Information processing device, control method thereof, and program
The information processing apparatus addresses the challenge of multiple users with different VPN requirements by implementing a customizable socket API package management system, allowing each user to set appropriate network connections for their applications, thereby enhancing flexibility and security.
Patent Information
- Application Number
- JP2021021060
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-02-12
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-02-12
AI Technical Summary
Conventional image forming apparatuses cannot handle situations where each user and application require different network connections, including the use of specific Virtual Private Networks (VPNs), due to limitations in their application platforms.
An information processing apparatus with a communication means for each application, allowing users to set connection destinations for each application via a customizable socket API package management system, ensuring that each application communicates using the appropriate network connection settings for the logged-in user.
Enables each user to connect their applications to the desired network, whether local or through a specific VPN, enhancing flexibility and security by ensuring that each application uses the appropriate network settings, thus addressing the limitations of conventional systems.
Smart Images

Figure 0007681982000004 
Figure 0007681982000005 
Figure 0007681982000006
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing apparatus, a control method thereof, and a program, and more particularly to an application platform for embedded applications executed on, for example, an image forming apparatus connected to a network. [Background technology]
[0002] An application platform is used for executing an application configured to operate on an image forming apparatus connected to a network on the image forming apparatus. Conventionally, in such an application platform, the application can generally communicate only with a local network to which a network interface of the image forming apparatus is connected. Alternatively, a proxy server may be installed in the local network, and the application may be able to connect to a wide area network through the proxy server. Alternatively, if the network interface is directly connected to the wide area network, the application may also be able to connect to the wide area network. If the network interface is connected to a Virtual Private Network (VPN) router that mediates VPN connections, it may be possible to connect to a VPN such as an internal network of a different location through a VPN connection provided by an organization such as a company.
[0003] In addition, conventionally, there are cases where an image forming apparatus has two or more network interfaces. In such cases, a technology has been proposed that provides settings for each user to determine which network interface an application will use for communication based on the settings (see Patent Document 1).
[0004] Also, a technology has been proposed in which a VPN agent and a VPN client are resident on various user devices, not limited to image forming devices, and associated with a user application. In the technology, a technology has been proposed in which the VPN agent intercepts the communication traffic of the associated user application, and a communication channel with a corporate network is established through a VPN tunnel using the VPN client (see Patent Document 2). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Patent No. 5550297 [Patent Document 2] Patent No. 5620400 Summary of the Invention [Problem to be solved by the invention]
[0006] On the other hand, in recent years, there are cases where an image forming device placed in a shared office space is shared by multiple users belonging to different organizations. In such a situation, it is common that applications installed on the image forming device are only provided with access to the Internet via a local network in the office or a proxy server. However, some users may require that they use a VPN provided by the organization to which they belong to connect to the organization's network for use with certain applications.
[0007] For example, consider the case of sending a scanned document by email. In this case, using a mail server on the local network of a shared office space may not be permitted due to the risk that the contents of the document may be read by the administrator of the mail server. Therefore, a user may want to connect to the network of the organization he or she belongs to in a remote location and send email using a mail server located on that network. In this way, the requirements for which applications to connect to which VPNs may differ from user to user.
[0008] In this case, a first user using the shared office space may want to connect the first application to the VPN of his / her organization while using the second application on a local network. Furthermore, a second user using the same shared office space may want to connect the first application to the VPN of his / her organization, which is a different organization from the first user. In the above example of the mail server, the mail server that the first user wants to connect to and the mail server that the second user wants to connect to are on different organization networks, and different VPN settings are required to connect them.
[0009] In this way, it is possible to imagine a situation in which, for each application, which network to connect to, whether a VPN needs to be used, and which VPN to connect to differ for each user. There are situations in which the network to connect to differs for each user and each application. However, there is a problem in that application platforms that operate on conventional image forming apparatuses cannot handle such situations.
[0010] The present invention has been made in consideration of the above-mentioned conventional examples, and has an object to provide an image forming apparatus, a control method thereof, and a program therefor, which enable connection to a desired network for each user and each application. [Means for solving the problem]
[0011] In order to achieve the above object, the present invention has the following configuration. That is, according to one aspect of the present invention, Multiple An information processing device capable of executing a number of applications, The above Multiple a communication means for providing a communication function for each of the plurality of applications; For each user, Multiple For each of the applications, Multiple a setting means for setting a connection means for each of the applications to connect to a respective connection destination via the communication means, The above Multiple Each of the applications communicates using the connection means set for the logged-in user. The present invention provides an information processing apparatus comprising: Effect of the Invention
[0012] According to the present invention, the image forming apparatus can connect to a desired network for each user and each application. [Brief description of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of an embodiment of the present invention. [Diagram 2] FIG. 11 illustrates an operation of a login processing module according to the embodiment of the present invention. [Diagram 3] FIG. 2 is a diagram illustrating a configuration related to a class loader according to an embodiment of the present invention. [Figure 4] FIG. 11 illustrates an operation of a logout processing module according to the embodiment of the present invention. [Diagram 5] FIG. 11 is a diagram illustrating an operation of a login processing module according to the second embodiment of the present invention. [Figure 6] FIG. 11 is a diagram illustrating an operation of a logout processing module according to the second embodiment of the present invention. [Figure 7]FIG. 2 is a diagram illustrating a hardware configuration of an image forming apparatus, focusing on a controller unit. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] (First embodiment) Hereinafter, the embodiments will be described in detail with reference to the attached drawings. Note that the following embodiments do not limit the invention according to the claims. Although the embodiments describe a number of features, not all of these features are essential to the invention, and the features may be combined in any manner. Furthermore, in the attached drawings, the same reference numbers are used for the same or similar configurations, and duplicated descriptions are omitted.
