of the above problems, in the present embodiment, a mechanism is provided to suppress an unintended network device from using the mobile communication network in a communication system connected to the mobile communication network. This will be specifically described below.

[0039] FIG. 4(A) and (B) are diagrams showing an example of the software configuration of the MFP 101. FIG. 4(A) shows an overall view of software modules, and FIG. 4(B) shows details of the router control service 401. Each module shown in FIGS. 4(A) and (B) is realized by the CPU 201 executing a program corresponding to each module stored in the storage 204 or the like.

[0040] The control module 400 is a software module that controls the entire MFP 101 including a printer, a scanner, and the like. The control module 400 includes a router control service 401, a log management service 402, and a device management service 403. In FIG. 4(A), for the convenience of the drawing, the control module closely related to communication with the router 121 is extracted, and the illustration of the control module for printing processing, scanning processing, copy processing, etc. is omitted.

[0041] The router control service 401 is a module that provides a service for detecting a state in which unauthorized use may occur and issuing a request to the router. The router control service 401 detects communication devices that may be subject to unauthorized use, attempts to change the settings of the mobile router, and issues notifications such as warnings to the users of the MFP 101.

[0042] The log management service 402 is a service for managing corresponding log information such as the operations and setting changes of the MFP 101. When the control service 401 detects a state in which unauthorized use may occur, it requests the log management service 402 to record a log. The log management service 402 that has received the request stores the detected log. Note that the log management service 402 also stores corresponding logs when security-related errors occur in the MFP 101 or when data access to the MFP 101 occurs. The log management service 402 transmits the stored logs to a service that provides SIEM (Security Information and Event Management). Note that the service that provides SIEM may be a cloud service converted onto a cloud server, or may be an on-premises service installed on the network within the company where the MFP 101 is installed.

[0043] The device management service 403 is a service for transmitting the device information of the MFP 101 to the device management server 132. The device management service 403 transmits device information such as a part of the logs stored by the log management service 402 and counter information indicating the number of printed sheets on the MFP 101 to the device management server 132. The device management service 403 shall also transmit the status information of consumables represented by toner, ink, etc. used by the MFP 101 as device information to the server 132. The information transmitted to the server 132 is information for providing services to customers, such as the maintenance of the MFP 101, the delivery of consumables, and the calculation of usage fees. The device management service 403 transmits device information regularly (for example, every 12 hours). In the present embodiment, for the sake of explanation, it is assumed that the device management service 403 is operationally configured to transmit device information via the router 121 via the LAN 120.

[0044] On the other hand, it is assumed that the log transmission to the service that provides SIEM by the log management service 402 is operationally configured to be transmitted via the LAN 110.

[0045] FIG. 4(B) is a block diagram illustrating the functional configuration of the router control service 401. The communication monitoring unit 410 includes a router cooperation unit 420 and a UI control unit 430. The communication monitoring unit 410 monitors the communication on the LAN 120 and verifies whether the MFP 101 and devices other than the router 121 exist on the LAN 120, thereby detecting the presence of communication devices that may be used for purposes other than Internet access provided by the router 121.

[0046] The router cooperation unit 420 includes a router information management unit 421 and a router setting processing unit 422. The management unit 421 stores information regarding the router 121, such as the MAC address, IP address of the router 121, and the IP address used by the MFP 101 to communicate with the router. This information is set based on the operations of service engineers, installation workers, etc. when constructing the communication system illustrated in FIG. 1. Also, authentication information required for setting changes in the router 121, the capability information of the router, etc. are also stored in the management unit 421. Note that the method for setting information regarding the router 121 is not limited to this. The router cooperation unit 420 can also be configured to acquire setting information from the router 121 using SNMP (Simple Network Management Protocol) and store it in the management unit 421. In this case, the router cooperation unit 420 makes an inquiry to the MIB (Management Information Base) agent provided by the router 121 using a GetRequest operation or the like that specifies an object identifier indicating the desired information. The router 121 responds with device information specified based on the object identifier included in the inquiry. Thus, some or all of the information can also be dynamically acquired from the router 121.

