Information processing device, information processing method, and program
The information processing device addresses the issue of users neglecting security setting changes by detecting network environment shifts and displaying necessary adjustments, thereby improving security through timely updates.
Patent Information
- Application Number
- JP2021199139
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-08
- Publication Date
- 2025-11-17
- Estimated Expiration
- 2041-12-08
AI Technical Summary
Existing information devices do not effectively notify users about necessary changes in security-related function settings due to changes in network environments, leading to potential security risks when users without specialized knowledge manage these devices.
An information processing device that detects changes in network configuration and displays information on security-related function settings on a user interface, providing guidance and manual settings based on the detected changes.
Enables users to promptly adjust security settings in response to network environment changes, enhancing security by ensuring appropriate configurations are maintained.
Smart Images

Figure 0007770891000001 
Figure 0007770891000002 
Figure 0007770891000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device that presents information relating to settings of security-related functions of an information device to a user. [Background technology]
[0002] In recent years, information devices have come to be used in a variety of environments, such as telecommuting and public spaces shared by an unspecified number of people. Furthermore, information devices connected to networks can be exposed to various security risks. Given this, general information devices have a configuration function that allows users to configure security-related functions.
[0003] Furthermore, Patent Document 1 discloses a technique for switching to a network setting that is prepared in advance and that corresponds to the network environment in which an information processing device is used, depending on the network environment in which the information processing device is used. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-94736 Summary of the Invention [Problem to be solved by the invention]
[0005] With the recent spread of information devices, there are an increasing number of cases where users without specialized security knowledge manage information devices. Patent Document 1 does not consider notifying users of information related to the settings of security-related functions of information devices in response to changes in the network environment. As a result, there is a problem that users continue to use information devices without changing the settings of security-related functions of the information devices, even when changes in the network environment would normally be desirable.
[0006] An object of the present invention is to provide an information processing device that presents to a user information relating to the settings of security-related functions of an information device in response to a change in the network environment. [Means for solving the problem]
[0007] In order to achieve the above object, the information processing device of the present invention comprises: Processing equipment to Address information Allocation The DHCP server Obtaining network configuration information Request to send a request means and Based on request Acquired Network configuration information First, network configuration information News and a storage means for storing the first network configuration information and the request means By Based on the newly acquired second network configuration information a detection means for detecting a change in the signal; and based on the detection of the change, The above information Processing equipment Regarding the configuration of security-related functions Table Display items on the screen Control it so that and a display control means. [Effects of the Invention]
[0008] According to the information processing device of the present invention, it is possible to provide an information processing device that presents information regarding the settings of security-related functions of an information device to a user in response to a change in the network environment. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 illustrates an example of a communication system. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of an MFP 101. [Figure 3] FIG. 2 is a diagram illustrating an example of the software configuration of an MFP 101. [Figure 4] FIG. 10 is a diagram showing an example of a screen displayed on the operation unit 206 of the MFP 101. [Figure 5]10 is a flowchart showing an example of network configuration information acquisition executed by the MFP 101 in the first embodiment. [Figure 6] 10 is a flowchart showing an example of network configuration change detection executed by the MFP 101 in the first embodiment. [Figure 7] 10 is a flowchart showing an example of display control of a screen displayed on an operation unit 206 of an MFP 101 in the first embodiment. [Figure 8] FIG. 10 is a diagram showing an example of a screen displayed on an operation unit 206 of an MFP 101 in the second embodiment. [Figure 9] 10 is a flowchart showing an example of display control of a screen displayed on an operation unit 206 of an MFP 101 in the second embodiment. [Figure 10] 11 is a flowchart showing an example of control of a screen displayed on an operation unit 206 of an MFP 101 in the third embodiment. [Figure 11] FIG. 13 is a diagram illustrating an example of a hardware configuration of a management cloud system 102 according to a fourth embodiment. [Figure 12] FIG. 13 is a diagram illustrating an example of the software configuration of a management cloud system 102 according to a fourth embodiment. [Figure 13] FIG. 13 is a diagram showing an example of a screen displayed on a PC 107 in the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] The following describes embodiments of the present invention with reference to the drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0011] First Embodiment First, the configuration of the communication system according to the present invention will be described using FIG. 1. In the communication system according to the present embodiment, the MFP (Multi Function Peripheral) 101 and the management cloud system 102 are connected via the LAN 103, the gateway 104, and the Internet 105.
[0012] The management cloud system 102 is a server that collects information from the MFP 101 and remotely monitors the status of the MFP 101. Also, the gateway 104 is a network router that relays communication from the MFP 101 to the Internet 105.
[0013] The MFP 101, the DHCP (Dynamic Host Configuration Protocol) server 106, and the PC 107 are connected via the LAN 103.