[0015] Hardware Fig. 7 shows the hardware configuration of an image forming apparatus of this embodiment, for example, a multi-function copier (MFP) 101. In Fig. 7, a control unit 102 including a CPU 1012 controls the operation of the entire printing apparatus 101. The CPU 1012 reads out a control program stored in a ROM 1014 and performs various controls such as communication control. A RAM 1013 is used as a temporary storage area such as the main memory and work area of the CPU 1012. A HDD 1023 stores data, various programs, or various information tables.
[0016] The printer I / F 1016 serves as an interface for outputting an image signal to a printer 1017 (printer engine) that forms an image. The scanner I / F 1018 serves as an interface for inputting a read image signal from a scanner 1019 (scanner engine) that reads an image. The CPU 1012 processes the image signal input from the scanner I / F 1018 and outputs it to the printer I / F 1016 as a recording image signal.
[0017] An operation panel I / F 1020 connects an operation panel 1021 to the control unit 1011. The operation panel 1021 is provided with a liquid crystal display unit having a touch panel function, a keyboard, and the like.
[0018] The network I / F 1022 is connected to a network such as a LAN, and transmits information to external terminals such as a client device or a cloud print registration service, or receives various information from these external devices. The network I / F 1022 provides the image forming apparatus with a communication function via software such as a socket API (socket application program interface) shown in FIG. 1. The blocks in the control unit 1011 are connected to each other via a system bus 1015.
[0019] This image forming apparatus can also be called an information processing apparatus, focusing on its communication and information processing functions.
[0020] System Configuration 1 shows the overall system configuration of the first embodiment of the present invention. Network 100 is a network within a shared office space. In general, in a shared office space, infrastructure such as desks and networks are provided, and multiple users who have individually signed contracts carry out their work within that environment. At this time, it is assumed that these users include people who belong to different organizations and people who work as freelancers, and they use the same image forming apparatus, etc.
[0021] Image forming apparatus 101 is the image forming apparatus shown in Fig. 7. In this embodiment, an example of the image forming apparatus is a so-called multifunction device that includes units such as a printer, a scanner, and a facsimile. Image forming apparatus 101 installed in a shared office space is connected to a network 100 in the shared office space, and is shared by users for purposes such as copying, scanning, printing, and sending and receiving facsimiles.
[0022] The controller 102 is a unit equipped with an information processing function for comprehensively controlling various units of the image forming apparatus 101. The controller 102 has a central processing unit (hereinafter, CPU), a random access memory (hereinafter, RAM), a read-only memory (hereinafter, ROM), a storage, and the like. The controller 102 is the same as the control unit 102 in FIG. 7. A hard disk drive (hereinafter, HDD), a solid state drive (hereinafter, SSD), or the like is used as the storage. The procedure shown below in the form of a flowchart is stored in the storage unit of the RAM, ROM, or storage of the controller 102, and is executed by the CPU.
[0023] The application platform 103 runs on the controller 102. The application platform 103 provides an application execution environment and an application management function for running one or more of the applications 104, 105, and 106. The applications 104, 105, and 106 are application programs that run on the application platform 103, and are referred to as applications here. Note that although three applications are illustrated here, the number of applications may be less or more than this.
[0024] When an application runs, it uses an application standard API 107, which is a standard API provided by the application platform 103. Note that here, the platform standard API 107 refers to one that does not include the standard socket API package 108. The standard socket API package 108 is usually treated as a part of the platform standard API 107, but in this embodiment, it is treated as a socket API package with a special position among multiple socket API packages.
[0025] The customized socket API package 109 is a customized socket API package designed to provide an API compatible with the standard socket API package 108. The customized socket API package 109 is not necessarily limited to being arranged only one, and a plurality of customized socket API packages 109 may be arranged. For example, the first customized socket API package 109 implements a protocol capable of executing communication with a first VPN implementation. In this case, the second customized socket API package 109-2 may implement a protocol capable of executing communication with a second VPN implementation different from the first VPN implementation. Alternatively, the plurality of customized socket API packages 109 may have the same VPN implementation. The customized socket API package 109 may include connection destination information and authentication information, and may be connectable only to a specific deployed VPN infrastructure. In this case, even if the VPN infrastructure is the same implementation, if authentication information corresponding to each connection destination is required, it may be necessary to prepare a separate customized socket API package 109 for each connection destination.
[0026] In this way, a socket API package management module 111 is provided to arrange and manage the standard socket API package 108 and one or more customized socket API packages 109. The socket API package management module 111 has a function of making the standard socket API package 108 available. The socket API package management module 111 also has a function of enabling installation in order to arrange and make available the customized socket API package 109. The socket API package management module 111 also has a function of enabling uninstallation in order to remove the customized socket API package 109 that is no longer necessary from the application platform 103. The socket API package management module 111 also has a function of enabling use of the currently installed customized socket API package 109.
