Information processing system, information processing device, server device, control method, and program
The system automatically configures security settings for diverse user environments by collecting environmental data, determining the installation context, and generating templates for information processing devices, addressing the challenge of manual configuration and environment recognition.
Patent Information
- Application Number
- JP2022005820
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-18
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2042-01-18
AI Technical Summary
Existing information processing devices struggle to automatically set security policies appropriate for diverse user environments, requiring manual configuration and accurate recognition of installation environments, which is challenging when multiple types of devices are present.
An information processing system that includes a first device to collect environmental information, determine the installation environment, detect and generate a setting template, and transmit it to a second device, enabling automatic security setting configuration based on the environment.
Facilitates easy and environment-specific security template setting for information processing devices, ensuring appropriate security configurations without manual intervention.
Smart Images

Figure 0007788868000001 
Figure 0007788868000002 
Figure 0007788868000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system, an information processing device, a server device, a control method, and a program. [Background technology]
[0002] In recent years, the environment surrounding information processing devices has undergone diverse changes. Traditionally, information processing devices installed in companies were protected from external attacks by the company's network boundary. However, as office environments have become more diverse, the environments in which information processing devices are installed are also changing accordingly. Examples include telecommuting, satellite offices, and rental offices. To ensure the security of information processing devices installed in such diverse environments, it is necessary to implement security settings appropriate for the environment.
[0003] In Patent Document 1, the environment in which the image processing device is installed is determined and a security policy appropriate for the installation environment is automatically applied, thereby realizing security settings appropriate for the installation environment without the user having to select a security policy.
[0004] In Patent Document 2, settings are made to one or more information processing devices existing within the same network, and the settings are applied to all the information processing devices at once. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2020-181228 [Patent Document 2] Japanese Patent Application Laid-Open No. 2015-49824 Summary of the Invention [Problem to be solved by the invention]
[0006] However, with the technology of Patent Document 1, it is difficult to ensure security for the entire user environment. If multiple types of information processing devices are installed in the user environment and there is an information processing device that does not have a function to automatically set a security policy appropriate for the environment, the user must configure that information processing device himself. Furthermore, with the technology of Patent Document 2, it is difficult to configure security settings appropriate for the environment. With Patent Document 2, the user must accurately recognize the installation environment and then select appropriate settings.
[0007] The present invention has been made in view of the above-mentioned problems, and has an object to provide a technique for easily setting a setting template suited to the installation environment for an information processing device in a user's environment. [Means for solving the problem]
[0008] An information processing system according to the present invention that achieves the above object comprises: An information processing system including a first information processing device and a second information processing device, The first information processing device a collection means for collecting information on the surrounding environment of the first information processing device; a determination means for determining an installation environment of the first information processing device based on the information; a detection means for detecting the second information processing device; a generation means for generating a setting template for setting the second information processing device based on the installation environment; a transmitting means for transmitting the setting template to the second information processing device; Equipped with The second information processing device a receiving means for receiving the setting template; an application unit that applies the setting template received by the receiving unit to the second information processing device; The present invention is characterized by comprising: [Effects of the Invention]
[0009] According to the present invention, a setting template suitable for the installation environment can be easily set for an information processing device in a user environment. [Brief explanation of the drawings]
[0010] [Figure 1] A block diagram showing the connection between the MFP and peripheral devices according to the present invention. [Figure 2] Internal configuration diagram of the controller unit of the MFP according to the present invention [Figure 3] 1 is a diagram showing the device configuration of an MFP 100 according to the present invention; [Figure 4] FIG. 1 shows the device configuration of an MFP 120 according to the present invention. [Figure 5] FIG. 1 shows security templates for each environment of the MFP 100 according to the first embodiment. [Figure 6] FIG. 1 shows setting files for the MFP 100 and the MFP 120 according to the first embodiment. [Figure 7] FIG. 1 is a diagram showing a blacklist of setting items according to the first embodiment. [Figure 8] 1 is a flowchart showing the processing procedure of the first embodiment. [Figure 9] FIG. 10 is a diagram showing a setting template selection table according to the first embodiment. [Figure 10] FIG. 10 shows the device configurations of an MFP 100, an MFP 120, and a server 130 according to a second embodiment. [Figure 11] 10 is a flowchart showing the processing procedure of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the claimed invention. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0012] In this embodiment, an information processing device having an environment determination function for determining the installation environment detects information processing devices existing in the same environment, and generates and distributes a setting template suitable for the environment to the detected information processing device. In this embodiment, an MFP (Multi-Function Peripheral), which is an image forming device, is described as an example of an information processing device, but the present invention is a technology that can be applied to information processing devices other than MFPs.
[0013] (Embodiment 1) [Configuration of information processing system] Referring to Figure 1, the connection configuration of the MFP and peripheral devices according to the present invention will be described. MFP 100, PC (Personal Computer) 110, and MFP 120 are connected via LAN 140. MFP 120 is a different model from MFP 100, although made by the same vendor. PC 110 performs processes such as sending and receiving print jobs and scan jobs to MFP 100. In addition, external server 130 (server device) communicates with MFP 100 and MFP 120 via Internet 150. MFP 100 has operation unit 102 for input and output with the user. MFP 100 has printer unit 103 for outputting electronic data onto paper media. MFP 100 has scanner unit 104 for reading paper media and converting it into electronic data.