[0014] <Hardware Configuration of MFP 101> Next, the hardware configuration of the MFP 101, which is an example of the information device in the present embodiment, will be described using FIG. 2.
[0015] The MFP 101 has a printer unit 208 that outputs electronic data to a paper medium and a scanner unit 210 that reads a paper medium and converts it into electronic data. In the present embodiment, the MFP 101 having a plurality of functions is exemplified as an example of the information device constituting the communication system, but it is not limited thereto. For example, a single-function scanner or printer device may be used. Also, a 3D printer or 3D scanner device may be used.
[0016] The control unit 200 including the CPU (Central Processing Unit) 201 controls the operation of the entire MFP 101. The ROM (Read Only Memory) 202 is used to store programs executed by the CPU 201. The RAM (Random Access Memory) 203 is used as a working memory for temporarily arranging data used by the CPU 201. The storage 204 stores print jobs, image data, various programs, and various setting information. Thus, hardware such as the CPU 201, ROM 202, RAM 203, and storage 204 constitutes a so-called computer.
[0017] The operation unit I / F (interface) 205 connects the operation unit 206 and the control unit 200. The operation unit 206 is provided with a liquid crystal display unit having a touch panel function, various hard keys, and the like. The operation unit 206 functions as a display unit for displaying information to the user and a reception unit for receiving the user's instructions.
[0018] The printer I / F 207 connects the printer unit 208 and the control unit 200. The MFP 101 performs output processing to a paper medium based on print data input via the printer I / F 207. The scanner I / F 209 connects the scanner unit 210 and the control unit 200. The scanner unit 210 reads a document placed on a document table (not shown) and generates image data.
[0019] A network cable is connected to the network I / F 211, and communication with an external device on the LAN 103 can be executed. In the present embodiment, it is assumed that it is a communication interface for performing wired communication, but it is not limited thereto. For example, it may be a wireless communication interface.
[0020] <Software Configuration of MFP 101> Next, the software configuration of the MFP 101, which is an example of an information device in this embodiment, will be described with reference to Fig. 3. Each unit shown in Fig. 3 is realized by the CPU 201 executing a program corresponding to each unit stored in the ROM 202.
[0021] The operation control unit 301 displays a screen for the user on the operation unit 206. It also detects user operations and switches screens or updates the display based on the detection results. The data storage unit 302 stores data in the ROM 202 or reads data from the ROM 202 in response to requests from other control units. For example, when a user wants to change some device setting, the operation control unit 301 first detects the content input by the user to the operation unit 206. Then, in response to a request from the operation control unit 301, the data storage unit 302 saves the content in the ROM 202.
[0022] The TCP / IP control unit 303 transmits network packets via the network I / F 211 in response to requests from other control units, and also has the function of receiving network packets from the outside and transferring the received packets to other control units.
[0023] The DHCP control unit 304 communicates with the DHCP server 106 in accordance with DHCP, thereby acquiring the IP address, subnet mask, lease period, and the like of the MFP 101 from the DHCP server 106. The DHCP control unit 304 starts the above acquisition process when it detects a link-up, such as when the device is started up, or at a timing based on the lease period of the IP address assigned by the DHCP server 106. Specifically, if it determines that the remaining lease period derived based on a comparison between the current time and the lease period is shorter than a predetermined period, it re-executes the acquisition process in order to renew the lease period.
[0024] The network configuration detection unit 305 collects network configuration information for the currently connected network and saves configuration information for the previously connected network. The network configuration information is composed of information about other information processing devices connected to the same network. One type of information is a MAC (Media Access Control) address that physically identifies the connected default gateway device. In this embodiment, the gateway 104 shown in FIG. 1 corresponds to the default gateway device. Furthermore, the MAC address and IP address of the DHCP server 106 that dynamically assigns IP addresses to clients on the network, and the network address assigned to the device by the DHCP server 106 also constitute network configuration information.
[0025] The security setting control unit 306 manages the correspondence between the setting items and the corresponding setting values of security-related functions for installation environments such as an internal LAN, a home, or a public space. Furthermore, when a user specifies an installation environment, the corresponding security-related functions are configured collectively. Examples of security-related function settings include a combination of setting items and setting values, such as encryption of communication paths, disabling legacy protocols, and enabling a personal firewall. Specifically, the security setting control unit 306 manages combinations of setting items and setting values predefined by the MFP 101 vendor for each installation environment. In this embodiment, a combination of setting items and setting values corresponding to a given installation environment is configured so that at least one setting value or one setting item differs from combinations of setting items and setting values corresponding to other installation environments. In this manner, this embodiment provides a mechanism for collectively reflecting setting values corresponding to installation environments by collectively reflecting combinations of setting items and setting values that are predefined for each installation environment and that are at least partially different.
