Management system, device, program and management method
The management system enables direct communication between a server and device to manage encryption keys with expiration dates, preventing key expiration and ensuring secure data decryption, thus maintaining device functionality.
Patent Information
- Application Number
- JP2021213025
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2041-12-27
AI Technical Summary
In a management system where an image forming device receives configuration data encrypted with an expiration-limited encryption key, the expiration of the key can lead to invalid data being provided to the device, disrupting its functionality.
A management system that allows direct communication between a server and a device to transmit and receive encryption keys with expiration dates and encrypted execution data, bypassing intermediate storage devices to prevent key expiration and ensure data decryption.
Prevents the expiration of encryption keys with expiration dates, ensuring the secure and timely decryption of execution data, thereby maintaining the functionality of the image forming device.
Smart Images

Figure 0007760911000001 
Figure 0007760911000002 
Figure 0007760911000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a technique for managing a terminal device. [Background technology]
[0002] Patent document 1 describes that a management server that communicates data with a management device and an image forming device acquires setting data for configuring the image forming device from the management device, and provides the acquired setting data to the image forming device in response to an inquiry from the image forming device. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-148957 Summary of the Invention [Problem to be solved by the invention]
[0004] In a management system in which a management device manages an image forming device via a management server as described above, when providing configuration data from a configuration server different from the management server to an image forming device, the image forming device may need to provide an encryption key with an expiration date to the configuration server. The configuration server provides the image forming device with the configuration data encrypted with the encryption key with an expiration date. The image forming device obtains the configuration data by decrypting the provided configuration data with the encryption key with an expiration date.
[0005] In this case, if the exchange of the expiration-limited encryption key and setting data between the setting server and the image forming device is carried out via the management device and management server, the expiration date of the expiration-limited encryption key may pass, and valid setting data may no longer be able to be provided to the image forming device.
[0006] The present disclosure aims to prevent the expiration of an encryption key with an expiration date. [Means for solving the problem]
[0007] One aspect of the present disclosure is a management system including a management device, a device that cannot directly communicate with the management device, a storage device, and a server. The storage device is configured to be able to communicate with the management device and the device. The server is configured to be able to communicate with the management device and the device.
[0008] The management device is configured to upload, upon receiving from the server, data identification information for identifying execution data used in a device execution process executed by the device, the data identification information to the storage device.
[0009] The device is configured to perform a transmission process, a decoding process, and a data utilization process. In the transmission process, when the data identification information is downloaded from the storage device, the data identification information and an encryption key with an expiration date are transmitted to the server.
[0010] In the decryption process, when execution data encrypted with an encryption key is received from the server, the received execution data is decrypted with the encryption key. The data use process executes the device execution process using the execution data decrypted in the decryption process.
[0011] The management system of the present disclosure configured as above can directly transmit and receive an encryption key with an expiration date and execution data encrypted with the encryption key between the server and the device without using a storage device. This prevents the expiration of the encryption key with an expiration date. This prevents the execution data from being decrypted due to the expiration of the encryption key.
[0012] Another aspect of the present disclosure is a device of a management system in which a management apparatus and a device are configured to be able to communicate with a storage device and a server, and a control unit of the device is configured to perform a transmission process, a decryption process, and a data utilization process.
[0013] The device of the present disclosure is an apparatus included in the management system of the present disclosure, and can obtain the same effects as the management system of the present disclosure. Yet another aspect of the present disclosure is a program configured to cause a control unit provided in a device of a management system in which the management device and the device are configured to be able to communicate with a storage device and a server to perform a transmission process, a decryption process, and a data usage process.
[0014] The program of the present disclosure is a program executed in the management system of the present disclosure, and can obtain the same effects as the management system of the present disclosure. Yet another aspect of the present disclosure is a management method executed by a device of a management system in which the management apparatus and the device are configured to be able to communicate with a storage device and a server, the method comprising a transmitting step, a decrypting step, and a data utilization step.
[0015] The management method of the present disclosure is a method executed by the management system of the present disclosure, and by executing this method, it is possible to obtain the same effects as the management system of the present disclosure. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 2 is a block diagram showing the configuration of a management system. [Figure 2] FIG. 2 is a block diagram showing the configurations of a master, a client, and a first-type terminal device. [Figure 3] FIG. 2 is a block diagram showing the configurations of a second type terminal device, a cloud server, and a license server. [Figure 4] FIG. 10 is an explanatory diagram illustrating an example of a management sequence by the management system. [Figure 5] FIG. 10 is an explanatory diagram illustrating an example of a schedule task table. [Figure 6] FIG. 10 is an explanatory diagram illustrating an example of an instant task table. [Figure 7] FIG. 10 is a sequence diagram showing the operation related to the function extension of the second type terminal device. [Figure 8] 10 is a flowchart showing a first validation process. [Figure 9] FIG. 10 is a sequence diagram showing the operation related to the function extension of the first type terminal device. [Figure 10] 10 is a flowchart showing a second activation process. DETAILED DESCRIPTION OF THE INVENTION
[0017] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. (1) Overall structure The management system 1 of this embodiment is a network system configured to manage terminal devices 4 and 5 located at multiple locations via a cloud server 6 through cooperation between a master 2 and a client 3 .
[0018] As shown in FIG. 1, the management system 1 includes a master 2, a client 3, terminal devices 4 and 5, a cloud server 6, and a license server 7. The master 2 is configured to be able to communicate with a terminal device 4 installed at a first base via a local area network. The master 2 is further configured to be able to communicate with a cloud server 6 and a license server 7 via a wide area network 8.
[0019] The client 3 is configured to be able to communicate with a terminal device 4 installed at a second location via a local area network. The client 3 is further configured to be able to communicate with a cloud server 6 and a license server 7 via a wide area network 8. The terminal device 5 installed at a third location is configured to be able to communicate with the cloud server 6 and the license server 7 via the wide area network 8.
[0020] The local area network may include, for example, at least one of a wireless LAN and a wired LAN. The wide area network 8 may include, for example, the Internet. A local area network may be established at the third location. In this case, the terminal device 5 may be connected to the wide area network 8 via the local area network within the third location.