[0027] The user management module 112 registers users who will use the applications 104, 105, and 106 on the application platform 103, and manages their authorities. In this embodiment, the user management module 112 also manages user groups to which the users belong.
[0028] ●Socket API association settings The socket API association setting management module 113 is a module for associating socket APIs. The socket API association settings managed by the socket API association setting management module 113 will be described with examples.
[0029] As a first example, consider a situation where a plurality of users, for example, three users, are registered by the user management module 112. Here, these users are referred to as user 1, user 2, and user 3. Also, assume that three applications 104, 105, and 106 are installed in the application platform 103 of the image forming apparatus 101 in this example. Furthermore, assume that three customized socket API packages 109 are installed in addition to the standard socket API package 108 in the application platform 103 of the image forming apparatus 101 in this example. These packages are represented as customized socket API packages 109-1, 109-2, and 109-3. The socket API package management module 111 manages the registration, deletion, and change of registered contents of such a plurality of customized socket API packages 109.
[0030] Table 1 below is a socket API management table for managing socket API association settings when settings are held for each user in this example. This is also called a socket API association setting. This table is stored in, for example, a storage device of the controller 102.
[0031] [Table 1]
[0032] In Table 1, the settings indicated as "default" are those that the socket API association setting management module 113 holds as associations between applications and socket API packages when no user is logged in. Also, when a new user is registered, the socket API association setting management module 113 copies the default settings and uses them as initial values. The socket API association setting management module 113 manages the addition, deletion, modification, etc. of such settings.
[0033] The settings shown as "User 1" in Table 1 are the settings for user 1. It shows that while user 1 is logged in, application 104 is set to use customized socket API package 109-1 as the socket API package. Also, application 105 and application 106 are set to use standard socket API package 108.
[0034] Similarly, the remaining portions of Table 1 are the settings for User 2 and User 3, respectively. The socket API association setting management module 113 has the functionality to manage settings by creating, modifying, and deleting settings as described herein.
[0035] As a second example, a case will be shown in which the user management module 112 has user group settings. In this example, six users, User 1 to User 6, are registered as a user group. The applications and socket API packages are assumed to be the same as those in the first example. In the second example, user groups exist, and it is assumed here that User Group 1, User Group 2, and User Group 3 are registered. Table 2 shown below is a user group setting table. This table is stored, for example, in a storage device possessed by the controller 102.
[0036] [Table 2]
[0037] This is a table for managing which user group each user belongs to. In this example, the user management module 112 manages user group settings that hold information on users, user groups, and user groups to which users belong. Table 2 shows that user 1 belongs to user group 1. Similarly, user 2 and user 4 also belong to user group 1. Furthermore, it shows that user 5 belongs to user group 2, and user 3 and user 6 belong to user group 3.
[0038] The user management module 112 manages the registration, deletion, modification of registered contents, etc. of individual users. In addition, if the application platform 103 has a user group setting such as that shown in Table 2, the user management module 112 also manages the setting.
[0039] The following Table 3 is a socket API management table that holds settings that specify which application and which socket API package are to be combined for each user group when managing settings using users and user groups. This is also called a socket API association setting. This table is stored in, for example, a storage device of the controller 102.
[0040] [Table 3]
[0041] "Default" indicates the association setting between the application and the socket API package when the user is not logged in. When a new user group is registered by the user management module 112, the socket API association setting management module 113 copies and uses this default setting entry as the initial setting for the new user group.
[0042] "User Group 1" indicates the settings for user group 1. While a user belonging to user group 1 is logged in, application 104 is set to use customized socket API package 109-1. In other words, this setting is valid for users 1, 2, and 4. Similarly, while these users are logged in, application 105 and application 106 are set to use standard socket API package 108.
[0043] Continuing on from Table 3, similarly, are the settings for user group 2 and user group 3. Here, it is assumed that user 1, user 2, and user 4 belong to the same organization, and this is reflected in the user group settings (Table 2). Here, it is assumed that users belonging to the same organization have the same combinations of applications 104, 105, and 106 and socket API packages, and that the method of using the image forming apparatus 101 is also common.
[0044] Only user 5 belongs to user group 2, but an implementation that allows a situation in which only one user belongs to one user group may be considered. Also, for users who are not explicitly assigned to a user group, an implementation that automatically generates and applies a virtual user group may be considered. Also, as such a user group, a default user group may be prepared in advance, and default settings may be applied.
[0045] The login processing module 114 executes login processing when a user belonging to a user group registered and managed by the user management module 112 performs a login operation on the image forming apparatus 101. The logout processing module 115 executes logout processing when a user belonging to a user group registered and managed by the user management module 112 performs a logout operation on the image forming apparatus 101.
[0046] The operating system 116 provides a software foundation necessary for the application platform 103 to operate on the controller 102. The network interface 117 is a network interface for the application platform 103 to communicate with other network nodes in the network 100 in the shared office space. The local network 118 is a local network installed in the network 100 in the shared office space. The proxy server 119 is used when a network device connected to the local network 118, including the image forming apparatus 101, connects to an external network from the network 100 in the shared office space. The wide area network 120 is a wide area network to which the network 100 in the shared office space is connected via the proxy server 119. The intra-organization network 121 is a network of an organization to which any user belongs. The VPN gateway 122 is configured to be open to the wide area network 120 by the intra-organization network 121 and to be able to connect from the wide area network 120 side using a VPN client. The intra-organization local network 123 is a local network in the intra-organization network 121 that is mutually connected to the wide area network 120 via a VPN gateway 122 .
