Device, system, method and program
The system enables secure server functionality in a LAN-less environment by using a local loopback connection to handle service requests and responses, addressing the vulnerability of open server ports.
Patent Information
- Application Number
- JP2024004117
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-01-15
- Publication Date
- 2025-10-29
- Estimated Expiration
- 2044-01-15
AI Technical Summary
Devices with server functions in a LAN-less environment are vulnerable to attacks when their server ports are left open.
A system that enables server functionality without using the device's server port by establishing a local loopback connection for service requests and responses, allowing the server to forward these through a secure connection.
This approach allows the use of server functions without exposing the device's server port, enhancing security by preventing direct attacks.
Smart Images

Figure 0007762238000002 
Figure 0007762238000003 
Figure 0007762238000004
Abstract
Description
[Technical Field]
[0001] The present invention , De The present invention relates to a device, a system, a method and a program. [Background technology]
[0002] In addition to the traditional on-premise in-house network environment, a technology called SASE (Secure Access Service Edge) that builds a network environment equivalent to an on-premise environment on the cloud is beginning to be used. An environment where an in-house network does not exist is sometimes called a LAN (Local Area Network)-less environment. Devices such as multifunction peripherals sometimes have server functions. Patent Document 1 proposes a technology for safely using the server functions of a device from a PC in a LAN-less environment while leaving the device's server port open. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2009-151479 Summary of the Invention [Problem to be solved by the invention]
[0004] If a server port of a device is left open, the server port may be vulnerable to attacks. An aspect of the present invention aims to provide a technology for enabling the server function of a device without using the server port of the device. [Means for solving the problem]
[0005] According to some embodiments, a system is provided comprising a device having server functionality and a server, the device comprising: connection request means for transmitting a connection request to the server for establishing a connection between the device and the server; and receiving means for receiving a service request for the server functionality from the server via the connection. sending the service request received from the server to the server function over a local loopback connection; an acquisition means for acquiring a response generated by the server function in response to the service request; and a transmission means for transmitting the response to the server. a setting means for acquiring from a user a setting as to whether or not the server function is to be enabled for a service request transmitted to the device without going through the connection; The server includes a connection establishing means for establishing the connection in response to the connection request from the device, and a forwarding means for forwarding the service request received from the information processing device while the connection is established to the device through the connection, and forwarding the response from the device to the service request to the information processing device. [Effects of the Invention]
[0006] The above embodiment allows the server functionality of the device to be used without using the server port of the device. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a block diagram illustrating an example of the hardware configuration of a system according to a first embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of the software configuration of the system according to the first embodiment. [Figure 3] FIG. 3 is a schematic diagram illustrating an example of a screen displayed in the system according to the first embodiment. [Figure 4] FIG. 3 is a sequence diagram illustrating an example of operation of the first embodiment. [Figure 5] FIG. 3 is a flowchart illustrating an example of operation of the first embodiment. [Figure 6] FIG. 3 is a flowchart illustrating an example of operation of the first embodiment. [Figure 7] FIG. 3 is a flowchart illustrating an example of operation of the first embodiment. [Figure 8]FIG. 10 is a block diagram illustrating an example of the hardware configuration of a system according to a second embodiment. [Figure 9] FIG. 10 is a schematic diagram illustrating an example of a screen displayed in the system according to the second embodiment. [Figure 10] FIG. 10 is a sequence diagram illustrating an example of operation of the second embodiment. [Figure 11] FIG. 10 is a flowchart illustrating an example of operation of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0009] First Embodiment Referring to FIG. 1, an example of the hardware configuration of a multifunction peripheral 100, a server 120, and a personal computer (PC) 130 according to the first embodiment will be described. In the first embodiment, a system 10 is configured by the multifunction peripheral 100 and the server 120. The system 10 is a system for providing services provided by the multifunction peripheral 100 to a PC 130. In the example of FIG. 1, the PC 130 is not included in the system 10. Alternatively, the PC 130 may be included in the system 10. In the example of FIG. 1, the system 10 includes one multifunction peripheral 100 and one server 120. Alternatively, the system 10 may include multiple multifunction peripherals 100 and one server 120. One multifunction peripheral 100 may be included in only one system 10, or may be included in two or more systems 10. In the example of FIG. 1, one PC 130 is shown. The system 10 may be used by multiple PCs 130.
[0010] The multifunction device 100 is a device having at least two of the following functions: a scan function, a print function, and a copy function. Instead of the multifunction device 100, any device (e.g., a dedicated printer, a sensor, a home appliance, etc.) capable of providing services to an external device (e.g., a PC 130) may be used in the system 10. In this way, a device capable of providing services to an external device may be called a device having a server function. In the following example, a web server function is used as an example of the server function of the multifunction device 100. Alternatively or in addition to this, the multifunction device 100 may have other server functions (e.g., a file transfer server function, an authentication server function, etc.).
[0011] The multifunction peripheral 100 may have the hardware components shown in Fig. 1. The multifunction peripheral 100 may not include some of the components shown in Fig. 1, or may include components not shown in Fig. 1. The same applies to the components of the server 120 and the PC 130.
[0012] The CPU (Central Processing Unit) 101 is a processor for controlling the overall operation of the multifunction peripheral 100. The ROM (Read Only Memory) 102 is a read-only nonvolatile memory. A boot program may be stored in the ROM 102. The boot program is read and executed by the CPU 101 when the multifunction peripheral 100 is powered on. The RAM (Random Access Memory) 103 is a readable and writable volatile memory. The RAM 103 temporarily stores programs, data, and the like used by the CPU 101 to control the multifunction peripheral 100.
[0013] The HDD (Hard Disk Drive) 104 is a storage device that semi-permanently stores programs and data used by the CPU 101 to control the multifunction peripheral 100. Other storage devices such as an SSD (Solid State Drive) may be used instead of or in addition to the HDD. The programs and data stored in the HDD 104 may be read into the RAM 103 by the CPU 101.
[0014] The network interface (I / F) 105 is a device for communicating with an external device. Communication with an external device may be wired or wireless. The network I / F 105 for wired communication may include a connector for connecting a cable and a signal processing circuit for processing transmitted and received data. The network I / F 105 for wireless communication may include an antenna for transmitting and receiving data and a signal processing circuit for processing transmitted and received data.
