Network system and information provision method
The network system allows secure and centralized presentation of device security information to administrators, addressing the lack of remote information dissemination in existing technologies by using a web browser and authorization mechanisms.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2022-05-31
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies lack a means for remotely presenting security information to administrators managing devices, such as tampering and lockout states, without providing a centralized and safe method for information dissemination.
A network system comprising an image processing device, information processing device, web browser, service provision system, and device management system that allows administrators to securely access and display security information through a web browser, using authorization information to manage access and display security information collected from devices.
Enables safe and centralized presentation of security information to target persons, ensuring secure and standardized access to device status and security alerts.
Smart Images

Figure 0007867380000005 
Figure 0007867380000006 
Figure 0007867380000007
Abstract
Description
Technical Field
[0001] The present invention relates to a network system and an information providing method.
Background Art
[0002] In recent years, it has become possible to connect devices to the Internet and remotely manage the states of the devices. For example, Patent Document 1 proposes a method for remotely detecting the presence of malware not only in the storage area of a hard disk but also in the firmware of the hard disk. Patent Document 2 proposes an information processing device and a lockout management system that appropriately manage the lockout state of a user with respect to an information processing device on a network to improve security.
Prior Art Documents
Patent Documents
[0003] <src <src
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] <src In the prior art, it is possible to remotely detect security information such as tampering and lockout states related to devices, but no means for remotely presenting security information to the administrators who manage the devices has been proposed. <src <src
[0005] <src The present invention solves this problem, and provides a network system and an information providing method for safely and centrally presenting the collected security information to the target person. <src
Means for Solving the Problems
[0006] <src To achieve the above objective, the present invention comprises the following configuration. According to one aspect of the present invention, a network system including an image processing device, an information processing device having a web browser, a service provision system that provides a website, and a device management system that collects and manages security information received from the image processing device, The information processing device, in response to user operation, logs into the service provision system via the web browser and, upon receiving an instruction to display security information, sends a request for authorization information to the service provision system. Upon receiving authorization information issued by the device management system from the service provision system via the web browser, the information processing device transmits a security information display request to the device management system, which includes the authorization information and the specification of a device identifier. If the device management system grants access to the security information to the user logged into the service provision system based on verification of the authorization information included in the security information display request, it transmits the security information display information associated with the device identifier to the information processing device. The information processing device receives security information display information from the device management system and displays a screen including the security information display information in the web browser. A network system characterized by the above is provided. [Effects of the Invention]
[0007] This invention makes it possible to safely and centrally present collected security information to the target person. [Brief explanation of the drawing]
[0008] [Figure 1] This diagram shows the network configuration. [Figure 2] This is a diagram showing the hardware configuration. [Figure 3A] This diagram shows the software configuration. [Figure 3B] This diagram shows the software configuration. [Figure 4] This diagram shows an example of authorization information issued by a cloud server. [Figure 5A] This diagram shows an example of a screen provided by a cloud server. [Figure 5B] This diagram shows an example of a screen provided by a cloud server. [Figure 5C] This diagram shows an example of a screen provided by a cloud server. [Figure 6] This is a flowchart of the process in Embodiment 1. [Figure 7A] This is a flowchart of the process in Embodiment 1. [Figure 7B] This is a flowchart of the process in Embodiment 1. [Figure 8] This figure shows an example of authorization information issued by Embodiment 2. [Modes for carrying out the invention]
[0009] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims. While the embodiments describe multiple features, not all of these features are essential to the invention, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.
[0010] [Embodiment 1] ●Network configuration Figure 1 shows the network configuration of a remote management system (also called a network system) to which the present invention is applied. The cloud server 101 is a server that collects and records the security information of the image forming apparatus and issues and verifies authorization information to the customer information management server 122, and can communicate with various apparatuses via the Internet 102. In the example of FIG. 1, the image forming apparatus 112 and the information processing apparatuses 111 and 121 are each connected to the network by one unit, but a plurality of units may be used. Note that, paying attention to the image processing function of the image forming apparatus, this may be referred to as an image processing apparatus. The cloud server 101 may be constituted by one or a plurality of computers, and is also called a device management system for managing a device called an image forming apparatus.
[0011] The customer network environment 110 is the network environment of a customer who has purchased the image forming apparatus 112. In the customer network environment 110, the image forming apparatus 112 and the information processing apparatus 111 are connected via a LAN (Local Area Network) 113. The LAN 113 can be connected to the Internet 102. The customer administrator uses the information processing apparatus 111 to connect to the customer information management server 122 and check the security information of the image forming apparatus 112. This check is performed by causing the security information to be displayed on the information processing apparatus 111 through the customer information management server 122.
[0012] The sales company network environment 120 is the network environment of a sales company that performs status management and remote maintenance of the image forming apparatus. In the sales company network environment 120, the information processing apparatus 121 and the customer information management server 122 are connected via a LAN 123. The LAN 123 can be connected to the Internet 102. Although only one distribution company network environment 120 is illustrated in the example of FIG. 1, there are a plurality of such environments for each region such as Japan and Europe. Further, it is assumed that each customer information management server 122 manages the image forming apparatuses 112 under a plurality of customer network environments 110. The customer information management server 122 may be composed of one or a plurality of computers, and is also called a service providing system because it provides services such as information provision to customers.
[0013] ● Hardware Configuration FIG. 2 shows the hardware configuration of the apparatuses constituting the remote management system to which the present invention is applied. FIG. 2(A) shows the hardware configuration of the image forming apparatus 112, and FIG. 2(B) shows the hardware configuration of the information processing apparatuses 111, 121, the customer information management server 122, and the cloud server 101. When the customer information management server 122 and the cloud server 101 are composed of a plurality of computers, each computer may have the configuration shown in FIG. 2(B).
[0014] The image forming apparatus 112 has the configuration shown in FIG. 2(A). The document feeder 201 automatically feeds the document to be read to the image reader 202. The image reader 202 (for example, a scanner) reads the fed document. The image forming unit 203 converts the read document and the received data into a print image and prints it. The paper feeder 204 feeds paper for printing. The Network I / F (Interface) 205 is connected to the LAN 113 and the Internet 102 via the network to exchange information with the outside.
[0015] Sensor 206 detects the status of each part of the device. CPU 207 executes programs to manage each process on the device. Hard disk 208 stores programs and data related to each process of the device. Non-volatile memory 209 is a memory that can retain data even without power supply and is rewritable, such as FRAM (registered trademark) (Ferroelectric Random Access Memory). Volatile memory 210 is a memory that can electrically store temporary data related to each process of the device and is rewritable. Display unit 211 displays the operating status of the device and information related to operations on the operation unit 212. Operation unit 212 receives instruction inputs to the device. Display unit 211 and operation unit 212 constitute the user interface. System bus 213 connects each part from the document feeding unit 201 to the operation unit 212 and exchanges data. However, not all components are connected to a single bus; for example, some blocks may constitute subsystems and be connected to the system bus 213.