[0026] Returning to the explanation of FIG. 3, the security setting control unit 306 issues a read request or a write request to the data storage unit 302 to refer to or change the setting values stored in the data storage unit 302 .
[0027] The management system communication unit 307 exchanges information between the management cloud system 102 and the MFP 101. Specifically, when a setting change is made in the data storage unit 302 of the MFP 101, the management cloud system 102 is notified of this. This processing allows the management cloud system 102 to identify the settings with which the MFP 101 is operating. Furthermore, when a setting change instruction is made in the management cloud system 102, the management system communication unit 307 also has a function of receiving and processing the notification. Upon receiving the setting change notification, the management system communication unit 307 performs processing to reflect the setting value in the data storage unit 302 of the MFP 101. In this way, in this embodiment, by synchronizing the information of the MFP 101 in both directions, it is possible to check or change the information of the MFP 101 as appropriate in the management cloud system 102.
[0028] Next, the screen displayed on the operation unit 206 of the MFP 101 will be described with reference to FIG.
[0029] 4A shows a menu screen 401 in normal operation. A notification area 402 is used to notify the user of information. A copy button 403, a scan button 404, and various setting buttons 405 are used to execute the corresponding functions of the MFP 101.
[0030] FIG. 4(b) shows a menu screen 411 that is displayed when a network configuration change, which will be described later, is detected. The copy button 413, scan button 414, and various setting buttons 415 are the same as those in FIG. 4(a). When the network configuration detection unit 305 detects a network configuration change, the operation control unit 301 displays a message indicating this in the notification area 412. That is, the operation control unit 301 performs control to present information regarding the settings of security-related functions to the user in response to a change in the network environment. Furthermore, when it detects that the user has tapped the notification area 412 displaying the message, the operation control unit 301 displays a screen 421 shown in FIG. 4(c) on the operation unit 206.
[0031] Screen 421 in FIG. 4( c) displays a manual for setting security-related functions of MFP 101 and a button for performing bulk setting. In this embodiment, it is assumed that MFP 101 is installed on an internal LAN, at home, or in a public space, and appropriate security setting manuals and bulk setting buttons are displayed according to the respective installation environments. Internal LAN recommended security setting list link 423 is a link for displaying a list of settings that should be set when the installation environment is an internal LAN. The same applies to home recommended security setting list link 424 and public space recommended security setting list link 425. Internal LAN bulk setting button 426 is a button for setting a series of security settings that are appropriate when the installation environment is an internal LAN in bulk. The same applies to home bulk setting button 427 and public space bulk setting button 428. When bulk setting buttons 426, 427, and 428 are pressed to change the security settings of MFP 101, MFP 101 updates the display state of notification area 422 to a state that does not include the above-mentioned message. That is, when the security settings are completed, the notification message displayed in the notification area 422 is erased.
[0032] Next, the process from when MFP 101 detects a change in network configuration until a display item related to security settings is displayed on operation unit 206 of MFP 101 will be described with reference to FIGS. 5 to 7. Each operation (step) shown in the flowcharts of FIGS. 5 to 7 is realized by CPU 201 loading into RAM 203 a program for implementing each control module stored in ROM 202 or storage 204 and executing the program. Note that data transmission and reception processes are realized in cooperation with network I / F 211. In addition, in cases where it is necessary to clarify the subject of a process, the software module executed by CPU 201 will be described as the subject. Each process shown in FIG. 5 is executed when MFP 101 starts up from a power-off state and operates in normal mode. Note that, due to space limitations, FIG. 5 shows only excerpts of steps related to acquiring network configuration information.
[0033] In S501, the network configuration detection unit 305 determines whether to acquire network configuration information. Specifically, the network configuration detection unit 305 determines to acquire network configuration information when it detects that the network I / F 211 has entered a link-up state or when it determines that it is time to make an inquiry to the DHCP server 106. If the network configuration detection unit 305 determines to acquire network configuration information, the process proceeds to S502. If the network configuration detection unit 305 does not determine to acquire network configuration information, the process proceeds to S508. A link-up occurs when the MFP 101 transitions from a state in which it is not connected to the network to a state in which it is connected to the network and can communicate with devices on the network. In this embodiment, a link-up occurs when a LAN cable is unplugged or plugged in, or when the MFP 101 transitions from a power-off state or a power-saving state to a normal power state. A link-up also occurs when the network settings of the network I / F 211 (e.g., a default gateway or an IP address) are changed based on a user operation via a network setting screen (not shown).
