Image processing device, control method and program

The image processing device ensures that copied images retain protection by adding encrypted data and decryption keys, preventing unauthorized access to sensitive areas.

JP7799430B2Active Publication Date: 2026-01-15CANON KK
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021174069
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-25
Publication Date
2026-01-15
Estimated Expiration
2041-10-25

AI Technical Summary

Technical Problem

Existing image processing technologies fail to ensure that a screenshot or copied image retains the same protection as the original image, allowing unauthorized users to view sensitive information if the image is saved.

Method used

An image processing device that adds protection information, such as encrypted data and decryption keys, to a copied image, ensuring that protected areas remain obscured unless the user has the necessary viewing authority.

Benefits of technology

The solution effectively maintains the protection of sensitive information in copied images, preventing unauthorized access even if the image is redistributed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007799430000001
    Figure 0007799430000001
  • Figure 0007799430000002
    Figure 0007799430000002
  • Figure 0007799430000003
    Figure 0007799430000003
Patent Text Reader

Abstract

To achieve a technique that, when creating a new image from an original image and storing the new image, can protect the newly stored image in the same way as the original image.SOLUTION: An image processing apparatus has: image processing means that creates an image to be stored; and a control means that controls the image processing means in response to an instruction to create a second image from a first image and store the created image. When storing the second image in response to the instruction, the image processing means adds, to the second image, protection information recorded in the first image and for protecting at least part of the image, and stores the protection information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an image processing technique for storing or displaying images whose viewing is restricted. [Background technology]

[0002] Conventionally, there have been techniques for masking parts of images using mosaic processing or the like from the viewpoint of privacy protection. Patent Document 1 describes a medical image system that masks the protected parts from a screenshot and attaches it to an email. However, if an image is permanently masked, it becomes necessary to switch between images provided to users who should not be able to view it and images provided to users who are allowed to view it.

[0003] Therefore, Non-Patent Document 1 proposes a technology in which an image with the mask removed is displayed to users who have viewing authority, and an image in which the protected portion is replaced with another image is displayed to users who do not have viewing authority. Patent Document 2 describes a technology in which specific information is added to image data and the specific information is erased when the image data is resaved, making it possible to determine whether the image data has been resaved or remains the original image data. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 5993575 [Patent Document 2] Patent No. 4209128 [Non-patent literature]

[0005] [Non-Patent Document 1] ISO / IEC 19566-4 Summary of the Invention [Problem to be solved by the invention]

[0006] However, if a user with viewing authority is viewing an unmasked image and takes and saves an image of the screen (screenshot image), the unmasked image will be saved, which could result in the redistribution of an image viewable by a user without viewing authority.

[0007] The present invention has been made in consideration of the above-mentioned problems, and its purpose is to realize a technology that, when a new image is generated from an original image and saved, enables the newly saved image to be protected in the same way as the original image. [Means for solving the problem]

[0008] In order to solve the above problems and achieve the object, an image processing device of the present invention has an image processing means that generates an image to be saved, and a control means that controls the image processing means in response to an instruction to generate a second image from a first image and save the second image, wherein the image processing means: The image processing device includes a protection information determination means for determining whether protection information for protecting at least a part of the first image is recorded in the first image when the second image is saved in response to the instruction, and a protection information storage means for adding the protection information determined by the protection information determination means to be recorded in the first image to the second image and saving the image, wherein the second image includes an image that has been processed so that a protection area included in at least a part of the first image cannot be viewed, and the protection information includes at least data in which the image in the protection area is encrypted and data indicating a position to restore the image in the protection area decrypted for the second image. .

