Image processing device and control method thereof, image processing system, and program
The image processing device addresses the challenge of secure data transmission by using a data inspection mechanism to verify and control scanned data transmission based on user authority and destination, enhancing security through flexible access control.
Patent Information
- Application Number
- JP2021187835
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-18
- Publication Date
- 2026-01-15
- Estimated Expiration
- 2041-11-18
AI Technical Summary
Existing image processing devices lack the capability to effectively verify and control the transmission of scanned data based on user authority and transmission destination, especially when data is sent to external destinations, and they fail to make flexible decisions regarding data access permissions.
An image processing device equipped with a data inspection mechanism that communicates with a system having a censorship function, performs character string extraction on scanned data, and determines transmission based on user authority and destination, using a cloud service for content inspection and flexible access control.
Enhances the effectiveness of preventing information leakage by allowing flexible decisions based on user authority and transmission destination, ensuring secure data transmission.
Smart Images

Figure 0007799447000001 
Figure 0007799447000002 
Figure 0007799447000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an image processing apparatus, a control method thereof, an image processing system, and a program. [Background technology]
[0002] In recent years, information leaks and attacks due to unauthorized operations have become a problem both inside and outside a company. In response to this situation, the security model is shifting from a boundary model where security is assured within the confines of a firewall to a zero trust model based on the idea that people are inherently evil.
[0003] Information processing devices, such as image forming devices, have a variety of functions, including the ability to send scanned data, fax, send stored documents, and send data to external storage and communication functions.Since the zero trust security model requires that everything be suspect, it is important to constantly verify that the data being exchanged will not lead to information leaks or be subject to unauthorized operations.
[0004] As a method for verifying scanned data and preventing unauthorized operations, a technology has been proposed that performs character string extraction (OCR) on scanned documents and checks (verifies) whether the extracted text matches pre-registered character strings and positions (Patent Document 1). This allows data verification to be performed with a smaller amount of memory than conventional image comparisons, and can prevent unauthorized copying of securities and the like.
[0005] In addition, a technology has been proposed that inspects data stored on an information disclosure server and determines whether to make it public or private based on the inspection results (Patent Document 2). This method makes it possible to appropriately keep private data that must not be made public, such as copyrighted material. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Publication No. 8-194412 [Patent Document 2] Japanese Patent Application Laid-Open No. 2010-266940 Summary of the Invention [Problem to be solved by the invention]
[0007] However, in the device of Patent Document 1, censorship is only performed when printing, copying, or other output is performed, and is not performed when the scanned data is sent to a destination. Furthermore, in the device of Patent Document 2, the decision is made based solely on the results of censorship, and it is not possible to determine whether the data should be made public or private, taking into account the permissions of the user viewing the data, making it difficult to appropriately restrict access.
[0008] The present invention has been made in consideration of at least some of the above-mentioned problems, and one object of the present invention is to provide a mechanism that enables an image processing device or an information processing device to utilize the censorship results even in images obtained by reading a display medium.
[0009] Another object of the present invention is to control a transmission job of a scanned image in accordance with the installation environment of the image processing apparatus and the user authority of the logged-in user, based on the result of inspection on the server. [Means for solving the problem]
[0010] The image processing device according to the present invention is an image processing device capable of communicating with a system having a censorship function, Manuscript Image obtained by reading data a first transmitting means for transmitting the a second transmitting means for transmitting the image data to a destination; receiving means for receiving a censorship result from the system; and based on the transmission destination , a given operation Run The present invention is characterized by having a means. [Effects of the Invention]
[0011] According to the present invention, it is possible to improve the effectiveness of preventing information leakage regarding the transmission of scan data to a transmission destination, and to make flexible decisions according to user authority and transmission destination. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a block diagram illustrating an example of an overall configuration of an information processing system. [Figure 2] FIG. 1 is a diagram illustrating an example of an overview of a censorship process. [Figure 3] FIG. 2 is a functional block diagram of a main controller. [Figure 4] FIG. 2 is a functional block diagram of a server device; [Figure 5] 10 is an example of a flowchart showing a scanning process and a data inspection process. [Figure 6] FIG. 10 is a diagram illustrating an example of an error screen. [Figure 7] 10 is an example of a flowchart illustrating a dictionary registration process. [Figure 8] FIG. 10 is a diagram illustrating an example of a censorship keyword input screen. [Figure 9] 10 is an example of a table used to determine whether transmission is permitted or not based on the inspection results. [Figure 10] 10 is an example of a flowchart illustrating a data inspection process. [Figure 11] 10 is an example of a flowchart illustrating a data inspection process. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0014] FIG. 1 is a block diagram showing the overall configuration of an information processing system including an information processing apparatus according to an embodiment of the present invention. An image forming apparatus 100 is shown as an example of this information processing apparatus, but is not limited to an image forming apparatus. The image forming apparatus 100 is, for example, an MFP (Multifunction Peripheral), an image processing apparatus, or a multifunction peripheral. FIG. 1 shows a block diagram showing the hardware of the image forming apparatus 100.
