Information processing device, control method and program for information processing device
The information processing device addresses inappropriate security settings by using environmental data to determine when to reconfigure security settings, ensuring accurate and timely adjustments.
Patent Information
- Application Number
- JP2021206260
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-20
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2041-12-20
AI Technical Summary
Existing technologies fail to address inappropriate security settings in information processing devices like MFPs due to insufficient initial installation environment information, leading to potential security vulnerabilities.
An information processing device with a determination information acquisition unit to gather data on its installation environment, an execution determination unit to decide when to re-execute security settings, and a setting unit to adjust security configurations based on determined environment and user input.
Prevents inappropriate security settings by ensuring accurate configuration at a later time, reducing the risk of security breaches.
Smart Images

Figure 0007788846000001 
Figure 0007788846000002 
Figure 0007788846000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] In recent years, environments in which information processing devices such as PCs (Personal Computers) and MFPs (Multi-Function Peripherals) are installed have become increasingly diverse. These devices may be installed in rooms with controlled access, such as offices, or in public places with physical access for anyone, such as convenience stores. There has also been an increase in cases where company information processing devices are installed at home and used for telecommuting. Furthermore, as the number of security functions provided by information processing devices has increased, security settings have also become more complex, forcing users of information processing devices to determine whether to enable and configure numerous security setting items one by one.
[0003] In Patent Document 1, information from other devices such as surveillance cameras and motion sensors is used to determine the installation environment of the MFP, and multiple security settings appropriate for the installation environment are automatically performed in one go, reducing the user's effort in setting them up. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-62558 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the technology of Patent Document 1 does not take into account cases where there is insufficient information to determine the installation environment of the MFP, such as immediately after installation. For example, if the MFP has just been installed and is not yet connected to other devices such as surveillance cameras, information about the installation environment cannot be obtained, which could result in inappropriate security settings. In addition, with the technology of Patent Document 1, there is a possibility that information for determining the installation environment may not be sufficiently accumulated immediately after installation of the MFP, making it impossible to determine the environment appropriately. For example, if the installation environment is determined after a series of days with few users, such as holidays, immediately after installation of the MFP, it may be erroneously determined that there are few users, even though there actually are many users, and a low security level may be set.
[0006] The present invention has been made in view of the above-mentioned problems, and aims to provide a technique for preventing inappropriate security settings from continuing. [Means for solving the problem]
[0007] To achieve the above object, an information processing device according to one aspect of the present invention comprises: An information processing device, A setting means for setting security for the information processing device based on the installation environment of the information processing device. and, a determination information acquisition means for acquiring determination information for determining an installation environment of the information processing device, the determination information including a cumulative operating time of the information processing device; an execution determination means for determining whether or not the security setting needs to be performed again by the setting means based on the determination information; Equipped with The setting means When the execution determination means determines that the security setting needs to be performed again, The security setting is performed again at a specific timing. [Effects of the Invention]
[0008] According to the present invention, it is possible to prevent inappropriate security settings from continuing. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram showing a connection configuration between an MFP and a PC according to the present invention. [Figure 2] FIG. 2 is a diagram showing the internal configuration of a controller unit of the MFP according to the first embodiment. [Figure 3] FIG. 2 is a block diagram of the software executed in the controller of the MFP according to the first embodiment. [Figure 4] 10 is a correspondence table relating to the installation environment, recommended security settings, and security levels of the second modified example according to the first embodiment. [Figure 5] 1 is a flowchart for carrying out the processing of the first embodiment. [Figure 6] 10 is a flowchart for carrying out processing of Modification 1 of Embodiment 1. [Figure 7] 10 is a flowchart for carrying out processing of Modification 2 of Embodiment 1. [Figure 8] FIG. [Figure 9] Configuration diagram of the settings display screen. [Figure 10] Screen layout diagram for advanced settings (re-execution interval settings) for the security automatic configuration function. [Figure 11] A diagram of the recommendation screen for recommended security settings. [Figure 12] A diagram of the recommended security settings bulk setting screen. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the claimed invention. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0011] In this embodiment, a process will be described in which an information processing device re-executes automatic security settings (installation environment determination and security settings) at a specific timing. In this embodiment, the information processing device is described as an MFP (multi-function peripheral), which is an image forming device, but the present invention is also applicable to information processing devices other than multi-function peripherals.
[0012] (Embodiment 1) [System configuration of embodiment 1] With reference to the block diagram of FIG. 1, a connection configuration of an information processing system including an MFP (multi-function peripheral) that functions as an information processing apparatus according to this embodiment and a client PC will be described.
[0013] The MFP 100 and client PC 110 are connected via a LAN 120. The MFP 100 has a controller unit 101, an operation unit 102 that inputs and outputs data to and from the user, a printer unit 103 that outputs electronic data to paper media, and a scanner unit 104 that reads paper media and converts it into electronic data. The operation unit 102, printer unit 103, and scanner unit 104 are connected to the controller unit 101, and function as a multifunction peripheral under the control of the controller unit 101. The client PC 110 performs processes such as sending print jobs to the MFP 100.