[0021] The terminal device 4 does not have the ability to use the cloud services provided by the cloud server 6. In other words, each terminal device 4 does not have the function of communicating with the cloud server 6. Hereinafter, this terminal device 4 will be particularly referred to as a first-type terminal device 4. On the other hand, the terminal device 5 is a terminal device that has the ability to use the cloud services provided by the cloud server 6. In other words, the terminal device 5 has the function of communicating with the cloud server 6. Hereinafter, this terminal device 5 will be particularly referred to as a second-type terminal device 5.
[0022] The first type terminal device 4 installed at the second base is managed by the master 2 via the client 3 and the cloud server 6. The second type terminal device 5 installed at the third base is managed by the master 2 via the cloud server 6 without going through the client 3.
[0023] The terminal devices 4 and 5 managed by the master 2 may be, for example, a group of terminal devices managed by an organization such as a company. In this case, each location may be an activity base of the organization. For example, the first location where the master 2 is located may be an office that houses the organization's management department. The other second and third locations may be branch offices of the organization that are distant from the first location.
[0024] Examples of the terminal devices 4 and 5 include a printer, a scanner, and a digital multifunction peripheral that integrates the functions of these devices. The master 2 and the client 3 are configured, for example, by installing a dedicated computer program on a personal computer.
[0025] (2) Equipment configuration 2, the master 2 includes a control unit 11, a communication unit 12, a display unit 13, an input unit 14, and a storage unit 15. The control unit 11 includes a CPU 21 and a memory 22. The CPU 21 as a processor executes processing in accordance with a computer program stored in the storage unit 15. The memory 22 is used as a work memory when executing the above processing.
[0026] The memory unit 15 includes storage devices such as a solid state drive and a hard disk drive, and stores various computer programs and data. The memory unit 15 stores a main management program 15a. The main management program 15a is a computer program that causes the CPU 21 to implement the management functions that should be implemented by the master 2. The processing mainly performed by the control unit 11 described below may be understood to be implemented by processing that the CPU 21 executes in accordance with the computer program.
[0027] The communication unit 12 is connected to a local area network of the base where the master 2 exists, and is further connected to a wide area network 8. The communication unit 12 may be connected to the wide area network 8 via a router (not shown). The display unit 13 is configured to display various screens for a user who operates the master 2. An example of the display unit 13 is a liquid crystal display. Examples of the various screens include a screen for displaying log information and status information of the terminal devices 4 and 5 to be managed, and a screen for remotely operating the terminal devices 4 and 5 in accordance with operation signals from the user.
[0028] The input unit 14 includes one or more input devices, such as a keyboard and a pointing device, for inputting operation signals from a user who operates the master 2. The control unit 11 operates in accordance with the operation signals input through the input unit 14.
[0029] The client 3 includes a control unit 31, a communication unit 32, a display unit 33, an input unit 34, and a storage unit 35. The control unit 31 includes a CPU 41 and a memory 42. The CPU 41 as a processor executes processing in accordance with a computer program stored in the storage unit 35.
[0030] A sub-management program 35a is stored in the storage unit 35. The sub-management program 35a is a computer program that causes the CPU 41 to realize functions related to the management functions of the master 2 that should be realized by the client 3. The processing mainly performed by the control unit 31 described below may be understood to be realized by processing that the CPU 41 executes in accordance with the computer program.
[0031] The communication unit 32 is connected to a local area network of the base where the client 3 exists, and is further connected to a wide area network 8. The communication unit 32 may be connected to the wide area network 8 via a router (not shown). The display unit 33 includes, for example, a liquid crystal display, and is configured to display various screens for a user operating the client 3. The input unit 34 includes one or more input devices for inputting operation signals from a user operating the client 3. The control unit 31 operates in accordance with the operation signals input through the input unit 34.
[0032] The first type terminal device 4 includes a control unit 51, a communication unit 52, a display unit 53, and an input unit 54. When the first type terminal device 4 is a digital multifunction peripheral, the first type terminal device 4 may further include a printing unit 55 and a reading unit 56. The first type terminal device 4 may include only one of the printing unit 55 and the reading unit 56.
[0033] The control unit 51 includes a CPU 61 and a memory 62. The memory 62 can include a non-volatile memory such as a flash memory in addition to a RAM, and can store computer programs, setting data, and the like in the non-volatile memory.
[0034] The CPU 61 as a processor performs overall control of the entire first-type terminal device by executing processes in accordance with a computer program stored in the memory 62. The processes mainly performed by the control unit 51 described below may be understood to be realized by the processes executed by the CPU 61 in accordance with the computer program.
[0035] The communication unit 52 is connected to the local area network of the base where the first type terminal device 4 exists so as to be able to communicate with the master 2 or client 3 present there. The display unit 53 includes, for example, a liquid crystal display, and is configured to display various screens for the user operating the first type terminal device 4. The input unit 54 includes one or more input devices, such as a touch panel on the liquid crystal display, for inputting operation signals from the user.
[0036] The printing unit 55 is configured to print an image on a sheet under the control of the control unit 51. Examples of the printing unit 55 include an inkjet printer and a laser printer. According to this embodiment, status information such as the remaining amount of coloring material and log information such as the number of printed sheets are provided to the master 2 from the first type terminal device 4 via the client 3 and the cloud server 6 in a manner described below. The reading unit 56 is configured to read a reading target such as a printed matter under the control of the control unit 51.
[0037] 3, the second type terminal device 5 includes a control unit 71, a communication unit 72, a display unit 73, and an input unit 74. When the second type terminal device 5 is a digital multifunction peripheral, the second type terminal device 5 may further include a printing unit 75 and a reading unit 76. The second type terminal device 5 may include only one of the printing unit 75 and the reading unit 76.
[0038] The control unit 71 includes a CPU 81 and a memory 82. The memory 82 can include a nonvolatile memory such as a flash memory, and can store computer programs, setting data, and the like in the nonvolatile memory.
[0039] The CPU 81 as a processor performs overall control of the entire device by executing processing in accordance with a computer program stored in the memory 82. A communication program 82a is stored in the memory 82. The communication program 82a is a program for using the cloud service provided by the cloud server 6. It may be understood that the processing mainly performed by the control unit 71 described below is realized by processing executed by the CPU 81 in accordance with the computer program.
[0040] The communication unit 72 is connected to the wide area network 8 so as to be able to communicate with the cloud server 6 and the license server 7. If a local area network is established at the third location, the communication unit 72 may be connected to the wide area network 8 via the local area network. The display unit 73 includes, for example, a liquid crystal display. The input unit 74 includes one or more input devices for inputting operation signals from the user.