[0009] The image processing device of the present invention has an image processing means for generating an image to be displayed, and a control means for controlling the image processing means in response to an instruction to display an image, and the image processing means has a protection information determination means for determining whether protection information for protecting at least a part of the image is recorded in the image to be displayed, and a viewing authority determination means for determining whether a user has viewing authority for the image to be displayed. The protection information includes at least encrypted data of an image in a protected area included in at least a part of the image to be displayed, and data indicating a position where the decrypted image in the protected area is to be restored relative to the image to be displayed. The viewing authority determination means determines whether or not the user has the viewing authority based on the presence or absence of information for decrypting the encrypted data. . [Effects of the Invention]

[0010] According to the present invention, when a new image is generated from an original image and saved, the newly saved image can be protected in the same way as the original image. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram showing the configuration of an apparatus according to a first embodiment. [Figure 2] 10 is a flowchart showing image saving processing according to the first embodiment. [Figure 3] FIG. 4 is an explanatory diagram of an image saving instruction according to the first embodiment. [Figure 4] FIG. 2 is a data structure diagram of image information according to the first embodiment. [Figure 5] FIG. 10 is a block diagram showing the configuration of an apparatus according to a second embodiment. [Figure 6] FIG. 10 is an explanatory diagram of a display image according to the second embodiment. [Figure 7] 10 is a flowchart showing image display processing and image saving processing according to the second embodiment. [Figure 8] FIG. 10 is an explanatory diagram of an image generation instruction according to the second embodiment. [Figure 9] FIG. 11 is an explanatory diagram of a method for updating image information and protection information according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.

[0013] Below, we will explain an embodiment in which the image processing device of the present invention is applied to an information processing device such as a personal computer (PC), or an information processing terminal such as a smart device or tablet PC, but it is not limited to this and may also be applied to an imaging device such as a digital camera that can capture images.

[0014] [Embodiment 1] In embodiment 1, when a screenshot or image of a display screen is copied and saved as new image information, if the original image information contains protection information to protect at least a portion of the image from being viewed, an example of a configuration is described in which the newly saved image information can also be saved with the protection information attached.

[0015] <Device Configuration> First, the configuration and functions of the image processing device of this embodiment will be described with reference to FIG.

[0016] FIG. 1 is a block diagram showing the configuration of an image processing apparatus according to this embodiment.

[0017] The image processing device 101 includes a control unit 102 , a memory 103 , a storage unit 104 , an operation unit 105 , a display unit 106 , an image processing unit 107 , a communication unit 108 , and a bus 109 .

[0018] The control unit 102 includes an arithmetic processor such as a CPU or an MPU that controls the entire image processing device 101. The control unit 102 executes a program stored in a storage unit 104, which will be described later, to realize processing of the embodiment, which will be described later.

[0019] The memory 103 is a RAM or the like used as a working area for expanding constants and variables for the operation of the control unit 102, programs read from the storage unit 104, etc. The memory 103 is also used as a buffer memory for temporarily storing data and commands (instructions) to be output to the control unit 102.

[0020] The storage unit 104 is a ROM, memory card, hard disk, etc. that stores an OS (operating system), which is basic software executed by the control unit 102, and applications that work with the OS to realize applied functions. The storage unit 104 stores programs that cause the control unit 102 to execute the processes of the first and second embodiments, which will be described later.

[0021] The operation unit 105 is an operation member such as a mouse or keyboard that accepts user operations and outputs various instructions to the control unit 102. The operation unit 105 is also formed integrally with the display unit 106 and includes a touch panel for operating images, UI screens, etc.

[0022] The display unit 106 is a display device such as a monitor or a display configured with an LCD or organic EL. The display unit 106 displays images held by the image processing device 101, and web pages and images received via a network by a communication unit 108 (described later). The display unit 106 also displays a UI screen for interactive operations.

[0023] The image processing unit 107 includes a GPU that executes processes such as image transformation, image color conversion, image composition, and reading / writing additional information (metadata) recorded in image information files. The image processing unit 107 executes a process of generating image information from a web page or image displayed on the display unit 106.

[0024] The image processing unit 107 includes a protection information determination unit 110 and a protection information storage unit 111. The protection information determination unit 110 determines whether protection information is recorded in the image information to be stored. The protection information storage unit 111 adds the protection information recorded in the image information to be stored to the image information to be newly stored and stores the added information.

[0025] In this embodiment, the image information to be saved is the original image information used to generate a screenshot image or a duplicate image.