[0034] In S508, CPU 201 determines whether a shutdown instruction for switching the operation mode of MFP 101 from normal operation mode to power-off mode has been received. If a shutdown instruction has been received, shutdown processing (not shown) is performed, and the series of processes ends. On the other hand, if a shutdown instruction has not been received, CPU 201 proceeds to S501 and waits for a condition for acquiring configuration information.
[0035] In S502, the network configuration detection unit 305 acquires the MAC address of the default gateway.
[0036] Next, in S503 and S504, the network configuration detection unit 305 cooperates with the DHCP control unit 304 to obtain the MAC address of the DHCP server and the network address assigned by the DHCP server.
[0037] Next, in S505, the network configuration detection unit 305 acquires RA (Router Advertisement) information from an IPv6 (Internet Protocol Version 6) router. The RA information includes a prefix to be assigned to a host and information about a default gateway to be used in IPv6 communication.
[0038] In S506, the network configuration detection unit 305 performs a network configuration change detection process based on the network configuration information acquired in S502 to S505 and the stored network configuration information. The detection process will be described later with reference to FIG.
[0039] In S507, the network configuration detection unit 305 stores the network configuration information acquired in S502 to S505 in the data storage unit 302 as network configuration information to be used for communication by the MFP 101. The network configuration information stored in S507 is used as the stored network configuration information the next time the condition for acquiring configuration information in S501 is met and the processing of S506 is executed.
[0040] Next, the process in S506 in which the network configuration detection unit 305 detects a change in the network configuration will be described with reference to FIG.
[0041] In S511, the network configuration detection unit 305 compares the MAC address of the default gateway acquired in S502 with the MAC address of the default gateway already stored in the data storage unit 302, and diagnoses whether there has been a change. If the MAC address of the default gateway acquired in S502 differs from the MAC address of the default gateway already stored in the data storage unit 302, that is, if there has been a change in the network configuration, the process proceeds to S515. If the MAC address of the default gateway acquired in S502 matches the MAC address of the default gateway already stored in the data storage unit 302, that is, if there has been no change in the network configuration, the process proceeds to S512.
[0042] In S512, the network configuration detection unit 305 compares the MAC address of the DHCP server acquired in S503 with the MAC address of the DHCP server already stored in the data storage unit 302, and diagnoses whether there has been a change, as in S511. If there has been a change, the process proceeds to S515, and if there has not been a change, the process proceeds to S513.
[0043] In S513, the network configuration detection unit 305 compares the network address acquired in S504 with the network address already stored in the data storage unit 302, and diagnoses whether there has been a change, as in S511. If there has been a change, the process proceeds to S515; if there has not been a change, the process proceeds to S514.
[0044] In S514, the network configuration detection unit 305 compares the RA information received from the IPv6 router acquired in S505 with the RA information received from the IPv6 router already stored in the data storage unit 302, and diagnoses whether there is a change, as in S511. If there is a change, the process proceeds to S515, and if there is no change, the series of processes ends.
[0045] In S515, the network configuration detection unit 305 stores information indicating that the network configuration has changed in the data storage unit 302, and the series of processes ends.
[0046] Finally, the process of displaying screen 411 indicating that there has been a change in the network configuration on operation unit 206 of MFP 101 will be described with reference to Fig. 7. The processes shown in Fig. 7 are display control processes that are executed in response to the fact that there has been a change in the network configuration being stored in S515 of Fig. 6. The process is started when operation control unit 301 refers to data storage unit 302 and stores information indicating that there has been a change in the network configuration.
[0047] In S521, the operation control unit 301 checks whether the operation unit 206 is in a sleep state. If the sleep state is released, the process proceeds to S522. If the sleep state is released, the process returns to S521 to wait for the operation unit 206 to be released.
[0048] In S522, the operation control unit 301 displays display items related to security settings in the notification area 412 of the screen 411, and ends the series of processes.
[0049] The notification area 412 described above is one example of a method for displaying display items related to security settings displayed in S522. In this embodiment, the display items related to settings are displayed in a status display area provided at the bottom of the operation unit 206, but the present invention is not limited to this. For example, the information related to settings may be presented to the user via a pop-up window or the like, or the display items related to settings may be displayed on a status confirmation screen (not shown).
[0050] By the series of processes described above, when the network configuration changes, display items relating to the settings of security-related functions can be displayed on the operation unit 206 of the MFP 101.
[0051] <Second embodiment> In the second embodiment, a process for terminating the display of display items related to security settings in the first embodiment at the user's discretion will be described. Also, a process for preventing the display of display items even when a change in network configuration is detected at the user's discretion will be described. The configuration is the same as that of the first embodiment except that the screen of FIG. 8 is displayed on the operation unit 206 instead of FIG. 4(c) and the process of FIG. 9 is executed instead of FIG. 7. The description will omit parts of the configuration that are the same as those of the first embodiment as appropriate.