[0041] The printing unit 75 is configured to print an image on a sheet under the control of the control unit 71. According to this embodiment, status information such as the remaining amount of coloring material and log information such as the number of printed sheets are provided to the master 2 from the second type terminal device 5 via the cloud server 6 in a manner to be described later. The reading unit 76 is configured to read a reading target such as a printed matter under the control of the control unit 71.
[0042] The cloud server 6 includes a control unit 91, a communication unit 92, a first storage 93, and a second storage 94. The control unit 91 includes a CPU 101 and a memory . CPU 101 as a processor executes processes in accordance with computer programs stored in memory 102. The processes executed by CPU 101 include processes for causing cloud server 6 to function as cloud storage. The processes mainly performed by control unit 91 described below may be understood to be realized by processes executed by CPU 101 in accordance with the computer programs.
[0043] The communication unit 92 is connected to the wide area network 8 so as to be able to communicate with the master 2, the client 3, and the second type terminal device 5. The cloud storage includes a table storage and an object storage. When the control unit 91 executes the above process, the first storage 93 functions as a table storage, and the second storage 94 functions as an object storage.
[0044] The exemplary first storage 93 functions as a NoSQL data store and is configured to store tables each consisting of a set of schema-less entities, each of which is configured with a set of properties.
[0045] The exemplary second storage 94 functions as an object storage that can read and write any text file and binary file as an object from the outside using the HTTP / HTTPS protocol.
[0046] Microsoft Azure is a well-known cloud service that provides the above-mentioned table storage and object storage. The cloud server 6 can operate in the same manner as such a cloud service. Azure is a registered trademark.
[0047] The license server 7 includes a control unit 111, a communication unit 112, and a storage unit 113. The control unit 111 includes a CPU 121 and a memory 122. The CPU 121 as a processor performs overall control of the license server 7 by executing processes in accordance with a computer program stored in the memory 122. The processes mainly performed by the control unit 111 described below may be understood to be realized by the processes executed by the CPU 121 in accordance with the computer program.
[0048] The communication unit 112 is connected to the wide area network 8 so as to be able to communicate with the master 2, the client 3, and the second type terminal device 5. The memory unit 113 includes storage such as a solid state drive and a hard disk drive, and stores various computer programs and data.
[0049] (3) Sequence overview Next, the operation sequence relating to management will be outlined. When the main management program 15a is installed in the master 2, processing in accordance with the main management program 15a is executed by the control unit 11 of the master 2. In other words, the master 2 comes to have a management function.
[0050] 4, the master 2 first performs a process of setting a cloud profile in S01. The master 2 sets the cloud profile in accordance with a setting operation performed by the main administrator via the input unit 14, for example.
[0051] Setting a cloud profile includes setting cloud parameters. The cloud parameters include initial setting parameters. As will be described later, the client 3 and the second-type terminal device 5 perform a polling operation on the cloud server 6 and an update operation of information held in the cloud server 6. This polling operation is an operation to periodically check the presence or absence of an instant task, which will be described later. The information update operation is an operation specified by a schedule task, which will be described later.
[0052] The initial setting parameters include, for example, a polling operation cycle (hereinafter referred to as a polling cycle) and an information update operation cycle (hereinafter referred to as an information update cycle). A plurality of information update cycles are set according to the type of information to be updated.
[0053] The cloud parameters may further include a schedule task template, which defines the process content of the schedule task to be executed by each of the terminal devices 4 and 5. The information update period corresponds to the execution period of one or more processes in the schedule task.
[0054] The schedule task template and the schedule task table exist separately. That is, in the first storage 93, the schedule task template is written to a first storage area, and the schedule task table is written to a second storage area different from the first storage area.
[0055] The setting of the cloud profile further includes setting a shared access signature (hereinafter referred to as SAS) for using the cloud service. SAS is an abbreviation for Shared Access Signature.
[0056] The SAS is set individually for each of the first storage 93 and the second storage 94 (i.e., the table storage and the object storage). When setting up a cloud profile on the master 2, the main administrator sets up the SAS set up for each of the first storage 93 and the second storage 94 as part of the cloud profile so that the first storage 93 and the second storage 94 can be accessed from the master 2.
[0057] The same SAS is also set when the main management program 15a is installed in the master 2. When the master 2 accesses the cloud server 6, the SAS set in the master 2 is sent to the cloud server 6. Then, if the sent SAS matches the SAS of the access destination set in the cloud server 6, communication with the access destination (i.e., reading and writing of data) becomes possible.
[0058] As shown in S02, in accordance with the operation of the primary administrator, the master 2 uploads cloud parameters according to the set cloud profile to the first storage 93 of the cloud server 6. As a result, as shown in S03, the uploaded cloud parameters are written to the first storage 93.
[0059] As shown in S04, the master 2 exports at least a portion of the cloud profile from the master 2 as a client profile (i.e., data to be read by the client 3). The client profile may include, for example, at least one of the above-mentioned initial setting parameters, schedule task template, and SAS. The client profile exported by the master 2 is provided to the client 3. The client profile may be provided to the client 3 by any method. For example, the client profile may be sent from the master 2 to the client 3 by email or other method.
[0060] As shown in S06, the sub-administrator operates the client 3 to install the sub-management program 35a on the client 3. At this time, as shown in S05, the sub-administrator operates the client 3 to import the client profile provided from the master 2. That is, various data set in the client profile is set in the client 3 as appropriate. For example, the SAS, polling period, information update period, etc. set in the client profile are imported and set in the client 3. The above-mentioned schedule task template may also be imported.
[0061] By installing the sub-management program 35a and setting the client profile as described above, the client 3 becomes able to use the cloud server 6. This allows the client 3 to communicate information with the master 2 via the cloud server 6. The client 3 is also configured to be able to execute a management relay function via the cloud server 6. The management relay function includes a task execution instruction from the master 2 to the first type terminal device 4, and the transmission of log information and status information from the first type terminal device 4 to the master 2, and is a function that relays information between the master 2 and the first type terminal device 4.
[0062] Furthermore, as shown in S07, the SAS is registered in the second type terminal device 5 by an input operation by the administrator of the second type terminal device 5 (hereinafter referred to as the device administrator). The registration of the SAS to the second type terminal device 5 may be performed, for example, via the input unit 74 of the second type terminal device 5. Alternatively, for example, the SAS may be registered to the second type terminal device 5 from an information processing device other than the second type terminal device 5. Specifically, a predetermined web server may be built into the second type terminal device 5. The SAS may be registered to the second type terminal device 5 by accessing the web server from an information processing device other than the second type terminal device 5, inputting the SAS via a user interface in the information processing device, and transmitting it to the web server.