[0026] The protection information is information for protecting a protection area included in at least a part of the image information to be saved from being viewed by applying a masking process or the like. The protection area is a person's face or confidential information included in the image, and in the case of a screenshot image, multiple images are displayed on one screen, so there may be multiple protection areas. . Protection The protection information includes encrypted data of the image in the protection area and coordinate data indicating the position where the decrypted image is restored relative to the masked image of the protection area, as will be described later in Fig. 6. The protection information is recorded as metadata in the image information or as a metadata file separate from the image information.

[0027] Key information is required to decrypt encrypted data included in the protected information. Therefore, the presence or absence of key information determines whether the protected area of ​​the image information to be saved or displayed can be viewed or not. The key information may be included in the protected information, but in order to restrict viewing by users without viewing authority, as will be described later in the second embodiment, it is desirable that the key information be managed separately from the protected information and obtained from an external source via a network or the like.

[0028] The communication unit 108 is an interface that connects to a network such as the Internet or a LAN (Local Area Network) so as to be able to communicate with the network.

[0029] A bus 109 connects the components 102 to 108 of the image processing device 101 so that data can be exchanged.

[0030] <Image Saving Process> Next, the image saving process of this embodiment will be described with reference to FIG.

[0031] FIG. 2 is a flowchart showing the image saving process of this embodiment.

[0032] 2 is realized by the control unit 102 of the image processing device 101 executing a program stored in the storage unit 104 and controlling each component of the image processing device 101. The process in FIG. 2 is started when a user operates the operation unit 105 to input a screenshot instruction or a copy instruction to the control unit 102 while a web page or image is displayed on the display unit 106 of the image processing device 101.

[0033] In the following description, it is assumed that the image information to be saved may or may not have protection information recorded thereon.

[0034] In step S201, when operation unit 105 accepts an image save instruction, control unit 102 generates image information to be saved from the image displayed on display unit 106, and waits until control unit 102 is ready to perform image save processing, holding the image information to be saved and the image save instruction in memory 103. When control unit 102 is ready to perform image save processing, control unit 102 outputs the image information to be saved and the image save instruction to image processing unit 107.

[0035] Fig. 4 is a data structure diagram of image information. As shown in Fig. 4, image information 401 includes metadata 402 and image data 403. Protection information 402a is recorded in the metadata 402. The image information 401 may include only an image file containing image data 403, and may also include a metadata file containing metadata 402 as a separate file.

[0036] In this embodiment, there is no limitation on the format of the metadata, and any format capable of recording protection information may be used, such as Exif. The image data 403 is pixel data, but depending on the file format, it may be spatial frequency converted data or compressed or encrypted data. In this embodiment, the image data 403 may be saved in any file format. It may also be a file format that includes metadata, such as JPEG or TIFF. Even in file formats that do not include metadata that records protection information, such as bitmap or RAW, a metadata file that records protection information as a separate file may also be used.

[0037] In step S202, when the image processing unit 107 receives image information to be saved and an image saving instruction from the control unit 102, the protected information determination unit 110 determines whether protected information is recorded in the image information to be saved. If the protected information determination unit 110 determines that protected information is recorded in the information to be saved, the process proceeds to S203. If the protected information determination unit 110 determines that protected information is not recorded in the image information to be saved, the process proceeds to S204.

[0038] In step S203, the protection information storage unit 111 adds the protection information determined in S202 to the image information to be newly stored. Thereafter, the image processing unit 107 outputs the image information to be newly stored with the protection information added thereto to the storage unit 104. Here, the image processing unit 107 may output an image storage completion notification to the control unit 102.

[0039] In step S204, the storage unit 104 stores the image information acquired from the image processing unit 107 to be newly stored.

[0040] It is assumed that image information is saved by recording a file of image information 401 in a predetermined location in the file system, but in a system that is constantly running or in a system that does not need to permanently store screenshot images or duplicate images, it is possible to record the image information 401 in memory unit 104 rather than recording it as a file, and then read it out from memory unit 104 and use it as needed.

[0041] Note that the timing at which image processing unit 107 outputs the image storage completion notification to control unit 102 may be after the processing of step S204. In this case, when storage unit 104 stores the image information to be newly stored, it outputs the image storage completion notification to image processing unit 107. When image processing unit 107 receives the image storage completion notification, it outputs the image storage completion notification to control unit 102. Alternatively, image processing unit 107 may not output the image storage completion notification to control unit 102, but may output the image storage completion notification to control unit 102 after storage unit 104 stores the image information to be newly stored.