[0015] The printer control unit 107 controls the operation (e.g., printing) of the printer 108. The scanner control unit 109 controls the operation (e.g., reading of an original) of the scanner 110. The panel control unit 111 controls the operation of the operation panel 112. The operation panel 112 is a touch panel type operation unit. The operation panel 112 may be configured with a display for displaying information to the user of the multifunction peripheral 100 and a touch sensor for acquiring instruction input from the user of the multifunction peripheral 100.
[0016] The above-mentioned components of the multifunction peripheral 100 are interconnected by a bus 106. Control signals from the CPU 101 and data signals between the components are transmitted and received via the bus 106.
[0017] The server 120 is an information processing device for relaying services provided by the multifunction peripheral 100 to the PC 130. Components 121 to 126 of the server 120 may be similar to components 101 to 105 of the multifunction peripheral 100, and therefore redundant description will be omitted. The input I / F 127 is a device for connecting an input device (e.g., a mouse or a keyboard) for acquiring instruction input from the user of the server 120. The output I / F 128 is a device for connecting an output device (e.g., a display or a speaker) for outputting information from the user of the server 120.
[0018] The PC 130 is an information processing device for using services provided by the system 10. Other information processing devices (for example, a smartphone or a tablet) may be used instead of the PC 130. The components 131 to 138 of the server 120 may be similar to the components 101 to 105 of the multifunction peripheral 100 and the components 127 to 128 of the server 120, and therefore redundant description will be omitted. An input device connected to the input I / F 137 and an output device connected to the output I / F 138 may be built into the PC 130.
[0019] The multifunction peripheral 100, the server 120, and the PC 130 are connected to a network 140. The multifunction peripheral 100 and the server 120 can communicate with each other through the network 140. The server 120 and the PC 130 can communicate with each other through the network 140. The multifunction peripheral 100 and the PC 130 may or may not be able to communicate directly. The network 140 may be a private network such as a local area network, or a public network such as the Internet.
[0020] An example of the software configuration of the multifunction peripheral 100, server 120, and PC 130 will be described with reference to FIG. 2. The multifunction peripheral 100 may have the software components shown in FIG. 2. The multifunction peripheral 100 may not include some of the components shown in FIG. 2, or may include components not shown in FIG. 2. The software components of the multifunction peripheral 100 may be implemented by the CPU 101 reading them from the ROM 102 or HDD 104 to the RAM 103 and executing them. Alternatively, at least some of the software components of the multifunction peripheral 100 may be implemented by a dedicated integrated circuit such as an ASIC (Application Specific Integrated Circuit). The same applies to the components of the server 120 and PC 130.
[0021] First, the software configuration of the multifunction peripheral 100 will be described. A setting management unit 201 manages the settings of the multifunction peripheral 100. For example, the settings of the multifunction peripheral 100 may be stored in the HDD 104. The setting management unit 201 may store new settings in the HDD 104, or may update or delete settings stored in the HDD 104, in response to a request from a user, an external device, or another component of the multifunction peripheral 100. The setting management unit 201 may respond with the settings stored in the HDD 104 in response to a request from a user, an external device, or another component of the multifunction peripheral 100.
[0022] The setting management unit 201 may receive a request for setting the multifunction peripheral 100 from a user via the operation panel 112, and may display the setting of the multifunction peripheral 100 on the operation panel 112. In addition, the setting management unit 201 may have a web server function. The setting management unit 201 may use the web server function to receive a request for setting the multifunction peripheral 100 from an external device (e.g., PC 130) via the network I / F 105, and may respond with the setting of the multifunction peripheral 100 to the external device. In this way, the setting management unit 201 may be an application having a web server function. For example, the setting management unit 201 may accept a connection request from an external device via HTTP (Hyper Text Transfer Protocol) on port 80. Alternatively or in addition to this, the setting management unit 201 may accept a connection request from an external device via HTTPS (HTTP Secure) on port 443. The setting management unit 201 may send and receive data (for example, requests and responses) used in processing related to the settings of the multifunction peripheral 100 through connections established by these protocols.
[0023] The web server function of the setting management unit 201 may be set to be enabled or disabled. When the web server function is enabled, the setting management unit 201 accepts requests from external devices via the network 140. When the web server function is disabled, the setting management unit 201 rejects requests from external devices via the network 140. For example, the setting management unit 201 may discard packets sent to a port for providing the web server function (e.g., port 80 or port 443).
[0024] The display control unit 202 displays information on the operation panel 112. For example, the display control unit 202 may generate a screen to be displayed on the operation panel 112. The registration request unit 203 requests the server 120 to register the multifunction peripheral 100. This request may include identification information and authentication information of the multifunction peripheral 100. The transfer unit 204 transfers data between the server function of the multifunction peripheral 100 (for example, the web server function of the setting management unit 201) and the server 120.
[0025] The communication control unit 205 connects to the network 140 using the network I / F 105 and communicates with other devices (e.g., the server 120) through the network 140. Communication between the above-mentioned components of the multifunction peripheral 100 and other devices is performed via the communication control unit 205.
[0026] Next, a description will be given of the software configuration of the server 120. The multifunction device management unit 221 manages the multifunction device 100 included in the system 10. For example, in response to receiving a registration request from the multifunction device 100, the multifunction device management unit 221 manages the multifunction device 100 by storing identification information of the multifunction device 100 in the HDD 124. The information of the multifunction device 100 managed by the multifunction device management unit 221 may be acquired from the user of the server 120 via the input I / F 127 of the server 120.
[0027] The transfer unit 222 transfers data between the multifunction peripheral 100 and the PC 130. The communication control unit 223 may be the same as the communication control unit 205, and therefore a duplicated description will be omitted.
[0028] Next, the software configuration of PC 130 will be described. Browser 231 is client software that uses services provided by a web server (for example, the web server function of multifunction peripheral 100). Browser 231 displays a screen generated based on data received from the web server on the display of PC 130. Browser 231 also transmits user input made on this screen to the web server. Communication control unit 232 may be the same as communication control unit 205, so a duplicated description will be omitted.
[0029] Examples of screens generated by the system 10 will now be described with reference to Figure 3. First, screen 300 in Figure 3(a) will be described, and the other screens in Figure 3 will be described later.