[0014] [Hardware configuration of controller unit 101] FIG. 2 is a block diagram showing details of the controller unit 101 of the MFP 100. The CPU 201 performs the main arithmetic processing within the controller. The CPU 201 is connected to a DRAM 202 via a bus. The DRAM 202 is used by the CPU 201 as a working memory for temporarily storing program data representing arithmetic instructions and data to be processed during the CPU 201's calculations. The CPU 201 is connected to an I / O controller 203 via a bus. The I / O controller 203 performs input and output to various devices according to instructions from the CPU 201. A SATA (Serial Advanced Technology Attachment) I / F 205 is connected to the I / O controller 203, and a Flash ROM 211 is connected to the SATA I / F 205. The CPU 201 uses the Flash ROM 211 to permanently store programs for implementing the functions of the MFP 100 and document files. A network I / F 204 is connected to the I / O controller 203. A wired LAN device 210 is connected to the network I / F 204.
[0015] The CPU 201 controls the wired LAN device 210 via the network I / F 204 to realize communication on the LAN 120. A panel I / F 206 is connected to the I / O controller 203, and the CPU 201 performs user input and output to the operation unit 102 via the panel I / F 206. A printer I / F 207 is connected to the I / O controller 203, and the CPU 201 performs paper media output processing using the printer unit 103 via the printer I / F 207. A scanner I / F 208 is connected to the I / O controller 203, and the CPU 201 performs document reading processing using the scanner unit 104 via the scanner I / F 208. A USB I / F 209 is connected to the I / O controller 203, and the CPU 201 controls any device connected to the USB I / F 209. The ROM 220 is connected to the CPU 201 via a bus and stores a control program for implementing a BIOS (Basic Input / Output System) 360 (described later).
[0016] When performing the copy function, the CPU 201 loads program data from the Flash ROM 211 into the DRAM 202 via the SATA I / F 205. The CPU 201 detects a copy instruction from the user via the panel I / F 206 on the operation unit 102 in accordance with the program loaded into the DRAM 202. When the CPU 201 detects a copy instruction, it receives an original as electronic data from the scanner unit 104 via the scanner I / F 208 and stores it in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 then transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207, where it performs output processing onto paper media.
[0017] When PDL (Page Description Language) printing is performed, the client PC 110 issues a print instruction via the LAN 120. The CPU 201 loads program data from the Flash ROM 211 into the DRAM 202 via the SATA I / F 205, and detects a print instruction via the network I / F 204 according to the program loaded into the DRAM 202. When the CPU 201 detects a PDL transmission instruction, it receives print data via the network I / F 204 and stores the print data in the Flash ROM 211 via the SATA I / F 205. After the CPU 201 has finished storing the print data, it develops the print data stored in the Flash ROM 211 into the DRAM 202 as image data. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207, and performs output processing onto paper media.
[0018] The following describes the flow of the process of re-executing automatic security settings according to the functional configuration and environment in this embodiment.
[0019] [Functional configuration of embodiment 1] Next, an example of the functional configuration realized by software executed by the controller unit 101 of the MFP 100 of the first embodiment will be described with reference to the block diagram of Fig. 3. All of the software executed by the controller unit 101 is executed by the CPU 201.
[0020] The CPU 201 executes the BIOS 360 stored in the ROM 220. The CPU 201 loads the loader 370, initrd 380, and controller software 300 stored in the Flash ROM 211 into the DRAM 202 and then executes them. The BIOS 360 executes basic processing for the CPU 201 to control the I / O controller 203 and the DRAM 202. The BIOS 360 also loads the loader 370 from the Flash ROM 211 and executes the start processing. The loader 370 loads the kernel 390 and initrd 380 from the Flash ROM 211 and executes the start processing. The initrd 380 loads the controller software 300 from the Flash ROM 211 and executes the start processing.
[0021] The operation control unit 301 is a user interface (UI) unit that displays a screen image for the user via the operation unit 102, detects user operations, and executes processes associated with screen components such as buttons displayed on the screen. For example, it displays a menu screen 801 as shown in FIG. 8. FIG. 8 shows the menu screen 801 displayed on the operation unit 102, which the user uses to instruct the execution of various functions of the multifunction peripheral. Button 802 is used by the user to instruct the copy function. Button 803 is used by the user to instruct the scan and save function. Button 804 is used by the user to instruct the scan and send function. Button 805 is used by the user to instruct a change in device settings.
[0022] Pressing button 805 further transitions to a settings screen 901, an example of which is shown in Fig. 9, where individual settings can be changed. Fig. 9 is a diagram showing settings screen 901, which is a screen on which the user instructs changes to settings related to various functions provided by MFP 100. Check box 902 is used to enable the automatic security setting function. Check box 903 is used to enable the firewall function. Check box 904 is used to enable the communication channel encryption function. Check box 905 is used to enable the HDD encryption function.