[0047] ● Management process for API association settings The management process of the socket API association settings shown in Tables 1 and 3 will be described. The socket API association settings can also be said to be settings of the connection destination of the application used for each user. This management may be performed, for example, by the socket API association setting module 113 displaying a management screen as a user interface for management in response to the operation of the operation panel 1021, and in response to a setting instruction input by the user via the management screen. In this case, for example, an administrator may log in with administrator authority and register, delete, or change the association of the socket API with the administrator authority. User groups, which will be described later, may also be managed in a similar manner.
[0048] On the management screen, for example, when user identification information is input, identification information of the socket API package for each application set for the user is displayed. If no association has been made, a message to that effect is displayed. Then, for example, when a change is instructed for a selected application, a list of configurable socket API packages is displayed, and one selected from the list is associated with the newly selected application and saved. When a deletion is instructed, identification information of the socket API package associated with the selected application may be deleted. When association is made for each user group, a socket API package may be associated with each application for each user group instead of for each user.
[0049] You can also set defaults that are not associated with any user. You can add, change, or delete default socket API packages for the default settings in the same way as for user settings.
[0050] The user group table in Table 2 may be maintained, for example, by the user management module 112. As with the API association settings, user groups are added or deleted via the user interface, and users belonging to the user groups are added or deleted and saved.
[0051] Furthermore, the association of the socket API with each application may not be exclusively associated with either a user or a user group, but may be made to coexist with both. For example, for a user who belongs to a user group, the settings for the user group may be used, and for a user who does not belong to the user group, the settings for that user may be used.
[0052] ●Login process FIG. 2 shows the process executed by the login processing module 114 when the user performs a login operation. When the user executes login, the login processing module 114 starts the process from step S201. Here, the case where the user 1 logs in will be described as an example. The process in FIG. 2 is realized by executing a program loaded in a memory such as the RAM 1013 by a processor such as the CPU 1012 of the controller 102. In the figure, an application is described as an app, and a socket API package is described as a socket API. This is the same in FIGS. 4 to 6. Furthermore, when a user is not logged in, the socket API package of each application is the default setting, which is the initial state of the procedure in FIG. 2. In the login process, the default socket API package loaded for each application is changed to the socket API package set for the login user or its user group. Note that only the socket API of the application will be described here, and other processes performed upon login will be omitted.
[0053] In step S202, the socket API association settings of the logged-in user (Table 1) or the socket API association settings of the user group to which the user belongs (Table 3) are obtained. Which one is obtained may depend on the settings or configuration. If the settings or configuration are for managing the networks to which applications are connected for each user, the socket API association settings in Table 1 are obtained. On the other hand, if the settings or configuration are for managing the networks to which applications are connected for each user group, the socket API association settings in Table 3 are obtained. In this case, the user group setting table in Table 2 is also obtained.
[0054] In the next step S203, the first of the applications 104, 105, and 106, for example, application 104, is focused on. The application focused on here may be one according to the authority of the logged-in user, but in this example, it is assumed that the logged-in user has the authority to use the applications 104, 105, and 106.
[0055] Proceed to step S204, and refer to the acquired socket API management table to determine whether the socket API package associated with the target application 104 for the login user is associated by default settings. If they are different, proceed to step S205. If they are the same, proceed to step S213. For example, assume that the application 104 is set to the customized socket API package 109-1 as indicated by the settings of user 1, rather than the default standard socket API package 108. In that case, proceed to step S205. Note that in this example, the next time the processing of this step is executed, the determination is made for application 105. Since the standard socket API package 108 is associated in both the default and user 1 settings, in this case the processing proceeds to step S213.
[0056] In step S205, the login processing module 114 closes all network connections opened by the application in the first socket API package associated by default with the target application. In the configuration shown in the example, the application 104 is associated with the standard socket API package 108 as the first socket API package in the default setting. At this time, the login processing module 114 operates to close all connections opened by the application 104 among the network connections held by the standard socket API package 108.
[0057] In the following step S206, the login processing module 114 determines whether the first or default socket API is the standard socket API package 108. If not, the process proceeds to step S207, otherwise the process proceeds to step S211. In the example configuration, the first socket API package associated by default with the application 104 for user 1 is the standard socket API package 108, so the process proceeds to step S211.
[0058] In step S207, the process proceeds to the case where the first socket API package is not the standard socket API package 108. In that case, since the dedicated class loader of the target application holds the contents of the first socket API package that have been read, they are unloaded.
[0059] 3 shows the relationship between the applications 104, 105, 106, the standard socket API package 108, the customized socket API package 109, and the class loaders. The class loader is a module for loading each module that operates on the application platform 103 from RAM, ROM, or storage for execution. The class loader includes a system class loader 301 and an application-specific class loader 302 that is generated for each application 104, 105, 106. The application platform 103 uses the system class loader 301 to load modules that are commonly used by the applications 104, 105, 106, such as the platform standard API 107 and the standard socket API package 108. On the other hand, the application platform 103 uses the application-specific class loader 302 to execute the execution code of the applications 104, 105, 106. The application platform 103 also uses the application-specific class loader 302 when loading the customized socket API package 109 for use in connection with the applications 104, 105, and 106.