[0016] The information processing devices 111 and 121, the customer information management server 122, and the cloud server 101 have the configuration shown in Figure 2(B). The display unit 221 displays windows, icons, messages, menus, and other user interface information. The operation unit 222 accepts input from end users using a keyboard and mouse. The CPU 223 executes programs and manages each process on the device. The hard disk 224 stores programs and data related to each process on the device. The volatile memory 225 is a memory that can electrically store temporary data related to each process on the device and is rewritable. The network interface 226 connects to the LAN 113132 and the internet 102 via the network and exchanges information with the outside world. The system bus 227 connects the parts 221 to 226 and exchanges data.
[0017] ●Software configuration Figures 3A and 3B show the software configuration of a remote management system to which the present invention is applied. Figure 3A(A) shows the software configuration of the cloud server 101, and Figure 3A(B) shows the software configuration of the image forming apparatus 112. Figure 3B(C) shows the software configuration of the customer information management server 122, and Figure 3B(D) shows the software configuration of the information processing apparatus 111.
[0018] ● Software configuration of Cloud Server 101 Each part of the software configuration of the cloud server 101 shown in Figure 3A(A) is realized in the cloud server 101 when the CPU 223 loads a program stored on the hard disk 224 onto the volatile memory 225 and executes it.
[0019] The tenant information storage unit 311 stores the tenant information table on the hard disk 224 of the cloud server 101. Table 1 shows an example of a tenant information table stored in the tenant information storage unit 311.
[0020] [Table 1]
[0021] In the tenant information table in Table 1, the tenant identifier column stores a tenant identifier that uniquely identifies the tenant information. The client identifier column stores a client identifier that uniquely identifies the customer information management server 122. In the example in Table 1, the customer information management server 122 with client identifier "client_123" can access the tenants with tenant identifiers "distributorA", "customerA", and "customerAA". It also shows that the customer information management server 122 with client identifier "client_abc" can access the tenants with tenant identifiers "distributorB" and "customerB". A tenant is a management unit for managing devices such as image forming apparatuses and information processing apparatuses and their users. One tenant may contain one or more information processing apparatuses 111 and one or more image forming apparatuses 112. Each tenant may also have one or more users.
[0022] Each record in the tenant information table is called a tenant information record, and it is registered by the customer information management server 122 when it starts connecting to the cloud server 101. It is also updated when tenant information is added, updated, or deleted from the cloud server 101.
[0023] The security information display setting storage unit 312 stores the security information display setting table on the hard disk 224 of the cloud server 101. Table 2 shows an example of a security information display setting table stored in the security information display setting storage unit 312.
[0024] [Table 2]
[0025] The security information display settings table in Table 2 shows one set (i.e., one record) of security information display settings. In Table 2, the setting value ID column is a column that stores the setting value ID, which is an identifier that uniquely identifies one set of security information display settings. The tenant identifier column is a column that stores the tenant identifier for which the display setting is valid. The default setting diagnosis column is a column that stores whether or not the diagnostic result of the setting status regarding the security settings of the image forming apparatus 112 is displayed. Default setting diagnosis is a diagnosis of the level of security by determining whether or not the setting values of the image forming apparatus remain at the default settings at the time of shipment. The tamper detection column is a column that stores whether or not tamper detection of the image forming apparatus 112 is displayed. The target of tamper detection includes programs stored on rewritable media, and may also include fixed value data.
[0026] The Authentication Lockout Detection column stores whether or not the image forming apparatus 112 displays an Authentication Lockout detection. Authentication lockout refers to a situation where, for example, login attempts fail repeatedly more than a predetermined number of times, and further login operations are not accepted. The After-Hours Login Detection column stores whether or not the image forming apparatus 112 displays an After-Hours Login detection. After-Hours Login refers to a login operation during a specified time period or a time period outside of the specified time period. The Restricted Time Start Time and Restricted Time End Time columns store the start and end times of the restricted time when the After-Hours Login Detection is displayed.
[0027] The columns from the default settings diagnostic column to the after-hours login detection column indicate the categories of events received from the image forming apparatus 112. Here, only security-related events are subject to settings for display (i.e., provision of display information). Each record in the security information display settings table is called a security information display settings record and is registered in the table on a tenant information basis. Security information display settings records are added when tenant information about a customer is added to the cloud server 101 and are updated when an update request is received from the customer information management server 122. The security information display settings table can also be described as information that defines the access rights or scope of each tenant's users for each category of security information. Alternatively, it can be described as information that indicates whether display is permitted or not.
[0028] The security information storage unit 313 stores a security information table, which holds the security information received from the image forming apparatus 112, in the hard disk 224 of the cloud server 101. Table 3 shows an example of a security information table stored in the security information storage unit 313.
[0029] [Table 3]
[0030] The security information table in Table 3 shows one set (i.e., one record) of security information. In Table 3, the security alert ID column is a column that stores the security alert ID, which is an identifier that uniquely identifies the security information. The tenant identifier column is a column that stores the tenant identifier, which uniquely identifies the customer that manages the image forming apparatus 112. The device ID column is a column that stores the device ID (also called the device identifier), which is an identifier that uniquely identifies the image forming apparatus 112. The category column is a column that stores the classification of the security information. In this embodiment, one of the following is stored: "default setting diagnosis," "tampering detection," "authentication lockout detection," or "after-hours login detection," corresponding to the setting value managed in the security information display setting table (Table 2). "Tampering detection" is also called "software integrity verification."
[0031] The alert level column stores the alert level of security information. In this embodiment, if the value of the category column is "Tampering Detected," it stores "Action Required," and for any other value, it stores "Confirmation Required," but this is not limited to this embodiment.
[0032] The deletion status column stores whether the security information is in a deleted state. In this embodiment, if the security information is in a deleted state, in the case of security information related to "default setting diagnosis," it means that the security settings of the image forming apparatus 112 are in a state where there are no problems. In the case of security information related to "tampering detection," "authentication lockout detection," and "after-hours login detection," it means that the customer administrator has checked the security information on the security status confirmation screen 501, which will be described later. For security information where the value of the category column is "default setting diagnosis," the value of the deletion status column is updated to the deleted state when the process in step S709 of Figure 7, which will be described later, is executed. For security information where the value of the category column is other than "default setting diagnosis," the value of the deletion status column is updated to the deleted state when the "Verification / Detection Content Confirmed Button" 521 of Figure 5, which will be described later, is pressed.