[0023] For example, by selecting the check box 902, the automatic security setting function is enabled, and recommendations and batch setting of security settings according to the environment in this embodiment are executed. The above is merely an example, and it is also possible to configure it so that, for example, settings changes of the user authentication function and the log recording function are instructed via the setting screen 901.
[0024] 3, the data storage unit 302 stores and reads data in the Flash ROM 211 in response to a request from another control unit. For example, if a user wants to change some device setting, the operation control unit 301 detects the content input by the user to the operation unit 102, and in response to a request from the operation control unit 301, the data storage unit 302 stores the content as a setting value in the Flash ROM 211. For example, by selecting the check box 903 in FIG. 9 described above, the firewall function is enabled, and at the same time, a setting value indicating that the firewall function is enabled is stored in the Flash ROM 211 by the data storage unit 302.
[0025] A job control unit 303 controls job execution in accordance with instructions from other control units. An image processing unit 304 processes image data into a format suitable for each purpose in accordance with instructions from the job control unit 303. A print processing unit 305 prints and outputs an image on paper media via a printer I / F 207 in accordance with instructions from the job control unit 303.
[0026] A reading processing unit 306 reads a placed document via a scanner I / F 208 in accordance with instructions from a job control unit 303. A network control unit 307 sets network settings such as an IP address in a TCP / IP control unit 308 at system startup or when a setting change is detected, in accordance with setting values stored in a data storage unit 302. The TCP / IP control unit 308 performs transmission and reception processing of network packets via the network I / F 204 in accordance with instructions from other controls. A USB control unit 309 controls the USB I / F 209 and controls any device connected via USB.
[0027] The determination information acquisition unit 310 has a function of acquiring determination information used to determine the installation environment of the MFP 100, and passing it to the installation environment determination unit 311 and the execution determination unit 314, which will be described later. The determination information acquisition unit 310 acquires, as determination information, information that can be used to determine the installation environment from information (data) stored in the MFP 100. As the determination information, for example, information on the presence or absence of a network boundary, information on the presence or absence of an Internet connection, and information on the presence or absence of a physical boundary that separates the inside and outside of the environment in which the MFP 100 is placed can be acquired and used.
[0028] Examples of information that can be used as determination information are given below. For example, the IP address of a proxy server stored in data storage unit 302 as a setting value for MFP 100 can be used as determination information. In this case, if the IP address of the proxy server is set, it can be determined that a network boundary exists; conversely, if it is not set, it can be determined that a network boundary does not exist. The IP address of MFP 100 stored in data storage unit 302 as a setting value for MFP 100 can also be used as determination information. In this case, if a global IP address is set as the IP address of MFP 100, it can be determined that an Internet connection exists; conversely, if a private IP address is set, it can be determined that an Internet connection does not exist. Note that it is difficult to determine whether or not a physical boundary exists from information that can be collected during normal operation of MFP 100. Therefore, for example, information regarding the existence of a physical boundary can be input by the user via a UI, and the input information can be used as determination information.
[0029] Note that the above-described information for determining whether or not there is a network boundary and whether or not there is an Internet connection is merely an example, and other information may be used for the determination. For example, if a firewall setting is configured in data storage unit 302 as a setting value of MFP 100, it may be determined that there is a network boundary, and conversely, if no firewall setting is configured, it may be determined that there is no network boundary. Another example is to learn data packets flowing through network control unit 307 using artificial intelligence (AI) technology such as machine learning or deep learning, generate and store information for determining whether or not there is a network boundary, and use this information to determine the installation environment.
[0030] The installation environment determination unit 311 determines the environment in which the MFP 100 is installed, using the determination information acquired by the determination information acquisition unit 310. The method of determining the installation environment can be realized, for example, by using table 401 in FIG. 4(A). Table 401 in FIG. 4(A) is a correspondence table in which the vertical axis represents the installation environment and the horizontal axis represents environmental determination elements that can be acquired from the determination information. In the case of FIG. 4(A), for example, if it is determined from the determination information that "physical boundary exists," "no network boundary exists," and "internet connection exists," it is determined that the MFP 100 is installed in a home environment, which is a home or telecommuting environment.
[0031] Furthermore, if it is determined that "physical boundary exists," "network boundary exists," or "no internet connection exists," it is determined that the MFP 100 is installed in an office environment such as a company. If it is determined that "physical boundary exists," "no network boundary," or "no internet connection exists," it is determined that the MFP 100 is installed in a completely isolated environment that is an environment completely isolated from the internet.
[0032] The environment determination elements in table 401, "physical boundary," "network boundary," and "internet connection," are examples, and other environment determination elements may be combined. The installation environments, "home," "office," and "complete isolation," are also examples, and other installation environments, such as "banks" that require high security, may be added separately. The criteria for determining the installation environment may be changed by changing the correspondence between the installation environment and the "yes" or "no" of the environment determination elements in table 401. For example, by changing the home physical boundary from "yes" to "no," environments with "no physical boundary," and "internet connection" can be determined to be home environments.