[0047] The router setting processing unit 422 requests the router 121 to make setting changes or requests the router 121 to shut down. The setting processing unit 422 uses the SNMP SetRequest operation to request the mobile router 121 to make setting changes or change the operating state. Note that the method of requesting the router 121 is not limited to this. When the router 121 provides a Web API, setting changes or changes to the operating state may be requested via the Web API. Further, the MFP 101 may remotely connect to the router using a protocol such as SSH (Secure Shell) and remotely operate the router 121.

[0048] Subsequently, the software configuration of the router 121 will be described with reference to FIG. 5. FIG. 5 is a diagram showing an example of the software configuration of the router 121. Each module shown in FIG. 5 is realized by the CPU 201 executing a program corresponding to each module stored in the storage 204 or the like.

[0049] The communication control unit 500 controls data communication via the LAN 120 and the mobile communication network 130 in cooperation with the network I / F 304 and the cellular modem 305. FIG. 5 illustrates a case where the router 121 has a packet filtering unit 501 for performing packet filtering. The packet filtering unit 501 provides a function generally called a firewall. That is, the filtering unit 501 provides a packet filtering function for permitting or discarding packet communication according to specified rules. The setting service 510 is a module that stores the settings of the router 121 in the setting value DB 511, receives a setting change request or a shutdown request from the MFP 101, and updates or changes the settings and operation mode of the router 121. The method of receiving a request may be to use SNMP as described above, or to be configured to receive a request by providing a Web API. Also, it may be configured to directly receive a request from the MFP 101 using a remote connection via SSH. Based on the request received from the MFP 101, the setting service 510 changes the operation settings of the packet filtering unit 501, shuts down the router 121, and causes the router 121 to transition to a power-off state where it does not provide a relay function.

[0050] Subsequently, specific control in the MFP 101 will be described using the flowcharts of FIGS. 7 and 8. FIGS. 7 and 8 are flowcharts showing an example of network monitoring control in the information processing apparatus 103. Each operation shown in the flowchart of FIG. 7 is realized by reading a program for realizing each module described in FIG. 4 into the RAM 203 and executing it by the CPU 201. In order to clarify the subject of processing, each module will be described with the module as the subject as necessary. The flowchart of FIG. 7 is a flowchart excerpting a series of processing related to monitoring control when the MFP 101 operates in a normal state after the communication system is constructed.

[0051] Also, for the sake of explanation, assume a case where the communication system described with reference to FIG. 2 switches to the network configuration illustrated in the schematic diagram of FIG. 6. Also, it is described that each device constituting the communication system participates or will participate in LAN120 with the network addresses shown in Table 1.

[0052]

Table 1

[0053] In S701, the CPU 201 determines whether a network packet has been received in cooperation with the network I / F 208. If a network packet has been received, the process proceeds to S702. If no network packet has been received, the process proceeds to S711. In S711, the CPU 201 determines whether an instruction to turn off the power has been received. If an instruction to turn off the power has been received, a shutdown process (not shown) is executed, and a series of monitoring and control is terminated. On the other hand, if an instruction to turn off the power has not been received, a process of waiting for the reception of a further network packet described in S701 is executed.

[0054] In S702, the CPU 201 determines whether the received network packet is a network packet received via the network I / F 208. If it is determined that the network packet is received via the network I / F 208, the process proceeds to S704. If it is determined that the network packet is received via a network I / F different from the network I / F 208, the process proceeds to S705.

[0055] In S705, the CPU 201 executes processing corresponding to the received network packet. For example, if the received network packet is a packet for transmitting print data, the CPU 201 receives the print data based on the packet and subsequent packets. Subsequently, the CPU 201 prints an image on a sheet based on the received print data. Also, for example, in the case of a discovery packet for discovering the MFP 101, the MFP 101 transmits a response to the discovery to the external device that is the request source. If the received network packet is a packet for a scan request, the CPU 201 cooperates with the scanner 230 to read a document placed on a document table (not shown) and generate image data. Subsequently, the CPU 201 generates a file (such as a PDF file or a JPEG file) including the generated image data and transmits the file to the external device that is the request source. When the processing in S705 is completed, the CPU 201 proceeds with the processing to S701 and waits for reception of further packets.