[0014] The operation unit 102, printer unit 103, and scanner unit 104 are connected to the controller unit 101 and function as a multifunction peripheral under the control of the controller unit 101. The client PC 110 performs processes such as sending and receiving print jobs and scan jobs to the MFP 100. The operation unit 102, printer unit 103, and scanner unit 104 of the MFP 120 have the same functions as those of the MFP 100, so they are given the same numbers and their descriptions are omitted. However, the controller unit 121 of the MFP 120 has the functions shown in FIG. 4 (described later), which are different from the controller unit 101 of the MFP 100, which has the functions shown in FIG. 3 (described later), so it is given a different number.
[0015] [Hardware configuration of controller unit 101] FIG. 2 is a block diagram showing the physical configuration of the controller unit 101 of the MFP 100. The configuration of the controller unit 121 of the MFP 120 is similar to that of the controller unit 101, and therefore will not be described here. A CPU 201 performs the main arithmetic processing within the controller unit. The CPU 201 is connected to a DRAM 202 via a bus. The DRAM 202 is used by the CPU 201 as a working memory for temporarily storing program data representing arithmetic instructions and data to be processed during the CPU 201's arithmetic processing. The CPU 201 is connected to an I / O controller 203 via a bus. The I / O controller 203 performs input and output to various devices according to instructions from the CPU 201. A SATA (Serial Advanced Technology Attachment) I / F 205 is connected to the I / O controller 203, and a Flash ROM 211 is connected to the SATA I / F 205. The CPU 201 uses the Flash ROM 211 to permanently store programs for implementing the MFP's functions and document files. A network I / F 204 is also connected to the I / O controller 203. A wired LAN device 210 is connected to the network I / F 204 .
[0016] The CPU 201 controls the wired LAN device 210 via the network I / F 204 to realize communication on the LAN 140. A panel I / F 206 is connected to the I / O controller 203, and the CPU 201 performs input and output for the user to the operation unit 102 via the panel I / F 206. A printer I / F 207 is connected to the I / O controller 203, and the CPU 201 performs output processing for paper media using the printer unit 103 via the printer I / F 207. A scanner I / F 208 is connected to the I / O controller 203, and the CPU 201 performs reading processing of an original using the scanner unit 104 via the scanner I / F 208. A USB I / F 209 is connected to the I / O controller 203, and the I / O controller 203 controls any device connected to the USB I / F 209.
[0017] When performing the copy function, the CPU 201 loads program data from the Flash ROM 211 into the DRAM 202 via the SATA I / F 205. The CPU 201 detects a copy instruction from the user via the panel I / F 206 on the operation unit 102 in accordance with the program loaded into the DRAM 202. When the CPU 201 detects a copy instruction, it receives an original as electronic data from the scanner unit 104 via the scanner I / F 208 and stores it in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207, and performs output processing onto paper media.
[0018] When PDL (Page Description Language) printing is performed, the client PC 110 issues a print instruction via the LAN 140. The CPU 201 loads program data from the Flash ROM 211 into the DRAM 202 via the SATA I / F 205. Then, a print instruction is detected via the network I / F 204 according to the program data loaded into the DRAM 202. When the CPU 201 detects a PDL transmission instruction, it receives print data via the network I / F 204 and stores the print data in the Flash ROM 211 via the SATA I / F 205. After the print data has been stored, the CPU 201 develops the print data stored in the Flash ROM 211 into the DRAM 202 as image data. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207, and performs output processing onto paper media.
[0019] The functional configuration and processing flow of this embodiment will be described below.
[0020] [Function Configuration] Next, with reference to the block diagram of Fig. 3, an example of a functional configuration realized by software executed by the controller unit 101 of the first MFP 100 according to the first embodiment will be described. The operation control unit 301 displays a screen image for the user on the operation unit 102, detects user operations, and executes processing associated with screen components such as buttons displayed on the screen. The data storage unit 302 stores data in the Flash ROM 211 and reads data in response to requests from other control units. For example, if the user wants to change some device setting, the operation control unit 301 detects the content input by the user to the operation unit 102, and in response to a request from the operation control unit 301, the data storage unit 302 saves it as a setting value in the Flash ROM 211.
[0021] A job control unit 303 controls job execution in accordance with instructions from other control units. An image processing unit 304 processes image data into a format suitable for each application in accordance with instructions from the job control unit 303. A print processing unit 305 prints and outputs an image on paper media via a printer I / F 207 in accordance with instructions from the job control unit 303. A reading processing unit 306 reads a placed document via a scanner I / F 208 in accordance with instructions from the job control unit 303.
[0022] The network control unit 307 performs network settings such as IP addresses on the TCP / IP control unit 308 in accordance with the setting values stored in the data storage unit 302 when the system is started or when a setting change is detected. The TCP / IP control unit 308 performs transmission and reception processing of network packets via the network I / F 204 in accordance with instructions from other controls. The USB control unit 309 controls the USB I / F 209 and controls any device connected via USB. The communication port control unit 310 controls the ports used by the TCP / IP control unit 308 when transmitting and receiving packets.