[0033] The recommendation unit 312 recommends to the user security settings suited to the environment according to the installation environment determined by the installation environment determination unit 311. Recommendations of security settings suited to each installation environment can be realized, for example, by using table 402 in Fig. 4(B). Table 402 in Fig. 4(B) is a correspondence table mapping the installation environment on the vertical axis and the recommended security settings on the horizontal axis.
[0034] In the case of Figure 4(B), for example, if the installation environment determination unit 311 determines that the installation environment is an office environment, the recommended security settings are "enabled" for the firewall function, "enabled" for the communication channel encryption function, and "enabled" for the HDD encryption function.If the installation environment is determined to be a home environment, the recommended security settings are "disabled" for the firewall function, "enabled" for the communication channel encryption function, and "disabled" for the HDD encryption function.If the installation environment is determined to be a completely isolated environment, the recommended security settings are "disabled" for the firewall function, "disabled" for the communication channel encryption function, and "disabled" for the HDD encryption function.
[0035] As a specific method of making recommendations to the user, for example, a recommended security settings screen 1101 is displayed on the operation unit 102 as shown in Fig. 11, and each security setting is displayed there as a recommended security settings list 1102. For example, if the installation environment is determined to be a home environment, the recommended security settings list 1102 displays the firewall function as "disabled," the communication channel encryption function as "enabled," and the HDD encryption function as "disabled" according to table 402 in Fig. 4(B). Note that the installation environments in table 402, "home," "office," and "complete isolation," are merely examples, just like table 401, and other installation environments may be added.
[0036] Furthermore, the recommended security settings are also examples, and for example, settings related to a tamper detection function may be added as other security setting items. Furthermore, the correspondence between the installation environment and the recommended security settings "Yes" or "No" in table 402 may be changed. For example, by changing the home firewall from "No" to "Yes," the recommended security settings for the home environment can be changed to recommend the firewall function "enabled," the communication channel encryption function "enabled," and the HDD encryption function "disabled."
[0037] The collective security setting unit 313 collectively sets the recommended security settings recommended by the recommendation unit 312 in the MFP 100. For example, pressing button 1103 on the recommended security setting screen 1101 causes the screen to transition to a collective setting screen 1201 shown in FIG. 12. The collective setting screen 1201 asks the user whether or not to execute the collective setting by displaying a question in a display area 1202. If the user selects check box 1203 ("Yes"), the collective security setting unit 313 performs the setting of each security function and the enabling / disabling of the function according to table 402 in FIG. 4(B) for each installation environment. The recommendation display may be configured to be displayed when the administrator logs in to the MFP 100.
[0038] For example, if the installation environment is determined to be a home environment, the collective security setting unit 313 stores, as setting values, values indicating that the firewall function is "disabled," the communication channel encryption function is "enabled," and the HDD encryption function is "disabled" in the data storage unit 302. At the same time, the CPU 201 performs the enable / disable process for each function. On the other hand, if the user selects the check box 1204 ("No"), the security setting is not performed, and the process ends there, for example by transitioning to the menu screen 801.
[0039] The installation environment determination unit 311, recommendation unit 312, and collective security setting unit 313 may hereinafter be collectively referred to as an automatic security setting unit 316, which is a function for performing automatic security setting.
[0040] The execution determination unit 314 determines whether or not it is necessary to re-execute the automatic security configuration process in the automatic security configuration unit 316, according to the determination information acquired by the determination information acquisition unit 310. For example, if the determination information acquisition unit 310 can acquire the IP address of the MFP 100 as the determination information, it determines that re-execution is not necessary, and if it cannot acquire the IP address, it determines that re-execution is necessary. By defining in advance conditions that serve as criteria for determining whether or not re-execution is necessary, it is possible to determine whether or not re-execution of the automatic security configuration is necessary, according to the determination information.
[0041] This is merely an example, and other methods of determination may be used. For example, if the amount of accumulated data packets flowing through network control unit 307 or the amount of log information of MFP100 stored in data storage unit 302 exceeds a predetermined threshold, it may be determined that re-execution is not necessary, and if not, that re-execution is necessary. Furthermore, execution determination unit 314 generates a flag indicating whether re-execution is necessary or not, so that re-execution unit 315, which will be described later, can re-execute the automatic security setting process as necessary. For example, this can be realized by generating binary data as a re-execution flag, where "1" indicates that re-execution is necessary and "0" indicates that re-execution is not necessary, and storing this in data storage unit 302.
[0042] In the following, setting the re-execution flag to require re-execution may be referred to as "enabling the re-execution flag," while setting it to not require re-execution may be referred to as "disabling the re-execution flag." Also, if the value of the re-execution flag remains unchanged before and after the re-execution flag is manipulated, the re-execution flag manipulation may be skipped. For example, when the re-execution flag is currently set to "1 (enabled)" and the re-execution flag is to be enabled, the execution decision unit 314 skips the enabling process.