[0015] The information processing system is configured by an image forming apparatus 100 being communicably connected to a server apparatus 180 and a PC 190 via a LAN 160. The image forming apparatus 100 has a main controller 110, an operation unit 130, a printer unit 140, and a scanner unit 150.
[0016] In the main controller 110, the CPU 111 reads programs for the main controller 110 stored in the ROM 112 or flash memory 114 into the RAM 113 and executes them. The ROM 112 is a read-only memory that stores the boot program, BIOS, fixed parameters, etc. of the main controller 110. The RAM 113 is a random access memory that is used to store programs and temporary data when the CPU 111 controls the main controller 110. The flash memory 114 stores a loader, kernel, and applications. In addition to the executable program, the flash memory 114 also stores license information for enabling functions of the image forming apparatus 100, and signatures and public keys used to detect program tampering.
[0017] HDD 115 is a hard disk drive that stores some applications, various data, and print data received from PC 190 via network I / F 120. A print application program is included among the programs read from flash memory 114 and executed by CPU 111. This print application program converts the print data stored in HDD 115 into image data that can be printed by printer unit 140, and this image data is also stored in HDD 115.
[0018] Furthermore, the firmware read from the flash memory 114 and executed by the CPU 111 includes a scanning application program. This scanning application program causes the scanner unit 150 to read image data, and the read image data is transferred to the HDD 115. The read image data is then stored in the HDD 115. For example, image data is obtained by the scanner unit 150 scanning a sheet. An example of an image processing device is a smartphone with a built-in camera. Image data obtained by capturing an image of a sheet or the display unit of an electronic device with the camera can also be processed.
[0019] The operation section I / F 116 is an I / F (interface) for transmitting instructions input by the user of the image forming apparatus 100 via the operation section unit 130 to the CPU 111. The operation section I / F 116 also receives processing content for switching the content displayed on the operation section unit 130 from the CPU 111 and transmits it to the operation section unit 130. The operation section unit 130 includes a liquid crystal display unit with a touch panel function, a keyboard, and the like, and displays the status of the image forming apparatus 100 and an operation menu, and receives instructions from the user.
[0020] The printer I / F 117 is an interface for connecting the main controller 110 and the printer unit 140. Here, the printer unit 140 prints on a recording medium based on image data transferred from the HDD 115 via the printer I / F 117.
[0021] The scanner I / F 118 is an interface for connecting the main controller 110 and the scanner unit 150. Here, the scanner unit 150 (scanner section) reads an image on a document as image data using a line sensor configured with a CCD (Charge Coupled Device) or the like. The scanner unit 150 transfers the read image data to the HDD 115 via the scanner I / F 118. The stored image data can be printed by the printer unit 140. By printing the image data read by the scanner unit 150 by the printer unit 140, a copying process becomes possible.
[0022] The USB-Host I / F 119 is an interface for connecting the main controller 110 and the external USB device 170. Here, a fax unit is an example of the external USB device 170. In the fax unit example, the external USB device 170 sends a fax based on image data transferred from the HDD 115 via the USB-Host I / F 119. The external USB device 170 also generates image data based on the received data and transfers the image data to the HDD 115 via the USB-Host I / F 119. Note that the image data stored in the HDD 115 is printed on a recording medium by the printer unit 140, as described above. Other examples of the external USB device 170 include a USB memory and a USB keyboard. Update files required for firmware updates can also be transferred from the USB memory.