[0033] The "Date and Time of Occurrence" column stores the date and time when the image forming apparatus 112 notified security information. The "Remarks" column stores the application name and login username when the security information notified by the image forming apparatus 112 is "tampering detected," "authentication lockout detected," or "after-hours login detected."
[0034] Each record in the security information table is called a security information record, and is registered per image forming apparatus 112 if the category is "default setting diagnosis," and per security information notified by the image forming apparatus 112 otherwise. Security information records are added by the processing of the security information recording control unit 323, which will be described later.
[0035] The display setting control unit 321 is a function that is executed when it receives a security information display setting request from the customer information management server 122. The display setting control unit 321 changes the display settings in response to the security information display setting request. The received request information includes authorization information, a tenant identifier that uniquely identifies the customer to be configured, and the changed display setting information. The display setting control unit 321 requests authorization information verification from the authorization information verification unit 325 (described later), and updates the security information display settings only if the authorization information verification process is successful. Furthermore, if the display setting of the item to be updated is updated from "ON" to "OFF", all records in the security information table (Table 3) whose category value matches the item to be updated are deleted.
[0036] The event receiving unit 322 is a function that is executed when an event from the image forming apparatus 112 is received via the Network I / F 226 provided on the cloud server 101. The received event includes at least a device ID that uniquely identifies the image forming apparatus 112 that sent the event, a tenant identifier that identifies the customer that manages the image forming apparatus 112, and event information. The event receiving unit 322 requests the security information recording control unit 323, described later, to record security information only if the received event information is security information. In this embodiment, the determination of whether the received event information is an event related to security information is made by referring to information that identifies the type of event, such as the event name included in the event information, but is not limited to this.
[0037] The security information recording control unit 323 is a function that is executed when it receives a request to record security information from the event receiving unit 322. In response to the request to record security information, the security information recording control unit 323 records the target security information if the conditions are met. The security information recording control unit 323 obtains a security information display setting record that matches the tenant identifier received from the event receiving unit 322 from the security information display setting table (Table 2). Furthermore, it identifies category information from the security information received from the event receiving unit 322. In this embodiment, the method of identifying category information can be done from the event name, but it is not limited to this. The security information recording control unit 323 refers to the acquired security information display setting record and the setting value of the identified category information, and if the setting value corresponding to the category is "OFF", it does not record the security information. If the setting value is "ON", it records the security information according to the flowchart in Figure 6 described later. In this embodiment, whether or not to collect security information is controlled based on the security information display setting. However, security information may be collected regardless of the setting value of the security information display setting, and the collected security information may be provided to the user according to the security information display setting. The settings for each category in the security information display settings record can be described as either indicating whether or not security information is collected, or whether or not security information is provided (displayed).
[0038] The authorization information issuing unit 324 is a function that is executed when it receives an authorization information issuance request for obtaining security information from the customer information management server 122. In response to the authorization information issuance request, the authorization information issuing unit 324 issues authorization information if the necessary conditions are met. Authorization information is an access token that is verified when accessing a resource, when security information is used as the resource. The customer information management server 122 can access multiple customer tenant information that it manages, as managed in the tenant information table (Table 1). On the other hand, the customer administrator belonging to a single customer tenant makes a request to display security information for the image forming apparatus 112.
[0039] When the customer information management server 122 receives a display request from the web browser of the information processing device 111, it provides a website that displays customer information and image forming device information managed by the customer information management server 122. This website provides information only after a user, such as a customer administrator, has successfully logged in. Furthermore, if the user requests the display of security information on that website, the customer information management server 122 requests authorization information to be issued, specifying the tenant identifier to which the user belongs, in order to limit the scope of security information displayed in the web browser. This user is the logged-in user who logged into the customer information management server 122 via the information processing device 111 and performed the display request, and usually belongs to the same tenant as the information processing device 111.
[0040] The authorization information issuing unit 324 stores a private key used to sign the authorization information it issues and a public key used to verify the issued authorization information. Figure 4 illustrates an example of authorization information issued by the authorization information issuing unit 324. Authorization information 401 represents the entire string of the issued authorization information. The authorization information is divided into a header section, a payload section, and a signature section, which are joined together by ".". Line breaks have been added between each section in the diagram for readability.
[0041] The header section 402 is JSON-formatted data containing information about the algorithm used for signing and the format of the authorization information. From the alg claim in the header section 402, it can be seen that the authorization information is signed with the HS256 algorithm. The payload section 403 contains information such as the date and time of issuance of the authorization information from the sub claim, the client identifier from the name claim, and the expiration date of the authorization information from the iat claim. The scope claim (authority information) specifies the scope of the authorization. In Figure 4, the specified authorization is, for example, access to device resources, in this example, access to security information. The extra claim is an extended claim in which tenant identifier information specified by the customer information management server 122 is stored. Although not described in detail here, the authorization information issuance unit 324 verifies whether the requester is correct when it receives an authorization information issuance request, and issues the authorization information only if the requester is correct.
[0042] The authorization information verification unit 325 is a function that is executed when it receives an authorization information verification request from the display setting control unit 321 or the security information display control unit 326. The authorization information verification unit 325 verifies the target authorization information in response to the authorization information verification request and responds with either a verification success or verification failure result. The received request information includes the authorization information and the tenant identifier of the target to be accessed. In the case of a verification request from the display setting control unit 321, the client identifier included in the payload of the authorization information is compared with the tenant information managed in the tenant information table (Table 1). As a result of the comparison, if the tenant identifier of a tenant that the client identified by the client identifier can access is specified, the verification is determined to be successful. For example, the client identifier corresponding to the tenant identifier received with the request information is obtained from the tenant information table, and if that client identifier matches the client identifier included in the authorization information, the verification is determined to be successful.
[0043] In the case of a verification request from the security information display control unit 326, the client identifier and the tenant identifier within the extended claim are obtained from the authorization information payload. Using the received authorization information as an example (Figure 4), the client identifier is "client_123" and the tenant identifier is "customerA". Next, the system searches the tenant information table (Table 1) for records where the combination of client identifier and tenant identifier matches. If a matching record exists, the verification is successful; otherwise, the verification fails.
[0044] Based on the above control, when displaying security information, it becomes possible to implement a control that allows access only to the security information of the customer tenant information to which the customer administrator accessing the customer information management server 122 belongs.
[0045] The security information display control unit 326 enables the display of security information in a web browser. Specifically, the website's display information (HTML) is provided with a script related to a confirmation UI that controls the display of security information embedded within it. In the web browser, this script is executed when a user requests the display of security information. In response to this execution, a confirmation UI unit (not shown) operating on the web browser sends a resource (security information) request, including authorization information obtained from the customer information management server 122, to the security information display control unit 326. When the security information display control unit 326 receives the security information display request, if the authorization information verification is successful, it returns security information within the scope of the authorization to the confirmation UI unit. Details will be described later in the flowchart of Figure 6.
