Information processing apparatus, information processing method, and program

The information processing apparatus ensures secure scan instructions by enabling encrypted communication and restricting push scans in unencrypted paths, preventing authentication information leakage and unauthorized access.

JP7716861B2Active Publication Date: 2025-08-01CANON KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021036675
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-08
Publication Date
2025-08-01
Estimated Expiration
2041-03-08

AI Technical Summary

Technical Problem

There is a risk of authentication information being eavesdropped during the transmission of scan instructions in unencrypted communication paths, potentially allowing unauthorized access to confidential data stored in external terminals.

Method used

Implementing an information processing apparatus that supports both pull and push scan instructions, enabling encrypted communication with image processing apparatuses to prevent the transmission of authentication information in unencrypted communication paths, and restricting push scan instructions when encryption is not satisfied.

Benefits of technology

Prevents the eavesdropping of authentication information, thereby reducing the risk of unauthorized access to external terminals and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007716861000001
    Figure 0007716861000001
  • Figure 0007716861000002
    Figure 0007716861000002
  • Figure 0007716861000003
    Figure 0007716861000003
Patent Text Reader

Abstract

To prevent authentication information from being wire-tapped by, when a processing terminal transmits scanning command including authentication information, not permitting transmission through unencrypted communication path or not allowing additional registration of a scanner terminal which cannot carryout encryption.SOLUTION: The present invention is directed to an information processing apparatus for executing an application using a predetermined protocol supporting both scanning methods of pull-scan commands and push-scan commands through a network. If conditions of any of a communication mode, a connection state, and a communication approval level as to an image processing apparatus is satisfied, a pull-scan command for the image processing apparatus is enabled, thereby a credential for use in the transmission processing for pull-scanning is transmitted. If the condition is not satisfied, the push-scan command for the image processing apparatus is not allowed.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus 、Emotion an information processing method, and a program.

Background Art

[0002] In recent years, a configuration in which a push scan request is transmitted from a client terminal to a scanner terminal, and the data scanned by the scanner terminal is transmitted to an external terminal has started to spread (Patent Document 1). In such a system, first, the user sets a document on the scanner terminal, specifies settings such as the destination and storage location for storing the scan result, the scan resolution, etc. from the client terminal, and selects scan start. A specified information and an instruction at the start of scanning are transmitted from the client terminal to the scanner terminal, and the scanner terminal that has received these information performs scanning. Thereafter, the scanner terminal connects to the specified destination terminal and transmits the scanned data.

[0003] Although various methods have been proposed for these scan protocols, the HTTP-based IPP Scan (PWG5100.17) and the eSCL protocol have become widespread. Further, as a protocol for searching and registering a scanner terminal in a client terminal, a search protocol such as mDNS (RFC6762) is common.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] By the way, the destination for saving the scan data can be specified as various external terminals such as a server within the same LAN, the own terminal that issued the scan instruction, or the storage of a cloud service. In order for the scanner terminal to connect to these external terminals, authentication is required, and the authentication information is also transmitted from the client terminal to the scanner terminal together with the scan start instruction request. The authentication information is information such as a token, a username, or a password. However, if the communication path from the client terminal to the scanner terminal is not encrypted, there is a risk that this authentication information will be eavesdropped. If the authentication information is eavesdropped, there is a problem that there is a risk that an imposter may access the external terminal and extract the confidential data stored in the storage, resulting in information leakage.

[0006] An object of the present invention is to prevent authentication information from being eavesdropped when a scan instruction including the authentication information is transmitted by a processing terminal.

Means for Solving the Problem

[0007] In order to achieve the object of the present invention, for example, an information processing apparatus according to an embodiment has the following configuration. That is, an information processing apparatus that executes an application that uses a predetermined protocol that supports both a pull scan instruction and a push scan instruction via a network, and when at least one of the communication mode, connection form, and communication approval level for the image processing apparatus satisfies the condition, control means for enabling a push scan instruction for the image processing apparatus; When the condition is satisfied by enabling at least encrypted communication with the image processing apparatus and the instruction for push scan is possible, transmission means for transmitting credentials used for transmission processing in push scan to the image processing apparatus, and the control means enables a pull scan instruction for the image processing apparatus when the image processing apparatus can perform a pull scan. by means of the encrypted communication

Effect of the Invention

[0008] It is possible to prevent authentication information from being eavesdropped when a scan instruction including the authentication information is transmitted by a client terminal.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Mode for Carrying Out the Invention

[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.

[0011] [Embodiment 1] FIG. 1 is a diagram showing an example of the configuration of a printing system including a processing terminal 101 which is an information processing apparatus according to the present embodiment. This printing system includes a processing terminal 101, image processing apparatuses 102 to 104 equipped with a scanning function, and a cloud storage service (service) 105. The processing terminal 101 communicates with the image processing apparatuses 102 to 104 existing within the same LAN via a network 100. The network 100 enables data transmission and reception between the processing terminal 101 and the image processing apparatuses 102 to 104, and any communication method may be adopted for the physical layer communication method. The image processing apparatuses 102 to 104 are equipped with a scanning function and communicate with a service 105 on the Internet via a communication network or a cellular network. Hereinafter, when simply referred to as an image processing apparatus, any one of the image processing apparatuses 102 to 104 is used.

[0012] The network 100 may be, for example, a communication network such as a LAN or WAN, a cellular network (such as LTE or 5G), or a wireless network compliant with IEEE 802.11, etc., and may be configured by combining a plurality of these communications. The processing terminal 101 may be any terminal capable of acquiring user input and performing operations, such as a desktop personal computer, a tablet, or a mobile phone terminal. The image processing apparatus 102 is not particularly limited as long as it has a scanning function, and may be, for example, a scanner alone or a multifunction device equipped with a printing function.