[0030] Screen 300 is a screen for acquiring settings related to the remote setting function from the user. The remote setting function may be a web server function for configuring the multifunction device 100 from an external device (e.g., PC 130) via the network 140. When the remote setting function is enabled, the user can check and change the settings of the multifunction device 100 from the external device via the network 140. When the remote setting function is disabled, the user cannot check or change the settings of the multifunction device 100 from the external device via the network 140. Even in this case, the user can check and change the settings of the multifunction device 100 using the operation panel 112 of the multifunction device 100.
[0031] The screen 300 may be displayed on the operation panel 112 of the multifunction peripheral 100 in response to a request from the user. An input to the screen 300 may be acquired by the operation panel 112 of the multifunction peripheral 100.
[0032] When the remote setting function of the setting management unit 201 is enabled, data for generating the screen 300 may be transmitted from the multifunction peripheral 100 to the PC 130 in response to a request from the browser 231 of the PC 130, and the screen 300 may be displayed on the display of the PC 130. Furthermore, input to the screen 300 may be acquired by an input device of the PC 130 and transmitted to the multifunction peripheral 100.
[0033] When the remote setting function is enabled, the data for generating the screen 300 may be sent directly from the multifunction device 100 to the PC 130 (i.e., without going through the server 120), or may be sent from the multifunction device 100 to the PC 130 via the server 120.
[0034] Button 301 is a graphics object for obtaining a user instruction to enable the remote setting function. When button 305 is pressed while button 301 is selected, the setting management unit 201 enables the remote setting function. Specifically, the setting management unit 201 may open ports 80 and 443. Button 302 is a graphics object for obtaining a user instruction to disable the remote setting function. When button 305 is pressed while button 302 is selected, the setting management unit 201 disables the remote setting function. Specifically, the setting management unit 201 may close ports 80 and 443. When button 306 is pressed, the setting management unit 201 does not reflect the settings on screen 300.
[0035] When button 301 is selected, the setting management unit 201 may further display window 303. Window 303 is an object for setting whether to limit the protocol accepted by the remote setting function to HTTPS, which uses Transport Layer Security (TLS). When it is set to limit to HTTPS, the setting management unit 201 may accept requests via HTTPS and reject requests via HTTP. Specifically, the setting management unit 201 may close port 80 and open port 443. When it is set not to limit to HTTPS, the setting management unit 201 may accept requests via HTTP and requests via HTTPS. Specifically, the setting management unit 201 may open ports 80 and 443.
[0036] Button 304 is a graphics object for acquiring a user instruction to set up a cloud connection. In response to pressing button 304, setting management unit 201 displays screen 310 shown in Fig. 3(b). Details of screen 310 will be described later.
[0037] The overall operation of the system 10 will be described with reference to the sequence diagram of Fig. 4. Fig. 4 describes a case where the web server function (e.g., remote setting function) of the multifunction device 100 (specifically, the setting management unit 201) is disabled. For example, the administrator of the multifunction device 100 may disable the web server function when the multifunction device 100 is used in a LAN-less environment. The operation of Fig. 4 may also be executable when the web server function of the multifunction device 100 is enabled.
[0038] The operations of the system 10 may include a registration operation 400, a connection operation 410, and a service providing operation 420. The registration operation 400 is an operation of registering the multifunction peripheral 100 with the server 120. The connection operation 410 is an operation of establishing a connection between the multifunction peripheral 100 and the server 120. The service providing operation 420 is an operation in which the system 10 provides a service provided by the web server function of the multifunction peripheral 100 to the PC 130. The connection operation 410 may be called a preparation operation because it is performed as preparation for executing the service providing operation 420. The service providing operation 420 transfers a request from the PC 130 from the server 120 to the multifunction peripheral 100, so the service providing operation 420 may be called a transfer operation.
[0039] First, the registration operation 400 will be described with reference to Figures 4 and 5. Figure 5(a) describes a method executed by the multifunction device 100 in the registration operation 400. The multifunction device 100 may start the operation of Figure 5(a) in response to an instruction from the user of the multifunction device 100 (for example, in response to pressing of button 314). Figure 5(b) describes a method executed by the server 120 in the registration operation 400. The server 120 may repeatedly execute the operation of Figure 5(b) during operation. Figure 5(b) describes the operation of the server 120 with respect to the multifunction device 100, but the server 120 may also execute similar operations with respect to other multifunction devices or other devices.
[0040] In S501, the registration request unit 203 of the multifunction peripheral 100 transmits a request to the server 120 to register the multifunction peripheral 100 in the server 120 (corresponding to S401 in FIG. 4). In the following description, the request to register the multifunction peripheral 100 in the server 120 will be referred to as a registration request.
[0041] The registration request may include identification information of the multifunction peripheral 100. As will be described later, the identification information of the multifunction peripheral 100 is used by a user who uses the web server function of the multifunction peripheral 100 to identify the multifunction peripheral 100 in the service providing operation 420. The identification information of the multifunction peripheral 100 may be any information that allows the user to identify the multifunction peripheral 100. For example, the identification information of the multifunction peripheral 100 may be a combination of the DNS (Domain Name System) name of the domain to which the multifunction peripheral 100 belongs, the serial number of the multifunction peripheral 100, the model name of the multifunction peripheral 100, and the installation location of the multifunction peripheral 100. Alternatively or in addition to this, the identification information of the multifunction peripheral 100 may include at least one of the IP (Internet Protocol) address of the multifunction peripheral 100, the MAC (Media Access Control) address of the multifunction peripheral 100, and the device name of the multifunction peripheral 100 set by the user. The identification information of the multifunction peripheral 100 may be set by the user before the execution of the method of FIG. 5( a ), or may be set when the multifunction peripheral 100 is manufactured and stored in the HDD 104 .
[0042] If the server 120 requires user authentication to register the multifunction peripheral 100, the registration request may include user credentials that instruct the multifunction peripheral 100 to send the registration request. The credentials may be, for example, a combination of a username and a password. Alternatively, the credentials may be other information that can authenticate the user as authentic, such as a client certificate. The user credentials may be used as user identification information for identifying the user.
[0043] 3(b), a description will be given of a screen 310 used to obtain an instruction to send a registration request from a user. As described above, the screen 310 may be displayed on the operation panel 112 of the multifunction peripheral 100 in response to pressing of the button 304 on the screen 300.