[0060] In the next step S208, it is determined whether the second socket API package associated with the target application in the settings of the login user is the standard socket API package 108. If so, the process proceeds to step S210. If not, the process proceeds to step S209. In step S209, a class loader dedicated to the target application loads a class of the second socket API package associated with the target application in the settings of the login user. Then, the process proceeds to step S213.
[0061] If the process proceeds to step S210, the system is set to search for a socket API package loaded by the dedicated class loader of the target application as the priority order when loading a class of the socket API package. In step S210, the priority order is changed to load classes from the standard socket API package. When the change is completed, the process proceeds to step S213.
[0062] If it is determined in step S206 that the default socket API of the application of interest is the standard socket API, the process branches to step S211. In this case, the currently connected socket API of the application of interest is the standard socket API, and is changed to another socket API. Therefore, in step S211, the dedicated class loader of the application of interest loads a second socket API package associated with the application of interest in the settings of the logged-in user. In this example, the class loader of application 104 loads customized socket API package 109-1.
[0063] Then, in the next step S212, if a new object generation of the socket API is requested in the application of interest, the priority is changed so that the object is generated using a class loaded by the dedicated class loader of the application of interest. In this example, if the application of interest 104 calls a socket API after step S212, the priority is changed so that the customized socket API package 109-1 held by the class loader of the application 104 is used. When the priority change is completed, the process proceeds to step S213.
[0064] In step S213, it is determined whether the application of interest is the last application for which the login user has authority. If it is the last application, the process proceeds to step S215. If not, the process proceeds to step S214. In this example, if the application 104 is the focus, the process proceeds to step S214 since there is the next application 105.
[0065] In step S214, the next application out of applications 104, 105, and 106 is selected, and processing returns to step S204 to continue. When processing of application 104 is completed, processing returns to step S204 to select application 105. When processing proceeds to this step next, processing of application 105 is completed and processing returns to application 106.
[0066] In step S215, the process is completed. In this example, when the process for the application 106 is completed for the third time, the process proceeds to step S215 and the process is completed.
[0067] By following the above steps, the connection between each application and the default socket API is disconnected, and the socket API configured for each user or user group is connected to each application. This allows the socket API to be changed to one that corresponds to the user's settings, and allows connection to the destination desired by the user.
[0068] Logout process FIG. 4 shows the process performed by the logout processing module 115 when the user performs a logout operation. When the user performs a logout operation, the logout processing module 115 starts the process from step S401. Here, the case where the user 1 logs out will be described as an example. At the time of logout, the socket API package loaded for each application for each user or user group is changed to a default socket API package. Note that this process is realized by executing a program loaded in a memory such as the RAM 1013 by a processor such as the CPU 1012 of the controller 102 in particular in response to the user's logout operation. In the logout process, the socket API package set for the login user or the user group loaded for each application is changed to a default socket API package. Note that only the socket API of the application will be described here, and other processes performed at the time of logout will be omitted.
[0069] In step S402, the default socket API association setting (Table 1) or the default user group socket API association setting (Table 3) is acquired. Which one is acquired may depend on the setting or configuration. This is similar to the login process.
[0070] In the next step S403, the first of the applications 104, 105, and 106 belonging to the application group 202, for example, the application 104 here, is focused on.
[0071] In step S404, it is determined whether the socket API package associated with the target application 104 according to the settings of the user attempting to log out is set as the default. If they are different, the process proceeds to step S405. If they are the same, the process proceeds to step S413. For example, for user 1, application 104 is associated with customized socket API package 109-1, so the process proceeds to step S405. The next time the process of this step is executed, the determination is made for application 105 in this example, so that the standard software API package 108 is associated both by default and in the settings of user 1, so the process proceeds directly to step S413.
[0072] In step S405, the login processing module 114 closes all network connections opened by the application in the first socket API package currently connected to the target application. In the configuration given as an example, the target application 104 is associated with the customized socket API package 109-1 as the first socket API package in the settings of user 1. At this time, the logout processing module 115 operates to close all network connections held by the customized socket API package 109-1 that are open by the application 104.
[0073] In the following step S406, the login processing module 114 determines whether the first socket API is the standard socket API package 108. If not, the process proceeds to step S407, and if so, the process proceeds to step S411. In the configuration given as an example, the first socket API package currently connected to the application 104 is not the standard socket API package 108, so the process proceeds to step S407. The currently connected socket API is the socket API set for the target application for the currently logged out user.
[0074] In step S407, the process proceeds to the case where the first socket API package is not the standard socket API package 108. In that case, since the dedicated class loader of the target application holds the contents of the first socket API package that have been read, they are unloaded.
[0075] In the following step S408, it is determined whether the default socket API package associated with the target application in the user's settings is the standard socket API package 108. If so, the process proceeds to step S410. If not, the process proceeds to step S409.
[0076] In step S409, the class loader dedicated to the application of interest loads the class of the default socket API package, and the process proceeds to step S413.
[0077] If the process proceeds to step S410, the system is set to search for a socket API package loaded by the dedicated class loader of the target application as the priority order when loading a class of the socket API package. Here, the priority order is changed so that the standard socket API package is loaded first. When the change is complete, the process proceeds to step S413.