[0046] Of the above configuration, the parts from the display setting control unit 321 to the security information display control unit 326 are collectively referred to as the status monitor.
[0047] ● Software configuration of the image forming apparatus 112 Each part of the software configuration of the image forming apparatus 112 shown in Figure 3A(B) is realized by the CPU 207 loading a program stored on the hard disk 208 onto the volatile memory 210 and executing it in the image forming apparatus 112.
[0048] The device information storage unit 331 has the function of storing a device information table on the hard disk 208 of the image forming apparatus 112. The device information table stores, in association with at least a device ID for uniquely identifying the image forming apparatus 112 and a tenant identifier for uniquely identifying the customer who manages the image forming apparatus 112.
[0049] The security information storage unit 332 has the function of storing a security information table on the hard disk 208 of the image forming apparatus 112. The security information table stores security information created by the security information recording unit 341, which will be described later. Each record in the security information table is called a security information record, and is added when the security information recording unit 341, which will be described later, records security information. The security information is divided into one or more categories. In this embodiment, for example, it may include at least one of four categories: default setting diagnosis, tampering detection, user authentication lockout detection, and login detection during the monitored time period, but in this example, it includes all of them.
[0050] The security information recording unit 341 has the function of recording security information to the security information holding unit 332 when a security-related event occurs on the image forming apparatus 112. In this embodiment, it is assumed that tampering is detected or a login operation is performed, but it is not limited to these cases. When recording security information, the date and time of occurrence and additional information are also recorded.
[0051] The security information transmission unit 342 is a function that transmits security information, along with its own device ID and tenant identifier, from the Network I / F 205 provided on the image forming apparatus 112 to the cloud server 101. In this embodiment, it is assumed that the image forming apparatus 112 is configured to transmit all security information to the cloud server 101, but the settings of the security information display setting unit 312 and the transmission settings of the image forming apparatus 112 may be controlled in conjunction. Furthermore, the transmission settings may be configured for each category.
[0052] The security information transmission unit 342 transmits two types of security information: security information records recorded in the security information holding unit 332 and security-related setting information for the image forming apparatus 112. This setting information includes the transmission settings described above. Security information records are transmitted each time the security information recording unit 341 adds a security information record. Security-related setting information is transmitted when the image forming apparatus 112 is started, after a certain period of time has elapsed since startup, and when there are updates to the security-related setting information.
[0053] For example, if the settings (display settings) of the security information display setting unit 312 and the transmission settings of the image forming apparatus 112 do not match, the cloud server 101 may instruct the image forming apparatus 112 to change the transmission settings to match the display settings. For example, if the display setting is "display" but the transmission setting is "not transmit", the cloud server 101 may instruct the image forming apparatus 112 to change the corresponding setting to "transmit".
[0054] ● Software configuration of customer information management server 122 Figure 3B(C) shows an example of the software configuration of the customer information management server 122. Each part of the software configuration of the customer information management server 122 is realized by the CPU 223 loading programs stored on the hard disk 224 onto the volatile memory 225 and executing them. The user information storage unit 361 stores user identification information and authentication information, etc. User identification information may include, for example, a user ID and a tenant identifier of the tenant to which the user belongs. Authentication information may include information necessary for authentication, such as a password for each user. Furthermore, if authorization information is assigned to a user, that authorization information may be associated with the user and stored. This association may be for each individual user or for the tenant to which the user belongs.
[0055] The display information storage unit 362 stores display information (also called screen information) for a website that is provided to a web browser or the like running on the information processing device 111. The display information is based on a page written in a predetermined description language such as HTML or XML, and the location of each page is specified by location information such as a URL or URI. The display information includes, for example, display information for displaying the status of a managed device such as an image forming apparatus 112. The display information may have fixed content such as text and graphics laid out, and may also have areas into which dynamic content is inserted. Furthermore, the display information may include scripts that are executed by the web browser, and dynamic content can be displayed by executing these scripts. In addition, security information display information obtained from the cloud server 101 may be temporarily stored in the display information storage unit 362.
[0056] The web server unit 351, in response to a request received from a web browser (also simply called a browser), retrieves the specified display information from the display information storage unit 362 and provides it to the browser.
[0057] The user authentication unit 352 performs user authentication in response to login operations on the login page provided to the web browser of the information processing device 111. User authentication may be performed by comparing the entered user identification information and authentication information with the user identification information and authentication information stored in the user information storage unit 361. If the comparison is successful, user authentication is successful, and the display information mentioned at the beginning is sent to the browser for display. This display information may include an operation menu, which may include, for example, a request to display security information or a change in security settings. A user who has been successfully authenticated is called a logged-in user. If the comparison fails, the information processing device 111 is notified accordingly.
[0058] The authorization information acquisition unit 353 requests authorization information from the cloud server 101 and obtains authorization information from the cloud server 101. The acquired authorization information may be provided to the web browser when displaying security information, or it may be stored in the user information storage unit 361.
[0059] User authentication may be performed by a separate authentication server; in that case, the user information storage unit 361 and the user authentication unit 352 are included in that authentication server.
[0060] ● Software configuration of the information processing device 111 Figure 3B(C) shows an example of the software configuration of the information processing device 111. The information processing device 111 includes a web browser unit 371 (web browser 371). This web browser unit 371 may be general-purpose software that executes a description language and scripts to display the screen and accepts information input from the user. Of course, it also has other basic software such as an operating system, but that has been omitted. This is also true for the software of other devices.
[0061] ●Display screen example Figures 5A-5C show an example of a customer information management screen provided by the customer information management server 122. The customer information management server 122 is a server that provides contract information and consumable information on a portal site (entry point website) for specific customers. By applying the present invention, the customer information management server 122 can further provide information in a form that incorporates a security information confirmation UI provided by the security information display control unit 326. The customer portal screen 501 is a portal site for specific customers provided by the customer information management server 122. When a user logs in by specifying the location of this portal site in a web browser 371, the customer portal screen 501 is sent from the customer information management server 122 to the web browser 371 and displayed.
[0062] The customer portal screen 501 in Figure 5A(A) includes customer information 502, which displays contract information, consumable information, etc., managed by the customer information management server 122, and a security information confirmation UI 511 related to the image forming apparatus 112 managed by the cloud server 101. The customer information 502 shows an example of displaying information related to the image forming apparatus 112 managed by the customer information management server 122, but is not limited to this. The security information confirmation UI 511 is a UI displayed for customer administrators to confirm (or refer to) security information related to the image forming apparatus 112.