[0063] The control unit 71 of the second type terminal device 5 in which the SAS is registered executes processing in accordance with the communication program 82a. The control unit 71 that executes processing in accordance with the communication program 82a is hereinafter referred to as the cloud connector. As shown in S08, the cloud connector uses the SAS to access the first storage 93 of the cloud server 6 and refers to the cloud parameters written by the master 2. The cloud connector acquires the cloud parameters and sets them in its own device.
[0064] When the cloud connector accesses the cloud server 6, the SAS of the access destination is sent from the cloud connector to the cloud server 6. Then, if the sent SAS matches the SAS of the access destination set in the cloud server 6, communication with the access destination (i.e., reading and writing of data) becomes possible.
[0065] When the second type terminal device 5 (i.e., the cloud connector) completes the initial settings (i.e., the processing of S07 and S08) including the setting of the above cloud parameters and SAS, it periodically executes the scheduled task according to the set information update period, as shown in S09.
[0066] When the client 3 completes the initial settings (i.e., processing of S05 and S06) including the setting of the above cloud parameters and SAS, it executes a scheduled task to periodically update the information stored in the first storage 93 of the cloud server 6 according to the set information update period, as shown in S10.
[0067] A schedule task using a cloud connector starts by first registering the device information in the first storage 93 if the corresponding device information is not registered in the first storage 93. The device information corresponding to a cloud connector is predetermined information indicating the second-type terminal device 5 in which the cloud connector is implemented.
[0068] If there is a type 1 terminal device 4 among the type 1 terminal devices 4 to be managed whose corresponding device information is not registered in the first storage 93, the schedule task by the client 3 starts by registering the device information of the type 1 terminal device 4 whose device information is not registered in the first storage 93. The device information of the type 1 terminal device 4 is predetermined information that indicates the type 1 terminal device 4.
[0069] The first storage 93 includes a schedule task table as one of its tables. The schedule task table includes a group of one or more entities. An entity includes multiple properties. In this embodiment, the multiple properties include, for example, "PartitionKey", "RowKey", "DeviceId", "NotifyParameter", "Progress", and "Source", as shown in FIG. 5.
[0070] The schedule task table has three entities related to "log," "status," and "registration" for each of the terminal devices 4 and 5. In other words, in this embodiment, there is an individual schedule task table (hereinafter referred to as "individual table") for each of the managed terminal devices 4 and 5, and the schedule task table can be considered to be a collection of these individual tables. Each individual table has three entities related to "log," "status," and "registration" for the corresponding terminal device 4 and 5.
[0071] If the corresponding terminal device is a first-type terminal device 4, the information in the entity is updated by the client 3 that manages the first-type terminal device 4. If the corresponding terminal device is a second-type terminal device 5, the information in the entity is updated by the cloud connector of the second-type terminal device 5.
[0072] If the entity is related to "log", the property "PartitionKey" stores "log", which is a string indicating that it is a "log". The entity related to "log" stores the log information of the terminal device corresponding to the device ID stored in the property "DeviceId" in the property "NotifyParameter". The device ID is identification information unique to each of the terminal devices 4 and 5.
[0073] The log information may include information indicating the total number of pages printed by the corresponding terminal device when the corresponding terminal device is a printer or a digital multifunction peripheral. The log information may also include, as a print history, information indicating the user who issued the print command and the number of pages printed for each print job.
[0074] If the entity is related to "status," the property "PartitionKey" stores "status," a string indicating that it is a "status." An entity related to "status" stores, in the property "NotifyParameter," status information for the terminal device corresponding to the device ID stored in the property "DeviceId." When the corresponding terminal device is a printer or a digital multifunction peripheral, the status information may include information on the remaining amount of coloring material in the corresponding terminal device and error information such as paper jams.
[0075] If the entity is related to "registration", the property "PartitionKey" stores "registration", which is a string indicating "registration". The entity related to "registration" stores device information of the terminal device corresponding to the device ID stored in the property "DeviceId" in the property "NotifyParameter". The device information includes multiple items that describe the basic configuration of the device.
[0076] The property "DeviceId" stores the device ID of the device that updated the entity. The property "NotifyParameter" stores a string written in JSON format to indicate the instructions for the scheduled task.
[0077] For example, the property "NotifyParameter" in an entity related to "status" is written in JSON format, associating the object identifier (OID) used in the management information base (MIB) of the corresponding parameter with its value. The descriptions "xxxxx..." and "yyyyy..." shown in task instruction T1 in Figure 5 are illustrative abstract representations of object identifiers. MIB stands for Management Information Base.
[0078] The instruction on the second line of task instruction T1 is ""xxxx···": "%MIB(xxxx···)%"". The above "xxxx···" is the object ID of the MIB.
[0079] The instruction on the third line of the task instruction T1 is ""yyyy···": "%MIB(yyyy···)%"". The above "yyyy···" is the object ID of the MIB.
[0080] If the above "xxxx..." is written as Oid1, the instruction on the second line is ""Oid1": "%MIB(Oid1)%"". And "%MIB(Oid1)%" is an instruction to get the value corresponding to Oid1, which is the object ID, and overwrite the obtained value with "%MIB(Oid1)%". Therefore, if the value corresponding to Oid1 is "XXXXXXX", in the registered data, ""Oid1": "%MIB(Oid1)%"" will be rewritten to ""Oid1": "XXXXXXX"".
[0081] Similarly, the instruction on the third line is ""Oid2": "%MIB(Oid2)%"" when the object ID "yyyy..." is written as Oid2. The descriptions "xxxxx..." and "yyyyy..." shown in the task result T2 in Figure 5 are illustrative abstract representations of the update results.
[0082] In each of the entities related to "log" and "registration", the character string in the property "NotifyParameter" is rewritten in the same way as in the entity related to "status".
[0083] The property "Progress" stores a string indicating the progress, such as the string "done" indicating that the task has been completed, the string "request" indicating that an instruction is being requested to be executed, or the string "processing" indicating that the task is currently being executed.