[0023] The network I / F 120 connects the main controller 110 to the LAN 160 and communicates with a PC 190 on the LAN. The PC 190 is connected to the image forming apparatus 100 via the LAN 160, and is capable of transmitting print data to the image forming apparatus 100, operating the apparatus via a web browser, transferring firmware files, and the like. The image forming apparatus 100 is further connected to a server device 180 via the LAN 160, and can set the server device 180 as a destination for scan data and various logs. The transmission method used here is, for example, Simple Mail Transfer Protocol (SMTP) or File Transfer Protocol (FTP), but the protocol is not limited thereto.
[0024] Furthermore, the image forming apparatus 100 can use the server apparatus 180 as a storage location for necessary settings and data. However, depending on the installation environment of the image forming apparatus 100, there are cases where the image forming apparatus 100 is not connected to the server apparatus 180. The same applies even if the server apparatus 180 is a cloud service or the like.
[0025] Next, a data inspection function for executing the inspection process of the scan data will be described.
[0026] 2 is a diagram showing an overview of a data censorship function using a cloud service. In this embodiment, the cloud service that provides the data censorship function is a system that has the censorship function.
[0027] It is assumed that cloud service 200 exists on server device 180 in Fig. 1. Although cloud service 200 exists on server device 180 in Fig. 1, cloud service 200 may be configured by multiple servers.
[0028] In step S201, when a job process that requires execution of scanning, such as copying, scan transmission, FAX transmission, or box storage, is input to the image forming apparatus 100, the process proceeds to step S202.
[0029] In step S202, the scan data is temporarily sent to the cloud service 200 to perform content inspection of the scan data.
[0030] In step S203, the cloud service 200 temporarily stores the received scan data in the storage 210, and performs censorship processing according to censorship keywords registered in advance by the administrator or the user.
[0031] Here, the cloud service 200 provides a data loss prevention (DLP) mechanism as one of its services. Data loss prevention (DLP) is a service that determines whether pre-registered censorship keywords are included in text data, and conceals or deletes the determined confidential information. A specific example will be described below using a case where a phone number is set as a censorship keyword.
[0032] First, the cloud service is configured to perform some kind of control on data containing phone numbers. The control can be varied, for example, notifying a pre-registered administrator of the number of phone numbers contained in the data in a multi-level alert, or converting the data to one with the phone number portion blacked out.
[0033] Next, when the data is saved to the cloud service or when censorship is instructed, the contents of the saved data are checked. If it is a phone number, for example, it is determined whether a phone number is listed by searching for a combination of a certain number of numbers and symbols.
[0034] Subsequently, if it is determined that the data contains a telephone number, control is carried out based on preset contents.
[0035] The types of censorship keywords that can be determined on the DLP, the content of the controls that can be set, and the method of checking the contents of the data vary depending on the cloud service that provides the service, and there are no limitations on the content.
[0036] In step S204, the result of the censorship process is notified to the image forming apparatus 100. The notified censorship result is assumed to be "low" if the scanned data does not contain the censored keyword, "medium" if a keyword similar to the censored keyword is contained, or "high" if the scanned data contains the censored keyword. The censorship result may be subdivided into multiple levels and notified depending on the likelihood of whether the censored keyword is contained, the number of times the keyword appears, etc.
[0037] In step S205, image forming apparatus 100 determines whether or not it is OK to actually send the scanned data based on the inspection result, user information managed by image forming apparatus 100, destination information for the scanned data, etc. If it is determined that the scanned data is OK to send, in step S206, the scanned data is sent to a destination specified by the user, such as PC 190. The destination for the scanned data is assumed to be specified by, for example, an email address or a telephone number, but it may also be possible to specify a chat room in a chat app or the like for sending the scanned data.
[0038] This makes it possible to prevent the leakage of confidential information by inspecting the contents of scanned data, and to achieve fine-grained access control according to the user's access rights.
[0039] Fig. 3 is a functional block diagram of the main controller 110. The configuration of software executed by the CPU 111 of the main controller 110 will be described using Fig. 3. The program shown in Fig. 3 is stored in the flash memory 114. Each functional unit shown in Fig. 3 is realized mainly by cooperation between the CPU 111, the flash memory 114, and the RAM 113.