[0013] The processing terminal 101 according to the present embodiment transmits a push scan start request to the image processing apparatus via the network 100 to cause the scanning to be executed. The image processing apparatus that has received the push scan start request uses the authentication information included in the packet of the push scan start request to connect to the service 105 which is the specified external destination and transmits the scanned data.

[0014] [Push Scan] Subsequently, the transmission and reception of communication in general push scan will be described with reference to FIGS. 2 to 5. In the present embodiment, the push scan instruction described below is performed by communication using the HTTP protocol with XML, and the scanner terminal search is performed by communication using the mDNS protocol. FIG. 2 is a diagram showing an example of a request and a response transmitted and received by the mDNS protocol.

[0015] FIG. 4 is a diagram showing an example of a sequence in which a user searches for an image processing apparatus using the processing terminal 101 and registers it in the processing terminal 101. In step S401, when the user selects the "Search" button from the operation screen of the processing terminal 101, the processing subsequent to step S402 is started. In step S402, the processing terminal 101 transmits a request (search request) as to whether there is a terminal with an active scanner service within the same link network using the mDNS protocol as shown in FIG. 2(a) by a multicast packet.

[0016] In the process according to this embodiment, it is described that the protocol of the plaintext scan service uses port number 80, and the protocol of the scan service encrypted by TLS uses port number 443. When both plaintext communication and encrypted communication are enabled in the communication between the image processing apparatus that has received a search request and the processing terminal 101, the image processing apparatus performs an mDNS response (search response) including both port numbers 80 and 443 as shown in Fig. 2(b). Also, when only one of them is enabled, the image processing apparatus performs a search response including only the service of the enabled one of port numbers 80 and 443, as shown in Figs. 2(c) and 2(d). TLS is communication using TCP / IP. If the TLS setting is enabled, the communication between the processing terminal 101 and the image processing apparatus 102 is encrypted, and if it is disabled, communication in plaintext is performed.

[0017] Steps S403 to S404 are processes in which the image processing apparatus that has received a search request from the processing terminal 101 returns a response. In this example, the image processing apparatus in step S403 transmits an mDNS response as shown in Fig. 2(c) to the processing terminal 101, and the image processing apparatus in step S404 transmits an mDNS response as shown in Fig. 2(b) or Fig. 2(d). Following steps S403 and S404, the process proceeds to step S405.

[0018] The processing terminal 101 that has received the search response in step S405 displays a list of the image processing apparatuses that have returned the search response on the display unit. In step S406, the processing terminal 101 acquires a desired selection by user input from among the list of image processing apparatuses.

[0019] In step S407, the processing terminal 101 can send a request (detailed request) for obtaining more detailed information to the image processing apparatus selected in step S406 in order to know what kind of scanning is possible. In step S408, the processing terminal 101 receives a response to the detailed request from the image processing apparatus. In step S409, the processing terminal 101 performs a process of registering the selected image processing apparatus in the internal memory, stores information indicating the selected image processing apparatus in the storage area, and ends the registration process. In the present embodiment, the information indicating the image processing apparatus for which the registration process has been completed is stored in the volatile area of the processing terminal 101. This storage state is maintained even when the power of the processing terminal 101 is turned off, and can be referred to and operated by the user at an arbitrary timing.

[0020] FIG. 5 is a diagram showing an example of a sequence in which the processing terminal 101 issues a push scan instruction based on a user operation. In this example, the following description will be given on the assumption that the image processing apparatus 102 in which only plain text communication is valid is selected in step S406 and the processing shown in FIG. 5 is performed. In step S501, with the original document of the scanned image set in the image processing apparatus 102 in advance, the user selects the scan start button from the operation screen of the processing terminal 101, and thus the processing subsequent to step S402 is started.

[0021] In step S502, in response to the selection of the scan start button, the processing terminal 101 transmits a scan start request as shown in Fig. 3(a) to the image processing apparatus 102. In step S503, the image processing apparatus 102 transmits a response to the scan start request as shown in Fig. 3(b) to the processing terminal 101. In the example of Fig. 3(a), the "DestinationURI" attribute indicates the destination of the push scan, and it is expressed that scan data is stored at the destination by POST indicated by "HttpMethod". Also, in the example of Fig. 3(a), it is shown that the attribute indicated by "JobPassword" is used as an authentication token when connecting to the destination. The destination of the (push) scan is the destination to which the scan data generated by the (push) scan is transmitted, and in this embodiment, it is assumed that the service 105 is specified. The authentication method required depends on the authentication settings of the destination, and for example, methods such as OAuth authentication, DIGEST authentication, or BASIC authentication are used.

[0022] In step S504, in response to receiving the scan start request, the image processing apparatus 102 performs scanning of the document. In step S505, the image processing apparatus 102 transmits a connection request to the destination (here, the service 105) specified in the scan start request. Here, the image processing apparatus 102 adds the necessary authentication information and transmits a connection request as shown in Fig. 3(c). The image processing apparatus 102 according to this embodiment transmits a connection request including BASIC authentication information, but any authentication information corresponding to the authentication method, such as an OAuth authentication token, may be used. In step S506, the image processing apparatus 102 receives a connection success response from the service 105 for which authentication has succeeded.