[0043] The re-execution unit 315 requests the automatic security setting unit 316 to execute the automatic security setting process according to the re-execution flag generated by the execution determination unit 314. For example, the re-execution unit 315 checks the re-execution flag stored in the data storage unit 302, and if the flag is "1 (enabled)", determines that re-execution is required. At this time, it determines via the execution determination unit 314 whether or not a threshold amount of judgment information has been accumulated. If the execution determination unit 314 determines that re-execution is required (insufficient judgment information), it determines that not enough judgment information necessary for environmental judgment has been accumulated, and continues to wait until it is accumulated.
[0044] On the other hand, if the execution determination unit 314 determines that re-execution is unnecessary (sufficient determination information has been accumulated), it requests automatic security setting processing from the automatic security setting unit 316. At this time, the automatic security setting unit 316 performs an installation environment determination by the installation environment determination unit 311, a security setting recommendation by the recommendation unit 312, and a batch setting process by the batch security setting unit 313. In this way, if it is determined that the determination information does not satisfy the predetermined condition, the timing when the determination information satisfies the predetermined condition can be set as the specific timing, and security setting can be performed again. The functional configuration of this embodiment has been described above.
[0045] [Processing flow of embodiment 1] Next, with reference to the flowchart of FIG. 5, a procedure for re-executing automatic security configuration according to the environment, which is performed by the information processing apparatus according to this embodiment, will be described.
[0046] <Explanation of the processing flow when first executed> First, a processing flow when the automatic security setting function is enabled for the first time after the installation of the MFP 100 will be described with reference to FIG.
[0047] The user instructs MFP 100 to enable the automatic security setting function via operation control unit 301 (S501). Determination information acquisition unit 310 acquires the determination information (S502). Execution determination unit 314 determines whether re-execution is required or not based on the determination information (S503). If re-execution is required, execution determination unit 314 enables a re-execution flag (S504), and performs automatic security setting processing by automatic security setting unit 316 (S506). On the other hand, if re-execution is not required, execution determination unit 314 disables the re-execution flag (S505), and performs automatic security setting processing (S506).
[0048] The automatic security setting process in S506 will now be described with reference to FIG.
[0049] The installation environment determination unit 311 determines the installation environment using the determination information acquired by the determination information acquisition unit 310 (S521). The recommendation unit 312 recommends security settings according to the installation environment determined in S521 (S522). The collective security setting unit 313 collectively sets the security settings recommended in S522 (S523).
[0050] <Explanation of processing flow after the first time> Next, the processing flow after the automatic security setting function is enabled for the first time will be described with reference to Fig. 5(B). Note that this processing flow can be executed as background processing during normal operation of the MFP 100.
[0051] The re-execution unit 315 checks the re-execution flag (S511), and if the flag is invalid (No in S512), the process ends. On the other hand, if the re-execution flag is valid (Yes in S512), the re-execution unit 315 causes the determination information acquisition unit 310 to acquire determination information (S513), and the execution determination unit 314 determines whether re-execution is necessary (S514). If it is determined in S514 that re-execution is necessary, the process waits until sufficient determination information has been accumulated (S513, S514). On the other hand, if it is determined in S514 that re-execution is not necessary, the execution determination unit 314 determines that sufficient determination information has been accumulated, and disables the re-execution flag (S515), and the re-execution unit 315 requests the automatic security setting unit 316 to perform automatic security setting processing (S506). Upon receiving the request, the automatic security setting unit 316 performs automatic security setting processing.
[0052] As described above, in this embodiment, when the information necessary for determining the installation environment is insufficient, such as immediately after installing the MFP, automatic security configuration is re-executed at a later appropriate timing. Therefore, even if an incorrect environment is recommended, for example, immediately after installing the MFP, the security configuration can be automatically corrected later to be appropriate for the installation environment, thereby reducing the risk that the user will continue to use the MFP with inappropriate security configuration.
[0053] (Variation 1) In this modification, the automatic security setting process is re-executed according to the timing set by the user (for example, a date and time set in advance by the user).
[0054] As described in the first embodiment, the re-execution process is performed in the background, and if the re-execution process runs while the MFP is in use, there is a possibility that normal processes such as printing and scanning will become slower. In this modified example, the user can set the re-execution timing as desired, and can, for example, specify a date and time when the MFP will not be used as the re-execution timing. This makes it possible to re-execute automatic security configuration without affecting normal processes such as printing and scanning.
[0055] The following describes functions of this modification that differ from those of the first embodiment. In this modification, in addition to the functions of the first embodiment, the execution determination unit 314 has a function of requesting the user to input the re-execution timing via a UI when it determines that re-execution is necessary. The re-execution timing can be input, for example, by having the user input the date and time of re-execution via the operation control unit 301, which is the UI. Alternatively, the re-execution interval can be selected by the user via the UI. In this case, the user can select and set, for example, "one week," "one month," or "two months" as the re-execution interval. If "one week" is selected and set, for example, the re-execution unit 315, described later, will re-execute the automatic security configuration every week. The re-execution date and interval input by the user are stored in the data storage unit 302 as information regarding the re-execution timing.