[0084] The property "Source" indicates the type of device that updated the entity. When an entity is updated by a client 3, the property "Source" of the entity stores the string "client", which indicates that the entity is a client 3. When an entity is updated by a cloud connector, the property "Source" of the entity stores the string "device", which indicates that the entity is a second-type terminal device 5.
[0085] The entity of the cloud connector of the second type terminal device 5 is updated by the cloud connector. The entity of the first type terminal device 4 is updated by the client 3 connected to the same local area network as the first type terminal device 4. That is, the client 3 updates the entity for each first type terminal device 4 under the client 3 (i.e., the first type terminal device 4 that is the management relay target). Identification information of the client 3 that has the first type terminal device 4 as the management relay target may be written as part of the device information in the registration entity of the first type terminal device 4.
[0086] The client 3 communicates with each of the first-type terminal devices 4 that are management relay targets within the same local area network, and acquires information necessary for updating device information from each of the first-type terminal devices 4. Based on the acquired information, the client 3 can update the registration entity of the corresponding first-type terminal device 4.
[0087] The client 3 further periodically communicates with each of the first-type terminal devices 4 that are management relay targets via the local area network to acquire corresponding log information and status information. Based on the acquired log information and status information, the client 3 can update the log entities and status entities of the corresponding first-type terminal devices 4.
[0088] The cloud connector of the second type terminal device 5 can periodically access the cloud server 6 and update its own log entity and status entity based on its own log information and status information.
[0089] The master 2 also functions as a client 3. That is, it can be understood that the master 2 functions as a client 3 with respect to the first type terminal device 4 at the first location. Specifically, three entities related to "log," "status," and "registration" corresponding to each of the first type terminal devices 4 at the first location (hereinafter referred to as master subordinate terminal devices) are generated in the schedule task table in the first storage 93 of the cloud server 6. The master 2, like the client 3, can acquire various information from the master subordinate terminal devices and update the registration entity, log entity, and status entity of each corresponding master subordinate terminal device.
[0090] 4, the master 2 further periodically accesses the first storage 93 of the cloud server 6 and refers to the log entities, status entities, and registration entities of the terminal devices 4 and 5. Based on these references, the master 2 can execute a process of storing the log information, status information, and device information of each of the terminal devices 4 and 5 in the storage unit 15.
[0091] Furthermore, the master 2 can display a list of the registered terminal devices 4 and 5 on the screen of the display unit 13, and can also display log information and status information of the terminal devices 4 and 5, in accordance with an operation signal output from the input unit 14 by a user operation. In this way, the management system 1 is configured so that the statuses of the terminal devices 4 and 5 used at multiple locations can be remotely monitored from one location where the master 2 is installed.
[0092] As shown in S12, the master 2 receives an instant task execution request operation from the main manager in accordance with an operation signal output from the input unit 14 by the main manager's operation, and generates data indicating an instant task entity (hereinafter referred to as instant task entity) in accordance with this execution request operation. An instant task is a non-periodic task other than a scheduled task.
[0093] Furthermore, the master 2 can register the corresponding instant task entity in the first storage 93 by transmitting the created data to the cloud server 6 as shown in S13.
[0094] The instant task entities are registered in the first storage 93 in the form of an instant task table, for example, as shown in FIG. The instant task table includes the properties "PartitionKey", "RowKey", "DeviceId", "NotifyParameter", "Progress" and "Result".
[0095] The property "PartitionKey" stores the string "instanttask" which indicates that it is an instant task. The property "RowKey" stores a transaction ID for identifying each instant task.
[0096] The property "DeviceId" stores a device ID for identifying the first type terminal device 4 or the second type terminal device 5 that is the destination of the instruction. The property "NotifyParameter" stores a string written in JSON format to indicate the instructions of the instant task.
[0097] The property "Progress" stores a character string indicating the progress of the instruction. The property "Result" stores a string indicating the execution result of the instant task.
[0098] When a specific file is required to execute an instant task, the master 2 stores the file in the second storage 94, as shown in S14 of FIG. 4. In this case, information indicating the storage destination of the file (e.g., a URL) is described in the property "NotifyParameter." For example, when the instant task is a firmware update for the terminal devices 4 and 5, the master 2 stores an update file required for the firmware update in the second storage 94. In this case, for example, the URL of the storage destination of the firmware update file may be described in the property "NotifyParameter."
[0099] As shown in S15, the cloud connector of the second type terminal device 5 accesses the first storage 93 of the cloud server 6 at the set polling period and searches for an instant task that targets itself. That is, the cloud connector determines whether or not a new entity of an instant task that should be executed by itself is registered in the instant task table.
[0100] When a new entity is registered, the cloud connector notifies Master 2 that it has received the instant task request by rewriting the string of the property “Progress” in the corresponding instant task entity from “request” to “processing”.
[0101] As shown in S18, the master 2 that has registered the instant task entity checks the status of the instant task corresponding to the instant task entity. Specifically, the master 2 periodically references the instant task entity in the instant task table registered in the first storage 93 at a set polling cycle. By periodically referencing the instant task entity, the master 2 can confirm that the instant task request has been received based on the updated value of the progress status property.
[0102] When executing an instant task, the cloud connector of the second type terminal device 5 refers to the property "NotifyParameter" in the instant task entity. If a data file required to execute the instant task exists in the second storage 94, the cloud connector downloads the data file from the second storage 94 based on the storage destination information (e.g., a URL) described in the property "NotifyParameter," as shown in S16.
[0103] When the instant task is completed, the cloud connector of the second type terminal device 5 updates the corresponding instant task entity as shown in S17. Specifically, the cloud connector rewrites the character string of the property "Progress" in the corresponding instant task entity from "processing" to "done," thereby notifying the master 2 that the execution of the instant task has been completed.
[0104] As shown in S19, the client 3 accesses the first storage 93 of the cloud server 6 at the set polling period and searches for an instant task that targets the management relay target. That is, the client 3 determines whether or not a new entity of the instant task to be executed by the first type terminal device 4 that is the management relay target of the client 3 has been registered in the instant task table. Hereinafter, each of one or more first type terminal devices 4 that are set as the execution target of the instant task in the instant task table among the first type terminal devices 4 that are the management relay target (that is, one or more first type terminal devices 4 that correspond to the device ID stored in the property "DeviceId") will be referred to as an instant task execution target.