[0023] In step S507, the image processing apparatus 102 transmits the scan data obtained by scanning the document to the service 105, and in step S508, it receives a response indicating the completion of reception of the scan data. Also, the processing terminal 101 periodically transmits an inquiry request regarding the scan job status as shown in Fig. 3(e) to the image processing apparatus 102. The image processing apparatus 102 that has received the inquiry request transmits a response regarding the scan job status as shown in Fig. 3(f) to the processing apparatus 101, and when the job has been successfully saved to the destination, it transmits a response indicating that the saving is complete to the processing apparatus 101.

[0024] In this example, since only plaintext communication is enabled for the image processing apparatus 102, the exchanges shown in Figs. 3(a) and 3(b) are performed in plaintext on port 80 of HTTP. Therefore, since the above-described authentication token and the like are transmitted in plaintext, there is a problem that there is a risk of packet eavesdropping and leakage of authentication information. If communication is performed using encrypted communication on port 443 of HTTPS, eavesdropping is easily prevented.

[0025] Therefore, the processing terminal 101 determines whether the communication mode, connection conditions, or approval level with the image processing apparatus 102 satisfies a predetermined condition, and if not, performs control so as not to enable the push scan instruction to the image processing apparatus 102. Here, as a case where the predetermined condition regarding the communication mode is not satisfied, the processing terminal 101 according to the present embodiment restricts the start of push scan by the image processing apparatus 102 when the communication with the image processing apparatus 102 is not encrypted. When the communication between the processing terminal 101 and the image processing apparatus 102 is encrypted, the processing terminal 101 does not restrict the start of push scan and can transmit the credentials to be transmitted to the service 105 in the push scan to the image processing apparatus 102. Credentials are authentication information required for user authentication such as BASIC authentication or DIGEST authentication, and are transmitted by the image processing apparatus 102 in step S505 described above. Hereinafter, it will be described assuming that a user name and a password are used as this authentication information.

[0026] Further, when the communication path with the image processing apparatus 102 is a P2P connection of a wireless LAN such as WiFi Direct, the processing terminal 101 does not restrict the start of push scanning as a case where a predetermined condition regarding the connection condition is satisfied. This is because in a P2P connection of a wireless LAN, since other terminals cannot participate in the connection and the wireless LAN layer is used, there is little risk of eavesdropping even when performing plaintext communication of HTTP.

[0027] FIG. 6 is a block diagram showing an example of the hardware configuration of the processing terminal 101. The processing terminal 101 includes a CPU 601, a ROM 602, a RAM 603, a storage unit 604, an operation unit 605, and a communication unit 606. The CPU 601 directly or indirectly controls each device (such as the ROM and the RAM) connected by internal devices, and executes a program for realizing the present invention. The ROM 602 is a read-only storage device that stores a program executed by the CPU 601, and stores the BIOS as firmware. The RAM 603 functions as a main memory or a work memory of the CPU 601, and is used to load a software module for realizing the present invention. The storage unit 604 is a storage area, for example, a hard disk drive (HDD) or a solid state drive (SSD) that stores an OS which is basic software and software modules. The operation unit 605 functions as a display unit that displays information to the user and a reception unit that receives the user's instructions. The operation unit 605 is, for example, a liquid crystal display unit having a touch panel function or a display provided with various hard keys.

[0028] The CPU 601 cooperates with the operation unit 605 to perform display control of information and reception control of user operations. The communication unit 606 is an interface for the processing terminal 101 to connect to the network. The communication unit 606 according to this embodiment is assumed to be a communication interface that performs wired communication compliant with Ethernet (registered trademark), but is not particularly limited to this as long as communication is possible. The communication unit 606 may be, for example, a wireless communication interface compliant with the IEEE 802.11 series. Also, the communication unit 606 may perform communication as a wireless communication interface. Further, for example, the communication unit 606 may perform communication by a mobile communication such as a 3G line such as CDMA, a 4G line such as LTE, or 5G NR. Note that each process performed by the CPU 601 according to this embodiment will be described as being realized by the processing terminal 101 which is dedicated hardware, but a part or all of the processes may be performed by a separate computer.

[0029] Next, with reference to FIGS. 7 to 9, control processing for restricting the start of push scan in the mode of plaintext communication without encryption by the processing terminal 101 according to this embodiment will be described. FIG. 7 shows an example of the screen flow of the operation unit 605 displayed by the processing terminal 101 according to this embodiment. The screen 701 is an example of a screen that displays a list of image processing apparatuses registered in the processing terminal 101. When the user selects an arbitrary terminal from which to perform a scan from the image processing apparatuses displayed on the screen 701, the screen transitions to the screen 702. The screen 702 is a main menu screen regarding the selected image processing apparatus, and displays the state of the image processing apparatus (for example, an idling state or a busy state) or buttons for performing detailed settings of the scan. In this example, when the user presses a button labeled "Open Scan Setting", the screen 703, which is a screen for performing detailed settings, is displayed. In the example of FIG. 7, the screen 703 is a screen for setting the size, resolution, or format for performing a scan, but any settings related to the scan, such as the position of the starting point of the scan or the feed direction of the original document, may be set.