[0063] The security information confirmation UI 511 is an area that displays security information obtained by the confirmation UI unit, which operates on a web browser, when it executes a request to display security information, including authorization information, to the cloud server 101. The authorization information is embedded in the website's display information and is obtained by the web browser via the customer information management server 122 in response to the execution of a script related to the confirmation UI, and then issued by the cloud server 101. This security information confirmation UI is a UI component implemented using a predetermined description language (such as JavaScript®) that can dynamically display the latest security information.
[0064] Message field 512 is an example of a message displayed when there is an item with a display setting of "ON" in the items managed by the security information display setting retention unit 312, but security information has not been received from the image forming apparatus 112. Message field 513, shown in Figure 5A(B), is an example of a message displayed when all display setting items managed by the security information display setting retention unit 312 are "OFF".
[0065] The message field 514 in Figure 5B(C) is an example of a message displayed when the display setting for "Default Settings Diagnosis," managed by the security information display setting retention unit 312, is "ON" and there are no security issues in "Default Settings Diagnosis." Specifically, this occurs when a record in the security information table (Table 3) with the category "Default Settings Diagnosis" has been deleted.
[0066] Message fields 520 and 521 are example messages displayed when the display setting for "Default Settings Diagnosis," managed by the security information display setting retention unit 312, is "ON." The display conditions for message field 521 are the same as those for message field 514.
[0067] The message field 530 and operation button 531 are example messages displayed when the display setting for any of the items managed by the security information display setting retention unit 312, namely "tampering detection," "authentication lockout detection," or "after-hours login detection," is set to "ON." Operation button 531 is displayed in an enabled state when there is unconfirmed security information, and in an disabled state when all information has been confirmed. Specifically, if there are no records related to "tampering detection," "authentication lockout detection," or "after-hours login detection" in the category values of the security information table (Table 3), or if all records are in a deleted state, operation button 531 is displayed in an disabled state. On the other hand, it is displayed in an enabled state when there are records that are not in a deleted state. When the enabled operation button 531 is pressed, the security information records that are not in a deleted state are updated to a deleted state, and operation button 531 becomes disabled.
[0068] Message field 541 is an example message displayed when the display setting for "Tamper Detection" managed by the security information display setting holding unit 312 is "ON" and there is no record in the security information table (Table 3) with the category value "Tamper Detection". Similarly, message field 551 is an example message displayed when the target category is "Authentication Lockout Detection" and the display setting is "ON", but there is no corresponding security information record. Message field 561 is an example message displayed when the target category is "After-Hours Login Detection" and the display setting is "ON", but there is no corresponding security information record.
[0069] Figure 5B(D) illustrates an example where only the "Tampering Detection" display setting is "ON," the display settings for all other items are "OFF," and no security information records exist.
[0070] Figures 5C(E)(F) illustrate an example of the security information confirmation UI 511 in a situation where a security problem has occurred. Message fields 515 and 516 display messages according to the alert level. Message field 515 is an example of a message displayed when the alert level is "Requires Confirmation". Message field 516 is an example of a message displayed when the alert level is "Requires Action". Specifically, message field 515 is displayed when the alert level of all security information records in the security information table (Table 3) that are not in a deleted state is "Requires Confirmation". Message field 516 is displayed when there are security information records in the security information table (Table 3) that are not in a deleted state and have an alert level of "Requires Action". Message field 522 is an example of a message displayed when there is a problem with the security setting information of the image forming apparatus 112. Specifically, this is when there are records in the security information table (Table 3) with a category value of "Default Setting Diagnosis" that are not in a deleted state.
[0071] Tamper detection records 542 and 543 display all records where the category value in the security information table (Table 3) is "Tamper Detection". Tamper detection record 542 (Figure 5C(E)) shows an example where the displayed record is in a deleted state (= confirmed by the customer administrator). Tamper detection record 543 (Figure 5C(F)) shows an example where the displayed record is not in a deleted state (= not confirmed by the customer administrator). This example shows how to display security information in an easy-to-understand way by displaying an icon to indicate that it has been confirmed, and an error icon if it has not been confirmed. If there are many target records, you may control the sort order by occurrence date and time or limit the number of displayed records.
[0072] Authentication lockout detection records 552 and 553 display all records where the category value in the security information table (Table 3) is "Authentication Lockout Detected". Authentication lockout detection record 552 shows an example where the displayed record is not in a deleted state (= not confirmed by the customer administrator). On the other hand, authentication lockout detection record 553 shows an example where the displayed record is in a deleted state (= confirmed by the customer administrator). Display control is the same as for tamper detection records 542 and 543.
[0073] Records 562 and 563 that detect logins outside of business hours display all records where the category value in the security information table (Table 3) is "Login detected outside of business hours". Record 562 shows an example where the record being displayed is not deleted (i.e., not yet confirmed by the customer administrator). On the other hand, record 563 shows an example where the record being displayed is deleted (i.e., confirmed by the customer administrator). Display control is the same as for records 542 and 543 that detect tampering.
[0074] By using the security information confirmation UI 511 described above, customer administrators can check the security status of the image forming apparatus 112 they manage in real time. Furthermore, since the security information is centrally provided by the cloud server 101 that manages the image forming apparatus, the customer information management server 122 does not need to create the security information confirmation UI 511. In addition, the format and content of the security information provided are standardized, eliminating inconsistencies in display format and information accuracy among multiple customer information management servers 122.
[0075] ● Display sequence of security information Hereafter, the first embodiment will be described using the flowchart in Figure 6. Figure 6 is a flowchart of the processes executed when a security-related event occurs in the image forming apparatus 112.
[0076] In step S601, a security-related event occurs in the image forming apparatus 112. The event includes, for example, information regarding the addition or configuration of verification or detection results belonging to one of the categories of security information.
[0077] In step S602, the security information transmission unit 342 sends the event information that occurred in S601, along with its own device ID and tenant identifier held by the device information holding unit 331, to the cloud server 101.
[0078] In step S603, if the image forming apparatus 112 detects a change in its security settings, it sends information regarding the security settings, along with its own device ID and tenant identifier stored in the device information holding unit 331, to the cloud server 101.
[0079] In step S604, the security information recording control unit 323 records the security information received by the event receiving unit 322 in S602 or S603. Details will be described later in the flowcharts in Figures 7A and 7B. Note that the processing in steps S601 to S603 is repeated each time an event occurs or a setting is changed in the image forming apparatus 112. In addition, although not described in detail here, the security setting information for the image forming apparatus 112 is transmitted from the security information transmission unit 342 when the image forming apparatus 112 is started up or at a fixed time.