[0042] Note that the format of image save instructions may vary. numberThe following patterns are possible. FIG. 3 is a diagram illustrating three examples of patterns. In FIG. 3, UI 301 is a UI screen displayed on the display unit 106. OS 302 and application 303 are software executed by the image processing device 101. Possible modes of transmitting and receiving an image save instruction include the modes shown in FIGS. 3(a) to 3(c). FIG. 3(a) shows a mode in which UI 301 outputs an image save instruction to OS 302, and image information is saved as a function of OS 302. FIG. 3(b) shows a mode in which UI 301 issues an image save instruction to OS 302, and OS 302 issues an image save instruction to application 303, and image information is saved as a function of application 303. FIG. 3(c) shows a mode in which UI 301 issues an image save instruction to application 303, and image information is saved as a function of application 303.

[0043] In the pattern of Fig. 3(a), it is conceivable that the OS 302 inputs an image save instruction in step S201 and executes the processing from step S202 onwards. In the pattern of Fig. 3(b), it is conceivable that the OS 302 inputs an image save instruction in step S201 and outputs the image save instruction to the application 303. Thereafter, it is conceivable that the application 303 inputs an image save instruction and executes the processing from step S202 onwards, and thereafter the application 303 outputs an image save instruction completion notification to the OS 302. In the pattern of Fig. 3(c), it is conceivable that the application 303 inputs an image save instruction in step S201 and executes the processing from step S202 onwards.

[0044] As a detailed example of the patterns in Figures 3(b) and 3(c), there are cases where the application 303 has an image display function, and cases where the application 303 does not have an image display function and only saves a screenshot image of the display screen.

[0045] In the image saving process of this embodiment, if protection information is added to newly saved image information, the protected area is masked so that it cannot be viewed. Key information is required to make the protected area viewable. Therefore, even if the newly saved image information is redistributed, the protected area can be protected so that it cannot be viewed.

[0046] As described above, according to this embodiment, when a new image is generated from an image to which protection information has been added and saved, the protection information is added to the newly saved image and saved, thereby making it possible to protect the newly saved image in the same way as the original image.

[0047] [Second embodiment] Next, a second embodiment will be described with reference to FIG.

[0048] In the second embodiment, an example of a configuration for controlling whether the protected area of ​​the image information to be displayed is viewable or not depending on whether the user has viewing authority, and a configuration for controlling whether protection information is added to the image information to be saved and saved, will be described.

[0049] In the image processing device 501 of the second embodiment, in addition to the configuration of the first embodiment shown in Fig. 1, the image processing unit 107 includes a viewing authority determination unit 502. The other configuration is the same as the configuration of the first embodiment shown in Fig. 1.

[0050] The protection information determination unit 110 determines whether protection information is recorded in the image information to be saved or the image information to be displayed. The protection information saving unit 111 adds the protection information recorded in the image information to be saved to the image information to be newly saved and saves it. Furthermore, the image processing unit 107 generates a display image in which a mask process is performed on the newly displayed image information so that the protected area cannot be viewed, based on the protection information recorded in the image information to be displayed.

[0051] In this embodiment, the image information to be displayed includes images held by the image processing device 501, web pages and images received via the network by the communication unit 108, and screenshot images and duplicate images saved by the image saving process of embodiment 1, and is the original image information used to generate the display image. Also, the image information to be saved is the original image information used to generate the screenshot images and duplicate images. Protection information will be described later with reference to FIG. 6.

[0052] In the following description, it is assumed that the image information to be displayed may or may not have protected information recorded thereon, and further that the user may or may not have key information for viewing the protected information of the image information to be displayed.

[0053] <Image Display Processing> First, with reference to FIG. 7(a), a process for controlling whether the protected area of ​​the image information to be displayed is viewable or not will be described depending on whether the user has viewing authority.

[0054] FIG. 7A is a flowchart showing the image display process of this embodiment.