[0105] When a new instant task entity for the instant task execution target is registered, the client 3 notifies the master 2 that it has received the instant task request by rewriting the character string of the property "Progress" in the corresponding instant task entity from "request" to "processing." The client 3 then references the property "NotifyParameter" in the instant task entity to identify the processing content to be executed. Based on the identified processing content, the client 3 then obtains data files required for executing the instant task from the second storage 94 as necessary, as shown in S20.
[0106] Thereafter, as shown in S21, the client 3 instructs the instant task execution targets to execute the instant task via the local area network. At this time, the data file obtained from the second storage 94 is transferred to each instant task execution target. The client 3 then obtains the execution result of the instant task from the instant task execution targets.
[0107] When the execution of the instant task for all instant task execution targets is completed, the client 3 updates the instant task entity of the corresponding instant task execution target as shown in S22. Specifically, the client 3 notifies the master 2 that the execution of the instant task is completed by rewriting the character string of the property "Progress" in the corresponding instant task entity from "processing" to "done."
[0108] To check the status, as shown in S23, the master 2 refers to the instant task entity in the instant task table of the first storage 93, and finds that the character string of the property “Progress” has been rewritten to “done.” This confirms that the instant task has been completed, and the master 2 writes the processing result to the memory unit 15.
[0109] The master 2 can further display the processing results on the screen of the display unit 13. As shown in S24, when the master 2 confirms that the registered instant task has been completed for all corresponding instant task execution targets, the master 2 deletes the instant task entity of the instant task that is no longer needed from the first storage 93 as shown in S25. The master 2 also deletes the data file (e.g., firmware update file) provided for the instant task from the second storage 94 as shown in S26.
[0110] In this way, the management system 1 is configured to be able to remotely control terminal devices 4 and 5 used at multiple locations from one location where the master 2 is installed, by registering and updating instant task entities in the first storage 93 of the cloud server 6 and transferring data files via the second storage 94.
[0111] (4) Processing related to function extensions Next, an operation sequence relating to the function expansion of the second type terminal device 5 will be briefly described. As shown in Fig. 7, in S101, the main administrator AD operates the input unit 14 of the master 2 to input to the master 2 a license for specifying the function extension of the second-type terminal device 5 and an administration password that has been preset for the second-type terminal device 5 that is the target of the function extension. The license is, for example, information formed by a 20-digit number separated by hyphens every four digits. The function extension in Fig. 7 is, for example, adding a function to the second-type terminal device 5 that enables the master 2 to remotely control the second-type terminal device 5.
[0112] Then, in S102, the master 2 uploads an instant task entity of a task (hereinafter referred to as a password check task) that instructs the second type terminal device 5, which is the target of the function extension, to check a password to the cloud server 6. The property "DeviceId" of the instant task entity of the password check task stores the device ID indicating the second type terminal device 5, which is the target of the function extension, and the property "NotifyParameter" stores a character string that instructs the master 2 to check the administration password entered.
[0113] The second type terminal device 5 searches for an instant task targeted at itself at the set polling period, and downloads an instant task entity of the password check task from the cloud server 6 in S103.
[0114] Then, the second type terminal device 5 executes a password check in S104. Specifically, the second type terminal device 5 checks whether the administration password included in the downloaded instant task entity matches the administration password set in the second type terminal device 5.
[0115] Furthermore, in S105, the second type terminal device 5 uploads the result of the password check to the cloud server 6. Specifically, the second type terminal device 5 stores a character string indicating whether the check was successful or not in the property "Result" of the instant task entity of the password check task targeted at itself.
[0116] Thereafter, in S106, master 2 downloads the result of the password check from cloud server 6. Specifically, master 2 obtains the character string stored in the property "Result" in the instant task entity of the password check task registered in cloud server 6.
[0117] If the password check is successful, the master 2 transmits the license input to the master 2 to the license server 7 in S107. Upon receiving the license, the license server 7 transmits to the master 2 in S108 an activation data generation ID corresponding to the received license.
[0118] Upon receiving the activation data generation ID, the master 2 uploads to the cloud server 6 in S109 an instant task entity of a task instructing activation of the function extension (hereinafter, activation task).
[0119] The property "DeviceId" of the instant task entity of the activation task stores the device ID indicating the second type terminal device 5 that is the target of the function extension. The property "NotifyParameter" of the instant task entity of the activation task stores, for example, the string {"ActionTypeId":"12", "DevicePassword":null, "ExecList":["abcd1234-5678-9012-efgh-3456"]}, as shown in task instruction T3 in Figure 6.
[0120] "ActionTypeId":"12" in task instruction T3 instructs execution of a process whose action ID is set as "12". In task instruction T3, "DevicePassword:null" indicates that a device password is not required. "ExecList:[abcd1234-5678-9012-efgh-3456]" indicates that the activation data generation ID is "abcd1234-5678-9012-efgh-3456".
[0121] The second type terminal device 5 searches for an instant task targeted at itself at the set polling period, and downloads the instant task entity of the activated task from the cloud server 6 in S110.
[0122] When the second type terminal device 5 downloads the instant task entity of the activation task, it extracts the activation data generation ID from the instant task entity of the activation task. Then, in S111, the second type terminal device 5 transmits the extracted activation data generation ID and an encryption key with an expiration date to the license server 7.
[0123] Upon receiving the activation data generation ID and the encryption key, the license server 7 encrypts the activation data corresponding to the received activation data generation ID with the received encryption key. Then, in S112, the license server 7 transmits the encrypted activation data to the second-type terminal device 5.
[0124] When the second type terminal device 5 receives the encrypted activation data, it decrypts the activation data with the encryption key. Then, in S113, the second type terminal device 5 applies the decrypted activation data to the second type terminal device 5, thereby activating the function extension corresponding to the license.
[0125] Then, the second type terminal device 5 uploads the execution result of the activation task to the cloud server 6. Specifically, the second type terminal device 5 stores a character string indicating whether or not the activation of the function extension was successful in the property "Result" of the instant task entity of the activation task targeted at itself.
[0126] Thereafter, in S115, the master 2 downloads the result of the activation from the cloud server 6. Specifically, the master 2 acquires the character string stored in the property "Result" in the instant task entity of the activation task registered in the cloud server 6.
[0127] Then, in S116, the master 2 displays the result of the activation on the display unit 13. This allows the main administrator AD to check whether the function extension has been activated in the second type terminal device 5 or not.