[0044] Field 311 is a graphics object for inputting the URL (Uniform Resource Locator) of the server 120. Field 312 is a graphics object for inputting a user name. Field 313 is a graphics object for inputting a password. In response to button 305 being pressed with fields 311 to 313 filled in, the setting management unit 201 generates a registration request including the information entered in fields 312 and 313 and identification information of the multifunction peripheral 100, and transmits this registration request to the URL entered in field 311. When button 315 is pressed, the setting management unit 201 does not transmit the registration request. If the server 120 does not require user authentication to register the multifunction peripheral 100, the screen 310 does not need to include fields 312 and 313, and the registration request does not need to include user credentials. The information entered in fields 311 to 313 may be stored in the HDD 104 for subsequent processing.
[0045] In S511, the multifunction device management unit 221 of the server 120 determines whether or not a registration request has been received from the multifunction device 100. If it is determined that a registration request has been received from the multifunction device 100 ("YES" in S511), the multifunction device management unit 221 transitions the process to S512, and otherwise ("NO" in S511), repeats S511.
[0046] In S512, the multifunction device management unit 221 of the server 120 authenticates the user who instructed the transmission of the registration request. For example, before executing the method of FIG. 5B, a list of credentials of users who are permitted to register the multifunction device 100 may be stored in the HDD 124 of the server 120. The multifunction device management unit 221 may determine that the authentication has been successful if the credential list stored in the HDD 124 includes the credential included in the registration request. On the other hand, the multifunction device management unit 221 may determine that the authentication has failed if the credential list stored in the HDD 124 does not include the credential included in the registration request.
[0047] If it is determined that the user authentication was successful ("YES" in S512), the multifunction device management unit 221 transitions the process to S513, and otherwise ("NO" in S512), the process transitions to S514. If the server 120 does not require user authentication to register the multifunction device 100, S512 may be omitted, and S513 may be executed after S511.
[0048] In S513, the multifunction device management unit 221 of the server 120 registers the multifunction device 100. Specifically, the multifunction device management unit 221 generates an access token for the multifunction device 100, associates this access token with the identification information of the multifunction device 100 included in the registration request, and stores this access token in the HDD 124. The multifunction device in which the identification information and the access token are stored in association with each other becomes the multifunction device registered with the server 120. When deregistering the multifunction device, the multifunction device management unit 221 may delete this information from the HDD 124. Furthermore, the multifunction device management unit 221 may register user identification information associated with the registration request in association with the multifunction device 100. The user identification information associated with the registration request may be the user credentials received in S512, or may be other information.
[0049] The multifunction device management unit 221 sends the generated access token to the multifunction device 100 (corresponding to S402 in FIG. 4). In S514, the multifunction device management unit 221 of the server 120 sends an error notification to the multifunction device 100. The error notification may indicate that user authentication has failed. After S513 or S514, the multifunction device management unit 221 of the server 120 waits for a registration request from the multifunction device 100 or another device in S511.
[0050] In S502, the registration request unit 203 of the multifunction peripheral 100 determines whether registration of the multifunction peripheral 100 has been successful. If it is determined that registration of the multifunction peripheral 100 has been successful ("YES" in S502), the registration request unit 203 transitions the process to S503, and otherwise ("NO" in S502), the registration request unit 203 transitions the process to S504. The registration request unit 203 may determine that registration of the multifunction peripheral 100 has been successful based on receiving an access token from the server 120. The registration request unit 203 may also determine that registration of the multifunction peripheral 100 has failed based on receiving an error notification from the server 120.
[0051] In S503, the multifunction peripheral 100 stores the access token received from the server 120 in the HDD 104. Specifically, the registration request unit 203 passes the access token received from the server 120 to the transfer unit 204 and instructs the transfer unit 204 to store the access token in the RAM 103 (corresponding to S403 in FIG. 4). In response to this instruction, the transfer unit 204 stores the access token in the RAM 103. Thereafter, the transfer unit 204 instructs the setting management unit 201 to store the access token stored in the RAM 103 in the HDD 104 (corresponding to S404 in FIG. 4). In response to this instruction, the transfer unit 204 stores the access token in the HDD 104.
[0052] In S504, the registration request unit 203 of the multifunction peripheral 100 may display an error message on the operation panel 112 indicating that registration of the multifunction peripheral 100 has failed.
[0053] Next, the connection operation 410 will be described with reference to Figures 4 and 6. Figure 6(a) describes a method executed by the multifunction peripheral 100 in the connection operation 410. The multifunction peripheral 100 may start the operation of Figure 6(a) in response to the completion of S503, in response to the multifunction peripheral 100 being powered on, or in response to an instruction from the user. Figure 6(b) describes a method executed by the server 120 in the connection operation 410. The server 120 may repeatedly execute the operation of Figure 6(b) during operation. Although Figure 6(b) describes the operation of the server 120 with respect to the multifunction peripheral 100, the server 120 may also execute similar operations with respect to other multifunction peripherals or other devices.
[0054] In S601, the transfer unit 204 of the multifunction peripheral 100 transmits a request to the server 120 to establish a connection between the multifunction peripheral 100 and the server 120 (corresponding to S411 in FIG. 4). In the following description, a request to establish a connection between the multifunction peripheral 100 and the server 120 is referred to as a connection request. This connection may include a TCP (Transmission Control Protocol) connection.
[0055] The connection request may include identification information and an access token of the multifunction peripheral 100. The identification information of the multifunction peripheral 100 may be the same as the identification information included in the registration request sent in S501. The access token may be the access token received in S502 and stored in the HDD 104.
[0056] The connection established between the server 120 and the multifunction peripheral 100 is maintained semi-permanently. For example, this connection is maintained unless the power of the multifunction peripheral 100 or the server 120 is turned off or unless the user of the system 10 explicitly disconnects the connection. Therefore, in the following description, this connection is referred to as a constant connection.
[0057] The connection request may explicitly or implicitly include an indication that the server 120 is prohibited from terminating the connection between the multifunction peripheral 100 and the server 120. For example, this indication may be that the connection request includes identification information and an access token of the multifunction peripheral 100. Alternatively, the connection request may include a flag that indicates that the server 120 is prohibited from terminating the connection between the multifunction peripheral 100 and the server 120.