[0056] In S703, the communication monitoring unit 410 analyzes the received packet and acquires information indicating the source MAC address. Subsequently, in S704, the monitoring unit 401 determines whether the source MAC address acquired in S703 matches the MAC address of the router 121 managed by the information management unit 421. If it is determined that the source MAC address matches the MAC address of the router 121 managed by the information management unit 421, the processing proceeds to S705, and if it is determined that they do not match, the processing proceeds to S707.

[0057] Supplement the determination of S704. When a new network device with a MAC address different from that of the router 121 is connected to the LAN provided by the router 121, packets such as ARP packets and various other packets are broadcast to the LAN that is the same segment. The MFP101 listens to this packet and can detect the participation of a new network device by monitoring whether it contains something other than the router 121. Therefore, for example, when the MFP101 receives a packet with the source MAC address set to 00-00-5E-00-53-C1 corresponding to the computer 601, the control after S706 will be executed. That is, the process of S704 can be rephrased as a process of determining whether a new device has joined the LAN120.

[0058] Note that in this embodiment, the monitoring unit 410 is assumed to obtain raw data including the header information of the received packet using a Raw socket and perform analysis, but it is not limited to this. For example, a firewall module represented by iptables can be provided in the MFP101, and the monitoring unit 410 and the firewall module can be configured to cooperate for monitoring. In this case, the CPU 201 sets a rule as the setting of the firewall module to output a log when a received packet that meets the conditions that the receiving IF is the network I / F 208 and the source MAC address is different from that of the router 121 is detected. With this setting, a log will be left when a new network device joins the LAN120. In this case, instead of the real-time monitoring process described in S701 - S704, the monitoring unit 410 periodically checks whether the log of a terminal having a MAC address different from the MAC address of the mobile router 121 is recorded. If it is determined from the result of the check process that the log of a terminal having a different MAC address is recorded, the process after S707 is performed.

[0059] Returning to the description of FIG. 7, in S707, the monitoring unit 410 requests the router cooperation unit 420 to change the settings of router 121. The cooperation unit 420 that has received the request cooperates with the management unit 421, the setting processing unit 422, and the network I / F 208 to request the router to change the settings.

[0060] Subsequently, the request processing to the router executed by the router cooperation unit 420 will be described with reference to FIG. 8. In S801, the router cooperation unit 420 acquires the information of router 121 from the management unit 421, and based on the information, determines whether the connected router has a packet filtering ring function. If it is determined that the router has a packet filtering function, the setting processing unit 422 is requested to set the filtering rules, and the process proceeds to S802. If it is determined that the router does not have a packet filtering function, the setting processing unit 422 is requested to shut down the router, and the process proceeds to S803.

[0061] In S802, the setting processing unit 422 sends a request to router 121 to add the filtering rules of the MAC filter exemplified in Table 2.

[0062]

Table 2

[0063] The setting service 510 of router 121 that has received the request stores the setting in the setting DB 511. Further, the setting service 510 of router 121 changes the default policy of the packet filtering unit 501 to a reject setting, and sets the MAC address of MFP101 in the reject exception list. The setting of this setting service 510 is performed using, for example, the iptables command. The packet filtering unit 501 of router 121 controls the communication on the LAN 120 side based on this setting, and discards the packets received from the LAN 120 or relays the packets to the mobile communication network. Due to this request for setting change, newly connected unintended network devices cannot communicate beyond router 121.

[0064] Returning to the description of FIG. 8, in S803, the setting processing unit 422 sends a remote shutdown request to the router 121. The router 121 that has received the shutdown request executes a shutdown process and transitions to the power-off state. By this shutdown request, when an unintended network device newly connected is connected, all communications beyond the router 121 can be made inoperable by stopping the operation of the router 121 itself.