[0128] Next, a description will be given of the procedure of the first validation process executed by the control unit 71 of the second type terminal device 5. The first validation process is a process that is repeatedly executed while the second type terminal device 5 is in operation. 8, when the first validation process is executed, the CPU 81 of the control unit 71 first determines in S210 whether or not the instant task entity of the password check task targeted at itself has been downloaded from the cloud server 6. Here, if the instant task entity of the password check task has not been downloaded, the CPU 81 proceeds to S240.
[0129] On the other hand, if the instant task entity of the password check task has been downloaded, the CPU 81 executes a password check in S220. Then, in S230, the CPU 81 uploads the result of the password check to the cloud server 6, and proceeds to S240.
[0130] When the process proceeds to S240, the CPU 81 determines whether or not the instant task entity of the activation task has been downloaded from the cloud server 6. Here, if the instant task entity of the activation task has not been downloaded, the CPU 81 ends the first activation process.
[0131] On the other hand, if the instant task entity of the activation task is downloaded, the CPU 81 extracts the activation data generation ID from the instant task entity of the activation task at S250, and transmits the extracted activation data generation ID and an encryption key with an expiration date to the license server 7.
[0132] Then, in S260, the CPU 81 determines whether or not encrypted activation data has been received from the license server 7. If encrypted activation data has not been received, the CPU 81 repeats the process of S260 to wait until encrypted activation data is received.
[0133] Then, upon receiving the encrypted activation data, the CPU 81 decrypts the activation data with the encryption key in S270. Furthermore, the CPU 81 applies the decrypted activation data to the second-type terminal device 5 in S280, thereby activating the function extension corresponding to the license.
[0134] Then, in S290, the CPU 81 uploads the execution result of the validation task to the cloud server 6, and ends the first validation process. Next, an operation sequence relating to the function expansion of the first type terminal device 4 will be briefly described.
[0135] 9, in S121, the main administrator AD operates the input unit 14 of the master 2 to input to the master 2 a license for specifying a function extension of the first type terminal device 4 and an administration password that has been set in advance for the first type terminal device 4 that is the target of the function extension. The function extension in FIG. 9 is, for example, adding a function to the first type terminal device 4 that enables the master 2 to remotely control the first type terminal device 4.
[0136] The master 2 then uploads to the cloud server 6 an instant task entity of a password check task that instructs the type 1 terminal device 4 that is the target of the function extension to check a password. The property "DeviceId" of the instant task entity of the password check task stores the device ID that indicates the type 1 terminal device 4 that is the target of the function extension, and the property "NotifyParameter" stores a character string that instructs the master 2 to check the administration password that has been input.
[0137] At the set polling period, the client 3 searches for instant tasks targeting the first type terminal device 4 (hereinafter referred to as the connected terminal device) connected to the client 3, and downloads the instant task entity of the password check task from the cloud server 6.
[0138] The client 3 then performs a password check. Specifically, the client 3 checks whether the administration password included in the downloaded instant task entity matches the administration password set in the connection terminal device.
[0139] Furthermore, the client 3 uploads the result of the password check to the cloud server 6. Specifically, the client 3 stores a character string indicating whether the check was successful or not in the property "Result" of the instant task entity of the password check task for the connected terminal device.
[0140] Thereafter, the master 2 downloads the result of the password check from the cloud server 6. Note that in FIG. 9, the operation for the password check is not shown. If the password check is successful, the master 2 transmits the license input to the master 2 to the license server 7 in S122.
[0141] Upon receiving the license, the license server 7 transmits to the master 2 in S123 an activation data generation ID corresponding to the received license. Upon receiving the activation data generation ID, the master 2 uploads the instant task entity of the activation task to the cloud server 6 in S124. The property "DeviceId" of the instant task entity of the activation task stores the device ID indicating the type 1 terminal device 4 that is the target of the function extension.
[0142] The client 3 searches for instant tasks that target the connected terminal device at the set polling period, and downloads the instant task entity of the enabled task from the cloud server 6 in S125.
[0143] After downloading the instant task entity of the activation task, the client 3 extracts the activation data generation ID from the instant task entity of the activation task. Then, in S126, the client 3 transmits the extracted activation data generation ID and an encryption key with an expiration date to the license server 7.
[0144] Upon receiving the activation data generation ID and the encryption key, the license server 7 encrypts the activation data corresponding to the received activation data generation ID with the received encryption key, and then transmits the encrypted activation data to the client 3 in S127.
[0145] When the client 3 receives the encrypted activation data, it decrypts the activation data using the encryption key. Then, in S128, the client 3 transmits the decrypted activation data to the first-type terminal device 4 that is the target of the function extension.
[0146] The first type terminal device 4 that has received the activation data applies the activation data to the first type terminal device 4, thereby activating the function extension corresponding to the license. Next, a description will be given of the procedure of the second activation process executed by the control unit 31 of the client 3. The second activation process is a process that is repeatedly executed while the client 3 is in operation.
[0147] 10, when the second activation process is executed, the CPU 41 of the control unit 31 first determines in S410 whether or not the instant task entity of the password check task for the connected terminal device has been downloaded from the cloud server 6. Here, if the instant task entity of the password check task has not been downloaded, the CPU 41 proceeds to S440.
[0148] On the other hand, if the instant task entity of the password check task has been downloaded, the CPU 41 executes a password check of the connected terminal device in S420. Then, in S430, the CPU 41 uploads the result of the password check of the connected terminal device to the cloud server 6, and proceeds to S440.
[0149] When the process proceeds to S440, the CPU 41 determines whether or not the instant task entity of the activation task of the connected terminal device has been downloaded from the cloud server 6. Here, if the instant task entity of the activation task of the connected terminal device has not been downloaded, the CPU 41 ends the second activation process.
[0150] On the other hand, when the instant task entity of the activation task of the connected terminal device is downloaded, the CPU 41 extracts the activation data generation ID from the instant task entity of the activation task at S450, and transmits the extracted activation data generation ID and an encryption key with an expiration date to the license server 7.
[0151] Then, in S460, the CPU 41 determines whether or not encrypted activation data for the connected terminal device has been received from the license server 7. If encrypted activation data has not been received, the CPU 41 repeats the process of S460 to wait until encrypted activation data is received.
[0152] Then, upon receiving the encrypted activation data, the CPU 41 decrypts the activation data with the encryption key in S470, and then transmits the decrypted activation data to the first type terminal device 4 that is the target of the function extension in S480.