[0080] In step S605, the web browser running on the information processing device 111 accesses the portal site provided by the customer information management server 122 and sends a login request, in accordance with the customer user's operation. Upon receiving the login request, the customer information management server 122 performs authentication processing on the login information received along with the login request. The customer user can log in using, for example, a customer ID or a user ID and authentication information as login information. It is also assumed that the customer information management server 122 manages the tenant information to which the customer administrator belongs. If the login is successful, the initial screen of the portal site is sent from the customer information management server 122 to the browser 371 and displayed. The initial screen displays buttons and menus for displaying security information.
[0081] In step S606, the system accepts a user instruction to display security information in accordance with the user's actions in the browser 371.
[0082] In step S606, the browser 371 sends a request for authorization information to the customer information management server 122 in response to the customer user's operation. This request includes at least device ID information (device identifier) that identifies the image forming apparatus 112 to be displayed.
[0083] In step S608, the customer information management server 122, having received a request from the customer administrator to display security information, identifies the tenant identifier to which the customer administrator belongs and requests the authorization information issuance unit 324 to issue authorization information for displaying security information.
[0084] In step S609, the authorization information issuing unit 324 issues authorization information, including the tenant identifier received in the authorization information issuance request, and transmits it to the customer information management server 122.
[0085] In step S610, the customer information management server 122, having received authorization information from the authorization information issuing unit 324, returns (or replies to) the authorization information to the browser 371. In step S611, the browser 371 passes the authorization information to the confirmation UI unit operating on the web browser, and the confirmation UI unit sends a security information display request to the security information display control unit 326. This display request corresponds to a resource request that includes authorization information.
[0086] In step S612, the security information display control unit 326 requests the authorization information verification unit 325 to verify the authorization information included in the display request. If the authorization information verification is successful, it verifies whether the customer information management server 122 can access the customer information identified by the tenant identifier included in the authorization information. Furthermore, it verifies whether the image forming apparatus 112 identified by the received device ID is under the management of the customer with the tenant identifier included in the authorization information. Here, it may also verify whether the image forming apparatus identified by the device ID belongs to the tenant identified by the tenant identifier. If all verifications are successful, it is determined that the customer administrator has the authority to display security information, and the processes in S613 to S615 are performed. If there is a problem with the verification result (verification fails), the processes in S616 to S618 are performed. The process in S610 makes it possible to prevent the display of security information even if, for example, someone tries to illegally display security information by specifying the device ID of an image forming apparatus 112 that is not under the management of the customer to which the customer administrator belongs.
[0087] In step S613, the security information display control unit 326 returns security information to the confirmation UI unit.
[0088] In step S614, the confirmation UI unit incorporates the security information into the security information confirmation UI 511. The security information confirmation UI may be, for example, information in which the security information is incorporated into a pre-prepared template according to the security information display settings. In step S615, the security information confirmation UI 511 is displayed on the browser, and the process ends. The customer user can refer to and confirm the security information on the display screen exemplified in Figures 5A-5C.
[0089] On the other hand, if the display of security information is refused, in step S616, the security information display control unit 326 notifies the confirmation UI unit that access is unavailable (i.e., display is unavailable).
[0090] In step S617, the confirmation UI unit incorporates a message 513 or the like, indicating that the display of security information is not possible, into the security information confirmation UI 511.
[0091] In step S618, the browser 371 displays a screen that does not contain security information and terminates the process.
[0092] As explained above, the flowchart in Figure 6 makes it possible to display security information received from the image forming apparatus 112 only to customer administrators who have the correct permissions.
[0093] In the procedure shown in Figure 6, authorization information is issued by the cloud server 101, but it may also be issued by an authorization system prepared separately from the cloud server 101. Furthermore, it is not necessary to obtain authorization information each time a security information display request is made; the authorization information obtained once can be saved and reused. In that case, if the authorization information becomes unavailable due to expiration or other reasons, it can be re-obtained.
[0094] ● Security information recording processing by cloud server 101 Figures 7A and 7B are flowcharts of the processes executed when the security information recording control unit 323 receives security information from the image forming apparatus 112. The security information recording control unit 323 makes recording decisions for each category of the received security information. Steps S702 to S703 are for "tamper detection," steps S704 to S709 are for "default setting diagnosis," steps S712 to S715 are for "authentication lockout detection," and steps S716 to S719 are for "after-hours login detection." One of these processes is performed depending on the category of the received security information.
[0095] In step S701, the security information recording control unit 323 identifies the tenant identifier and the security information category from the received security information. The security information category is determined from the event name, but is not limited to this.
[0096] In step S702, if the category identified in S701 is "Tampering Detection", the record of the tenant identifier identified in S701 is retrieved from the security information display settings table (Table 2) and the display setting for "Tampering Detection" is checked. If the display setting is "ON", the process in step S703 is executed; if the display setting is "OFF", the process in step S704 is executed.
[0097] In step S703, the security information recording control unit 323 adds the received security information to the record in the security information table (Table 3). The security alert ID of the record to be added is newly issued, the category is "Tampering detected", the alert level is "Action required", and the deletion status is "FALSE" (not deleted). If the received security information includes an application name, the information is also added to the remarks column.
[0098] In step S704, if the category identified in S701 is "Default Settings Diagnosis", the record of the tenant identifier identified in S701 is retrieved from the security information display settings table (Table 2), and the display setting for "Default Settings Diagnosis" is checked. If the display setting is "ON", the process in step S720 is executed; if the display setting is "OFF", the process in step S710 is executed. Security information related to "Default Settings Diagnosis" is notified as a combination of the security setting name and setting value of the image forming apparatus 112. When the image forming apparatus 112 is started up or during periodic transmission, all combinations are notified, and if there is a change in the setting value, only the changed combination is notified.
[0099] The details of step S720, which branches off from step S704, are shown in Figure 7B, but in this explanation, it will be described as a single process with Figure 7A. Step S720 performs a default setting diagnosis. S720 includes steps S705 to S709.
[0100] The process from steps S705 to S707 is executed repeatedly for each combination of notified setting values. The security information recording unit 323 is assumed to have pre-managed setting names and their corresponding initial values (not shown). In this embodiment, a security problem is determined if all predefined setting values are at their initial values, and no security problem is determined if even one setting value differs from the initial value. However, the determination method is not limited to this method. For example, it may be determined that there is no problem if two or more predetermined setting items are set to values different from the initial values, or it may be determined that there is no problem if all setting items are set to values different from the initial values.
[0101] In step S705, the security information recording control unit 323 determines whether the received security information setting name is subject to default setting diagnosis. If it is subject to diagnosis, the process in step S706 is executed. If it is not subject to diagnosis, the process in step S707 is executed.