[0055] The process in Fig. 7(a) is realized by the control unit 102 of the image processing device 501 executing a program stored in the storage unit 104 and controlling each component of the image processing device 501. The process in Fig. 7(a) is started when a user operates the operation unit 105 to input an instruction to the control unit 102 to display image information on the display unit 106.

[0056] In step S701, the control unit 102 reads out image information to be displayed, and waits until the control unit 102 is ready to perform image display processing, holding the image information to be displayed and an image generation instruction in the memory 103. When the control unit 102 is ready to perform image display processing, the control unit 102 outputs the image information to be displayed and an image generation instruction to the image processing unit 107. Note that the storage unit 104 may store image information acquired from outside via a network.

[0057] In step S702, when the image processing unit 107 receives image information to be displayed and an image generation instruction from the control unit 102, the protected information determination unit 110 determines whether protected information is recorded in the image information to be displayed. If the protected information determination unit 110 determines that protected information is recorded in the image information to be displayed, the process proceeds to S703. If the protected information determination unit 110 determines that protected information is not recorded in the image information to be displayed, the process proceeds to S705.

[0058] In step S703, the viewing authority determination unit 502 determines whether the user has viewing authority for the image information to be displayed. If the viewing authority determination unit 502 determines that the user has viewing authority for the image information to be displayed, the process proceeds to S704. If the viewing authority determination unit 502 determines that the user does not have viewing authority for the image information to be displayed, the process proceeds to S705. In order to determine whether viewing is restricted, for example, the image processing device 501 may determine whether it has key information for the protection information recorded in the image information to be displayed. Note that the key information may be obtained from an external source via a network or the like and stored in the storage unit 104 of the image processing device 501, or may be obtained via the network at the timing when determining whether or not the user has viewing authority.

[0059] In step S704, the image processing unit 107 generates a display image that makes the protected area of ​​the image information to be displayed viewable based on the protection information recorded in the image information to be displayed, and proceeds to step S706.

[0060] In step S705, the image processing unit 107 generates a display image in which the protected area of ​​the image information to be displayed is made unviewable, and the process proceeds to step S706.

[0061] FIG. 6 is an explanatory diagram of a display image according to this embodiment.

[0062] Assume that the image information to be displayed is an image in which the protected area 601 is prohibited from being viewed, as shown in Fig. 6(b). In this case, if protection information is recorded in the image information to be displayed or if the user has permission to view it, the encrypted image information in the protected area 601 in Fig. 6(c) is decrypted using key information to restore the image in Fig. 6(b), i.e., an image in which the protected area 601 is prohibited from being viewed, as shown in Fig. 6(a). On the other hand, if protection information is not recorded in the image information to be displayed or if the user does not have permission to view it, the image in Fig. 6(b), i.e., an image in which the protected area 601 in Fig. 6(a) is prohibited from being viewed, is generated.

[0063] In this embodiment, the metadata 402 of the image information 401 in Fig. 4 records, as protection information, image information in which the image in the protected area 601 in Fig. 6(c) is encrypted, key information for decrypting the encrypted image in the protected area 601 in Fig. 6(c), and coordinate data indicating the position at which the image in the protected area 601 in Fig. 6(c) is restored after decryption of the image in which the protected area 601 has been masked as shown in Fig. 6(b). Note that the key information does not have to be recorded in the metadata 402, and may be held by the image processing device 501 or obtained from an external device via a network as long as it can be obtained at the time of decryption.

[0064] For example, if the image of the protected area 601 in Fig. 6(c) is rectangular and contains metadata describing the size of the image, the coordinate data may be coordinate information indicating the coordinates (X, Y) of the upper left point. If the metadata describing the size of the image in Fig. 6(c) is not included or if the image is to be decoded at a size different from that described in the metadata of the image in Fig. 6(c), in addition to the coordinate information indicating the coordinates (X, Y) of the upper left point, coordinate data for the width W and height H are also recorded in the metadata. When restoring the image in Fig. 6(a), this coordinate data is used.

[0065] In step S706, image processing unit 107 outputs the display image generated in step S704 or S705 and an image generation completion notification to control unit 102. When control unit 102 receives the image generation completion notification from image processing unit 107, it outputs the display image to display unit 106. Display unit 106 displays the display image received from control unit 102.