[0040] The startup control unit 311 is a program that controls processing at startup of the image forming apparatus 100, and starts up the OS (operating system) of the main controller 110 and launches a basic system for running various programs. The operation unit control unit 312 is a program for controlling the operation unit 130 via the operation unit I / F 116. The printer control unit 313 is a program for controlling the printer unit 140 via the printer I / F 117. The scanner control unit 314 is a program for controlling the scanner unit 150 via the scanner I / F 118.
[0041] The image processing unit 315 performs image processing on the scan data received via the scanner control unit 314 .
[0042] The USB control unit 316 is a program for controlling the external USB device 170 via the USB-Host I / F 119. The communication control unit 317 communicates with the server device 180 and the PC 190 via the network I / F 120. This communication is performed via the LAN 160, and setting data required for sending scan data and inspecting the data is transferred. The transferred files are saved in the HDD 115.
[0043] The censorship setting management unit 318 manages a setting value (on / off of censorship mode) indicating whether or not censorship needs to be performed during scanning. The censorship setting management unit 318 also accepts settings necessary for performing censorship from the user and saves them in the HDD 115. A setting screen for accepting settings necessary for performing censorship may be displayed on the operation unit 130 via the operation control unit 312, or may be provided by a web server function so that the user can operate it using a web browser installed in the PC 190. The censorship setting management unit 318 saves the setting values accepted by these means in the HDD 115, and provides them as setting values when the censorship processing management unit 319 causes the cloud service to perform censorship.
[0044] The censorship processing management unit 319 transmits the scan data scanned by the scanner control unit 314 to the data censorship service 400, causing the data to be inspected. A processing request to the cloud service 200 is made using the communication control unit 317, and is made using a REST API (Representational State Transfer API). Note that this may also be realized using SOAP (Simple Object Access Protocol) or the like.
[0045] The received inspection result is notified to the inspection result determination unit 320 .
[0046] When the censorship result determination unit 320 determines that the scanned data contains a censorship keyword that prohibits transmission, the censorship result determination unit 320 further checks the user's authority and the destination of the scanned data.
[0047] These conditions are checked against a judgment table held by the censorship setting management unit 318, which will be described later, to determine whether transmission is possible. If it is determined that transmission is not possible, an error notification is issued. This error notification is sent to, for example, the operation unit 130 or an external device connected to the LAN 160, and notifies the user that an error has occurred during censorship.
[0048] The user data management unit 321 manages data for each individual user. The data managed here includes an address book used for faxing, scan data stored in the BOX 200, and various setting values.
[0049] The authentication control unit 322 manages authentication information for each user and accepts authentication operations when using the image forming apparatus 100. Based on the authentication information performed by the authentication control unit 322, it becomes possible to read data associated with authority from the user data management unit 321.
[0050] Next, the software configuration of the data inspection service 400 used to inspect scan data will be described with reference to FIG.
[0051] The data censorship service 400, a cloud service capable of performing data censorship, runs on the server device 180. The authentication control unit 401 performs user management and authentication for using the data censorship service 400. The data censorship service can also be accessed directly using a web browser installed on the PC 190. In this case, authentication is also performed using the authentication control unit 401.
[0052] The data censorship processing unit 402 censors the scan data transmitted from the censorship processing management unit 319 of the image forming device 100. The censorship may be performed according to a censorship keyword specified when receiving a processing request from the image forming device 100, or may be set in advance in the censorship setting management unit 403.
[0053] The censorship setting management unit 403 manages the settings of censorship keywords and censorship algorithms required for censorship.
[0054] The user data management unit 404 manages the scan data sent from the image forming apparatus 100 .
[0055] A communication control unit 405 performs communication with the image forming apparatus 100 and functions as a web server.
[0056] Next, the scanning of the original and the inspection process of the scanned data will be described with reference to FIGS.
[0057] 5A is a flowchart showing scan transmission processing performed by image forming apparatus 100. Note that the operation of image forming apparatus 100 is an example of operation in this embodiment. This processing is realized by CPU 111 expanding a program stored in flash memory 114 into RAM 113 and executing it. This processing is started when a job requiring scanning is submitted. Possible jobs requiring scanning include copy jobs, scan transmission jobs, FAX transmission jobs, and BOX storage jobs. In the case of a transmission job, the transmission destination is specified when the job is submitted.