[0078] If it is determined in step S406 that the current socket API of the application of interest is the standard socket API, the process branches to step S411. In this case, the currently connected socket API of the application of interest is the standard socket API, and is changed to another socket API. Therefore, in step S411, the dedicated class loader of the application of interest loads a second socket API package associated with the application of interest in the settings of the logged-out user. In this example, the class loader of application 104 loads customized socket API package 109-1.
[0079] In the next step S412, if a new object generation of the socket API is requested in the application of interest, the priority is changed so that the object is generated using a class loaded by the dedicated class loader of the application of interest. After the priority change is completed, the process proceeds to step S413.
[0080] In step S413, it is determined whether the application under focus is the last one. If it is the last one, the process proceeds to step S415. If not, the process proceeds to step S414. In this example, if the application under focus is application 104, there is the next application 105, so the process proceeds to step S414.
[0081] In step S414, the next application out of applications 104, 105, and 106 is selected, and processing continues by returning to step S404. Here, when processing of application 104 ends, processing returns to step S404 with focus on application 105. When proceeding to this step next, processing of application 105 ends and attention is focused on application 106.
[0082] If the application under consideration in step S414 is the last one, the process proceeds to step S415. In step S415, the process is completed. For example, when the process for application 106 is completed, the process proceeds to step S415 and the process is completed.
[0083] With the above procedure, the socket API is configured so that when logging out, the connection between the socket API set for each user or user group and the application is disconnected, and the socket API with the default settings is connected to the application. This makes it possible to change the socket API from the one corresponding to the user settings to the default settings, and to prevent connections by unauthorized users.
[0084] As described above, in the first embodiment of the present invention, the application platform 103 has a function for managing the customized socket API package 109. The application platform 103 also has a function for managing the association between the applications 104, 105, and 106 and the socket API packages 108 and 109 for the users registered and managed in the application platform 103 or the user groups to which the users belong. In addition, the application platform 103 reconnects each of the applications 104, 105, and 106 to the associated socket API packages 108 and 109 every time the user logs in and out. As a result, while the user is logged in, each of the applications 104, 105, and 106 performs network communication using the socket API packages 108 and 109 associated by the user's settings. Then, when the user logs out, each of the applications 104, 105, and 106 returns to a state in which it performs network communication using the socket API packages 108 and 109 associated by default settings.
[0085] As a result, while the user is logged in to use the image forming apparatus 101, for example, the application 104 uses the customized socket API package 109-1 to communicate with, for example, the VPN gateway 122 of the organization to which the user belongs. Meanwhile, during this time, the application 105 and the application 106 can also use the standard socket API package 108 to communicate with the local network 118 of the shared office space in which the image forming apparatus 101 is installed.
[0086] These are realized by the application platform 103 managing and setting the socket API package, so there is no need to make any special modifications to the applications 104, 105, and 106.
[0087] Furthermore, when users belonging to different organizations use the image forming device 101 installed in the network 100 in the shared office space, the applications 104, 105, and 106 can be connected to the intra-organizational network 121 of the organization to which the users belong through a VPN. In this case, the contents of communication can be concealed from the local network 118 of the shared office space by connecting to the VPN gateway 122 using a customized socket API package 109 that provides a VPN connection. This reduces the risk that data exchanged with the intra-organizational local network 123 of the users belonging to different organizations can be intercepted.
[0088] Second Embodiment Next, a second embodiment of the present invention will be described with reference to the drawings. In this embodiment, the overall system configuration of the second embodiment of the present invention is the same as that shown in FIG. 1 and FIG. 7. In this embodiment, a table for managing socket API association settings when settings are held for each user is the same as that shown in Table 1. In this embodiment, a table for managing which user group a user belongs to when the user management module 112 manages users and user groups is the same as that shown in Table 2. In this embodiment, a table for storing settings that specify which application and which socket API package are to be combined for each user group when settings are managed using users and user groups is the same as that shown in Table 3. In this embodiment, the relationships between the applications 104, 105, 106, the standard socket API package 108, the customized socket API package 109, and the class loaders are the same as those shown in FIG. 3.
[0089] ●Login process Figure 5 shows the processing performed by the login processing module 114 when the user performs a login operation. This processing is realized by executing a program loaded into a memory such as the RAM 1013 by a processor such as the CPU 1012 of the controller 102. When the user is not logged in, the socket API package of each application is in the default setting, which is the initial state of the procedure in Figure 5. In the login process, the default socket API package loaded for each application is changed to the socket API package set for the logged-in user or the user group. At this time, the execution of the target application is temporarily stopped. Note that only the socket API of the application is described here, and other processes performed during login are omitted.
[0090] When the user executes a login, the login processing module 114 starts the processing from step S501. In step S502, the socket API association setting of the logged-in user is acquired. In the subsequent step S503, attention is paid to the first one of the applications 104, 105, and 106. Note that even if a plurality of reference numerals are referred to, the application of interest is one of them.
[0091] In step S504, it is determined whether the socket API packages 108 and 109 associated with the application of interest among the applications 104, 105, and 106 in the setting of the logged-in user are different from the first socket API packages 108 and 109 associated with the default setting. If they are different, the process proceeds to step S505. If they are the same, the process proceeds to step S514.
[0092] In step S505, the application platform 103 is requested to stop the target applications 104, 105, and 106, and the application platform 103 executes the request. The login processing module 114 waits until the application stop processing is completed, and proceeds to the next step S506. In the following step S506, the dedicated class loader 302 of the target applications 104, 105, and 106 is unloaded.