[0030] When the user selects an item on screen 703, the operation unit 605 displays a screen for performing detailed settings related to the selected item. Screens 704 to 708 are examples of setting screens corresponding to each of the items selected on screen 703. Screen 704 is a screen for setting the destination of push scan. On screen 704, it is possible to set whether the destination for storing scan data is the local terminal or an external terminal, the path for storing scan data, and the authentication information necessary for connecting to the destination. The item "Destination" is displayed on screen 704, and the setting of whether the destination is the local terminal or an external terminal and the details (URL) when the destination is an external terminal are input. Screen 704 displays a form for inputting authentication information in response to a request for user authentication that requires a username and password, such as BASIC authentication or DIGEST authentication from the destination terminal. This authentication information may be set in advance, or when the image processing apparatus 102 sends a request for user authentication to the processing terminal 101, a screen prompting the input of authentication information may be displayed as a pop-up on the operation screen of the processing terminal 101. Also, when the user authentication with the service 105 using this authentication information has already been completed, an item for setting whether to send the token stored in the processing terminal 101 to the image processing apparatus 102 may be provided on screen 703. In this embodiment, various protocols such as HTTP, FTP, or SMB may be used as the protocol setting for connecting to the service 105, and the parameters necessary for setting the destination (here, the service 105) can be arbitrarily changed.

[0031] Figure 8 is a flowchart showing an example of a process in which the CPU 601 of the processing terminal 101 according to this embodiment restricts the start of push scan by displaying a warning screen. When the "Scan" button is pressed on screen 703, the CPU 601 of the processing terminal 101 starts the process of step S801 and advances the process to step S802.

[0032] In step S802, the CPU 601 determines whether scanning can be started. Here, the CPU 601 first determines whether the scanning process by the image processing apparatus 102 is push scanning or pull scanning. If it is pull scanning, since the exchange of authentication information as described above is not necessary, the process proceeds to step S805 assuming that scanning can be started. If it is push scanning, the process proceeds to step S803 in order to avoid leakage of authentication information.

[0033] In step S803, the CPU 601 determines whether the communication path between the processing terminal 101 and the image processing apparatus 102 is a P2P connection via a wireless LAN such as WiFi Direct. If it is a P2P connection, the process proceeds to step S805 assuming that scanning can be started. On the other hand, if it is not a P2P connection, such as in an environment where communication is performed via a general LAN connection, the process proceeds to step S804.

[0034] In step S804, the processing terminal 101 determines whether the communication with the image processing apparatus 102 is encrypted. If the communication is not encrypted, such as the communication with the image processing apparatus 102 that only supports HTTP communication via port 80, the process proceeds to step S806. If the communication is encrypted, the process proceeds to step S805.

[0035] In step S805, the processing terminal 101 determines that the communication with the image processing apparatus 102 is encrypted, and transmits a request for instructing the start of push scanning as shown in Fig. 3(a) to the image processing apparatus 102, and ends the processing. On the other hand, in step S806, the processing terminal 101 determines that the communication with the image processing apparatus 102 is not encrypted, presents a warning screen as shown in the screen 707 to the user, and ends the processing. Further, the processing terminal 101 periodically checks the scan job status, and may present a completion display such as the screen 705 or the screen 706 to the user when the saving of scan data is completed after step S805. The screen 705 is a completion display when the cloud 105 is an external device separate from the processing terminal 101, and the screen 706 is a completion display when the destination of the scan processing is the processing terminal 101.

[0036] According to such processing, by controlling whether to transmit a push scan start request packet including authentication information according to whether any of the communication mode, connection state, and approval level between the processing terminal and the image processing apparatus as a scanner satisfies a predetermined condition, information leakage can be prevented. In particular, when it is determined that the communication path between the processing terminal and the image processing apparatus is encrypted, by controlling not to transmit a scan start request packet, leakage of authentication information can be prevented.

[0037] Note that even when the processing terminal 101 obtains consent from the user regarding the transmission of authentication information to the service 105, it may not restrict the start of push scanning. That is, for example, in response to the user's approval that the authentication information may be transmitted in plain text, such as when the processing terminal 101 and the image processing apparatus 102 are connected within a completely closed LAN, the start process of push scanning may continue. For this purpose, the processing terminal 101 can present a screen to the user to confirm whether to continue the push scanning process (for example, when the communication with the image processing apparatus 102 is not encrypted) and obtain the user's selection. This process is, for example, step S906 (FIG. 7(b)) of FIG. 9 described later. When it is approved to continue the scanning process, the start of push scanning is not restricted on the assumption that the communication approval level satisfies the above-mentioned predetermined conditions. Also, when it is not approved to continue the scanning process, the start of push scanning is restricted on the assumption that the communication approval level does not satisfy the above-mentioned predetermined conditions.

[0038] FIG. 9 is a flowchart showing an example of a process for restricting the start of push scanning in which the CPU 601 of the processing terminal 101 according to the present embodiment displays a confirmation screen for continuing the start process of push scanning instead of the warning screen shown in FIG. 8. In the process shown in FIG. 9, the same process as that shown in FIG. 8 is performed except that the processes of step S901 and step S902 are performed instead of step S806, and thus duplicate explanations are omitted.

[0039] In step S901 which is performed when it is determined in step S804 that the communication is not encrypted, the processing terminal 101 presents a confirmation screen to the user to confirm whether to continue the push scan start process. In this example, a confirmation screen as shown in screen 708 of FIG. 7(b) is displayed, and the user's selection of whether to continue or cancel the process is obtained. In step S902, the processing terminal 101 determines whether the user's selection for the confirmation screen displayed in step S901 approves the continuation of the process or cancels it. If the continuation of the process is selected, the process proceeds to step S805, and an instruction to start the push scan is issued. If the cancellation of the process is selected, the process ends.