[0102] In step S706, the security information recording control unit 323 determines whether the setting value of the received setting name is the initial value. If the setting value is not the initial value, the process in step S709 is executed; if the setting value is the initial value, the process in step S707 is executed.
[0103] In step S707, the security information recording control unit 323 determines whether it has checked all combinations of setting values of the received security information. If all checks are complete, it determines that all setting values were initial values and executes the process in step S708. If there are still setting values that have not been checked, the same determination is made for the next setting value.
[0104] In step S708, the security information recording control unit 323 updates or adds a record to the security information table (Table 3). If a record exists in which the value of the device ID column is the same as the ID that identifies the image forming apparatus 112 and the value of the category column is "default setting diagnosis", only the value of the occurrence date and time column is updated. If the value of the deletion status column is "TRUE", it is updated to "FALSE". If no such record exists, a new security alert ID is issued and a record is added with the category "default setting diagnosis", the alert level "requires confirmation", and the deletion status "FALSE".
[0105] In step S709, the security information recording control unit 323 updates or adds a record to the security information table (Table 3). If a record exists in which the value of the device ID column is the same as the ID that identifies the image forming apparatus 112 and the value of the category column is "default setting diagnosis", only the value of the occurrence date and time column is updated. If the value of the deletion status column is "FALSE", it is updated to "TRUE". If no such record exists, a new security alert ID is issued and a record is added with the category "default setting diagnosis", alert level "good", and deletion status "TRUE".
[0106] Returning to Figure 7A, in step S710, it is determined whether the category identified in S701 is "login detection". In this embodiment, two types of security information are recorded and managed for login detection: "authentication lockout detection" and "after-hours login detection". Since the security information notified from the image forming apparatus 112 is login detection information, the recording of security information is determined according to the content of the notified login detection information and the settings of the security information display setting table (Table 2). If the category identified in S701 is "login detection", the process in step S711 is executed, and if it is not "login detection", the process is terminated.
[0107] In step S711, the security information recording control unit 323 obtains the record of the tenant identifier identified in S701 from the security information display setting table (Table 2) and obtains the display settings for "authentication lockout detection" and "after-hours login detection".
[0108] In step S712, the security information recording control unit 323 checks the display setting for "authentication lockout detection". If the display setting is "ON", the process in step S713 is executed; if the display setting is "OFF", the process in step S716 is executed.
[0109] In step S713, the security information recording control unit 323 determines from the received security information, which is login detection information, whether the login is related to lockout detection. If it is a login related to lockout, the process in step S714 is executed; otherwise, the process in step S715 is executed.
[0110] In step S714, the security information recording control unit 323 adds a record to the security information table (Table 3). A new security alert ID is issued for the record to be added, and a record with the category "Authentication Lockout Detected", alert level "Requires Confirmation", and deletion status "FALSE" is added. If the received security information includes the login username, the information is also added to the remarks column.
[0111] In step S715, the security information recording control unit 323 determines that no authentication lockout has occurred and does not record security information related to the detection of the authentication lockout.
[0112] In step S716, the security information recording control unit 323 checks the display setting for "After-hours login detection". If the display setting is "ON", the process in step S717 is executed; if the display setting is "OFF", the process is terminated.
[0113] In step S717, the security information recording control unit 323 retrieves the record of the tenant identifier identified in S701 from the security information display setting table (Table 2) and obtains the setting values for "restriction time start time" and "restriction time end time". From the received security information, which is login detection information, it identifies the time of successful login and determines whether the login occurred within the restriction time start and end times of the security information display setting record. If the login occurred within the restriction time, the process in step S718 is executed; if the login occurred outside the restriction time or was a login failure, the process in step S719 is executed.
[0114] In step S718, the security information recording control unit 323 adds a record to the security information table (Table 3). A new security alert ID is issued for the record to be added, and a record with the category "After-hours login detected", alert level "Requires confirmation", and deletion status "FALSE" is added. If the received security information includes the login username, the information is also added to the remarks column.
[0115] In step S719, the security information recording control unit 323 determines that no logins occurred within the restricted time period, and therefore does not record security information regarding the detection of logins outside of the restricted time period, and terminates the process.
[0116] As explained above, the flowchart in Figure 7 makes it possible to record security information notified from the image forming apparatus 112 in a format suitable for displaying customer information security information. Furthermore, according to this embodiment, security information from the image forming apparatus can be collected by the cloud server and provided to the customer information management server as a UI component. The customer information management server can then provide screen information incorporating this UI component to a browser for display. Therefore, the customer information management server can provide security information to the user without directly accessing it, thereby improving security and standardizing the display format.
[0117] In this embodiment, display settings are provided for each category, but a single display setting may be used for the entire security setting. Alternatively, in addition to display settings for each category, an overall display setting may be provided, and the logical AND of these settings may be used to determine whether or not the logged-in user can access the security information.
[0118] <Variation> In the above embodiment, the customer information management server 122 sends screen information with a script embedded to the browser. The browser, which executes the script, then obtains the security information confirmation UI from the cloud server 101 and displays it. Alternatively, the customer information management server 122 may be configured to embed the security information confirmation UI obtained from the cloud server 101 into the display information of a pre-created template and send it to the information processing device 111. In this case, the customer information management server 122 can obtain the security information confirmation UI if it presents the confirmation information to the cloud server 101 and authentication is successful. In this configuration, the template only needs to include fixed components of a pre-prepared portal site, and the security information confirmation UI only needs to be embedded in those fixed parts. Therefore, in addition to the effects of the above embodiment, there is also the effect of reducing the load on the information processing device 111.
[0119] [Embodiment 2] Embodiment 1 described a method for securely displaying security information of an image forming apparatus 112 under the control of a customer (i.e., tenant) to which a customer administrator (also called a customer user) belongs. This embodiment describes a method for controlling the display of security information according to the role of the customer administrator.
[0120] Table 4 shows an example of a security information display setting table stored in the security information display setting holding unit 312 in this embodiment.
[0121] [Table 4]
[0122] Table 4 is the security information display settings table from Table 2 with the addition of a department settings column, storing the display settings for each department. In the example in Table 4, it is shown that the IT department can display security information for "default settings diagnosis" and "tampering detection," and the management department can display security information for "authentication lockout detection" and "after-hours login detection" (i.e., display is permitted or allowed). Department-specific display settings can also be said to indicate the scope of access rights to security information for each department.