[0056] In this modification, in addition to the functions of the first embodiment, the re-execution unit 315 has a function of requesting re-execution of the automatic security setting process in accordance with information regarding the re-execution timing stored by the execution determination unit 314 in the data storage unit 302. For example, if information indicating "22:00, May 1, 2021" is stored in the data storage unit 302 as information regarding the re-execution timing, the re-execution unit 315 waits until "22:00, May 1, 2021." Then, at the timing of "22:00, May 1, 2021," the re-execution unit 315 requests the execution determination unit 314 to perform the re-execution determination process and the automatic security setting unit 316 to perform the automatic security setting process, as in the first embodiment.
[0057] The above is merely an example, and any other method that allows specifying the re-execution date and time may be applied.
[0058] The following describes the process of re-executing automatic security configuration according to the environment in this modified example. Note that processes that are substantially the same as those in the first embodiment are given the same numbers and descriptions thereof are omitted, and only differences are described below.
[0059] <Explanation of the processing flow when first executed> First, the processing flow when the automatic security setting function is enabled for the first time after installation of MFP 100 in this modified example will be described with reference to Fig. 6(A). If re-execution is required (Yes in S503), execution determination unit 314 enables the re-execution flag (S504) and requests the user to input the timing of re-execution (S601). In response to the input request, the user inputs the timing of re-execution.
[0060] <Explanation of processing flow after the first time> Next, the processing flow after the above-described automatic security setting function is enabled for the first time in this modified example will be described with reference to Fig. 6(B). The re-execution unit 315 waits until it is time to re-execute (S611). When it is time to re-execute, the re-execution unit 315 requests the determination information acquisition unit 310 to perform determination information acquisition processing (S513) and requests the execution determination unit 314 to perform re-execution determination processing (S514). If it is determined in S514 that re-execution is required, the execution determination unit 314 requests the user to input the re-execution timing (S613).
[0061] As described above, in this modification, the user can arbitrarily set the timing for re-executing the automatic security configuration process to a date and time when the MFP is not in use, thereby minimizing the impact on the user's normal operations.
[0062] (Variation 2) In this modified example, if there is insufficient judgment information, the installation environment is not judged based on the judgment information, and automatic security settings are performed based on the security level of the installation environment and the current setting values of the MFP. However, if the installation environment is judged when there is insufficient judgment information, there is a possibility that the installation environment will be judged incorrectly and security settings that are lower than those of the actual installation environment will be recommended. Therefore, in this modified example, if there is insufficient judgment information, security settings with a higher security level than the security settings of the installation environment judged from that information will be recommended. This makes it possible to avoid a decrease in the security level due to an incorrect judgment of the installation environment.
[0063] The following describes functions of this modified example that differ from those of embodiment 1. In this modified example, in addition to the functions of embodiment 1, the recommendation unit 312 recommends a higher security level setting when there is insufficient judgment information, in accordance with a predetermined table 403 described later with reference to FIG. 4(C). Whether there is insufficient judgment information can be determined from the judgment result of the execution judgment unit 314.
[0064] For example, if the re-execution flag stored in the data storage unit 302 has a value indicating validity, it can be determined that the determination information is insufficient, and if invalid, it can be determined that the determination information is sufficient. Table 403 shown in FIG. 4(C) is a table in which rows indicating default values, which are initial settings of the MFP 100, have been added to table 402 of recommended security settings for each installation environment described in the first embodiment, and the rows are arranged in descending order of security level from top to bottom. The recommendation unit 312 compares the current setting values of the MFP 100 with the default values in table 403 and determines whether the setting values should be changed. If the current setting values remain the default values, the security settings for each installation environment determined by the installation environment determination unit 311 are compared with the security level of the default values using table 403, and the one with the higher security level is recommended.
[0065] For example, if the installation environment determination unit 311 determines that the environment is a completely isolated environment, by referring to table 403 it can be determined that the security level of a completely isolated environment is lower than the default value, and therefore the default value is recommended. On the other hand, if the installation environment determination unit 311 determines that the environment is a home environment, it can be determined that the security level is higher than the default value, and therefore the security settings for the home environment are recommended. On the other hand, if the setting value has been changed from the default value, it is not possible to compare the security levels using table 403, and therefore the security setting with a security level of "medium", which is the standard security setting, is recommended.
[0066] For example, in the case of table 403, recommended security settings for a home environment with a security level of "medium" are recommended. Note that the above security levels and default values are examples, and the security levels may be swapped by, for example, changing the correspondence between the O and X in table 403. Also, in this modified example, the security settings recommended when the setting value is changed from the default value are set to a security level of "medium," but this is an example. For example, security settings for an office environment with a security level of "high" in table 403 may be recommended.
[0067] Next, Fig. 7 is a flowchart showing details of the automatic security setting process (S506) in Fig. 5(C) in this modification. Below, the differences between this modification (Fig. 7) and embodiment 1 (Fig. 5(C)) will be described.