[0058] In S611, the transfer unit 222 of the server 120 determines whether or not a connection request has been received from the multifunction device 100. If it is determined that a connection request has been received from the multifunction device 100 ("YES" in S611), the transfer unit 222 transitions the process to S612, and otherwise ("NO" in S611), repeats S611.
[0059] In S612, the transfer unit 222 of the server 120 determines whether the multifunction peripheral 100 that sent the connection request is registered with the server 120. If it is determined that the multifunction peripheral 100 that sent the connection request is registered with the server 120 (YES in S612), the transfer unit 222 transitions the process to S613, and otherwise (NO in S612), the transfer unit 222 transitions the process to S614. Specifically, the transfer unit 222 may inquire of the multifunction peripheral management unit 221 whether the multifunction peripheral 100 that sent the connection request is registered with the server 120 (corresponding to S412 in FIG. 4). The multifunction peripheral management unit 221 may determine that the multifunction peripheral 100 that sent the connection request is registered with the server 120 when the combination of the identification information and access token included in the connection request is stored in the HDD 104. If the combination of the identification information and the access token included in the connection request is not stored in the HDD 104, the multifunction device management unit 221 may determine that the multifunction device 100 that sent the connection request is not registered in the server 120. As described above, the identification information of the multifunction devices registered in the server 120 and the access token associated therewith are stored in the HDD 104. The multifunction device management unit 221 returns the determination result to the transfer unit 222 (corresponding to S413 in FIG. 4). In the above example, it is determined whether the multifunction device 100 is registered in the server 120 based on the combination of the identification information and the access token. Alternatively, it may be determined whether the multifunction device 100 is registered in the server 120 based on only one of the identification information and the access token.
[0060] In S613, the transfer unit 222 of the server 120 establishes a constant connection between the multifunction peripheral 100 and the server 120 based on the fact that the multifunction peripheral 100 is registered with the server 120 (corresponding to S414 in FIG. 4). The server 120 maintains this constant connection. In S614, the transfer unit 222 of the server 120 sends an error notification to the multifunction peripheral 100. The error notification may indicate that the multifunction peripheral 100 is not registered with the server 120. After S613 or S614, the transfer unit 222 of the server 120 waits for a connection request from the multifunction peripheral 100 or another device in S611.
[0061] In S602, the transfer unit 204 of the multifunction peripheral 100 determines whether the establishment of the constant connection has been successful. If it is determined that the establishment of the constant connection has been successful ("YES" in S602), the transfer unit 204 transitions the process to S603, and otherwise ("NO" in S602), the transfer unit 204 transitions the process to S604. The transfer unit 204 may determine that the establishment of the constant connection has been successful based on a notification of connection completion from the server 120. The transfer unit 204 may also determine that the establishment of the constant connection has failed based on receiving an error notification from the server 120.
[0062] In S603, the transfer unit 204 of the multifunction peripheral 100 maintains the constant connection. That is, the multifunction peripheral 100 does not disconnect the constant connection while in operation. In S604, the transfer unit 204 of the multifunction peripheral 100 may display an error message indicating that the establishment of the constant connection has failed on the operation panel 112. When the method of FIG. 6(a) is started without an instruction from the user, the transfer unit 204 may record the error message in a log instead of displaying the error message on the operation panel 112.
[0063] Next, the service providing operation 420 will be described with reference to FIGS. 4 and 7. FIG. 7(a) describes a method executed by the PC 130 in the service providing operation 420. The PC 130 may start the operation of FIG. 7(a) in response to receiving an instruction from the user of the PC 130 to display a list of multifunction peripherals registered in the server 120. FIG. 7(b) describes a method executed by the server 120 in the service providing operation 420. The server 120 may repeatedly execute the operation of FIG. 7(b) during operation. Although FIG. 7(b) describes the operation of the server 120 with respect to the multifunction peripheral 100, the server 120 may also execute similar operations with respect to other multifunction peripherals or other devices. FIG. 7(c) describes a method executed by the multifunction peripheral 100 in the service providing operation 420. The multifunction peripheral 100 may repeatedly execute the operation of FIG. 7(c) after a constant connection is established.
[0064] In S701, the browser 231 of the PC 130 sends a request to the server 120 for a list of multifunction peripherals registered in the server 120 (corresponding to S421 in FIG. 4). In the following description, this request will be referred to as a list request. The URL of the server 120 may be input by the user. As will be described below, the PC 130 can connect to a multifunction peripheral registered in the server 120 via the server 120 and use the web server function of the multifunction peripheral. If user authentication is required to request a list of multifunction peripherals registered in the server 120, the list request may include the user's credentials.
[0065] In S711, the multifunction device management unit 221 of the server 120 determines whether a list request has been received from the PC 130. If it is determined that a list request has been received from the PC 130 ("YES" in S711), the multifunction device management unit 221 transitions the process to S712, and otherwise ("NO" in S711), the process transitions to S713.
[0066] In S712, the multifunction device management unit 221 of the server 120 responds to the PC 130 with a list of multifunction devices registered in the server 120 (corresponding to S422 in FIG. 4). For example, the server 120 responds to the PC 130 with data for displaying a screen including a list of multifunction devices. Information about the multifunction devices registered in the server 120 is stored in the HDD 124. The multifunction device management unit 221 may include in the response identification information of the multifunction device stored in the HDD 124 (i.e., the identification information included in the registration request acquired in S511). If user authentication is required to respond with the list, the multifunction device management unit 221 may authenticate the user and respond with the list only if the authentication is successful. The user authentication may be performed in the same manner as in S512, or may be performed by another method.
[0067] The multifunction device management unit 221 may respond to the PC 130 with a list of all multifunction devices registered in the server 120. Alternatively, the multifunction device management unit 221 may respond with a list of multifunction devices that are registered in the server 120 and that are registered in association with user identification information acquired in connection with the list request. In this case, the user of the PC 130 can obtain information only about the multifunction devices that he or she has registered. The type of list that the server 120 responds with may be set in advance and stored in the HDD 124.
[0068] In S702, the browser 231 of the PC 130 displays a screen including the list received from the server 120 on the display of the PC 130. An example of such a screen 320 is shown with reference to Fig. 3(c). A graphics object 321 is a list of the multifunction peripherals returned from the server 120 (i.e., the multifunction peripherals registered with the server 120).