[0058] Before starting a job involving scanning, the CPU 111 determines the user authority of the logged-in user of the multifunction peripheral. This determination method may be performed by acquiring information from an authentication server (not shown), or by having a means for registering the user authority of the logged-in user of the multifunction peripheral in an operation setting management table or the like in advance.
[0059] In step S501, the scanner control unit 314 uses the scanner unit 150 to read a display medium such as a document printed on a sheet, and the image processing unit 315 converts the read result into data.
[0060] In step S502, it is confirmed whether the job requiring scanning executed in S501 is a job involving transmission. Specifically, it is expected that this confirmation will be made by checking whether a transmission destination has been specified, but the confirmation method is not limited to this. Examples of jobs involving transmission are expected to be scan transmission jobs and fax transmission jobs. If it is a job involving transmission, the process proceeds to S503, and if it is not a job involving transmission such as a copy job or BOX storage job, this flow ends. This is because it is expected that inspection will be performed when the copy is executed in the case of a copy job, and when printing, etc. is executed using the scanned data stored in the BOX after it has been stored in the BOX in the case of a BOX storage job.
[0061] For example, as described above, assume that censorship is set for a specific storage area on a cloud service.
[0062] In step S503, the censorship setting management unit 318 checks whether the censorship mode is set to ON. If the censorship mode is set to ON, the scanned data is sent to the cloud storage to perform data censorship in step S504. If the censorship mode is set to OFF, the scanned data is sent in step S511 according to the sending settings set by the user when the scan was performed. In step S504, the censorship processing management unit 319 logs in to the data censorship service 400 and sends the scanned data to the data storage area.
[0063] In step S505, the censorship processing management unit 319 requests the data censorship service 400 to perform censorship (DLP). At this time, the censorship settings previously set in the censorship setting management unit 317 are also notified. The request here is assumed to be a request using an API published on a cloud service. For example, execution request information according to a specific API is sent from the image forming apparatus 100 to the server apparatus 180. Note that an API that collectively instructs steps S504 and S505 may also be used. For example, the API command specifies the specific area that has been set above. The command is an example of an execution request.
[0064] In step S506, the result of the inspection by the data inspection service 400 is received.
[0065] In step S507, the inspection result determination unit 320 determines whether or not the scan data can be transmitted based on the inspection result received in step S506 and the user's authority.
[0066] In step S508, it is determined whether it is permitted to transmit the scanned data, and if it is permitted, the scanned data is transmitted in step S509. If it is determined that it is not permitted to transmit, a message indicating that an error has occurred is displayed on the operation unit 130 in step S510.
[0067] In step S510, the error notification control unit 320 executes a notification process. In this notification process, the error notification control unit 320 uses the operation unit control unit 312 to display an error screen 600 on the operation unit 130, as shown in FIG.
[0068] 6(a) is a diagram showing an example of an error screen 600. An error message is displayed on the error screen 600, thereby informing the user that the censored data could not be output due to high demands for preventing information leakage. Note that the notification process is not limited to displaying a message, and may also include displaying a mark or providing a sound notification.
[0069] 6(b), the notification process may also notify the user of the error content 610 by email. In this case, the error notification control unit 320 confirms with the authentication control unit 322 who the current user is, and obtains the user's email address from the user data management unit 321. By sending an email via the communication control unit 317, the user is notified that the scanned data cannot be output.
[0070] It is also possible to use both the on-screen notification and the notification by e-mail. That is, the error screen 600 may be displayed on the operation unit 130 until the user logs off, and after the user logs off, it may be determined that the user is not in front of the image forming apparatus 100 and the user may be notified by e-mail. Even in this case, the scan data is not sent.
[0071] FIG. 5( b ) is a flowchart showing the data inspection process performed by the data inspection service 400 .
[0072] In step S521, communication control unit 405 receives scan data from image forming apparatus 100. In step S522, user data management unit 404 stores the received data in cloud storage. The received data is stored in the specific area described above. The cloud storage may have a storage area within server device 180, or may be physically present in linked cloud service 200.
[0073] In step S523, an instruction to execute the inspection process and the inspection details are received from the image forming apparatus 100. In this embodiment, the inspection details are received from the image forming apparatus 100, but they may be set in advance on the cloud service 200.