[0065] In S804, the setting processing unit 422 receives the result of the request from the router 121 and notifies the cooperation unit 420 of the received result. The cooperation unit 420 stores the result in the router information management unit 421 and notifies the monitoring unit 410 that is the request source of the result. When the result storage and notification processing are completed, the CPU 201 proceeds to S708 in FIG. 7.

[0066] Returning to the description of FIG. 7, in S708, the monitoring unit 410, in cooperation with the UI control unit 430 and the operation unit 210, displays a warning message corresponding to the result on the operation unit 210. Details of the warning message will be described later.

[0067] In S709, the communication supervision unit 510 requests the log management service 402 to generate a log indicating the possibility of unauthorized use of the router 121 and the corresponding handling result. The log management service 402 that has received the generation request generates a security log and records it on the storage 204.

[0068] In S710, the device management service 403 detects the writing of logs and transmits the log information to the device management server 132 and the SIEM service. Note that the timing of transmitting the security logs to the device management server 132 is not limited to this. For example, it may be transmitted at the timing of periodically transmitting device information. Also, when shutting down the router 121 in S803, it may be configured to transmit in advance the possibility of unauthorized use and the fact that the router 121 is scheduled to be shut down before executing the process of S803.

[0069] Note that one of the purposes of the SIEM service is to detect security incidents in real time. Therefore, in this embodiment, the security logs shall be transmitted to the SIEM service at the timing of S710.

[0070] Finally, the warning message will be described with reference to FIG. 9. FIGS. 9(A) to (C) are diagrams showing an example of the warning message displayed on the operation unit 210.

[0071] The message 800 in FIG. 9(a) is an example of a message displayed when the result of the request process indicates that the addition of a filtering rule to the router 121 was successful. By checking this message, a user such as an administrator can understand that an event that could lead to a security incident has occurred. Also, by checking the operation unit 126 for a user who made an unintended connection described in FIG. 6, it can be understood that the router 121 cannot be used except by the MFP 101.

[0072] The message 801 in FIG. 9(b) is an example of a message displayed when the result of the request process indicates that a shutdown request was made. By checking this message, a user such as an administrator can understand that an event that could lead to a security incident has occurred. Also, it can notify the user that the state has transitioned to a state where communication via the router is unavailable.

[0073] The message 802 in FIG. 9(C) is an example of a message to be displayed when the result of the request process indicates a failure or no response, etc. By checking this message, a user such as an administrator can understand that an event that may lead to a security incident has occurred. Also, it is possible to notify the user that it is necessary to review the settings.

[0074] Note that the content of the warning message is not limited to this. For example, the content of the message may be displayed in a simplified manner to the extent of notifying an error code or that there is a problem with the network.

[0075] As described above, according to this embodiment, in a communication system connected to a mobile communication network, it becomes possible to suppress an unintended network device from using the mobile communication network.

[0076] Also, in the above-described embodiment, processing for utilization suppression is performed at the timing when the connection form illustrated in FIG. 6 is changed. Therefore, it is possible to save the labor of a maintenance engineer from statically performing packet filtering settings for the router 121 as an initial setting.

[0077] Also, an event may occur in which the MAC address of the network I / F connected to the LAN 120 changes, such as a board replacement due to maintenance of the MFP 101 or a change in the interface used for connection. On the other hand, when the router 121 is restarted, the filtering rules described in FIG. 8 are discarded and reset to the default filtering rules according to the configuration file. Therefore, even if the MAC address used by the MFP 101 for connection to the LAN 120 changes, there is an effect that the communication system can be reconstructed without changing the settings on the router 121 side just by restarting the router 121.

[0078] <Modification Example> In addition to the processing of S704, a process of determining whether the source MAC address of the received packet received from I / F208 matches the MAC address of MFP101 may be added. When adding this process, if it is determined that the source MAC address of the received packet received from I / F208 matches the MAC address of MFP101, MFP101 may be controlled to transmit the shutdown request described in S803. By adding this process, it becomes possible to appropriately suppress the use even in a case where a network device with the source MAC address spoofed to, for example, "00-00-5E-00-53-CA" is newly connected.