[0069] The following describes the processing that occurs when button 332 is pressed while one of the multifunction peripherals is selected using the radio buttons of graphics object 321. In the following description, it is assumed that multifunction peripheral 100 is selected. In S703, browser 231 of PC 130 transmits a request to server 120 to connect to the web server function (e.g., remote setting function) of multifunction peripheral 100 (corresponding to S423 in FIG. 4). In the following description, such a request is referred to as a service request. The service request may be a request via HTTPS. When button 323 is pressed, browser 231 does not transmit a service request.
[0070] In S713, the transfer unit 222 of the server 120 determines whether or not a service request has been received from the PC 130. If it is determined that a service request has been received from the PC 130 ("YES" in S713), the transfer unit 222 transitions the process to S714, and otherwise ("NO" in S713), the process transitions to S715. When S713 is executed, a constant connection is established.
[0071] In S714, the transfer unit 222 of the server 120 transfers the service request received from the PC 130 to the multifunction device 100 via the constant connection (corresponding to S424 in FIG. 4). Because the constant connection was established in response to the connection request from the multifunction device 100, the server 120 can send the service request to the multifunction device 100 even if the port for the web server function of the multifunction device 100 is closed.
[0072] In S721, the transfer unit 204 of the multifunction peripheral 100 determines whether or not a service request has been received from the server 120 via a constant connection. If it is determined that a service request has been received from the server ("YES" in S721), the transfer unit 204 transitions the process to S722, and otherwise ("NO" in S721), repeats S721.
[0073] In S722, the multifunction peripheral 100 transmits a service response to the service request to the server 120. The service response may be an HTTPS response. The multifunction peripheral 100 may transmit this service response via a constant connection.
[0074] Specifically, the transfer unit 204 of the multifunction peripheral 100 transmits the service request to the web server function of the setting management unit 201 via a local loopback connection within the multifunction peripheral 100 (corresponding to S425 in FIG. 4). This connection request may be an HTTPS request. The web server function of the setting management unit 201 generates a connection response to the connection request and returns it to the transfer unit 204 (corresponding to S426 in FIG. 4). The transfer unit 204 transfers this connection response to the server 120 as a service response (corresponding to S427 in FIG. 4).
[0075] In S715, the transfer unit 222 of the server 120 determines whether or not a service response has been received from the multifunction device 100 via the constant connection. If it is determined that a service response has been received from the multifunction device 100 ("YES" in S715), the transfer unit 222 transitions the process to S716, and otherwise ("NO" in S715), the process transitions to S711.
[0076] In S716, the transfer unit 222 of the server 120 transfers the service response received from the multifunction peripheral 100 to the PC 130 (corresponding to S428 in FIG. 4). In S704, the browser 231 of the PC 130 displays a screen generated based on the service response received from the server 120 (for example, a screen provided by the web server function of the setting management unit 201) on the display of the PC 130.
[0077] According to the above-described method, even if the port for the web server function of the multifunction device 100 is closed, the web server function of the multifunction device 100 can return a response to a request via the server 120. Therefore, even if the multifunction device 100 is placed in a LAN-less environment, the web server function of the multifunction device 100 can be provided to the PC 130 with the port kept closed (i.e., with improved security). For example, even if the PC 130 is connected to a different network from the multifunction device 100, as long as the PC 130 can access the server 120, the PC 130 can use the web server function of the multifunction device 100, improving convenience.
[0078] Furthermore, because the server 120 receives service requests from the PC 130 while a constant connection is established, the server 120 can quickly transfer the service requests to the multifunction device 100. Furthermore, because the web server function of the multifunction device 100 (for example, its setting management unit 201) can be used as is, there is no need to create a web server function that operates as a client, and this reduces unnecessary maintenance costs for developers.
[0079] In the above-described embodiment, the multifunction device 100 provides a web server function, and the PC 130 communicates with the multifunction device 100 via the server 120 using HTTPS. Alternatively, the multifunction device 100 may provide a server function using another protocol, and the PC 130 may use the server function of the multifunction device 100 using the other protocol via the server 120. For example, a network device management client running on the PC 130 may obtain information from the multifunction device 100 via the server 120 using SNMP (Simple Network Management Protocol).
[0080] In the above-described method, steps S421 and S422 in Fig. 4 and steps S701, S702, S711, and S712 in Fig. 7 may be omitted. In this case, in step S703, the PC 130 may specify the multifunction peripheral to connect to and send a service request to the server 120. This type of configuration is useful for protocols and applications that do not display a screen.
[0081] <Second embodiment> A system 80 according to the second embodiment will be described with reference to Fig. 8. In the following description of the second embodiment, differences from the first embodiment will be mainly described, and explanations of points that may be the same as those in the first embodiment will be omitted.
[0082] System 80 differs from system 10 in that it has multifunction peripheral 100 instead of multifunction peripheral 800. As with the first embodiment, system 80 may include multiple multifunction peripherals or other devices, and may include both multifunction peripherals 100 and multifunction peripherals 800, among others.
[0083] The multifunction peripheral 800 differs from the multifunction peripheral 100 in that it has multiple network I / Fs. In the example of FIG. 8, the multifunction peripheral 800 has two network I / Fs, namely, network I / F 105 and network I / F 801. Therefore, the multifunction peripheral 800 can be connected to different networks. For example, the network I / F 105 can be connected to the network 140. The network 140 can be a LAN installed in an on-premises environment. The network I / F 801 can be connected to the Internet 803 via an access point 802. In this way, the multifunction peripheral 800 can be connected to both an on-premises environment and a LAN-less environment.
[0084] The network I / F 801 may communicate with the access point 802 via a wired or wireless connection. The network I / F 105 may be treated as a primary network I / F, and the network I / F 801 may be treated as a secondary network I / F. Alternatively, the network I / F 105 may be treated as a secondary network I / F, and the network I / F 801 may be treated as a primary network I / F.
[0085] With reference to FIG. 9, an example of a screen generated by the system 80 will be described. A screen 900 in FIG. 9(a) is a screen for acquiring settings related to the remote setting function from the user. The screen 900 differs from the screen 300 in that it further includes a radio button 901, but may be similar in other respects. The radio button 901 is a graphics object for acquiring from the user a designation of whether the remote setting function is to be set for the network I / F 105 or the network I / F 801. The setting management unit 201 of the multifunction peripheral 800 acquires settings related to the remote setting function from the user for each of the two network I / Fs 105 and 801 using the screen 900. Specifically, when "Main Line" is selected using the radio button 901, the setting management unit 201 acquires settings related to the network I / F 105. When "Second Line" is selected using the radio button 901, the setting management unit 201 acquires settings related to the network I / F 801.