[0074] Next, in step S524, OCR is performed on the scan data acquired in step S522, thereby extracting character strings (text data) from the scan data. In step S525, the data censorship processing unit 402 performs data censorship. The data censorship processing unit 402 compares the extracted character string with the censorship dictionary to determine whether the extracted character string contains a censored keyword. At least one censored keyword is registered in the censorship dictionary through dictionary registration (described later in FIG. 7). The censorship dictionary is managed by the censorship setting management unit 403. In this embodiment, OCR is performed on the scan data on the cloud service 200, but it is also possible to perform OCR on the MFP and then send only the text data to the cloud service 200.
[0075] In step S526, the data inspection result indicating whether or not the extracted character strings contain a character string that matches the censorship keyword as a result of the data inspection in step S525 (i.e., whether or not the extracted character strings contain the censorship keyword) is transmitted to the image forming apparatus 100. Specifically, the data inspection processing unit 402 transmits the inspection result to the image forming apparatus 100 via the communication control unit 405. The data inspection result is returned as a severity level of "low," indicating that the censored character string was not contained; a severity level of "high," indicating that the censored character string is contained at a high rate; or a severity level of "medium," indicating that the censored character string is contained to a certain extent. In this embodiment, the result is notified at one of three levels, "low," "medium," and "high," depending on the rate at which the censored keyword is contained; however, the levels may be further subdivided depending on the number of times the censored keyword appears or the likelihood of the character string.
[0076] In step S527, the scanned data that has been inspected is deleted from the cloud storage.
[0077] Note that jobs other than copy jobs, scan jobs, fax jobs, and BOX storage jobs may also be subject to inspection on the cloud service. If any other job is submitted, the corresponding processing will be executed.
[0078] Next, a determination table 900 used by the inspection result determination unit 320 in determining whether transmission is permitted or not in step S507 will be described with reference to FIG.
[0079] The decision table 900 includes not only the inspection results but also factors such as the user's user authority and the destination of the scanned data, and determines whether or not to allow transmission based on these factors. For example, if the inspection result shows a severity of "low" and an email is to be sent, it is determined that the transmission is allowed. However, if the inspection result shows a severity of "high," variations can be set in advance, such as allowing transmission for users with managerial authority but not for general employees. This allows for more flexible determination of whether or not to allow transmission. The decision table shown here is just an example, and it may also be possible to set the determination of whether or not to allow transmission based on other factors such as the transmission protocol, device installation location, and file format.
[0080] 7 is a flowchart showing the dictionary registration process. This process is realized by CPU 111 expanding a program stored in flash memory 114 into RAM 113 and executing it. This process starts when the user inputs an instruction to execute dictionary registration via operation unit 130.
[0081] First, when an instruction to execute dictionary registration is input, a setting screen is displayed. The setting screen is displayed on the operation unit 130, or on a web browser provided in the PC 190 by the web server function.
[0082] In step S701, the censorship setting management unit 318 waits for the user to access the setting screen, and when the user accesses the setting screen, in step S702, the censorship setting management unit 318 displays a censorship keyword input screen 800 shown in Fig. 8 on the operation unit 130. The censorship keyword input screen 800 shown in Fig. 8 displays a keyword list display area 801, a keyword input acceptance area 802, an OK button 803, and a cancel button 804. In addition to this, it is also possible to set the operation settings and censorship character strings according to the censorship results of the scan data on a user or group basis.
[0083] In step S703, the censorship setting management unit 318 accepts input of a censorship keyword from the user on the censorship keyword input screen 800. In step S704, the censorship setting management unit 318 saves the input censorship keyword in the HDD 115 and ends the processing shown in Fig. 7. When a registered censorship keyword exists, the registered content of the censorship keyword can be updated by executing the processing shown in Fig. 7. Censorship in the above-mentioned determination processing is performed using the latest censorship keyword.
[0084] Furthermore, if the extracted character string contains a character string that matches a censorship keyword, an error is reported (S509), so that the user can be informed that the scanned data cannot be output in order to prevent information leakage.
[0085] In addition, the necessity of censorship can be set by setting the censorship mode ON or OFF, and the judgment process is executed on the condition that the censorship mode is set to be necessary. This allows smooth processing of saving and outputting data that does not pose a risk of information leakage.