[0040] Also, when the processing terminal 101 restricts the start of the push scan, it may alternatively propose to the user to perform a pull scan. In the case of a pull scan, since the exchange of authentication information is not required as described above, the risk of leakage of authentication information can be avoided even in plaintext communication. In this example, instead of displaying the warning screen in step S806, the processing terminal 101 presents a screen for the user to select whether to perform a pull scan.

[0041] [Embodiment 2] In the search process of the image processing apparatus as performed in steps S401 to S405 in Embodiment 1, the processing terminal 101, which is an information processing apparatus according to Embodiment 2, controls so as not to be able to perform push scanning by the image processing apparatus by restricting the display of an image processing apparatus with unencrypted communication in the search result list. Except for these series of processes, the processing terminal 101 according to the present embodiment performs basically the same processes as in Embodiment 1, and thus redundant explanations are omitted.

[0042] The processing terminal 101 according to this embodiment restricts displaying an image processing apparatus with unencrypted communication in the search result list, or restricts displaying the image processing apparatus in the search result list by confirming whether to actually perform registration when selected from the list. In FIG. 11 to be described later, a flowchart for the case of not displaying in the search result list is shown, and in FIG. 12, a flowchart for the case of confirming whether to actually perform registration is shown.

[0043] The processing terminal 101 according to this embodiment searches for an image processing apparatus by transmitting a search request as a multicast packet in a method similar to, for example, step S402. Here, the processing terminal 101 refers to the mDNS response of the image processing apparatus to the search request and determines whether the communication with each searched image processing apparatus is encrypted. This is determined by referring to the port number from a response as shown in, for example, FIGS. 2(b) to 2(d). In the following example, the processing terminal determines whether push scanning is possible based on whether the communication is encrypted, but this may be a condition based on the connection form or a condition based on the approval level.

[0044] The processing terminal 101 can control not to display an image processing apparatus determined to have unencrypted communication during the search in the search result list. Also, when all search results are displayed in the list and an image processing apparatus to be registered is selected by the user, if the communication with the image processing apparatus is not encrypted, a prompt to that effect may be presented and a selection on whether to continue the registration may be obtained (for example, screen 1005). In that case, if the communication with the selected image processing apparatus is encrypted, the selected image processing apparatus is registered in the list as a registered apparatus.

[0045] Figures 10 to 12 are diagrams for explaining an example of the processing at the time of searching for an image processing apparatus performed by the processing terminal 101 according to the present embodiment. FIG. 10 shows an example of the screen flow of the operation unit 605 displayed at the time of the search process of the image processing apparatus by the processing terminal 101 according to the present embodiment. Further, FIG. 11 is a flowchart showing an example of the processing for restricting the display at the time of searching for the image processing apparatus, which is performed by the CPU 601 of the processing terminal 101 in the process as shown in FIG. 10.

[0046] Screen 1001 is a screen for displaying a list of image processing apparatuses registered in the processing terminal 101. The operation unit 605 can search for and register a new image processing apparatus by acquiring the user's operation on the screen 1001. At step S1101, the processing terminal 101 transmits a search request as a multicast packet. Here, when the user selects the "Search" button on the screen 1001, the CPU 601 transmits an mDNS search packet as shown in FIG. 2(a) to the image processing apparatus, and the operation unit 605 performs a display indicating that the search is in progress as shown in the screen 1002.

[0047] In step S1102, the processing terminal 101 receives mDNS responses from each image processing device that has performed a search. In step S1103, the processing terminal 101 determines whether the scan service of the response packet uses encrypted communication. For the image processing devices that use encrypted communication, the process of step S1104 is performed, and for the image processing devices that do not use encrypted communication, the process of step S1105 is performed. In step S1104, the processing terminal 101 adds, as devices with encrypted communication, the image processing devices that use encrypted communication via HTTPS communication using port 443 as shown in, for example, FIGS. 2(b) and 2(d) to the list of search results. On the other hand, in step S1105, the processing terminal 101 does not add the image processing device that performs the scan service of HTTP communication using port 80 as shown in FIG. 2(c) to the list of search results as a device without encryption. When the process of step S1104 or step S1105 is completed, the process proceeds to step S1106, and after the processes of steps S1103 to S1105 are repeated until the mDNS search response is completed, the process proceeds to step S1107. In step S1107, the processing terminal 101 displays the list of search results of the image processing devices on the display screen. The processing terminal 101 displays, in the list, the image processing devices 103 and 104 excluding the image processing device 102 that supports only plaintext communication, for example.

[0048] According to such processing, it is possible to determine whether the communication path with the processing terminal is encrypted when searching for the image processing device for registration. Therefore, by excluding the image processing devices with unencrypted communication from the search results, the risk of leakage of authentication information can be reduced.

[0049] On the other hand, FIG. 12 is a flowchart showing an example of a process of performing a restriction after registering in a list of image processing apparatuses searched by the CPU 601 of the processing terminal 101 in the process as shown in FIG. 10. In step S1201, the processing terminal 101 transmits a search request as a multicast packet in the same manner as in step S1101. In step S1102, the processing terminal 101 receives an mDNS response from each image processing apparatus that has performed a search in the same manner as in step S1102.

[0050] In step S1203, the processing terminal 101 adds each image processing apparatus that has returned an mDNS response to the list of search results. In step S1204, the processing terminal 101 determines whether or not the process of step S1203 has been performed for all image processing apparatuses that have returned an mDNS response. If it has been performed for all image processing apparatuses, the process proceeds to step S1205, and if not, the process returns to step S1203. In step S1205 after receiving all responses, the processing terminal 101 generates and displays a list of search results of image processing apparatuses as shown on screen 1003.