[0068] The recommendation unit 312 determines whether or not there is insufficient judgment information (S701). If the judgment information is sufficient (if the predetermined conditions are satisfied), the recommendation unit 312 recommends security settings as is, and the collective security setting unit 313 performs collective security settings (S522, S523). On the other hand, if there is insufficient judgment information (if the predetermined conditions are not satisfied), the recommendation unit 312 determines whether or not there are any changes to the setting values from the default values (S702). If it is determined that there are any changes to the setting values from the default values, the recommendation unit 312 recommends security settings that correspond to an installation environment with a security level of "medium" (S703), and the collective security setting unit 313 performs collective security settings (S523).
[0069] On the other hand, if it is determined in S702 that the default values remain unchanged, the recommendation unit 312 compares the security levels of the security settings corresponding to the installation environment determined by the installation environment determination unit 311 with the default values (S704). If it is determined in S704 that the default values have a higher security level, the processing ends immediately. On the other hand, if it is determined in S704 that the security settings corresponding to the installation environment determined by the installation environment determination unit 311 have a higher security level, the recommendation unit 312 recommends the security settings corresponding to the installation environment (S522). Then, the collective security setting unit 313 performs collective security setting (S523).
[0070] As described above, in this modification, when there is insufficient judgment information, a setting with a higher security level is recommended and set, thereby making it possible to avoid a decrease in security level due to an incorrect judgment of the installation environment.
[0071] (Other variations) In addition to or instead of the judgment information handled in the above embodiment and its modified examples, the judgment information can also be the cumulative operating time of MFP 100. In this case, execution judgment unit 314 can determine that re-execution is necessary if the judgment information, that is, the cumulative startup time of the MFP, is less than a threshold value, and that re-execution is not necessary if it exceeds the threshold value.
[0072] Furthermore, although only information stored in MFP 100 is used as determination information, this is merely an example, and for example, information stored on a server that can communicate with MFP 100 can also be used as determination information.
[0073] 5A in the first embodiment and the processes of S503, S504, S505, and S601 in Fig. 6A in the first modification may be performed after other processes. For example, the processes of S503, S504, and S505 may be performed after the automatic security setting process of S506 in Fig. 5A.
[0074] Furthermore, the determination information used by the execution determination unit 314 can be limited to information for determining whether or not an Internet connection is present. As described in the first embodiment, the information for determining whether or not an Internet connection is present is, for example, an IP address setting, and whether or not an Internet connection is present can be determined based on whether or not the IP address is a global IP, so the installation environment can be determined with relatively high accuracy. Furthermore, because whether or not an Internet connection is present is a factor that has a significant impact on security risks, it can be considered an important factor for determining the installation environment. Therefore, if it is possible to determine whether or not an Internet connection is present, it may be determined that the minimum required security settings can be recommended with high accuracy, and whether or not re-execution is necessary may be determined based only on information regarding whether or not an Internet connection is present.
[0075] Furthermore, in the first modification, when the execution determination unit 314 determines that re-execution is necessary, the user is requested to input the re-execution timing, but the user may also be allowed to set this in advance. For example, as shown in Fig. 10, the re-execution interval can be set via a detailed setting screen 1001 for the automatic security setting function of the operation control unit 301. The detailed setting screen 1001 for the automatic security setting function includes a "none" checkbox 1002 indicating that the re-execution interval is not to be set in advance. It also includes a checkbox 1003 indicating that re-execution should be performed every other week, and a checkbox 1004 indicating that re-execution should be performed every other month.
[0076] For example, if the user checks the checkbox 1003, a value indicating a re-execution interval of every week is saved in the data storage unit 302, and the re-execution unit 315 re-executes the automatic security configuration process according to this value. At this time, since the re-execution interval has already been set, the process of S601 in FIG. 6(A) (request to input the re-execution timing) is skipped. Similarly, the process of S613 in FIG. 6(B) (request to input the re-execution timing) is also skipped. Note that the detailed setting screen 1001 for the automatic security configuration function is merely an example, and another method may be used as long as it allows the re-execution timing to be similarly set in advance.
[0077] Furthermore, in the first modification, the process is terminated immediately after S613 in FIG. 6B, but the automatic security setting process of S506 may be performed after the process of S613.
[0078] Furthermore, when the automatic security configuration process is re-executed, rather than automatically re-executing it in the background, a message requesting re-execution may be displayed via a UI or the like, and the re-execution may be performed only after obtaining permission from the user. In this case, for example, before the process of S506 shown in Figure 5(B) or 6(B), a process may be added in which a message is displayed on the UI asking whether or not to re-execute the automatic security configuration. Then, the process may be re-executed only if the user presses a button to permit re-execution, and if the user declines, the process may simply end.
[0079] Furthermore, although the recommendation of recommended security settings by the recommendation unit 312 and the batch setting by the batch security setting unit 313 have been described as successive processes, the process may end with the recommendation by the recommendation unit 312. In this case, the user will change the settings with reference to the list of recommended recommended security settings. In this case, the components of the automatic security setting unit 316 may also be limited to the installation environment determination unit 311 and the recommendation unit 312.