[0023] The environmental information collection unit 320 collects information about the setting values of the first MFP 100 stored in the data storage unit 302 at the start of operation. The information collection unit 320 collects information about the environment surrounding the first MFP 100, such as packets received by the first MFP 100 from devices connected via the LAN 140, such as the PC 110, the second MFP 120, and the server 130, and responses to packets sent by the first MFP 100 to devices within the network. The information about the setting values of the first MFP 100 includes, for example, an IP address and its type (global address, private address), and a setting as to whether or not a proxy server is used when the first MFP 100 communicates with devices outside the LAN. The information also includes a setting for the protocol used for communication, and a sharing setting for files stored in the data storage unit 302 of the first MFP 100. The information about the environment surrounding the first MFP 100 includes, for example, the source IP address and its type (global address, private address) of packets received by the first MFP 100, and information about the port used for communication.
[0024] The information may also include the TTL (Time to Live) of the packet, a response to an ARP (Address Resolution Protocol) sent by the MFP, a response from the DNS server, information about the second MFP 120 (identification information such as an IP address or MAC address), etc. Here, the information collected by the environmental information collecting unit 320 has been exemplified as described above, but other information that can be collected by the first MFP 100 may also be referenced. Hereinafter, the information about the surrounding environment described above may be referred to as "environmental information." The collected environmental information is stored in the data storage unit 302. Also, while the environmental information collecting unit 320 has been exemplified here as starting processing at the start of operation, the processing may also be started in response to a user's instruction to start processing to the environmental information collecting unit 320 via the operation unit 102.
[0025] The environment determination unit 321 determines the installation environment of the first MFP 100 based on the environment information collected by the environment information collection unit 320. The environment determination unit 321 reads the environment information stored in the data storage unit 302, and classifies the environment of the first MFP 100 into predefined environments such as SOHO, public, intranet, and isolated environment. Here, the installation environment of the first MFP 100 has been exemplified as above, but it may also be classified into other environments.
[0026] As a method of determining the environment, for example, if a proxy setting of the first MFP 100 or communication from a proxy server is detected, it is determined to be an intranet environment in which network boundary protection by a proxy server is applied. If network boundary protection is not applied like an intranet environment but the MFP is operated on a private network, it is determined to be an SOHO environment. If a global address is set as the IP address or the MFP is directly communicating with an external server or client, and the MFP is accessible to an unspecified number of users, it is determined to be a public environment.
[0027] Furthermore, if there is no communication with the Internet environment, it is determined to be an isolated environment. Here, a rule-based determination method that determines the environment based on specific conditions is exemplified, but the environment may also be determined using AI that has learned the relationship between collected environmental information and the environmental determination results, or other methods may be used to determine the environment.
[0028] The security setting control unit 322 determines the security settings of the first MFP 100 based on the environment determination result of the environment determination unit 321. The security settings are determined according to a setting template defined for each environment held by the first MFP 100, which will be described later with reference to FIG. 5. The setting template describes a plurality of setting values for the MFP to perform settings suited to the installation environment. The security setting control unit 322 applies the setting values described in the setting template as the MFP settings, thereby enabling the MFP to perform settings suited to the installation environment. Here, although the example has been given in which the security settings are determined according to the setting template held by the first MFP 100, the security settings may be changed individually, or the user may change the security settings. After the security setting control unit 322 finishes processing, it requests the detection unit 330, which will be described later, to start MFP detection processing.
[0029] In response to a request from security setting control unit 322, detection unit 330 detects MFPs in the same environment as first MFP 100. MFPs to be detected are MFPs that exist on the same network as first MFP 100, and do not include MFPs that belong to different subnetworks or different domains. Furthermore, the model of the MFP to be detected is the same as first MFP 100, or a different model from the same vendor as first MFP 100 (a model with a different version from first MFP 100, a low-cost model, etc.). In other words, it can be the same model or a model of the same type from the same vendor. Note that it is also possible to determine that a detected MFP exists on the same network, provided that it is separated by F / W or the like.
[0030] As a method of detecting an MFP, for example, the first MFP 100 broadcasts an ARP packet within the LAN and identifies the MFP as a detection target by referencing the vendor ID (vendor information) and model ID of the MAC address included in the response. Alternatively, a dedicated communication protocol may be used between MFPs to identify the MFP as a detection target.
[0031] After detecting an MFP in the same environment, the detection unit 330 requests the setting template generation process control unit 340, which will be described later, to start the setting template generation process. Here, although the operation of the detection unit 330 is illustrated as being automatically started after the processing of the security setting control unit 322 is completed, the user may also instruct the start of the process via the operation unit 102.
[0032] Setting template generation process control unit 340 requests the MFP (second MFP 120) detected by detection unit 330 to start a setting file update process for applying a setting template suited to the environment, which is performed by setting template generation unit 342, which will be described later. Then, the setting template generation process control unit 340 waits for reception of a first setting file 601, which describes setting items of the detected MFP, which will be described later with reference to FIG. 6.
[0033] Setting file receiving unit 341 receives first setting file 601 transmitted by second MFP 120. After receiving first setting file 601, setting file receiving unit 341 requests setting template generating unit 341 to start processing.