[0079] Furthermore, in the device management server 132 or the SIEM service that has received the log information transmitted in S710, it is also possible to detect the possibility of unauthorized use and perform a line stop process for the router 121. The server 132 or the SIEM service that has received the log information transmits a request to stop the communication using the SIM card installed in the router 121 or the eSIM incorporated in the router 121 to the server of the mobile communication service. The request includes subscriber identification information for uniquely identifying the SIM card or eSIM. The server that has received the request updates the authentication information held by the base station of the mobile communication network or the backend server connected to the base station so that the SIM card or eSIM cannot be connected to the mobile communication network. In this case, the device management server 132 may further transmit the above-described stop (interruption) request when the regular communication of the device information from MFP101 has stopped and a certain period of time has elapsed. By performing this control, unauthorized use can be suppressed even when the router 121 is taken away or the like.

[0080] Furthermore, in the present embodiment, as an example, the default policy is set to reject, and a filtering rule for setting the MAC address of MFP101 as an exception to the rejection is exemplified, but it may be modified to the addition of the rules exemplified in Table 3.

[0081]

Table 3

[0082] The rule shown in Table 3 indicates that the default policy is permission, and as an exception to the permission, it shows setting the MAC address of the computer 601, which is a newly connected network device. By adding this rule as well, a similar effect can be obtained. Also, in the above-described embodiment, the case where access restriction is performed using the MAC address as an example of the identification information for identifying the network device has been illustrated, but it is not limited thereto. For example, an IP address may be used as the identification information for identifying the network device. In this case, the same type of rule may be added with an IP address filter.

[0083] Furthermore, for the purpose of troubleshooting, etc. when initial installation or communication trouble occurs, etc., the suppression function may be temporarily turned off by the operation of the maintenance user. Also, a function for initializing the filtering setting of the router 121 by the operation of the maintenance user, etc. may be provided. In this case, the MFP 101 may be configured to display an operation screen for turning off or initializing the suppression function only when a special operation disclosed only to the maintenance user is received.

[0084] Furthermore, in order to reduce the possibility of attaching a device having a hub function such as the switch 600, an instant adhesive or the like for adhering the connector end and the acceptor to restrict attachment and detachment may be packaged as an accessory of the MFP 101. The MFP 101 displays a setting screen for assisting in constructing a communication system including the router 121 and the MFP 101 via it. A service engineer or an installation worker changes the setting of the IP address for communicating with the router 121 and other operation settings of the MFP 101 via the setting screen. The MFP 101 attempts to connect to the Internet 131 based on the settings made by the service engineer or the installation worker. Further, the MFP 101 displays a screen prompting to adhere one end of the cable to the router 121 and the other end of the cable to the MFP 101 in accordance with the successful connection to the Internet 131. Note that the screen may include a message prompting to fix the router 121 itself to the MFP 101.

[0085] When constructing a communication system consisting of the MFP 101 and the router 121, a service engineer or an installation worker can perform construction work to suppress attachment and detachment and the removal of the router 121 using the instant adhesive which is the accessory. Further, since a message prompting adhesion is displayed in accordance with the successful connection to the Internet 131, it is possible to suppress forgetting the construction work. By performing this process, it is possible to increase the psychological and physical hurdles for users who try to make unauthorized use, and further suppress the possibility of unauthorized data communication.

[0086] <Other Embodiments> The present invention can also be realized by supplying a program for realizing one or more functions of each of the above-described embodiments to a system or an apparatus via a network or a storage medium, and causing one or more processors in a computer of the system or the apparatus to read and execute the program. Further, it can also be realized by a circuit (for example, ASIC or FPGA) for realizing one or more functions.