[0052] Fig. 8 is an example of a screen displayed on the operation unit 206 of the MFP 101, instead of Fig. 4(c) in the first embodiment. In Fig. 8, in addition to the display items shown in Fig. 4(c), there is a cancel button 609 that ends the display of display items related to security settings. There is also a hide button 610 that prevents the display of display items from being displayed even when a change in the network configuration is detected. In the notification area 602, a message indicating that a change in the network configuration has been detected is displayed, similar to Fig. 4(c).
[0053] When the operation control unit 301 detects that the user has selected the cancel button 609, it updates the display state of the notification area 602 to a state that does not include the above-mentioned message. In other words, the notification message that was displayed in the notification area 602 is erased.
[0054] Furthermore, when the operation control unit 301 detects that the user has selected the no notification button 610, it updates the display state of the notification area 602 to a state that does not include the above-mentioned message. That is, the notification message that was displayed in the notification area 602 is erased. Furthermore, the operation control unit 301 cooperates with the data storage unit 302 to set an operation so that no notification is made even when a change in the network configuration is detected thereafter. This operation setting is stored in the data storage unit 302. The operation setting stored in the data storage unit 302 is referred to as appropriate in the flowchart of FIG. 9, which will be described later.
[0055] Next, the processing of MFP 101 when the user selects release button 609 or non-notification button 610 will be described with reference to Fig. 9. The processing shown in Fig. 9 is started when the fact that there has been a change in the network configuration is stored in data storage unit 302 in S515 of Fig. 6.
[0056] In S701, the operation control unit 301 checks whether the operation unit 206 is in a sleep state. If the sleep state is released, the process proceeds to S702. If the sleep state is released, the process returns to S701 and waits for the operation unit 206 to be released.
[0057] In S702, the operation control unit 301 refers to the data storage unit 302 and determines whether or not the non-notification button 610 has been selected on the operation unit 206. If information indicating that the non-notification button 610 has been selected is stored in the data storage unit 302, the process proceeds to S703. If information indicating that the non-notification button 610 has been selected is not stored, the process proceeds to S704.
[0058] In S703, a screen (for example, screen 401) that does not include display items related to security settings is displayed, and the series of processes ends.
[0059] In S704, the operation control unit 301 displays a screen (for example, the screen 411) including display items related to security settings, and the process proceeds to S705.
[0060] In S705, the operation control unit 301 determines whether or not the operation of selecting the non-notification button 610 by the user has been accepted on the operation unit 206. If the operation control unit 301 has accepted the operation of selecting the non-notification button 610 by the user, the process proceeds to S706, and if the selection operation has not been accepted, the process proceeds to S707.
[0061] In S706, the operation control unit 301 stores in the data storage unit 302 information that the non-notification button 610 was selected on the operation unit 206. The information stored here is used to determine whether or not the non-notification button 610 was selected in S702. After the processing of S706 is performed, the process proceeds to S708.
[0062] In S707, the operation control unit 301 determines whether or not it has accepted an operation by the user to select the release button 609 on the operation unit 206. If the operation control unit 301 has accepted an operation by the user to select the release button 609, the process proceeds to S708, and if the selection operation has not been accepted, the series of processes ends.
[0063] In S708, the operation control unit 301 displays a screen that does not include display items related to security settings, and ends the series of processes. That is, the display of display items related to security settings is ended, and the series of processes is ended.
[0064] Through the series of processes described above, the display of security-related function settings can be terminated at the user's discretion, or the display can be prevented even when a change in network configuration is detected.
[0065] <Third embodiment> In the third embodiment, a form will be described in which the display control of the first embodiment is performed only when a user with administrator authority logs in to the MFP 101. Note that the configuration is the same as that of the first embodiment except that the processing of Fig. 10 is executed instead of that of Fig. 7. The description will omit parts of the configuration that are the same as those of the first embodiment as appropriate.
[0066] Fig. 10 is a flowchart showing display items related to security-related function settings when a user with administrator privileges logs in to the MFP 101. The processes shown in Fig. 10 are excerpts of the control that the MFP 101 performs from waiting for a user to log in to performing login processing and screen display.
[0067] In S801, the CPU 201 determines whether a login event has occurred. Specifically, for example, if a user ID and password are entered via a login screen (not shown) displayed on the operation unit 206 and user authentication is successful based on the information, a login event occurs that logs the authenticated user into the MFP 101. If a login event has occurred, the process proceeds to S802; if a login event has not occurred, the process returns to the start and waits for a login operation.