[0034] Setting template generation unit 342 generates a setting template for second MFP 120 by updating first setting file 601 received by setting file reception unit 341. This method involves first requesting setting file generation unit 350, which will be described later, to generate second setting file 602 in which setting items for first MFP 100, which will be described later with reference to Fig. 6, are written. The items in first setting file 601 are compared with the items in the generated second setting file 602, and for identical items, the setting items in second setting file 602 are copied to the setting items in first setting file 601.
[0035] For setting items that exist only in the first setting file 601, a setting item blacklist 701, which will be described later with reference to Fig. 7, is referenced to determine the setting value. Protocols with known vulnerabilities and legacy protocols are registered in the setting item blacklist 701, and since enabling setting items related to these may affect the security of the MFP, the setting values are updated to OFF. Setting items that are not registered in the setting item blacklist 701 are not updated and the original setting values are left unchanged. The first setting file 601 updated by this process is transmitted to the second MFP 120 by a setting template transmission unit 343, which will be described later, as a setting template for the second MFP 120.
[0036] Setting template transmission unit 343 transmits the setting template of second MFP 120 generated in response to a request from setting template generation unit 342 to second MFP 120. Setting file generation unit 350 generates a setting file that describes its own setting items from the setting information stored in data storage unit 302.
[0037] Next, an example of a functional configuration realized by software executed by controller unit 121 of second MFP 120 of embodiment 1 will be described with reference to the block diagram of Fig. 4. The second MFP 120 is a different type of MFP from the first MFP 100, and is a device that does not have an environment information collection function, an environment determination function, an environment-appropriate setting template application function, or an environment-appropriate setting template generation / distribution function. Note that functions that are the same as those described in the functional configuration of controller unit 101 of first MFP 100 shown in Fig. 3 are assigned the same numbers, and descriptions thereof will be omitted.
[0038] The setting file transmission unit 360 transmits a setting file in which setting items of the second MFP 120 are described to the other MFPs.
[0039] The setting update process control unit 361 starts the setting update process when it receives a request to start the setting update process from another MFP. First, it requests the setting file generation unit 350 to generate a first setting file 601 in which its own setting items are written. The generated first setting file 601 is transmitted by the setting file transmission unit 360 to the MFP that has requested the start of the setting update process. Note that, as a countermeasure against spoofing of the MFP that has requested the start of the setting update process, the process may be started only when a pre-registered MFP requests the start of the setting update process. Alternatively, the sender of the request to start the setting update process may be authenticated. For example, the MFP's certificate may be received along with the request to start the setting update process, and the MFP may be authenticated by verifying the validity of the received certificate on the MFP vendor's server, etc.
[0040] The setting template receiving unit 362 receives setting templates transmitted from other MFPs. The setting template applying unit 363 reflects the contents of the setting template received by the setting template receiving unit 362 in its own security settings.
[0041] [Example of a configuration template] 5 shows an example of a setting template 501 for each environment held by the first MFP 100. The first MFP 100 reflects the security settings described in the setting template 501 in the first MFP 100 according to the environment determined by the environment determination unit 321. For example, in the case of an intranet environment, it is assumed that communication will be performed outside the network boundary, and communication is encrypted using Transport Layer Security (TLS). Furthermore, since defensive measures are implemented at the network boundary, the MFP firewall and file sharing within the network are set arbitrarily. Furthermore, in the case of a public environment, since access is possible by an unspecified number of users, the MFP firewall is enabled and file sharing is disabled as a measure to prevent information leakage.
[0042] 6 shows an example of a first setting file 601 and a second setting file 602 in which setting items of the MFP are described. The first setting file 601 is a setting file in which setting items of the MFP for which security settings are to be updated are described. The second setting file 602 is a setting file used when updating the setting items of the first setting file 601. When the setting template generation unit 342 generates a setting template, the first setting file 601 is updated based on the setting items of the second setting file 602.
[0043] For example, the TLS setting is OFF in the first setting file 601 and ON in the second setting file 602. When the setting files are updated, the TLS setting in the first setting file 601 is updated to ON in accordance with the setting in the second setting file 602.
[0044] The setting of SMB (Server Message Block) v1 (not shown) in the first setting file 601 is an item that does not exist in the second setting file 602, so a setting item blacklist 701, which will be described later with reference to Fig. 7, is referenced. Setting items registered in the setting item blacklist 701 are recommended to be turned off in view of known vulnerabilities, and SMB v1 is set to OFF because it is registered in the blacklist 701.
[0045] FIG. 7 shows an example of a setting item blacklist 701. Protocols with known vulnerabilities and legacy protocols are registered in the setting item blacklist 701. The setting template generation unit 342 references the setting item blacklist 701 when updating the first setting file 601. Protocols registered in the setting item blacklist 701 may affect the security of the MFP if used due to known vulnerabilities or whether they are supported, so it is recommended that their functions be turned off. For example, SMB v1 has many known reported vulnerabilities, is an old protocol, and has not been fixed, so it is recommended that it not be used. AppleTalk is a legacy protocol that is no longer in use, and it is recommended that it not be used because it cannot be addressed even if a vulnerability is discovered.
[0046] [Processing flow] With reference to the flowcharts of Figures 8(A), 8(B), 8(C), and 8(D), a description will be given of a processing flow when the first MFP 100 of this embodiment generates and distributes a setting template to the second MFP 120. Note that Figures 8(A), 8(B), and 8(C) show processing performed by the first MFP 100, and Figure 8(D) shows processing performed by the second MFP 120.