[0093] In step S507, it is determined whether the first, i.e., default, socket API package 108, 109 of the target application 104, 105, 106 is the standard socket API package 108. If so, the process proceeds to step S511. If not, the process proceeds to step S508.
[0094] In step S508, it is determined whether the second socket API package associated with the target application in the settings of the logged-in user is the standard socket API package 108. If so, the process proceeds to step S510. If not, the process proceeds to step S509.
[0095] In step S509, the settings are changed so that the second socket API package is loaded into the dedicated class loader 302 of the target application. In this case, the first socket API package is also the customized socket API package 109, and there is no need to change the priority order between the class loaders 301, 302 when using a socket API package. Thereafter, when the target applications 104, 105, 106 use a socket API, an object is generated using the customized socket API package 109. When the setting change is completed, the process proceeds to step S512.
[0096] When the process proceeds to step S510, the login processing module 114 causes the system class loader 301 to generate an object when the target application 104, 105, or 106 uses a socket API. This is because the second socket API package is a standard socket API package. For this reason, the priority order between the class loaders 301 and 302 is changed. When the priority order change is complete, the process proceeds to step S512.
[0097] When the process proceeds to step S511, the class loader 302 dedicated to the application of interest loads the second socket API package associated with the application of interest. Then, when the application of interest uses a socket API, the priority order between the class loaders 301 and 302 is changed so that the customized socket API package 109, which is the second socket API package, is used. When the change in the priority setting is completed, the process proceeds to step S512.
[0098] In step S512, a new class loader 302 dedicated to the application of interest is loaded. In the following step S513, a start process of the application of interest 104, 105, 106 is requested to the application platform 103, and the application platform 103 executes the start process. The login processing module 114 waits until the application start process is completed, and when the application has started, the process proceeds to step S514.
[0099] In step S514, it is determined whether the application 104, 105, or 106 under consideration is the last application registered in the application platform 103. If so, the process proceeds to step S516. If not, the process proceeds to step S515. In step S515, the process focuses on the next application 104, 105, or 106, and the process returns to step S504 and is executed. When step S516 is reached, the process is completed.
[0100] By following the above procedure, the priority of the class loader and the socket API package to be loaded can be changed while the target application is stopped, making it possible to more easily and safely realize a connection between the application and the socket API package.
[0101] Logout process FIG. 6 shows the process executed by the logout processing module 115 in this embodiment when the user performs a logout operation. The process is realized by executing a program loaded in a memory such as the RAM 1013 by a processor, particularly the CPU 1012, of the controller 102. When the user is logged in, the socket API package of each application corresponds to the setting of the user or user group, which is the initial state of the procedure in FIG. 5. In the logout process, the socket API package loaded for each application and set for the logged-in user or its user group is changed to the socket API package of the default setting. At this time, the execution of the target application is temporarily stopped. Note that only the socket API of the application will be described here, and other processes performed at the time of logout will be omitted.
[0102] When a user executes logout, the logout processing module 115 starts processing from step S601. In step S602, the socket API association setting of the user who has logged out is obtained. In the following step S603, the first of the applications 104, 105, and 106 is focused on.
[0103] In step S604, it is determined whether the socket API package associated with the application of interest 104, 105, 106 by default setting is different from the first socket API package 108, 109 associated by the user setting to log out. If they are different, the process proceeds to step S605. If they are the same, the process proceeds to step S614.
[0104] In step S605, the application platform 103 is requested to stop the target applications 104, 105, and 106, and the application platform 103 executes the request. The logout processing module 115 waits until the application stop processing is completed, and proceeds to the next step S606. In the next step S606, the dedicated class loaders 302 of the applications 104, 105, and 106 are unloaded.
[0105] In step S607, it is determined whether the first, i.e., user-defined, socket API package of the target application 104, 105, 106 is the standard socket API package 108. If so, the process proceeds to step S611. If not, the process proceeds to step S608.
[0106] In step S608, it is determined whether the second socket API package associated with the target application by default is the standard socket API package 108. If so, the process proceeds to step S610. If not, the process proceeds to step S609.
[0107] In step S609, the settings are changed so that the second socket API package is loaded into the dedicated class loader 302 of the target application. In this case, the first socket API package is also the customized socket API package 109, and there is no need to change the priority order between the class loaders 301 and 302 when using a socket API package. After this, when the target applications 104, 105, and 106 use a socket API, an object is generated using the customized socket API package 109. When the setting change is completed, the process proceeds to step S612.
[0108] When the process proceeds to step S610, the logout processing module 115 causes the system class loader 301 to generate an object when the target application 104, 105, or 106 uses a socket API. This is because the second socket API package is a standard socket API package. For this reason, the priority order between the class loaders 301 and 302 is changed. When the priority order change is complete, the process proceeds to step S612.
[0109] When the process proceeds to step S611, the class loader 302 dedicated to the application of interest loads the second socket API package with default settings. Then, when the application of interest uses a socket API, the priority order between the class loaders 301 and 302 is changed so that the customized socket API package 109, which is the second socket API package, is used. When the change in the priority setting is completed, the process proceeds to step S612.