[0066] In the image display processing of this embodiment, if protection information is recorded in the image information to be displayed or if the user has viewing authority, the protection area is displayed as viewable, but if protection information is not recorded in the image information to be displayed or if the user does not have viewing authority, the protection area is displayed as not viewable.

[0067] In the present embodiment, an example of a configuration has been described in which whether the protected area of ​​the image information to be displayed is viewable or not is controlled depending on whether the user has a viewing authority, but the present invention is not limited to this. For example, even when the image information is displayed on a display device other than the image processing device 501 of the present embodiment, the image of FIG. 6(c) is encrypted and recorded in the metadata 402 as protection information for the image information to be displayed, and therefore the image of FIG. 6(b) can be displayed as the displayed image. In this way, even when the image information is displayed on a display device other than the image processing device 501 of the present embodiment, if the user does not have a viewing authority for the image information to be displayed, the protected area can be displayed so as not to be viewable, as in the image of FIG. 6(b).

[0068] Note that the format of image generation instructions is various. numberThe following patterns are possible. Figure 8 is a diagram explaining three example patterns. The image generation instruction can be transmitted and received in the following forms: (a) to (c) of Figure 8. Figure 8(a) is a form in which UI301 outputs an image generation instruction to OS302, and the OS302 controls the viewing restriction as a function of the OS302 to generate a display image. Figure 8(b) is a form in which UI301 outputs an image generation instruction to OS302, and OS302 outputs an image generation instruction to application 803, and the application 803 controls the viewing restriction as a function of the application 803 to generate a display image. Figure 8(c) is a form in which UI301 outputs an image generation instruction to application 803, and the application 803 controls the viewing restriction as a function of the application 803 to generate a display image.

[0069] As described above, according to the image display process of this embodiment, it is possible to control whether the protected area of ​​the image information to be displayed is viewable or not.

[0070] Furthermore, in this embodiment, it is also possible to control whether or not protection information is added to image information to be saved and then saved, depending on whether or not the user has the viewing authority.

[0071] <Image Saving Process> Next, with reference to FIG. 7(b), a process for controlling whether or not to add protection information to image information to be saved and save it, depending on whether or not the user has the viewing authority, will be described.

[0072] FIG. 7B is a flowchart showing the image saving process of this embodiment.

[0073] The process in Fig. 7(b) is realized by the control unit 102 of the image processing device 501 executing a program stored in the storage unit 104 and controlling each component of the image processing device 501. The process in Fig. 7(b) is started when the user operates the operation unit 105 to input a screenshot instruction or a copy instruction to the control unit 102 while image information to be displayed, such as a web page or a reproduced image, is displayed on the display unit 106 of the image processing device 501.

[0074] Steps S711 and S712 are similar to steps S201 and S202 in FIG.

[0075] In step S712, if the protection information determination unit 110 determines that protection information is recorded in the image information to be saved, the process proceeds to S713. If the protection information determination unit 110 determines that protection information is not recorded in the image information to be saved, the process proceeds to S714. 5 Proceed to next step.

[0076] In step S713, the viewing authority determination unit 502 determines whether the user has viewing authority for the image information to be saved. If the viewing authority determination unit 502 determines that the user has viewing authority for the image information to be saved, the process proceeds to S714. If the viewing authority determination unit 502 determines that the user does not have viewing authority for the image information to be saved, the process proceeds to S715.

[0077] Steps S714 and S715 perform the same processing as steps S203 and S204 in FIG.

[0078] In the image saving process of this embodiment, protection information is recorded in the image information to be saved, and if the user has permission to view the image information to be saved, the newly saved image information is masked so that the protected area 601 cannot be viewed, as shown in Figure 6(b). Key information is required to make the protected area viewable. Therefore, even if the newly saved image information is redistributed, the protected area can be protected so that it cannot be viewed.

[0079] Furthermore, if no protection information is recorded in the image information to be saved or if the user does not have the authority to view the image information to be saved, there is no need to add protection information to the newly saved image information, and therefore only image information that has been masked so that the protected area 601 cannot be viewed is saved, as shown in Figure 6(b).