Description of Reference Numerals

[0087] 101 MFP 121 Router 201 CPU

Claims

1. A communication system including at least a relay device connected to a mobile communication network and an information processing device connected to the relay device via a local area network, a transmission means for transmitting a request to change an operation setting of the relay device when the information processing device detects that an information processing device other than the relay device is connected to the local area network; a restriction means for restricting communication between the different information processing devices via the mobile communication network in response to reception of the request by the relay device; having The request is a request to shut down the relay device, and the restriction means, upon receiving the request, restricts communication via the mobile communication network by shutting down the relay device.

2. A communication system including at least a relay device connected to a mobile communication network and an information processing device connected to the relay device via a local area network, a transmission means for transmitting a request to change an operation setting of the relay device when the information processing device detects that an information processing device other than the relay device is connected to the local area network; the relay device has a restriction means for restricting communication between the different information processing device and the different information processing device via the mobile communication network in response to receiving the request; A communication system characterized in that, when predetermined conditions are satisfied, a second transmission step is executed in which information identifying the subscriber and a request to suspend use are transmitted to a server of a provider that provides mobile communications services using the mobile communications network to which the relay device is connected.

3. the communication system includes a device management server that manages the information processing device; the information processing device further comprises a third transmission means for transmitting information indicating that an information processing device other than the relay device is connected to a device management server; The communication system described in claim 2, characterized in that the specified condition is satisfied when the equipment management server receives information indicating that a different information processing device has been connected, and the transmission of the request to interrupt in the second transmission process is executed by the equipment management server.

4. The communication system according to claim 2 or 3, characterized in that the request is identification information of the information processing device and a request to set in the relay device a packet filtering condition that allows transmission and reception of packets to the information processing device identified by the identification information, and does not transmit or receive packets to a different information processing device via the relay device.

5. 5. The communication system according to claim 4, wherein the identification information is a MAC address or an IP address of the information processing device.

6. The control method according to claim 2 or 3, characterized in that the request is a request to shut down the relay device, and the restricting means, upon receiving the request, restricts communication via the mobile communication network by shutting down the relay device.

7. The communication system according to any one of claims 1 to 6, characterized in that the information processing device further has a notification means for making a predetermined notification when it detects that an information processing device other than the relay device has been connected to the local area network.

8. 8. The communication system according to claim 1, wherein the information processing device is a printing device that prints an image on a sheet.

9. 9. The communication system according to claim 1, wherein the information processing device and the relay device are connected by a wired cable.

10. The communication system according to claim 9, further comprising a display control means for displaying on a display unit of the information processing device a screen prompting the user to attach one end of the wired cable to the information processing device and to attach the other end of the wired cable to the relay device after a local area network consisting of the information processing device and the relay device has been constructed.

11. An information processing device connected to a relay device connected to a mobile communication network via a local area network, a transmitting means for transmitting to the relay device a request for operating the relay device so as to restrict communication by the different information processing device through the mobile communication network when it is detected that an information processing device different from the relay device is connected to the local area network; The information processing device is characterized in that the request is a request to shut down the relay device, and the relay device, upon receiving the request, shuts down the relay device, thereby restricting communication via the mobile communication network.

12. An information processing device connected to a relay device connected to a mobile communication network via a local area network, a transmitting means for transmitting to the relay device a request for operating the relay device so as to restrict communication by the different information processing device through the mobile communication network when it is detected that an information processing device different from the relay device is connected to the local area network; An information processing device characterized in that, when predetermined conditions are met, information identifying the subscriber and a request to suspend use are transmitted to a server of a provider that provides mobile communications services using the mobile communications network to which the relay device is connected.

13. 13. A program for operating a computer of an information processing device as each of the means of the information processing device according to claim 11 or 12.

Citation Information

Patent Citations

  • Method for automatic modification of ip addresses and router device capable of the same

    JP2002330155A

  • Remote control system, measuring system, and program for remote control system

    JP2019062495A

  • Network system

    JP2019083446A

  • Network monitoring device, network monitoring method, network monitoring program, and network monitoring system

    JP2019102862A

  • Management of mobile hotspot connections

    US20110294502A1