[0068] In S802, the CPU 201 checks whether the login is by a user with administrator authority. If the login is by a user with administrator authority, the process proceeds to S803, where a screen for the administrator is displayed. If the login is by a user without administrator authority, the process proceeds to S806, where a screen for a general user is displayed.
[0069] In S804, the operation control unit 301 refers to the data storage unit 302, and if information indicating a change in the network configuration is stored, the operation control unit 301 proceeds to S805 and displays display items related to the settings of security-related functions. If information indicating a change in the network configuration is not stored, the operation control unit 301 waits for detection of a change in the network configuration.
[0070] By performing the above-described series of processes, it is possible to display display items related to the settings of security-related functions only to users with administrator privileges. In other words, it is possible to control so that display items related to the settings of security-related functions are not displayed to general users who do not have the privileges to set security-related functions.
[0071] In this embodiment, after displaying the screen for the administrator, a screen including display items related to the settings described in S805 is displayed (the display screen is updated and the display items are displayed on the screen for the administrator), but the present invention is not limited to this. For example, if it is determined in S802 that an administrator has logged in, the determination in S804 may be made, and depending on the determination result, whether or not the display items are included in the screen when the screen for the administrator is displayed may be changed.
[0072] <Fourth embodiment> In the first to third embodiments, a case has been exemplified in which the network configuration change shown in Fig. 6 is detected by the network configuration detection unit 305 of the MFP 101, and display items related to the settings of security-related functions are displayed on the operation unit 206 of the MFP 101. In the fourth embodiment, a case will be described in which the network configuration change is detected by the management cloud system 102, and the display items are displayed on a web browser of an external device. Note that the communication system shown in Fig. 1, the hardware configuration of the MFP 101 shown in Fig. 2, and the software configuration of the MFP 101 shown in Fig. 3 are the same as those in the first embodiment.
[0073] The hardware configuration of the management cloud system 102 that detects changes in the network configuration will be described with reference to FIG.
[0074] A control unit 900 including a CPU 901 controls the entire management cloud system 102. A ROM 902 is used to store programs executed by the CPU 901. A RAM 903 is used to temporarily store data used by the CPU 901. A storage 904 stores various programs and various setting information. In this way, the hardware such as the CPU 901, ROM 902, RAM 903, and storage 904 constitutes a so-called computer.
[0075] The operation unit I / F 905 connects the operation unit 906 and the control unit 900. The network I / F 907 is connected to the Internet 105.
[0076] The software configuration of the management cloud system 102 will be described with reference to Fig. 12. Each unit shown in Fig. 12 is realized by the CPU 901 executing a program stored in the ROM 902 corresponding to each unit.
[0077] The web browser communication unit 1001 displays a screen for the user in response to a request from a web browser running on the PC 107. It also detects user operations and switches screens or updates the display based on the detection results. The data storage unit 1002 stores data in distributed resources on the cloud or reads data from distributed resources in response to requests from other control units. For example, if a user wants to change some device settings, the user first transmits the changes to the web browser communication unit 1001. Then, in response to a request from the web browser communication unit 1001, the data storage unit 1002 saves the transmitted contents as setting values in the distributed resources on the cloud.
[0078] The authentication control unit 1003 uses the authentication information sent to the web browser communication unit 1001 and the account information stored in the data storage unit 1002 to perform user authentication.
[0079] The MFP communication unit 1004 controls communication with the MFP 101 , and when it receives setting values and network configuration information for the MFP 101 , it stores the received information in the data storage unit 1002 .
[0080] The network configuration detection unit 1005 acquires network configuration information from the data storage unit 1002 and compares the currently connected network configuration information with the network configuration information of the previous connection. If a change in the network configuration is detected, the data storage unit 1002 stores this information.
[0081] The management information control unit 1006 performs processing to generate the contents of management information to be displayed to the user via the web browser communication unit 1001. For example, when displaying that the network configuration information has changed, the management information control unit 1006 processes the data stored in the data storage unit 1002 to generate appropriate display information.
[0082] 13, the screens displayed on the web browser running on the PC 107 will be described. Management screens 1101 and 1111 in FIG.
[0083] 13(a) shows a management screen 1101 in normal operation. A network diagnosis status notification section 1102 is used to notify the user whether or not a network configuration change, which will be described later, has been detected, and normally notifies the user that no network configuration change has been detected. A notification area 1103 is an area used to notify the user of information.