[0080] In this way, according to the image saving process of this embodiment, it is possible to control whether or not to add protection information to image information to be saved and save it, depending on whether or not the user has the viewing authority.

[0081] Note that the timing at which image processing unit 107 outputs the image save completion notification to control unit 102 may be after the processing of step S715. In this case, when control unit 102 outputs the image save completion notification to display unit 106, image processing unit 107 outputs the image save completion notification to control unit 102. Alternatively, image processing unit 107 may not output the image save completion notification to control unit 102, but may output the image save completion notification to control unit 102 after display unit 106 displays the image.

[0082] Although the application 303 in FIGS. 3(b) and 3(c) and the application 803 in FIGS. 8(b) and 8(c) are logically different applications, they may be the same application.

[0083] [Third Embodiment] Next, a third embodiment will be described with reference to FIG.

[0084] In the third embodiment, an example will be described in which, when image information to be saved is not displayed in the original image size, the protection information of the image information to be saved is updated and displayed.

[0085] In this embodiment, when protection information is added to newly saved image information in step S203 of FIG. 2 and step S714 of FIG. 7(b), the protection information included in the metadata 402 is updated and the updated protection information is added.

[0086] The metadata 402 of the image information 401 records, as protection information, the encrypted image of Fig. 6(c), key information used to decrypt the encrypted image of Fig. 6(c), and coordinate data indicating the position where the image of Fig. 6(c) is restored in the image of Fig. 6(b). For example, if the image of Fig. 6(c) is a rectangular image, the coordinate data may be coordinate information indicating the coordinates (X, Y) of the upper left point.

[0087] However, as shown in FIGS. 8(b) and 8(c), when an image generated as a function of application 803 is displayed, the displayed image is not necessarily displayed in the original image size as in FIG. 6(a) or 6(b), as shown in FIG. 9. In this case, the image information to be saved (screenshot image) will be saved in a size different from the original image size. The display position of the image will also be offset (X0, Y0) from the entire original image. Furthermore, the image obtained by decrypting the encrypted image of FIG. 6(c) will no longer have the dimensions of width W and height H. Furthermore, when the encrypted image of FIG. 6(c) is decrypted and restored to the image of FIG. 6(b), it must be restored to a position different from the coordinates (X, Y) of the image of FIG. 6(b), which is the protection information before the update.

[0088] Therefore, in this embodiment, when protection information is added to image information to be newly saved in step S203 of FIG. 2, the display size of the image information to be saved is acquired, and the scales in the horizontal and vertical directions of the screen are calculated from the acquired display size and the size of the original image information (image information to be saved before the display size is changed). The width W' and height H', which are the display size of the image in FIG. 6(c), which is the protection information before updating, are calculated from the image size, width W, height H, and the acquired scale. In addition, the width W' and height H' are calculated from the image position in FIG. 6(a) or FIG. 6(b). Rao The coordinates (X', Y') of the image information to be saved after the update are calculated from the coordinates (X0, Y0) of the offset position, the coordinates (X, Y) of the image in Figure 6(b), which is the protected information before the update, and the obtained scale.

[0089] Using the information obtained as described above as updated protection information, the encrypted image of Fig. 6(c), key information used to decrypt the encrypted image of Fig. 6(c), and coordinate data indicating the position where the image of Fig. 6(c) is restored in the image of Fig. 9 are added to the metadata 402 of the image information to be newly saved. The coordinate data includes coordinate information indicating the coordinates (X', Y') of the upper left point, as well as the width W' and height H'.

[0090] According to this embodiment, when the display image is not displayed in the original image size, the protection information of the image information to be newly saved can be updated to match the display image and saved.