[0086] Furthermore, while the diagram in FIG. 5 shows proofreading only for jobs that involve scanning and transmission, DLP may also be performed in cloud storage for jobs that do not involve transmission, such as copy jobs and BOX storage jobs. The following explanation will be given for the case of a copy job. When DLP is performed in cloud storage even for a copy job, processes from S503 to S506 are performed. In S507, it is determined whether printing is possible based on the results of DLP execution, and in S508 it is confirmed whether printing is possible, and if so, printing is performed in S509. If printing is not possible, an error is displayed in S510. Note that the determination of whether printing is possible may also be made on the cloud service.
[0087] In the above-described embodiment, once the scan data inspection is complete, the scan data stored in the cloud storage is deleted. However, in cases where you want to store data in the cloud storage or where the cloud service 200 provides a data transmission function, you may want to make effective use of the data stored in the cloud storage. Therefore, in another embodiment, the cloud service 200 transmits the file.
[0088] Figure 10 is a flowchart showing the process of sending scanned data stored in cloud storage to an external device via the cloud.
[0089] Steps S501 to S507 are the same as those in FIG. 5, and therefore the description thereof will be omitted.
[0090] In step S1001, if the determination in step S507 that transmission is possible is made, the process proceeds to step S1002, where the cloud service 200 is notified to send the scan data already stored in the cloud storage to the specified destination. If transmission is not possible, an error dialog is displayed in step S1003, and the scan data is deleted from the cloud storage in step S1004. Specifically, a request to delete the scan data is made to the cloud storage.
[0091] If the censorship mode is OFF, the scanned data is sent to the cloud storage in step S1005, and in step S1006, the data is sent to the destination specified by the cloud service 200 in the same manner as in step S1002.
[0092] If the user wishes to save the scanned data in cloud storage, the user does not issue a transmission request in steps S1002 and S1006, but saves the scanned data in the desired storage location.
[0093] However, once the data is saved in cloud storage, it becomes possible to access the file from the PC 104 or the like, which is undesirable because it would allow access to the scanned data before censorship. In step S504, it is preferable to send the scanned data to the cloud service 200 and set a private flag when the scanned data is saved in the cloud service. Setting the private flag makes it possible to prevent file access by others. Alternatively, a process such as resetting the state to public may be performed at the timing of step S1002.
[0094] According to this embodiment, it is possible to achieve the same effect as the above-described embodiment in terms of enhancing the effectiveness of preventing information leakage regarding scan data. Furthermore, it is possible to efficiently use scan data stored in the cloud service 200.
[0095] In the above-described embodiments, the image forming apparatus 100 consistently performs the process of determining whether transmission is permitted. However, in a case where a cloud service 200 that constantly links with the image forming apparatus 100 is deployed, it is more efficient for the cloud service 200 to determine whether transmission is permitted. Therefore, in the third embodiment, it is assumed that the image forming apparatus 100 is capable of communicating with a first cloud service (management server) 200 that manages and transmits data, and a second cloud service 200 (censorship server) that provides a data censorship service. A method will be described in which the image forming apparatus 100 transmits scanned data to the management server, and then transmits the data to the censorship server for data censorship. The management server and censorship server refer to the cloud services that provide the above-described services, respectively.
[0096] FIG. 11A is a flowchart showing a process in which the image forming apparatus 100 transmits scan data to the first cloud service 200.
[0097] In step S1101, the image forming apparatus 100 scans an original document, and in step S1102, transmits the scanned data to the first cloud service 200.
[0098] In step S1103, a notification of whether transmission is possible is received from the first cloud service 200. In step S1104, it is confirmed whether transmission is possible, and if transmission is possible, the process ends. If transmission is not possible, an error message is displayed in step S1105.
[0099] FIG. 11(b) is a flowchart illustrating the process of determining whether data can be transmitted in the first cloud service 200.
[0100] In step S1111, the scan data and the destination information designated by the user are received from the image forming apparatus 100.
[0101] Steps S1112-S1116 are the same as steps S503-S507, and therefore the explanation will be omitted.
[0102] In step S1117, the scanned image is deleted from the second cloud storage. Specifically, a request to delete the scanned image is sent to the second cloud storage.