[0086] 9(b) is a screen used to obtain an instruction to send a registration request from a user. Screen 910 differs from screen 310 in that it further includes a graphics object 911, but may be similar in other respects.
[0087] The graphics object 911 is used to acquire from the user a setting as to whether or not to enable a web server function (e.g., a remote setting function) for service requests sent to the multifunction peripheral 800 without going through a constant connection. When ON is selected in the graphics object 911, the setting management unit 201 disables the web server function for service requests sent to the multifunction peripheral 800 without going through a constant connection. When OFF is selected in the graphics object 911, the setting management unit 201 enables the web server function for service requests sent to the multifunction peripheral 800 without going through a constant connection.
[0088] The settings made on screens 900 and 910 may be stored in HDD 104 and used in subsequent processing. For example, when multifunction peripheral 800 is powered on, setting management unit 201 may read settings related to the remote setting function stored in HDD 104 and set the server port according to these settings. Graphics object 911 may be used in the first embodiment. That is, for a multifunction peripheral having one network I / F 105 such as multifunction peripheral 100, it may be possible to set whether to enable the web server function for service requests sent to multifunction peripheral 800 without going through a constant connection.
[0089] Table 1 below shows whether service requests to the web server function are possible with the above settings.
[0090] [Table 1]
[0091] When the remote setting function is disabled, the setting management unit 201 disables the server port for receiving remote requests for the remote setting function. As described above, the remote setting function is disabled by button 302 on screen 900. In this case, both service requests via a constant connection and service requests not via a constant connection cannot be made.
[0092] When the remote setting function is enabled, the setting management unit 201 enables a server port for receiving remote requests for the remote setting function. As described above, the remote setting function is enabled by the button 301 on the screen 900. In this case, a service request can be made without going through a constant connection. When the remote setting function is enabled and the server 120 is not registered on the screen 910, a constant connection is not established. Therefore, a service request cannot be made via a constant connection.
[0093] A constant connection is established when the remote setting function is enabled and the server 120 is registered on the screen 910. Therefore, a service request can be made via the constant connection.
[0094] If the setting on screen 910 is such that the web server function is disabled for service requests sent to the multifunction device 800 without going through a constant connection, service requests cannot be made without going through a constant connection. If the setting on screen 910 is such that the web server function is enabled for service requests sent to the multifunction device 800 without going through a constant connection, service requests can be made without going through a constant connection.
[0095] For example, when it is desired to use the remote setting function with a priority on performance in an on-premises environment, the remote setting function may be enabled for the network I / F 105, and the multifunction peripheral 800 may not be registered with the server 120. This allows the PC 130 connected to the network 140 to be restricted to making service requests that do not go via a constant connection. On the other hand, the remote setting function may be enabled for the network I / F 801 connected to the Internet 803, the multifunction peripheral 800 may be registered with the server 120, and service requests that do not go via a constant connection may be disabled. This improves security.
[0096] Next, the operation of the system 80 will be described with reference to Figures 10 and 11. Figure 10 shows a sequence diagram of the system 80. Figure 11 describes a method executed by the multifunction peripheral 800. The multifunction peripheral 800 may execute the method of Figure 11 in response to receiving a service request from the PC 130 without going through a constant connection (corresponding to S1001 in Figure 10).
[0097] In S1101, the setting management unit 201 of the multifunction peripheral 800 determines whether the remote setting function is enabled. If the setting management unit 201 determines that the remote setting function is enabled ("YES" in S1101), it transitions the process to S1102, and otherwise ("NO" in S1101), it terminates the process. If the remote setting function is disabled, the setting management unit 201 may discard the received remote request.
[0098] In S1102, the setting management unit 201 of the multifunction peripheral 800 determines whether the remote setting function is enabled for service requests that do not go through a constant connection. If the setting management unit 201 determines that the remote setting function is enabled for service requests that do not go through a constant connection ("YES" in S1102), the processing proceeds to S1103, and otherwise ("NO" in S1102), the processing proceeds to S1104.
[0099] In step S1103, the setting management unit 201 of the multifunction peripheral 800 responds to the remote request. For example, the setting management unit 201 responds to the PC 130 with a screen for configuring the multifunction peripheral 800.
[0100] In S1104, the setting management unit 201 of the multifunction peripheral 800 returns a response to the PC 130 to redirect the PC 130 to the server 120 (corresponding to S1002 in FIG. 10). For example, this response may include the URL of the server 120. Thereafter, the PC 130 may execute the processes from S701 onward in FIG. 7A. Alternatively, the PC 130 may execute the processes from S703 onward in FIG. 7A, targeting the multifunction peripheral 800. By redirecting the PC 130 in this way, the process for executing the service request continues.
[0101] In the above-described embodiment, whether to enable the remote setting function for service requests that do not go through a constant connection is set in accordance with a user instruction. When a setting is made for any network I / F to connect to a LAN-less environment (i.e., when the setting is made to disable the remote setting function for service requests sent to the multifunction peripheral 800 without going through a constant connection), the setting management unit 201 of the multifunction peripheral 800 may automatically enable the remote setting function for this network I / F for service requests sent to the multifunction peripheral 800 via a constant connection. For example, when the setting is made to close all server ports (well-known ports) of the multifunction peripheral 800, the setting management unit 201 of the multifunction peripheral 800 may automatically enable the remote setting function for service requests sent to the multifunction peripheral 800 via a constant connection.