[0153] Then, in S490, the CPU 81 determines whether or not the execution result of the function extension activation has been received from the first type terminal device 4 that is the target of the function extension. If the execution result of the activation has not been received, the CPU 81 repeats the process of S490 to wait until the execution result of the activation is received.
[0154] Then, upon receiving the execution result of the activation, the CPU 81 uploads the execution result of the activation task to the cloud server 6 in S500, and ends the second activation process. (5) Effects The management system 1 configured in this manner includes a master 2, clients 3 and second-type terminal devices 5 that cannot communicate directly with the master 2, a cloud server 6, and a license server 7. The cloud server 6 is configured to be able to communicate with the master 2, clients 3, and second-type terminal devices 5. The license server 7 is configured to be able to communicate with the master 2, clients 3, and second-type terminal devices 5. The second-type terminal device 5 is a terminal device that is not connected to the master 2 so as to be able to communicate. The client 3 is connected to at least one first-type terminal device 4 that is not connected to the master 2, cloud server 6, and license server 7 so as to be able to communicate.
[0155] When the master 2 acquires an activation data generation ID for identifying the activation data from the license server 7, the master 2 uploads the activation data from the license server 7 to the cloud server 6. The activation data is data used in a function extension process executed by the client 3 and the second type terminal device 5 to extend the functions of the first type terminal device 4 and the second type terminal device 5.
[0156] The client 3 and the second type terminal device 5 execute a transmission process, a decryption process, and a data use process. In the transmission process, when the activation data generation ID is downloaded from the cloud server 6, the activation data generation ID and an encryption key with an expiration date are transmitted to the license server 7.
[0157] In the decryption process, when activation data encrypted with an encryption key is received from the license server 7, the received activation data is decrypted with an encryption key with a validity period. The data use process executes the function extension process using the enablement data decrypted in the decryption process.
[0158] Such a management system 1 can transmit and receive an encryption key with a time limit and activation data encrypted with the encryption key with a time limit directly between the license server 7 and the client 3 and the second-type terminal device 5 without going through the cloud server 6. This allows the management system 1 to prevent the expiration of the encryption key with a time limit. This allows the management system 1 to prevent the occurrence of a situation in which the encryption key expires and the activation data cannot be decrypted.
[0159] In the embodiment described above, the master 2 corresponds to a management apparatus, the client 3 and the second type terminal apparatus 5 correspond to devices, the cloud server 6 corresponds to a storage device, and the license server 7 corresponds to a server.
[0160] Furthermore, S250 and S450 correspond to a transmission process and a transmission step, S270 and S470 correspond to a decryption process and a decryption step, and S280 and S480 correspond to a data use process and a data use step.
[0161] Furthermore, the function extension process corresponds to the device execution process, the activation data corresponds to the execution data, and the activation data generation ID corresponds to the data identification information. The second type terminal device 5 corresponds to a terminal device that is not communicatively connected to the management device. The first type terminal device 4 corresponds to a terminal device that is not communicatively connected to the management device, storage device, and server. The client 3 corresponds to a sub-management device. The sub-management program 35a and the communication program 82a correspond to programs.
[0162] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modifications. In the above embodiments, multiple functions of one component may be realized by multiple components, or one function of one component may be realized by multiple components. Furthermore, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of the above embodiments may be omitted. Furthermore, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.
[0163] In addition to the above-mentioned client 3 and second-type terminal device 5, the present disclosure can also be realized in various forms, such as a system having the client 3 and the second-type terminal device 5 as components, a program for causing a computer to function as the client 3 and the second-type terminal device 5, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and a management method. [Explanation of symbols]
[0164] 1...management system, 2...master, 3...client, 5...second-type terminal device, 6...cloud server, 7...license server, 35a...sub-management program, 82a...communication program
Claims
1. A management device; a device that cannot directly communicate with the management device; a storage device configured to be able to communicate with the management device and the device; a server configured to be able to communicate with the management device and the device; the management device is configured to, when acquiring data identification information for identifying execution data used in a device execution process executed by the device from the server, upload the data identification information to the storage device; The device comprises: a transmission process of transmitting the data identification information and an encryption key with an expiration date to the server when the data identification information is downloaded from the storage device; a decryption process for decrypting the execution data encrypted with the encryption key from the server; a data use process for executing the device execution process using the execution data decrypted in the decryption process; 2. A management system configured to:
2. The management system according to claim 1, A management system in which the device is a terminal device that is not communicatively connected to the management device.
3. The management system according to claim 1, The device is a sub-management device connected to at least one terminal device that is not communicatively connected to the management device, the storage device, and the server.
4. A management system in which a management device and a device that cannot directly communicate with the management device are configured to be able to communicate with a storage device and a server, The control unit of the device a transmission process of downloading, from the storage device, data identification information, which is information acquired from the server by the management device and further uploaded to the storage device by the management device, and which is information for identifying execution data used in device execution processing executed by the device, and transmitting the data identification information and an encryption key with an expiration date to the server; a decryption process for decrypting the execution data encrypted with the encryption key from the server; a data use process for executing the device execution process using the execution data decrypted in the decryption process; The device that is configured to run
5. A management system is configured such that a management device and a device that cannot directly communicate with the management device can communicate with a storage device and a server, the management system comprising: a control unit provided in the device; a transmission process of downloading, from the storage device, data identification information, which is information acquired from the server by the management device and further uploaded to the storage device by the management device, and which is information for identifying execution data used in device execution processing executed by the device, and transmitting the data identification information and an encryption key with an expiration date to the server; a decryption process for decrypting the execution data encrypted with the encryption key from the server; a data use process for executing the device execution process using the execution data decrypted in the decryption process; A program that is configured to cause
6. A management method executed by a management device and a device that cannot directly communicate with the management device in a management system configured to be able to communicate with a storage device and a server, comprising: a transmitting step of downloading, from the storage device, data identification information, which is information acquired from the server by the management device and further uploaded to the storage device by the management device, and which is information for identifying execution data used in device execution processing executed by the device, and transmitting the data identification information and an encryption key with an expiration date to the server; a decryption step of, when receiving the execution data encrypted with the encryption key from the server, decrypting the received execution data with the encryption key; a data use step of executing the device execution process using the execution data decrypted in the decryption step; A management method comprising:
Citation Information
Patent Citations
File management system and file management program
JP2006072664A
Image processing apparatus, control method of the same, program, and image processing system
JP2016131323A
Server device and program
JP2019148957A