[0103] If transmission is possible in step S1118, the scanned data is sent to the destination specified by the user in step S1119, and the image forming apparatus 100 is notified of the success of the transmission in step S1120. Note that the destination is assumed to be specified by an email address or a telephone number, but transmission may also be made by specifying a talk room such as a chat app. If transmission is not possible, the image forming apparatus 100 is notified of the failure of the transmission in step S1121.
[0104] If the censorship mode is set to OFF, the scan data is sent to the destination designated by the user in step S1122.
[0105] The operation of the second cloud service 200 is the same as that of the cloud service 200 in the first embodiment, and therefore a description thereof will be omitted.
[0106] According to this embodiment, in terms of increasing the effectiveness of preventing information leakage regarding scanned data, the same effect as that of the above-mentioned embodiment can be achieved by linking a management server that manages the data with a censorship server that provides data censorship services.
[0107] Furthermore, by performing all the processes up to the determination of whether transmission is possible in the cloud service 200, more resources can be used than in the image forming apparatus 100, and processing can be completed in a short time.
[0108] While the present invention has been described in detail above based on preferred embodiments thereof, the present invention is not limited to these specific embodiments, and various forms within the scope of the gist of the present invention are also included in the present invention. Parts of the above-described embodiments may be combined as appropriate.
[0109] (Other Examples) The present invention can also be realized by supplying a program that realizes one or more of the functions of the above-described embodiments to a system or device via a network or a non-transitory storage medium, and having one or more processors in the computer of the system or device read and execute the program. The above program and the storage medium storing the program constitute the present invention. The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more of the functions. [Explanation of symbols]
[0110] 111 CPU 314 Scanner Control Unit 319 Censorship Processing Management Department 402 Data Inspection Processing Unit 404 User Data Management Department
Claims
1. An image processing device capable of communicating with a system having a censorship function, a first transmitting means for transmitting image data obtained by scanning a document to the system; a second transmitting means for transmitting the image data to a destination; receiving means for receiving the inspection result from the system; an execution means for executing a predetermined operation based on the received inspection result and the transmission destination; 1. An image processing device comprising:
2. The predetermined operation is a preset operation.
2. The image processing device according to claim 1, wherein:
3. An authentication means for authenticating a login user is provided, 3. The image processing apparatus according to claim 1, wherein the predetermined operation is set based on the user authority of the logged-in user.
4. If the predetermined operation based on the received inspection result is set to transmittable, the second transmitting means executes a process of transmitting the image data to a transmission destination.
4. The image processing device according to claim 1, wherein the image processing device is a computer.
5. If the predetermined operation based on the received inspection result is set to prohibit transmission, a request to delete the image data is sent to the system.
5. The image processing device according to claim 1, wherein the image processing device is a computer.
6. A display unit for displaying a screen is provided, If the predetermined operation based on the received inspection result is set to transmission-prohibited, the execution means displays a message indicating that transmission is prohibited on the display unit.
6. The image processing device according to claim 1, wherein the image processing device is a computer.
7. 7. The image processing apparatus according to claim 6, wherein the predetermined operation is set on a setting screen displayed on the display unit.
8. 8. The image processing apparatus according to claim 1, wherein the system having the censorship function is configured by one or more servers.
9. an extraction means for extracting text data from the image data; The first transmitting means transmits the text data extracted by the extracting means to the system.
9. The image processing device according to claim 1, wherein the image processing device is a computer.
10. The original is a sheet 10. The image processing device according to claim 1, wherein the image processing device is a computer.
11. An image processing device capable of communicating with a system having a censorship function, a first transmission step of transmitting image data obtained by scanning a document to the system; a second sending step of sending the image data to a destination; receiving a censorship result from the system; an execution step of executing a predetermined operation based on the received inspection result and the transmission destination; 1. A method for controlling an image processing apparatus, comprising:
12. A program for causing a computer to execute the control method according to claim 11.
Citation Information
Patent Citations
Color copying machine
JP1996194412A
Information censorship system, information disclosure server, device, method and program for censoring information
JP2010266940A
Image processing system, image processing apparatus and server in the image processing system, and data control method and program
JP2012231431A
Image forming system
JP2020129709A