[0080] In addition, in the first modification, the automatic security configuration may be automatically re-executed according to the re-execution timing without the execution decision unit 314 performing the process. In this case, for example, as described in the above modification, the re-execution unit 315 performs the re-execution according to the re-execution timing preset via the setting screen. In this modification, the execution decision unit 314 does not operate the re-execution flag. Specifically, the processes of S503, S504, S505, and S601 in FIG. 6A are eliminated, and the process of S506 is performed directly after S502. Furthermore, the processes of S511, S512, S514, S515, and S613 in FIG. 6B are eliminated, and the process of S506 is performed directly after S513. For example, if the re-execution interval is set to every week, the re-execution unit 315 executes the automatic security configuration every week.
[0081] Furthermore, in the above-described modified example, the re-execution interval is a fixed value, but it may be gradually extended. For example, if the re-execution interval is set to once a week, the re-execution may be gradually extended, such as once a week for the first month, once every two weeks for the next month, and once every three weeks for the next month. The installation environment depends on the connection status of peripheral devices and the communication and operation status, so it is unstable immediately after installation, but tends to stabilize over time.
[0082] Therefore, by frequently re-executing the process immediately after installation when the environment is unstable, and gradually increasing the re-execution interval as the environment stabilizes, it is possible to efficiently re-execute the automatic security configuration process based on the installation environment.
[0083] In addition, in the above embodiment and modified examples, the processing of Fig. 5(A) and Fig. 6(A) has been described as processing when the automatic security setting function is enabled for the first time after the MFP is installed, but this is merely an example. For example, when the automatic security setting is enabled for the first time after the MFP is initialized, the processing of Fig. 5(A) and Fig. 6(A) may be performed in the same way as the first time after the MFP is installed.
[0084] As described above, at a specific timing (for example, when a certain amount of installation environment judgment information has been accumulated, or when the user specifies a timing), the user is requested to perform the installation environment judgment process again, or the installation environment judgment and configuration are performed automatically. This allows the security configuration to be corrected later to suit the installation environment, even if the security configuration is configured based on an incorrect judgment immediately after the MFP is installed, thereby reducing the risk that the user will continue to use the MFP with inappropriate security settings.
[0085] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0086] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0087] 310: Determination information acquisition unit, 311: Installation environment determination unit, 312: Recommendation unit, 313: Bulk security setting unit, 314: Execution determination unit, 315: Re-execution unit
Claims
1. An information processing device, a setting unit for setting security for the information processing device based on an installation environment of the information processing device; a determination information acquisition means for acquiring determination information for determining an installation environment of the information processing device, the determination information including a cumulative operating time of the information processing device; an execution determination means for determining whether or not the security setting needs to be performed again by the setting means based on the determination information; Equipped with The information processing apparatus is characterized in that the setting means performs the security setting again at a specific timing when the execution determining means determines that the security setting needs to be performed again.
2. The information processing apparatus according to claim 1 , wherein the determination information includes information regarding whether or not the information processing apparatus has a network boundary.
3. 3. The information processing apparatus according to claim 1, wherein the determination information includes information regarding whether the information processing apparatus is connected to the Internet.
4. 4. The information processing apparatus according to claim 1, wherein the determination information includes information relating to the presence or absence of a physical boundary that separates the inside and outside of an environment in which the information processing apparatus is placed.
5. a recommendation unit that recommends security settings suitable for the installation environment of the information processing device determined based on the determination information; 5. The information processing apparatus according to claim 1, wherein the setting unit sets the security settings recommended by the recommendation unit in the information processing apparatus.
6. 6. The information processing apparatus according to claim 1, wherein the execution determining unit determines that the security setting needs to be performed again when the determination information does not satisfy a predetermined condition.
7. The information processing device according to claim 6, characterized in that, when it is determined that the judgment information does not satisfy the predetermined condition, the setting means performs the security setting again, using the timing at which the judgment information satisfies the predetermined condition as the specific timing.
8. The information processing device according to claim 6 or 7, characterized in that when it is determined that the judgment information does not satisfy the specified conditions, the setting means compares the security settings corresponding to the current installation environment of the information processing device determined from the judgment information with the default security settings of the information processing device according to a specified table, and sets security settings with a higher security level.
9. 7. The information processing apparatus according to claim 1, wherein the specific timing is a date and time preset by a user of the information processing apparatus.
10. 10. The information processing apparatus according to claim 1, wherein the information processing apparatus is an image forming apparatus.
11. A control method for an information processing device, comprising: a setting step in which a setting unit of the information processing device performs security setting on the information processing device based on an installation environment of the information processing device; a determination information acquisition step in which a determination information acquisition means of the information processing device acquires determination information for determining an installation environment of the information processing device, the determination information including a cumulative operating time of the information processing device; an execution determination step in which an execution determination means of the information processing device determines whether or not the security setting needs to be performed again by the setting step based on the determination information; A control method for an information processing device, characterized in that in the setting step, if it is determined in the execution determination step that the security settings need to be made again, the security settings are made again at a specific timing.
12. A program for causing a computer to function as the information processing device according to any one of claims 1 to 10.
Citation Information
Patent Citations
Image forming system
JP2011066714A
Information processing system, information processing device, and control method of information processing system
JP2016062558A