[0047] 8(A), in the first MFP 100, at the start of operation or in response to a user instruction, the environment information collection unit 320 collects information about the surrounding environment of the first MFP 100 (S801). The environment determination unit 321 determines the installation environment of the first MFP 100 based on the collected environment information (S802). The security setting control unit 322 determines the security settings to be applied to the first MFP 100 based on the result of the environment determination and the setting template 501 according to the environment (S803).
[0048] For example, if the installation environment of the first MFP 100 is a SOHO, the SOHO settings of the setting template 501 are applied (S804). If the installation environment is public, the public settings of the setting template 501 are applied (S805). If the installation environment is intranet, the intranet settings of the setting template 501 are applied (S806). After applying the setting template to the first MFP 100, setting templates are generated and distributed to MFPs existing in the same environment (S810).
[0049] 8(B), the process (S810) of generating and distributing a setting template to MFPs existing in the same environment by the first MFP 100 will be described in detail. First, the detection unit 330 searches for an MFP existing in the same environment as the first MFP 100 (S811). If no MFP exists in the same environment, the process ends. On the other hand, if another MFP (second MFP 120) existing in the same environment is detected (S812), the setting template generation process control unit 340 of the first MFP 100 requests the second MFP 120 to start setting update processing (S813).
[0050] The setting file receiving unit 341 of the first MFP 100 receives the setting file 601 from the second MFP 120 (S814), and the setting template generating unit 342 generates a setting template for the second MFP 120 using the first setting file 601 (S820). After the generation of the setting template is complete, the setting template sending unit 343 sends the setting template for the second MFP 120 to the second MFP 120 (S815), and the process ends.
[0051] Next, the details of the setting template generation process (S820) will be described using Fig. 8(C). First, setting file generation unit 350 generates second setting file 602 describing setting items for first MFP 100 (S821). Next, setting template generation unit 341 compares the setting items of first setting file 601 received from second MFP 120 with the setting items of second setting file 602 (S822). Then, for setting items that are identical, the setting values of second setting file 602 are copied to first setting file 601 (S824).
[0052] For setting items that exist only in the first setting file 601, the blacklist of setting items 701 is referenced, and setting items registered in the blacklist of setting items 701 are updated to OFF (S825). After the above-mentioned processing is performed for all setting items in the first setting file 601, the processing ends.
[0053] Next, the setting update processing of the second MFP 120 will be described with reference to Fig. 8(D). In the second MFP 120, upon receiving a request to start the setting update processing from the first MFP 100, the setting update processing control unit 361 starts its own setting update processing (S831). The setting file generation unit 350 of the second MFP 120 generates a first setting file 601 (S832), and the setting file transmission unit 360 transmits the first setting file 601 to the first MFP 100 (S833). The second MFP 120 waits to receive a setting template of the second MFP 120 (S834). After the setting template reception unit 362 receives the setting template of the second MFP 120, the setting template application unit 363 applies the setting items of the setting template of the second MFP 120 to itself (S835), and the processing ends.
[0054] In this manner, in this embodiment, the first MFP 100 can generate and distribute a setting template to the second MFP 120.
[0055] (Modification 1 of Embodiment 1) In the first embodiment, an example has been described in which a setting template for the second MFP 120 is generated by updating a first setting file 601 in which setting items for the MFP 120 are described based on a second setting file 602 in which setting items for the MFP 100 are described. In contrast, in the present modified example, an example will be described in which a setting template to be used for updating the first setting file 601 is selected based on information (such as an IP address) of the second MFP 120, thereby updating the file to have optimal values for the second MFP 120.
[0056] Since the first MFP 100 and the second MFP 120 exist in the same environment, the surrounding environment, such as the presence or absence of a network boundary and the devices that communicate with the MFPs, can be considered to be the same. However, depending on the settings of the second MFP 120, there may be cases where they cannot be considered to be the same environment. For example, suppose the first MFP 100 and the second MFP 120 are installed in an intranet environment protected by a network boundary.
[0057] In this environment, if the second MFP 120 has set a global address as its IP address, there is a possibility that the MFP 120 may be directly communicating with an external network even in an environment with network boundary protection, and in that case, a public environment without network boundary protection would be suitable as the installation environment for the second MFP 120. In this situation, if the first configuration file 601 is updated based on the settings of the first MFP 100, a discrepancy will occur between the security settings and the installation environment, and therefore it cannot be said that appropriate settings have been made.
[0058] Therefore, when updating first setting file 601, first MFP 100 refers only to the setting items described in first setting file 601 and information related to second MFP 120 from among the environmental information collected by first MFP 100. This causes environment determination unit 321 to determine the installation environment of second MFP 120. Then, based on the result of the determination, setting template generation unit 342 reselects a setting template suitable for second MFP 120 and updates first setting file 601 based on that setting template.
[0059] 5 for an intranet environment, and the recommended settings for the firewall and file sharing are arbitrary values. If, during installation environment determination, it is determined that the installation environment of the second MFP 120 is public, the first setting file 601 is updated based on the public template, and is therefore updated to firewall: ON and file sharing: OFF, which differ from the recommended settings of the first MFP 100. Here, an example has been given in which the installation environment of the second MFP 120 is determined to select the optimal setting template for the MFP 120, but the optimal settings for the second MFP 120 may also be determined using AI or the like.