[0051] In step S1206, the processing terminal 101 obtains a selection by the user of the image processing apparatus to be registered from the list. In step S1207, the processing terminal 101 determines whether or not the communication between the image processing apparatus selected in step S1206 and the processing terminal 101 is encrypted, in the same manner as in step S1103. If the selected image processing apparatus includes an encrypted scan service, the process proceeds to step S1208, and the processing terminal 101 adds the image processing apparatus to the registered list and the process ends. On the other hand, if the selected image processing apparatus does not include an encrypted scan service, the process proceeds to step S1209.

[0052] In step S1209, the processing terminal 101 displays a screen for obtaining a user selection regarding whether to continue the registration process without including encrypted communication as shown on screen 1005. In step S1210, the processing terminal 101 determines whether the user has selected to continue the registration process in step S1209. If the continuation is selected, the process proceeds to step S1208, the processing terminal 101 adds the image processing apparatus to the registered list, displays a completion-of-addition message as shown on screen 1006, and ends the process. If the continuation is not selected, the registration process is canceled and the process ends.

[0053] According to such processing, when searching for an image processing apparatus for registration, it is possible to determine whether the communication path with the processing terminal is encrypted. Next, for an image processing apparatus whose communication is not encrypted, by confirming whether to actually perform registration when selecting from the list, the risk of leakage of authentication information can be reduced.

[0054] [Embodiment 3] In the printing system 100 according to the embodiment, push scanning is performed in which the service 105 is used as the destination of scanning by the image processing apparatus 102. On the other hand, when pull scanning is performed by the image processing apparatus 102 with the processing terminal 101 as the destination of the scan data, it is not necessary to include authentication information in the scan start instruction. From this perspective, the processing terminal 101, which is an information processing apparatus according to Embodiment 3, determines whether the image processing apparatus 102 can perform pull scanning. Next, the processing terminal 101 issues an instruction to start pull scanning if the image processing apparatus 102 can perform pull scanning, and issues an instruction to start push scanning if the image processing apparatus 102 cannot perform pull scanning.

[0055] The processing terminal 101 according to this embodiment has the same configuration as the processing terminal 101 of Embodiment 1 and performs the same processing, except that when the image processing apparatus 102 is capable of pulse scanning, it transmits an instruction to start pulse scanning. Therefore, duplicate explanations are omitted. In this embodiment, pulse scanning is described as being a scan in which the image processing apparatus 102 performs scanning in response to a scan start instruction from the processing terminal 101, and the storage destination of the scan data is the processing terminal 101.

[0056] FIG. 13 is a flowchart showing an example of the transmission process of a pulse scan start request performed by the processing terminal 101 according to this embodiment. The process shown in FIG. 13 starts when a scan start instruction to the image processing apparatus 102 is given, for example, when the "Scan" button on the screen 703 in FIG. 7 is pressed by the user.

[0057] In step S1301, the processing terminal 101 detects that the user has given a scan start instruction to the image processing apparatus 102. In step S1302, the processing terminal 101 determines whether the destination (storage destination) of the data by the scan of the image processing apparatus 102 is the local terminal, that is, the processing terminal 101, or an external terminal such as the service 105. Here, the processing terminal 101 makes the above determination by referring to the item "Destination" input by the user on the screen 704 in FIG. 7. If the destination is the local terminal, the process proceeds to step S1303, and if not, the process proceeds to step S803 in FIG. 8 to perform subsequent processing related to push scanning.

[0058] In step S1303, the processing terminal 101 determines whether the processing terminal 101 can perform pull scanning. Here, it is determined whether the processing terminal 101 is equipped with a pull scanning function, and if it is equipped with a pull scanning function, whether the valid / invalid setting thereof is enabled. If the processing terminal 101 can also perform pull scanning, the process proceeds to step S1304; otherwise, the process proceeds to step S803 in FIG. 8 to perform subsequent processing related to push scanning. In step S1304, the processing terminal 101 sends a start instruction to the image processing apparatus 102 to start the scan as a pull scan, and ends the process.

[0059] According to such processing, if pull scanning is possible in this system, pull scanning can be started. In pull scanning, since the authentication information is not included in the scan start request, there is no problem even when data is transmitted and received by plaintext HTTP communication. Therefore, leakage of authentication information can be prevented.

[0060] [Embodiment 4] The processing terminal 101 according to Embodiment 1 searched for a terminal where a scan service exists without distinguishing between push scanning and pull scanning as shown in FIG. 2(a). On the other hand, the processing terminal according to this embodiment performs a search process assuming the existence of a "pull scan service" and a "push scan service" in addition to the conventional "scan service".

[0061] FIG. 17 is a packet example of service search and response by the mDNS service when, in addition to the "scan service", there exist a "pull scan service" and a "push scan service". When compared with the example of FIG. 2, the services of pull scan and push scan are added to both the packet from the processing terminal and the response packet from the image processing apparatus. An image processing apparatus that supports only the conventional scan service may return the same response as in the example of FIG. 2. FIG. 17(b) is an example of a packet response from an image processing apparatus that supports the pull scan service and performs plaintext communication (with a port number of 80). Further, FIG. 17(c) is an example of a packet response from an image processing apparatus that supports both the pull scan service and the push scan service and performs encrypted communication (with a port number of 443).

[0062] In this embodiment, search requests are made separately for pull scan and push scan, and responses are made for each of them. Therefore, even for an image processing apparatus in which "use of TLS" is invalid and "Push" is valid as described in Embodiment 5 to be described later, if pull scan is possible, a response can be returned with information indicating that fact.