[0091] [Other embodiments] The present invention can also be realized by supplying a program that realizes one or more functions of each embodiment to a system or device via a network or storage medium, and having one or more processors in the computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0092] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]

[0093] 101, 501... image processing device, 102... control unit, 103... memory, 104... storage unit, 105... operation unit, 106... display unit, 107... image processing unit, 108... communication unit, 110... protected information determination unit, 111... protected information storage unit, 502... viewing authority determination unit

Claims

1. image processing means for generating an image to be saved; a control means for controlling the image processing means in response to an instruction to generate a second image from a first image and store the second image; The image processing means a protection information determination means for determining whether protection information for protecting at least a part of the first image is recorded in the first image when the second image is to be saved in accordance with the instruction; a protection information storage means for adding the protection information determined by the protection information determination means to be recorded in the first image to the second image and storing the added protection information; the second image includes an image that has been processed so that a protected area included in at least a part of the first image cannot be viewed; An image processing device characterized in that the protection information records at least data in which the image of the protected area is encrypted and data indicating the position to restore the image of the protected area decrypted for the second image.

2. the image processing means includes a viewing authority determination means for determining whether or not a user has a viewing authority for the first image; 2. The image processing device according to claim 1, wherein, when the viewing authority determination means determines that the user does not have the viewing authority, the protection information storage means stores the second image without adding the protection information to it.

3. 3. The image processing apparatus according to claim 2, wherein the viewing authority determining means determines whether the user has the viewing authority based on the presence or absence of information for decrypting the encrypted data.

4. An image processing device as described in any one of claims 1 to 3, characterized in that the image processing means updates the size of the image of the protection area in the protection information to be added to the second image and data indicating the position at which the image of the protection area is to be restored relative to the second image based on the size of the first image and the size at which the first image is displayed.

5. 5. The image processing device according to claim 1, wherein the second image is a screenshot image or a duplicate image of the first image.

6. image processing means for generating an image to be displayed; a control means for controlling the image processing means in response to an instruction to display an image, The image processing means a protection information determination means for determining whether protection information for protecting at least a part of the image is recorded in the image to be displayed; a viewing authority determination means for determining whether or not a user has a viewing authority for the image to be displayed, the protection information includes at least encrypted data of an image of a protection area included in at least a part of the image to be displayed, and data indicating a position where the image of the protection area decrypted with respect to the image to be displayed is to be restored; The image processing apparatus according to claim 1, wherein the viewing authority determining means determines whether the user has the viewing authority based on the presence or absence of information for decrypting the encrypted data.

7. the image processing means generates an image in which a protected area of ​​the image to be displayed is viewable when the protected information determination means determines that the protected information is recorded in the image to be displayed and when the viewing authority determination means determines that the user has the viewing authority; The image processing device described in claim 6, characterized in that if the protection information determination means determines that the protection information is not recorded in the image to be displayed or if the viewing authority determination means determines that the user does not have the viewing authority, an image is generated in which the protected area of ​​the image to be displayed is not viewable.

8. A control method for an image processing device, comprising: receiving an instruction to generate and store a second image from the first image; a step of determining whether protection information for protecting at least a part of the first image is recorded in the first image when the second image is to be saved in accordance with the instruction; adding the protection information determined to be recorded in the first image to the second image and storing the second image; the second image includes an image that has been processed so that a protected area included in at least a part of the first image cannot be viewed; A control method characterized in that the protection information records at least data in which the image of the protected area is encrypted and data indicating the position to restore the image of the protected area decrypted for the second image.

9. A control method for an image processing device, comprising: an image processing step for generating an image to be displayed in response to an instruction to display the image; The image processing step includes: a first step of determining whether protection information for protecting at least a part of the image is recorded in the image to be displayed; a second step of determining whether the user has a viewing authority for the image to be displayed; the protection information includes at least encrypted data of an image of a protection area included in at least a part of the image to be displayed, and data indicating a position where the image of the protection area decrypted with respect to the image to be displayed is to be restored; In the second step, it is determined whether or not the user has the right to view the encrypted data based on whether or not information for decrypting the encrypted data is available.

10. A program for causing a computer to function as the control means and image processing means of the image processing apparatus according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • IEC19566-4

  • Gate valve

    JP1984093575A

  • Image forming device capable of constituting network system, image forming system, image forming method, and storage medium

    JP2001043058A

  • Image generation method and device, image output method and device, and program

    JP4209128B2

  • Information processing system, information processing method, terminal device, and information processing device

    WO2020049958A1