[0060] In this way, by selecting a setting template to be used for updating the first setting file 601 based on the information of the second MFP 120, the setting file is updated to have optimal values for the second MFP 120.
[0061] (Modification 2 of Embodiment 1) In the first embodiment, an example has been described in which the first MFP 100 generates a setting template for the second MFP 120 by updating the first setting file 601 received from the second MFP 120. In contrast, in this modified example, an example will be described in which a setting template for the second MFP 120 is generated without using the first setting file 601.
[0062] For example, in the first MFP 100, the setting template generation unit 342 selects an optimum setting template for the second MFP 120 from setting templates that the first MFP 100 has in advance, based on the environmental information determined by the first MFP 100 and the identification information (such as a model ID) of the second MFP 120. For example, the first MFP 100 has a setting template selection table 901 as shown in FIG.
[0063] The setting template selection table 901 lists the setting templates that are suitable for each setting environment for each MFP model. By using the setting template selection table 901, the first MFP 100 can select an appropriate setting template based on the MFP model ID and installation environment.
[0064] For example, if the model ID of the second MFP 120 is "A" and the determination result of the installation environment is intranet, then "intra_A" is selected, which is a setting template for the intranet environment of an MFP whose model ID in setting template selection table 901 is A. Setting template sending unit 343 of the first MFP 100 sends the selected setting template to the second MFP 120. Then, setting template application unit 363 applies the setting template received by setting template receiving unit 362, and the second MFP 120 can perform settings that are optimal for the installation environment.
[0065] In this way, the first MFP 100 transmits the setting template for the second MFP 120 without using the first setting file 601 .
[0066] (Embodiment 2) The following describes information processing in embodiment 2. Note that in embodiment 2, the same components as those in embodiment 1 are denoted by the same reference numerals, and detailed descriptions thereof will be omitted.
[0067] In the first embodiment, an example has been described in which the first MFP 100 determines the installation environment and generates and distributes a setting template to the second MFP 120. In contrast, in the second embodiment, the server determines the installation environment and generates and distributes a setting template.
[0068] [Function Configuration] The functional configuration of the MFP and server in the second embodiment will be described with reference to the block diagram of Fig. 10. The first MFP 100 and second MFP 120 have substantially the same functional configuration as those already described with reference to Figs. 3 and 4. However, the functional configuration of the first MFP 100 is partially different from that of the first embodiment, and will be described with reference to Fig. 10. Note that with regard to the first MFP 100, second MFP 120, and server 130 in the first embodiment, components assigned the same numbers as those in Fig. 3 have the same functions, and therefore description thereof will be omitted.
[0069] Environmental information transmission unit 1001 of first MFP 100 transmits environmental information collected by environmental information collection unit 320 to server 130. Here, the environmental information includes information (such as IP address and MAC address) for identifying second MFP 120 detected by detection unit 330 of MFP 100.
[0070] An environment information receiving unit 1002 of the server 130 receives the environment information transmitted from the first MFP 100. An environment determining unit 321 of the server 130 determines the installation environment of the first MFP 100 based on the received environment information.
[0071] The setting template generation unit 1003 of the server 130 generates a setting template for the second MFP 120 by updating the first setting file 601 received from the second MFP 120 based on the result of the environment determination by the environment determination unit 321. When updating the setting file, the first setting file 601 may be updated by referencing a setting template that is already stored based on the result of the environment determination. Alternatively, the first setting file 601 may be updated by selecting optimal setting values using AI.
[0072] [Processing flow] Next, with reference to the flowcharts of Figures 11(A), 11(B), and 11(C), the process performed by the server 130 of this embodiment when generating and distributing a setting template to the second MFP 120 based on environmental information collected by the first MFP 100 will be described. The process for applying the setting template by the second MFP 120 is the same as the process described with reference to Figure 8(D), and therefore a description thereof will be omitted. Note that the flowchart of Figure 11(A) is the process performed by the first MFP 100. The flowcharts of Figures 11(B) and 11(C) are the process performed by the server 130.
[0073] In the first MFP 100, at the start of operation, the environment information collection unit 320 collects information about the installation environment of the first MFP 100 (S1101). After collecting the environment information, the detection unit 330 searches for an MFP (second MFP 120) that exists in the same environment (S1102). As a result of checking the presence or absence of an MFP (S1103), if the MFP does not exist, the processing is terminated, and if the MFP is present, the environment information transmission unit 1001 transmits environment information including information for identifying the second MFP 120 to the server 130 (S1104).
[0074] 11(B), the environment determination process of the server 130 and the update process of the first setting file 601 will be described. The environment information receiving unit 1002 of the server 130 receives environment information from the first MFP 100 (S1111), and the environment determination unit 321 determines the installation environment of the first MFP 100 based on the received information (S1112). After determining the installation environment, the setting template generation process control unit 340 requests the second MFP 120 to start setting update processing (S1113). The setting file receiving unit 341 of the server 130 receives the first setting file 601 from the second MFP 120 (S1114).