[0063] In this system, the image processing apparatus includes information indicating whether push scan is possible in a response and transmits the response to a search request from the processing terminal 101. However, considering prevention of leakage of authentication information, it is not necessary to indicate to the processing terminal 101 that push scan is possible when performing plaintext communication. From such a viewpoint, the image processing apparatus according to this embodiment does not transmit information including the fact that push scan is possible to the processing terminal in response to a search request from the processing terminal 101 when the communication with the processing terminal 101 is plaintext communication. That is, information indicating that push scan is not possible is transmitted as the response.

[0064] According to such processing, the image processing apparatus side can perform an appropriate service response using pull scanning as well by making the image processing apparatus perform service responses for push scanning and pull scanning respectively.

[0065] [Embodiment 5] The image processing apparatus 1600 according to Embodiment 4 performs push scanning in response to a push scan start instruction from the processing terminal 101 in the same manner as the image processing apparatus 102 of Embodiment 1. In addition, the image processing apparatus 1600 sets whether to perform encrypted communication (enabled / disabled), and sets whether to perform push scanning (enabled / disabled) according to the setting. Here, the image processing apparatus 1600 is set not to perform push scanning when encrypted communication is set to be disabled. That is, by linking the setting of encrypted communication with the setting of whether push scanning is possible, and preventing push scanning from being performed when encrypted communication is not performed, leakage of authentication information is prevented.

[0066] The image processing apparatus 1600 according to the present embodiment is implemented in a standard that exists for the "pull scan service" and the "push scan service" in addition to the "scan service" according to Embodiment 4. Therefore, the image processing apparatus 1600 returns a response based on the setting of whether to perform the above-described encrypted communication (enabled / disabled) and the setting of whether to perform push scanning (enabled / disabled) determined according to the setting in response to a search request from the processing apparatus 101. However, the image processing apparatus 1600 is not particularly limited to implementation in this standard, and may perform a response generated in a conventional standard as shown in FIG. 2 of Embodiment 1.

[0067] FIG. 16 is a block diagram showing an example of the hardware configuration of an image processing apparatus 1600 according to the present embodiment. The image processing apparatus 1600 includes a CPU 1601, a ROM 1602, a RAM 1603, a storage unit 1604, a printer processing unit 1605, a scanner processing unit 1606, a communication unit 1607, and an operation unit 1608. The CPU 1601 directly or indirectly controls each device (such as a ROM and a RAM) connected by internal devices, and executes a program for realizing the present invention. The ROM 1602 is a read-only storage device that stores a program executed by the CPU 1601, and stores the BIOS as firmware. The RAM 1603 functions as a main memory or a work memory of the CPU 1601, and is used to load a software module for realizing the present invention. The storage unit 1604 is a storage area, for example, a hard disk drive (HDD) or a solid state drive (SSD) that stores an OS which is basic software and software modules. The scanner processing unit 1606 performs a process of reading and digitizing an image file scanned by a platen or a feeder. The printer processing unit 1605 controls copying or controls discharging a printed image on a specified image file in response to a print instruction from an external terminal. The operation unit 1608 functions as a display unit that displays information to the user and a reception unit that receives the user's instructions. The operation unit 1608 is, for example, a liquid crystal display unit having a touch panel function or a display provided with various hard keys.

[0068] The CPU 1601 cooperates with the operation unit 1608 to perform display control of information and reception control of user operations. The communication unit 1607 is an interface for connecting the image processing apparatus 1600 to a network. The communication unit 1607 according to the present embodiment is assumed to be a communication interface that performs wired communication compliant with Ethernet (registered trademark), but is not particularly limited to this as long as communication is possible. The communication unit 1607 can communicate in the same manner as the communication unit 606 of the first embodiment.

[0069] FIG. 14 shows an example of a scan setting screen displayed on the operation unit 1608 of the image processing apparatus 1600. The user makes a desired scan setting via the screen 1400 shown in FIG. 14. On the screen 1400, an item “Use Network Scan” for setting whether to use the network scan function is set. Depending on the setting of enabling / disabling the use of network scan, the transmission / reception of data via the network by an application function such as IPP scan or eSCL scan is set to be enabled / disabled. Also, when the setting of “Use TLS” on the screen 1400 is set to be enabled / disabled, the transmission / reception of data via plaintext communication using HTTP port 80 is set to be enabled / disabled. That is, when “Use TLS” is set to be enabled, the transmission / reception of data by plaintext communication is performed. Further, on the screen 1400, as the types of transmission types, “Pull” and “Push” are individually set to be enabled / disabled. Here, when “Pull” is set to be enabled, the pull scan function of the image processing apparatus 1600 is enabled, and when “Push” is set to be enabled, the push scan function of the image processing apparatus 1600 is enabled. Either one of the “Pull” setting and the “Push” setting may be set to be enabled, or both may be set to be enabled. After the user selects these various scan settings and presses the “SAVE” button, the CPU 1601 acquires the selected various settings and stores them in the storage unit 1604.

[0070] FIG. 15 is a flowchart showing an example of a process of prohibiting push scan settings when encrypted communication is disabled, which is performed by the image processing apparatus 1600. Hereinafter, the description will be given on the assumption that each process proceeds by user selection of items on the screen 1400. However, the expression is not particularly limited to this as long as the same settings are made. The process shown in FIG. 15 starts from step S1501 when a save instruction for scan settings is received, such as when the "SAVE" button on the screen 1400 is pressed. In step S1501, the CPU 1601 detects the pressing of the "SAVE" button by the user, and uses the settings acquired and stored by the pressing as the processing target to perform subsequent processing. In step S1502, the CPU 1601 determines whether the item "Use network scan" is valid or invalid. If the item "Use network scan" is valid, the process proceeds to step S1503; if it is invalid, the process proceeds to step S1506.