[0102] <Summary of the embodiment> [Item 1] A system including a device having a server function and a server, The device comprises: a connection request means for transmitting a connection request to the server to request establishment of a connection between the device and the server; receiving means for receiving a service request for the server function from the server through the connection; an acquisition means for acquiring a response generated by the server function in response to the service request; a transmitting means for transmitting the response to the server, The server a connection establishing means for establishing the connection in response to the connection request from the device; a transfer means for transferring the service request received from the information processing device while the connection is established to the device through the connection, and transferring the response from the device to the service request to the information processing device. [Item 2] 2. The system according to claim 1, wherein the acquisition means of the device transmits the service request received from the server to the server function via a local loopback connection. [Item 3] The device further comprises a registration request means for transmitting a registration request to the server to request registration of the device; the server further comprises a management means for registering the device that has transmitted the registration request; 3. The system according to item 1 or 2, wherein the connection establishment means of the server establishes the connection based on the device being registered. [Item 4] Item 4. The system according to item 3, wherein the management means of the server receives a list request from the information processing device for a list of registered devices, and responds to the list request with a list of registered devices. [Item 5] The management means of the server registering user identification information acquired in connection with the registration request in association with the device; 5. The system according to item 4, wherein the system responds with a list of the devices registered in association with the user identification information acquired in connection with the list request. [Item 6] The system described in any one of items 1 to 5, wherein the device further comprises a setting means for acquiring from a user a setting as to whether the server function is to be enabled for service requests sent to the device without going through the connection. [Item 7] the device comprises a plurality of network interfaces; 7. The system according to item 6, wherein the setting means of the device acquires the setting from a user for each of the plurality of network interfaces. [Item 8] 8. The system of claim 6 or 7, wherein the device further comprises a redirection means for redirecting the information processing device that sent a service request to the device without going through the connection to the server when the device is set to disable the server function for service requests sent to the device without going through the connection. [Item 9] The system described in any one of items 6 to 8, wherein the setting means of the device automatically enables the server function for service requests sent to the device via the connection in response to being set to disable the server function for service requests sent to the device without going through the connection. [Item 10] 10. The system according to any one of items 1 to 9, wherein the transfer means of the server transfers the service request to the device using HTTPS. [Item 11] 11. The system of any one of items 1 to 10, wherein the device is a multifunction peripheral. [Item 12] A method executed in a system including a device having server functionality and a server, the device sending a connection request to the server requesting establishment of a connection between the device and the server; the server establishing the connection in response to the connection request from the device; a step of the server transferring a service request for the server function of the device, which is received from the information processing device while the connection is established, to the device via the connection; receiving the service request over the connection by the device; the device obtaining a response generated by the server function to the service request; the device sending the response to the server; the server forwarding the response from the device to the service request to the information processing device. [Item 13] A device having a server function, a connection request means for transmitting a connection request to the server to request establishment of a connection between the device and the server; receiving means for receiving a service request for the server function from the server through the connection; an acquisition means for acquiring a response generated by the server function in response to the service request; sending means for sending the response to the server. [Item 14] A program for causing a computer to function as each means of the device described in item 13. [Item 15] a server, a connection establishing means for establishing a connection between a device having a server function and the server in response to a connection request from the device; A server comprising: a transfer means for transferring a service request for the server function of the device received from an information processing device while the connection is established to the device via the connection, and transferring a response from the device to the service request to the information processing device. [Item 16] A program for causing a computer to function as each means of the server described in item 15.
[0103] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0104] 10 systems, 100 multifunction devices, 120 servers, 130 PCs
Claims
1. A system including a device having a server function and a server, The device comprises: a connection request means for transmitting a connection request to the server to request establishment of a connection between the device and the server; receiving means for receiving a service request for the server function from the server through the connection; an acquisition means for transmitting the service request received from the server to the server function via a local loopback connection and acquiring a response generated by the server function in response to the service request; a transmitting means for transmitting the response to the server; a setting means for acquiring from a user a setting as to whether or not the server function is to be enabled for a service request transmitted to the device without going through the connection; Equipped with The server a connection establishing means for establishing the connection in response to the connection request from the device; a transfer means for transferring the service request received from the information processing device while the connection is established to the device through the connection, and transferring the response from the device to the service request to the information processing device.
2. The device further comprises a registration request means for transmitting a registration request to the server to request registration of the device; the server further comprises a management means for registering the device that has transmitted the registration request; The system of claim 1 , wherein the connection establishment means of the server establishes the connection based on the device being registered.
3. 3. The system according to claim 2, wherein the management means of the server receives a list request from the information processing device for a list of registered devices, and responds to the list request with the list of registered devices.
4. The management means of the server registering user identification information acquired in connection with the registration request in association with the device; The system according to claim 3 , wherein the system responds with a list of the devices registered in association with user identification information acquired in connection with the list request.
5. the device comprises a plurality of network interfaces; 2. The system of claim 1, wherein the configuration means of the device obtains the configuration from a user for each of the plurality of network interfaces.
6. The system of claim 1, further comprising a redirection means for redirecting the information processing device that sent a service request to the device without going through the connection to the server when the device is set to disable the server function for service requests sent to the device without going through the connection.
7. 2. The system of claim 1, wherein the setting means of the device automatically enables the server function for service requests sent to the device via the connection in response to being set to disable the server function for service requests sent to the device without going through the connection.
8. The system of claim 1 , wherein the forwarding means of the server forwards the service request to the device over HTTPS.
9. The system of claim 1 , wherein the device is a multifunction peripheral.
10. A method executed in a system including a device having server functionality and a server, the device sending a connection request to the server requesting establishment of a connection between the device and the server; the server establishing the connection in response to the connection request from the device; a step of the server transferring a service request for the server function of the device, which is received from the information processing device while the connection is established, to the device via the connection; receiving the service request over the connection by the device; the device transmitting the service request received from the server to the server function over a local loopback connection and obtaining a response generated by the server function to the service request; the device sending the response to the server; the server transferring the response from the device to the service request to the information processing device; and the device acquiring from the user a setting as to whether the server function is enabled for service requests sent to the device without going through the connection.
11. A device having a server function, a connection request means for transmitting a connection request to the server to request establishment of a connection between the device and the server; receiving means for receiving a service request for the server function from the server through the connection; an acquisition means for transmitting the service request received from the server to the server function via a local loopback connection and acquiring a response generated by the server function in response to the service request; a transmitting means for transmitting the response to the server; a setting means for acquiring from a user a setting as to whether the server function is to be enabled for a service request sent to the device without going through the connection.
12. A program for causing a computer to function as each of the means of the device according to claim 11.
Citation Information
Patent Citations
Method, system, and computer program commodity for data communication using interconnection architecture
JP2004005661A
Network system, direct access method, network household electrical appliance, and program
JP2009151479A
Mediation server and computer program for mediation server
JP2023097076A