[0075] Then, the setting template generation unit 1003 generates a setting template for the second MFP 120 by updating the first setting file 601 (S1120). Details of the processing of S1120 will be described later with reference to FIG. 11(C). After the generation of the setting template is complete, the setting template transmission unit 343 transmits the setting template to the second MFP 120 (S1115). Thereafter, the setting template reception unit 362 of the second MFP 120 receives the setting template for the second MFP 120 from the server 130. Then, the setting template application unit 363 updates the settings of the second MFP 120 based on the received setting template.
[0076] 11(C), the configuration template generation process (S1120) by the server 130 will be described in detail. The configuration template generation unit 1003 selects a configuration template suitable for the installation environment based on the result of the environment determination by the environment determination unit 321 (S1121). After referring to the environment determination result (S1122), if the installation environment is SOHO, a template for the SOHO environment is selected (S1123). If the installation environment is public, a template for the public environment is selected (S1124). If the installation environment is intranet, a template for the intranet environment is selected (S1125). The first configuration file 601 is updated using the selected configuration template (S1126), and the process ends.
[0077] In this way, server 130 generates and distributes a setting template to second MFP 120 based on the environmental information collected by first MFP 100. Note that, although the present embodiment has been exemplified in which first MFP 100 detects second MFP 120, if server 130 is installed within a LAN, server 130 may detect second MFP 120.
[0078] (Modification 1 of Embodiment 2) In the second embodiment, an example has been described in which the first setting file 601 is transmitted and received between the server 130 and the second MFP 120. In addition to this, in the present modified example, an example will be described in which the first MFP 100 relays the transfer of the first setting file 601 between the server 130 and the second MFP 120.
[0079] In the second embodiment, the second MFP 120 needs to communicate directly with the server 130 to update the first setting file 601. However, there is a possibility that the second MFP 120 cannot communicate with the external server 130 due to settings of a network device or the like. For example, if IP addresses are filtered by settings of a firewall or the like, the second MFP 120 and the server 130 cannot communicate with each other.
[0080] Therefore, in this modification, the first MFP 100 relays the delivery of the first setting file 601. First, the setting file transmission unit 360 of the second MFP 120 transmits the first setting file 601 to the first MFP 100. The first MFP 100 transmits the first setting file 601, which has been received by the setting file reception unit 341 of the first MFP 100, to the server 130 via the setting file transmission unit 360.
[0081] Server 130 generates a setting template for second MFP 120 by having setting template generation unit 1003 update first setting file 601 received by setting file reception unit 341. The generated setting template for second MFP 120 is transmitted to first MFP 100 by setting template transmission unit 343 of server 130. The first MFP 100 transmits the setting template for second MFP 120 received by setting template reception unit 362 to second MFP 120 via setting template transmission unit 343.
[0082] In this way, the first MFP 100 relays the transfer of the first setting file 601 between the server 130 and the second MFP 120.
[0083] (Modification 2 of Embodiment 2) In the second embodiment, an example has been described in which the server 130 updates the first setting file 601 received from the second MFP 120 to generate a setting template for the second MFP 120 and distributes it to the second MFP 120. In contrast, in this modified example, an example will be described in which a setting template is distributed to the second MFP 120 without using the first setting file 601.
[0084] For example, as in the case shown in Modification 2 of Embodiment 1, server 130 uses setting template selection table 901 such as that shown in FIG. 9 to select an optimal setting template for second MFP 120 from among the setting templates stored in advance by setting template generation unit 1003. That is, setting template selection table 901 is referenced based on the identification information (such as a model ID) of second MFP 120 and the determination result of the installation environment, and an optimal setting template is selected. Then, setting template transmission unit 343 transmits the selected setting template to second MFP 120. The second MFP 120 can perform settings optimal for the installation environment by having setting template application unit 363 apply the setting template received by setting template reception unit 362.
[0085] In this way, the server 130 distributes the setting template for the second MFP 120 without using the first setting file 601.
[0086] (Other variations) In the above-described embodiment, an example was given in which the first MFP 100 generates and distributes a setting template to the second MFP 120, which is a different model from the first MFP 100. However, the target for generating and distributing a setting template may also be the same model as the first MFP 100. In other words, the first MFP 100 has functions similar to the setting file transmission unit 360, setting update processing control unit 361, setting template reception unit 362, and setting template application unit 363 of the second MFP 120. This enables the generation and distribution of setting templates between the first MFP 100 and a second MFP of the same model.
[0087] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0088] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0089] 100: MFP, 120: MFP, 130: External server
Claims
1. An information processing system including a first information processing device and a second information processing device, The first information processing device a collection means for collecting information on the surrounding environment of the first information processing device; a determination means for determining an installation environment of the first information processing device based on the information; a detection means for detecting the second information processing device that is present in the same installation environment as the installation environment; a generation unit that generates a setting template for setting the second information processing device based on the installation environment; a transmitting means for transmitting the setting template to the second information processing device; Equipped with The second information processing device a receiving means for receiving the setting template; an application unit that applies the setting template received by the receiving unit to the second information processing device; An information processing system comprising:
2. The first information processing device The information processing system according to claim 1 , further comprising: an application unit that applies a setting to the first information processing apparatus based on the installation environment.
3. 3. The information processing system according to claim 1, wherein the setting template is a setting template related to security.