[0084] FIG. 13B shows a management screen 1111 that is displayed when a network configuration change is detected. When a network configuration change is detected, a network diagnostic status notification unit 1112 notifies the user of the change. A notification area 1113 displays a message indicating the change and prompting the user to configure security settings. Furthermore, a security configuration manual 1110 is displayed on the management screen 1111. This embodiment assumes that the MFP 101 is installed on an internal LAN, at home, or in a public space, and displays a security configuration manual appropriate for each installation environment. The internal LAN recommended security settings list link 1114 is a link to a web manual that displays a list of settings that should be configured when the installation environment is an internal LAN. The same applies to the home recommended security settings list link 1115 and the public space recommended security settings list link 1116. Note that, in consideration of the fact that setting items may vary slightly depending on the model or model, different web manuals may be provided for each model or model of the managed device. In this case, the management information control unit 1006 identifies the model information of the managed MFP that the user registered in the management cloud system 102. Next, the management information control unit 1006 generates display information including a link to display the web manual corresponding to the identified model information. This process makes it possible to display an appropriate link corresponding to the model or model of the managed object.
[0085] Although this embodiment has a screen configuration that displays information about one MFP 101, a list of all MFPs linked to the user's account may be displayed for a user who owns multiple MFPs. Furthermore, notification may be given by displaying a list of only MFPs with warnings. Alternatively, a graphic such as a pie chart may be used to indicate the ratio of MFPs with warnings to MFPs without warnings, allowing the overall status to be understood at a glance. Furthermore, notification that there are no problems overall may be given only if no warnings are present.
[0086] Next, we will explain the processes related to obtaining network configuration information, detecting changes in the network configuration, and displaying the screen on the web browser.
[0087] First, as in the first embodiment, the network configuration detection unit 305 of the MFP 101 acquires network configuration information through the processing shown in S501 to S505 of Fig. 5. Next, the management system communication unit 307 of the MFP 101 transmits the network configuration information acquired by the network configuration detection unit 305 to the management cloud system 102. Furthermore, the MFP communication unit 1004 of the management cloud system 102 receives the network configuration information from the MFP 101. The network configuration information is transmitted from the MFP 101 to the management cloud system, for example, when the MFP 101 acquires the network configuration information, or periodically.
[0088] When the network configuration information is saved in the data storage unit 1002 of the management cloud system 102, a process for detecting a change in the network configuration is initiated. The detection flow is the same as that in Fig. 6, but each process is executed by the network configuration detection unit 1005 of the management cloud system 102 instead of the network configuration detection unit 305 of the MFP 101. Furthermore, if there is a change in the network configuration, that fact is stored in the data storage unit 1002 of the management cloud system 102.
[0089] The configuration information compared for change detection is the configuration information received from MFP 101 and the configuration information already stored in data storage unit 1002. When the detection process is completed, the configuration information received from MFP 101 is stored in data storage unit 1002. The configuration information stored here will be used as the already stored configuration information the next time change detection processing is performed.
[0090] Next, a process for displaying the management screen 1111 on a web browser will be described. As described above, the web browser communication unit 1001 of the management cloud system 102 displays a screen for a user in response to a request from a web browser running on the PC 107 or the like. In this embodiment, when the management cloud system 102 receives an acquisition request to acquire a management screen from the web browser, it provides the web browser with a management screen corresponding to the acquisition request.
[0091] Specifically, the user operates the web browser of the PC 107 to perform an operation to access the management screen of the management cloud system 102. The web browser detects this operation and transmits a request to the management cloud system 102 to obtain the management screen.
[0092] The web browser communication unit 1001 of the management cloud system 102 that receives the management screen request responds with a different management screen depending on whether a network configuration change has been detected in the data storage unit 1002. If the data storage unit 1002 stores information that a network configuration change has been detected, the web browser communication unit 1001 responds with web data corresponding to the management screen 1111 to the web browser that requested the management screen. Through the above procedure, display items including information regarding the settings of security-related functions can be displayed on the web browser.
[0093] Note that instead of displaying the security setting manual 1110 on the management screen 1111, the screen may be configured so that a link for displaying the security setting manual 1110 is displayed on the management screen 1111. The screen may also be configured so that the notification area 1113 serves as a link for displaying the security setting manual 1110.
[0094] The batch setting button described in the first embodiment may also be displayed on the management screen 1111. The processing in this case will be described below. First, the Web browser communication unit 1001 receives information from the Web browser of an external device, via the management screen 1111, indicating that the user has pressed the batch setting button corresponding to a specific installation environment. Next, the Web browser communication unit 1001 requests the MFP communication unit 1004 to perform batch setting on the MFP 101. Having accepted the batch setting request, the MFP communication unit 1004 transmits a setting request to the MFP 101 indicating that batch setting corresponding to the specific installation environment should be performed. The management system communication unit 307 of the MFP 101 receives the setting request. Then, the security setting control unit 306 of the MFP 101, having received the setting request, changes the security settings of the MFP 101. Through the above processing, it is possible to perform batch setting of the security-related functions of the MFP 101 from the Web browser on the PC 107.