[0110] In step S612, a new class loader 302 dedicated to the application of interest is loaded. In the following step S613, a start process of the application of interest 104, 105, 106 is requested to the application platform 103, and the application platform 103 executes the start process. The logout processing module 115 waits until the application start process is completed, and when the application has started, the process proceeds to step S614.
[0111] In step S614, it is determined whether the application 104, 105, or 106 under consideration is the last application registered in the application platform 103. If so, the process proceeds to step S616. If not, the process proceeds to step S615. In step S615, the process focuses on the next application 104, 105, or 106, and the process returns to step S604 and is executed. When step S616 is reached, the process is completed.
[0112] As described above, in the second embodiment of the present invention, the applications 104, 105, and 106 are stopped and started when reconnecting to the associated socket API packages 108 and 109 at the time of user login and logout. The application platform 103 has a function for stopping and starting the applications 104, 105, and 106, and it is expected that the applications 104, 105, and 106 are also designed in advance to be safely stopped and started. In the second embodiment of the present invention, the priority of the class loaders 301 and 302 and the customized socket API package 109 loaded by the application-specific class loader 302 are changed while the applications 104, 105, and 106 are stopped. This makes it possible to more easily and safely realize reconnection between the applications 104, 105, and 106 and the socket API packages 108 and 109.
[0113] As described above, in both the first and second embodiments, the socket API is reconfigured for each application according to the settings for each logged-in user. Therefore, the logged-in user can connect to the connection destination set in the socket API. For example, if a gateway of a specific virtual private network (VPN) is set as the connection destination, the user can access the VPN and use the resources provided by the network. This is not limited to VPNs, and since it can be set for each user, even if multiple users share one image forming apparatus, it is possible to switch the network available to each user.
[0114] Furthermore, the above settings can be made for each user group. Furthermore, if there is no logged-in user, the socket API for each application can be reconfigured to use a specific default socket API. This makes it possible to limit the connection destinations permitted for guest users.
[0115] [Other Examples] The present invention can also be realized by a process in which a program for implementing one or more of the functions of the above-described embodiments is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that implements one or more of the functions.
[0116] The invention is not limited to the above-described embodiments, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0117] 103 Application platform, 108 Standard socket API package, 109 Customized socket API package, 111 Socket API package management module, 114 Login processing module, 115 Logout processing module
Claims
1. An information processing device capable of executing multiple applications, a communication means for providing a communication function to each of the plurality of applications; a setting means for setting, for each user, a connection means for connecting each of the plurality of applications to a respective connection destination via the communication means; Each of the plurality of applications communicates using the connection means set for the logged-in user.
23. An information processing apparatus comprising:
2. 2. The information processing device according to claim 1, the setting means further sets, for each of the plurality of applications, a connection means for connecting each of the plurality of applications to a respective connection destination via the communication means as a default setting; When there is no logged-in user, each of the plurality of applications performs communication using the connection means set as the default setting.
23. An information processing apparatus comprising:
3. 3. The information processing device according to claim 2, The present invention further includes a configuration means for configuring the connection means so as to connect the connection means set for each of the plurality of applications for the logged-in user to each of the plurality of applications in response to a login of the user.
23. An information processing apparatus comprising:
4. 4. The information processing device according to claim 3, The configuration means configures the connection means to connect, in response to a user's logout, each of the plurality of applications to the connection means set for each of the plurality of applications as the default setting.
23. An information processing apparatus comprising:
5. 4. The information processing device according to claim 3, The configuration means does not perform configuration such that, for an application for which the connection means set for each of the plurality of applications for the login user is the same as the connection means set for each of the plurality of applications as the default setting, the application and the connection means are connected to each other.
23. An information processing apparatus comprising:
6. 6. The information processing device according to claim 5, When configuring the connection means to connect the application and the connection means, the configuration means temporarily stops execution of the application.
23. An information processing apparatus comprising:
7. 7. The information processing device according to claim 1, The user includes a user group having a plurality of users.
23. An information processing apparatus comprising:
8. 8. The information processing device according to claim 1, Further comprising a user interface; The setting means sets, for each of the plurality of applications for each user, a connection means for connecting each of the plurality of applications to each connection destination via the communication means in response to an instruction via the user interface.
23. An information processing apparatus comprising:
9. 9. The information processing device according to claim 1, The connection means is a socket application program interface (API).
23. An information processing apparatus comprising:
10. The information processing device according to claim 9, The socket API includes connection destination information, and the connection means connects to a connection destination corresponding to the connection destination information.
23. An information processing apparatus comprising:
11. 11. The information processing device according to claim 1 , The information processing apparatus is an image forming apparatus further including an image forming means and an image reading means.
23. An information processing apparatus comprising:
12. A program for causing a computer to function as the information processing device according to any one of claims 1 to 10.
13. An information processing device capable of executing a plurality of applications and having a communication means for providing a communication function for each of the plurality of applications, setting, for each user, a connection means for connecting each of the plurality of applications to a respective connection destination via the communication means; Each of the plurality of applications communicates using the connection means set for the logged-in user.
23. A method for controlling an information processing apparatus comprising:
Citation Information
Patent Citations
Wind instrument mouthpiece fixing device
JP1980050297A
Ultrasonic wave converter and method of manufacturing same
JP1981020400A
Exchange
JP1995283870A
Network connection route searching method
JP1998301877A
Method for designating constitutive selection of end user application
JP2000020286A