4. An information processing system according to any one of claims 1 to 3, characterized in that the detection means of the first information processing device detects a device of the same model or of the same vendor and system as the first information processing device as the second information processing device.
5. 4. The information processing system according to claim 1, wherein the detecting means detects the second information processing apparatus that exists in the same installation environment as the installation environment of the first information processing apparatus.
6. The detecting means of the first information processing device transmitting a broadcast requesting a MAC address to devices existing on the same network as the first information processing device; The second information processing device is detected by checking the vendor information and model ID of the received MAC address.
6. The information processing system according to claim 5.
7. The first information processing device a setting file receiving means for receiving, from the second information processing device, a first setting file in which setting items of the second information processing device are described; a file generating means for generating a second setting file in which setting items of the first information processing device are described; The information processing system according to any one of claims 1 to 6, characterized in that the generation means of the first information processing device generates the setting template by copying the setting values of the second setting file to the first setting file for the same setting item.
8. the information about the surrounding environment includes information about other information processing devices; 8. The information processing system according to claim 1, wherein the generation means of the first information processing device generates the setting template for setting the second information processing device further based on information about the second information processing device.
9. The information processing system of any one of claims 1 to 7, characterized in that the generation means of the first information processing device generates the setting template for setting the second information processing device by selecting a setting template suitable for the second information processing device from a plurality of setting templates based on information about the surrounding environment and identification information of the second information processing device.
10. The information processing system according to any one of claims 1 to 9, characterized in that the application means of the second information processing device applies the setting template when the first information processing device is a device that has been pre-registered or is a device that has been authenticated by the second information processing device.
11. An information processing system including a first information processing device, a second information processing device, and a server device, The first information processing device a collection means for collecting environmental information indicating a surrounding environment of the first information processing device; a detection means for detecting the second information processing device; a transmitting means for transmitting the environmental information and the identification information of the second information processing device to the server device; Equipped with The server device a receiving means for receiving the environmental information and the identification information; a determination unit that determines an installation environment of the first information processing device based on the environmental information; a generating means for generating a setting template for setting the second information processing device when the second information processing device is in the same environment as the installation environment, based on the installation environment and the identification information; a transmitting means for transmitting the setting template to the second information processing device; Equipped with The second information processing device a receiving means for receiving the setting template; an application unit that applies the setting template received by the receiving unit to the second information processing device; An information processing system comprising:
12. the transmitting means of the server device transmits the setting template to the first information processing device when the setting template cannot be transmitted to the second information processing device; The first information processing device further comprising a receiving means for receiving the setting template from the server device, 12. The information processing system according to claim 11, wherein the transmitting means of the first information processing apparatus transmits the setting template received from the server apparatus to the second information processing apparatus.
13. The information processing system according to claim 11 or 12, characterized in that the generation means of the server device generates the setting template for setting the second information processing device by selecting a setting template suitable for the second information processing device from among a plurality of setting templates based on the installation environment and the identification information.
14. 14. The information processing system according to claim 1, wherein the first information processing apparatus and the second information processing apparatus are image forming apparatuses.
15. An information processing device, a collection means for collecting information on the surrounding environment of the information processing device; a determination means for determining an installation environment of the information processing device based on the information; a detection means for detecting other information processing devices; a generation means for generating, based on the installation environment, a setting template for setting the other information processing device when the other information processing device is in the same environment as the installation environment; a transmitting means for transmitting the setting template to the other information processing device; An information processing device comprising:
16. A server device that communicates with a first information processing device and a second information processing device, a receiving means for receiving environmental information indicating a surrounding environment of the first information processing device and identification information of the second information processing device; a determination unit that determines an installation environment of the first information processing device based on the environmental information; a generating means for generating a setting template for setting the second information processing device when the second information processing device is in the same environment as the installation environment, based on the installation environment and the identification information; a transmitting means for transmitting the setting template to the second information processing device; A server device comprising:
17. A control method for an information processing device, comprising: a collection step of collecting information about the surrounding environment of the information processing device; a determination step of determining an installation environment of the information processing device based on the information; a detection step of detecting other information processing devices; a generation step of generating, based on the installation environment, a setting template for setting the other information processing device when the other information processing device is in the same environment as the installation environment; a transmitting step of transmitting the setting template to the other information processing device; 1. A method for controlling an information processing device, comprising:
18. A method for controlling a server device that communicates with a first information processing device and a second information processing device, comprising: a receiving step of receiving environmental information indicating a surrounding environment of the first information processing device and identification information of the second information processing device; a determining step of determining an installation environment of the first information processing apparatus based on the environmental information; a generating step of generating, based on the installation environment and the identification information, a setting template for setting the second information processing device when the second information processing device is in the same environment as the installation environment; a transmitting step of transmitting the setting template to the second information processing device; 10. A method for controlling a server device, comprising:
19. A program for causing a computer to execute the control method according to claim 17 or 18.
Citation Information
Patent Citations
Image formation device and image forming system
JP2008049581A
Printer settings customization mechanism
JP2011123892A
Image forming apparatus, processing method thereof, and program
JP2012104920A
Image processing device, distribution system, setting value reflection method, and computer program
JP2014192841A
Information processing device, apparatuses, apparatus management system, and program
JP2015049824A