[0095] As in the second embodiment, the management screen 1111 may have a screen configuration including a cancel button for ending the display of display items related to security settings, and a hide button for preventing the display of display items even when a change in the network configuration is detected.
[0096] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of each of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC or FPGA) that realizes one or more functions. [Explanation of symbols]
[0097] 101 MFP 301 Operation control section 302 Data storage unit 305 Network Configuration Detector
Claims
1. a requesting means for transmitting a request for acquiring network configuration information of a DHCP server that assigns address information to the information processing device; a storage means for storing the network configuration information acquired based on the request as first network configuration information; a detection means for detecting a change based on the first network configuration information stored in the storage means and the second network configuration information newly acquired by the request means; a display control means for controlling the display of display items relating to settings of security-related functions of the information processing device on a screen based on the detection of the change; An information processing device comprising:
2. The information processing device further includes an acquisition means for acquiring address information assigned to the information processing device, the storage means further stores the address information acquired by the acquisition means as first address information; the detecting means, when the change is not detected, detects a change based on the first address information and the second address information newly acquired by the acquiring means; the display control means controls the display items to be displayed on the screen based on the detection of a change based on the address information by the detection means.
2. The information processing apparatus according to claim 1, wherein:
3. 3. The information processing apparatus according to claim 1, wherein the display item includes a message that prompts the user to change the settings of the security-related function.
4. The display control means If the first network configuration information and the second network configuration information are different, the change is detected and the display item is displayed; An information processing device according to any one of claims 1 to 3, characterized in that, when the first network configuration information and the second network configuration information match, the display item is not displayed, assuming that the change has not been detected.
5. An information processing device as described in any one of claims 1 to 4, characterized in that the display control means further controls to display another display item for collectively setting security-related functions of the information processing device based on the usage environment of the information processing device.
6. The information processing device manages different sets of setting values associated with each of a plurality of usage environments, the other display item is a display item for receiving from a user a selection of one item from a plurality of items associated with a plurality of usage environments; 6. The information processing apparatus according to claim 5, wherein, when the selection is accepted, security-related functions are set based on a group of setting values that are managed in association with one usage environment corresponding to the selected item.
7. 7. The information processing apparatus according to claim 5, wherein when the display item is pressed, the other display item is displayed.
8. The information processing device according to claim 1 , further comprising: a receiving unit that receives an operation to terminate the display of the display item.
9. The display control means controls the display item to be displayed on the screen based on the detection of the change and a predetermined setting, 9. The information processing apparatus according to claim 1, wherein the predetermined setting is a setting set by a user as to whether or not the display item is to be displayed when the change is detected.
10. 10. The information processing device according to claim 1, wherein the network configuration information acquired based on the request includes at least one of a MAC (Media Access Control) address of a default gateway, a MAC address of a DHCP (Dynamic Host Configuration Protocol) server, and a network address assigned by the DHCP server.
11. 11. The information processing apparatus according to claim 1, wherein the request is an inquiry to a network regarding network configuration information to be allocated to the information processing apparatus.
12. 12. The information processing apparatus according to claim 1, wherein the timing of the request is at least one of a timing when a link-up of the information processing apparatus is detected and a timing when an inquiry is to be made to a DHCP server.
13. 13. The information processing apparatus according to claim 1, wherein the screen is a screen that is displayed when a user having administrator authority logs into the information processing apparatus.
14. 13. The information processing apparatus according to claim 1, wherein the screen is a screen displayed on a web browser of an external device when the information processing apparatus receives an acquisition request to acquire the screen via the web browser of the external device.
15. a request step of transmitting a request for acquiring network configuration information of a DHCP server that assigns address information to the information processing device; a storage step of storing the network configuration information acquired based on the request as first network configuration information; a detection means for detecting a change based on the first network configuration information stored in the storing step and the second network configuration information newly acquired in response to the request; a display control step of controlling the display items relating to settings of security-related functions of the information processing device to be displayed on a screen based on the detection of the change; An information processing method comprising:
16. A computer, a requesting means for transmitting a request for acquiring network configuration information of a DHCP server that assigns address information to the information processing device; a storage means for storing the network configuration information acquired based on the request as first network configuration information; a detection means for detecting a change based on the first network configuration information stored in the storage means and the second network configuration information newly acquired by the request means; a display control means for controlling, based on the detection of the change, to display on a screen a display item relating to settings of security-related functions of the information processing device; A program to function as a
Citation Information
Patent Citations
Electronic equipment, communication environment setting method and program
JP2004094736A
Information processing device, control method of information processing device, and program
JP2016212832A
Information processing apparatus that prevents unauthorized access thereto, method of controlling the information processing apparatus, and storage medium
US20190141073A1