[0071] In step S1503, the CPU 1601 determines whether the "Push" setting is valid or invalid. If the "Push" setting is valid, the process proceeds to step S1504; otherwise, the process proceeds to step S1506. In step S1504, the CPU 1601 determines whether the "Use TLS" setting is valid or invalid. If the "Use TLS" setting is invalid, the process proceeds to step S1505; otherwise, the process proceeds to step S1506.

[0072] When the "Push" setting is valid and the "Use TLS" is set to be valid, the authentication information included in the push scan communication will be communicated in plain text. Therefore, in step S1505, the CPU 1601 controls the system so that push scan based on the scan settings acquired in S1501 is not performed. Here, a warning message indicating that this combination of settings is impossible is displayed on the display unit, and the process ends without saving the acquired settings. In step S1606, which is the case where the setting is not "the 'Push' setting is valid and the 'Use TLS' is valid", the CPU 1601 stores the acquired settings assuming that there are no security problems.

[0073] That is, the image processing apparatus 1600 according to the present embodiment excludes the compatibility between push scan execution and plain text communication, and the realization method thereof is not particularly limited. For example, the image processing apparatus 1600 may display a warning message when the "SAVE" button is pressed as shown in the flow of FIG. 15, and may also enable the "Use of TLS" setting in conjunction when the "Push" setting is enabled. Further, when the "Use of TLS" is set to invalid, the image processing apparatus 1600 may automatically disable the "Push" setting, for example, gray it out so that it cannot be selected.

[0074] According to such processing, when the push scan setting on the image processing apparatus side is enabled, encrypted communication can always be performed. Therefore, when the push scan setting on the scanning apparatus is enabled, interlocking or prohibited setting processing is performed so that the encrypted communication setting is always enabled, and since the communication path including the authentication information is always encrypted, it is possible to prevent the authentication information from being eavesdropped.

[0075] In the present embodiment, the setting as shown in FIG. 14 has been described as being performed in the image processing apparatus 1600. However, the setting may be input on a different device. For example, for the scan setting in which the "SAVE" button is pressed and input on an external device such as the processing terminal 101, the image processing apparatus 1600 may perform the processing after step S1502.

[0076] (Other Embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiment to a system or apparatus via a network or a storage medium, and having one or more processors in the computer of the system or apparatus read and execute the program. Further, it can also be realized by a circuit (for example, ASIC) that realizes one or more functions.

[0077] The invention is not limited to the above embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, the claims are appended to disclose the scope of the invention.

Explanation of Reference Numerals

[0078] 101: Processing terminal, 601: CPU, 602: ROM, 603: RAM, 604: Storage unit, 605: Operation unit, 606: Communication unit

Claims

1. An information processing apparatus that executes an application using a predetermined protocol that supports both a pull scan instruction and a push scan instruction via a network, control means for enabling a push scan instruction to the image processing apparatus when at least one condition regarding a communication mode, a connection form, and an approval level for the image processing apparatus is satisfied; transmission means for transmitting, by the encrypted communication, credentials used for transmission processing in push scan to the image processing apparatus when the condition is satisfied by the fact that at least the encrypted communication with respect to the image processing apparatus is valid and the push scan instruction is possible, and having, wherein the control means enables a pull scan instruction to the image processing apparatus when the image processing apparatus can perform a pull scan, the information processing apparatus being characterized in that.

2. The information processing apparatus according to claim 1, wherein the condition is satisfied when the connection form is WiFi Direct.

3. further comprising acquisition means for acquiring approval from a user for the transmission of the credentials by the transmission means, The information processing apparatus according to claim 1 or 2, wherein the condition is further satisfied when approval from the user is acquired.

4. The information processing apparatus according to any one of claims 1 to 3, wherein the control means proposes to the user to give a pull scan instruction to the image processing apparatus when the condition is not satisfied.

5. further comprising determination means for determining whether or not the image processing apparatus can perform a pull scan, The information processing apparatus according to any one of claims 1 to 4, wherein the control means controls so that a push scan instruction to the image processing apparatus cannot be given when at least one condition regarding a communication mode, a connection form, and an approval level for the image processing apparatus is not satisfied.

6. An information processing method performed by an information processing apparatus that executes an application using a predetermined protocol that supports both a pull scan instruction and a push scan instruction via a network, A control step that enables an instruction for push scanning to the image processing apparatus when a condition regarding at least any one of a communication mode, a connection form, and an approval level of communication to the image processing apparatus is satisfied; A transmission step of transmitting, by the encrypted communication, credentials used for transmission processing in push scanning to the image processing apparatus when the condition is satisfied by at least the encrypted communication to the image processing apparatus being effective and the instruction for push scanning is possible; and The control step enables an instruction for pull scanning to the image processing apparatus when the image processing apparatus can perform pull scanning. An information processing method characterized by this.

7. A program for causing a computer to function as each means of the information processing apparatus according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Information processor, information processing method, computer program, and recording medium

    JP2008003697A

  • Information processing apparatus, information processing method, and program

    JP2015022509A

  • Scanning device and program

    JP2015070493A

  • Image processing device, communication device, and image processing system

    JP2016019011A

  • Portable terminal device, scan mode determination system, scan mode determination method and scan mode determination program

    JP2017112508A