[0123] Figure 8 shows the payload 801 of the authorization information issued by the authorization information issuing unit 324 to which this embodiment is applied. The customer information management server 122 to which this embodiment is applied adds the customer administrator's tenant information and department information in the processing of step S608 and makes an authorization information issuance request. The user's department is, for example, held in the user information holding unit 361, and the department of the logged-in user may be obtained when logging in and held in association with the logged-in user. The authorization information issuing unit 324, upon receiving the authorization information issuance request, adds the tenant identifier and department information to the extra claim, which is an extended claim, and issues the authorization information.
[0124] In the verification process of step S612 to which this embodiment is applied, the image forming apparatus 112 determines that only security information that the department to which it belongs, as included in the extended claim, is permitted to display, is available for display. That is, the security information that may be displayed is determined for each category, for example, as in Embodiment 1. At that time, in addition to the ON / OFF setting of each category, the display setting for each department received in the extended claim of the authorization information is determined by referring to the security information display setting table. Then, in step S613, the security information of the category for which the display setting is ON and the department's display setting is permitted or allowed is transmitted to the information processing device 111 (particularly the web browser 371). The subsequent processing is the same as in Embodiment 1.
[0125] As described above, this embodiment enables, in addition to the effects of Embodiment 1, the display of security information according to the department to which the customer administrator belongs.
[0126] Furthermore, in addition to controlling the display of security information by department, it is also possible to control the display of security information by user. In that case, for example, the user information storage unit 361 may associate information indicating whether or not to display information by category, similar to the department settings in Table 4, with each user, and the system may refer to this information to decide whether or not to display security information. In this case, the customer information management server 122, rather than the cloud server 101, will store the display settings for each user, so the customer information management server 122 may make that decision.
[0127] ●Configuration of the embodiment The above embodiments can be summarized as follows. [Item 1] A network system including an image processing device, an information processing device having a web browser, a service provision system that provides a website, and a device management system that collects and manages security information received from the image processing device, The information processing device, in response to user operation, logs into the service provision system via the web browser and, upon receiving an instruction to display security information, sends a request for authorization information to the service provision system. Upon receiving authorization information issued by the device management system from the service provision system via the web browser, the information processing device transmits a security information display request to the device management system, which includes the authorization information and the specification of a device identifier. If the device management system grants access to the security information to the user logged into the service provision system based on verification of the authorization information included in the security information display request, it transmits the security information display information associated with the device identifier to the information processing device. The information processing device receives security information display information from the device management system and displays a screen including the security information display information in the web browser. A network system characterized by the following:
[0128] [Item 2] The network system described in item 1, The device management system determines, based on the permissions included in the authorization information, whether to grant the user logged into the service provision system access to the security information associated with the device identifier. A network system characterized by the following:
[0129] [Item 3] The network system described in item 2, The device management system determines, in addition to the authorization information, whether to allow the user to access the security information associated with the device identifier, based on the security information display settings. A network system characterized by the following: [Item 4] The network system described in item 3, The device management system determines whether to allow the user to access the security information associated with the device identifier, based on the settings of the department to which the logged-in user belongs, in addition to the settings for displaying the authorization information and the security information. A network system characterized by the following:
[0130] [Item 5] A network system as described in item 3 or 4, The image processing device determines whether or not to transmit the security information to the device management system according to a transmission setting indicating whether or not to transmit the security information to the device management system. The device management system instructs the image processing device to set the transmission setting to transmit if the transmission setting received from the device management system is set to not transmit and the display setting is set to allow access. A network system characterized by the following:
[0131] [Item 6] A network system according to claim 5, The aforementioned transmission settings and display settings are configured for each category of security information. A network system characterized by the following:
[0132] [Item 7] A network system according to any one of claims 1 to 6, If the device management system does not permit the security information display request based on the authorization information, it transmits information indicating that it is not permitted to the information processing device. The information processing device receives information indicating the "unavailable" status from the device management system and displays a screen in the web browser that includes information indicating that the security information cannot be displayed. A network system characterized by the following:
[0133] [Item 8] A network system according to any one of claims 1 to 7, The aforementioned security information includes at least one of the following categories: default configuration diagnostics, tampering detection, user authentication lockout detection, and login detection during monitored time periods. The device management system collects at least one category from the image processing device as security information for each device identifier. A network system characterized by the following:
[0134] [Item 9] The network system described in item 1, A network system characterized in that the transmission of a security information display request to the device management system and the display of a screen including the security information display information received from the device management system are performed in the web browser and implemented by a script embedded in the display information provided by the service provision system.
[0135] [Item 10] A method for providing information via a network system including an image processing device, an information processing device having a web browser, a service provision system that provides a website, and a device management system that collects and manages security information received from the image processing device, The information processing device, in response to user operation, logs into the service provision system via the web browser and, upon receiving an instruction to display security information, sends a request for authorization information to the service provision system. Upon receiving authorization information issued by the device management system from the service provision system via the web browser, the information processing device transmits a security information display request to the device management system, which includes the authorization information and the specification of a device identifier. If the device management system grants access to the security information to the user logged into the service provision system based on verification of the authorization information included in the security information display request, it transmits the security information display information associated with the device identifier to the information processing device. The information processing device receives security information display information from the device management system and displays a screen including the security information display information in the web browser. A method for providing information characterized by the following features.
[0136] [Other examples] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.
[0137] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of Symbols]
[0138] 101 Cloud server, 110 Customer network environment, 111 Information processing device for customer network environment, 112 Image forming device for customer network environment, 120 Sales company network environment, 121 Information processing device for sales company network environment, 122 Customer information management server
Claims
1. A network system including an image processing device, an information processing device having a web browser, a service provision system that provides a website, and a device management system that collects and manages security information received from the image processing device, The information processing device, in response to user operation, logs into the service provision system via the web browser and, upon receiving an instruction to display security information, sends a request for authorization information to the service provision system. Upon receiving authorization information issued by the device management system from the service provision system via the web browser, the information processing device transmits a security information display request to the device management system, which includes the authorization information and the specification of a device identifier. If the device management system grants access to the security information to the user logged into the service provision system based on verification of the authorization information included in the security information display request, it transmits the security information display information associated with the device identifier to the information processing device. The information processing device receives security information display information from the device management system and displays a screen including the security information display information in the web browser. A network system characterized by the following:
2. A network system according to claim 1, The device management system determines, based on the permissions included in the authorization information, whether to grant the user logged into the service provision system access to the security information associated with the device identifier. A network system characterized by the following:
3. The network system according to claim 2, The device management system determines, in addition to the authorization information, whether to allow the user to access the security information associated with the device identifier, based on the security information display settings. A network system characterized by the following:
4. The network system according to claim 3, The device management system determines whether to allow the user to access the security information associated with the device identifier, based on the settings of the department to which the logged-in user belongs, in addition to the settings for displaying the authorization information and the security information. A network system characterized by the following:
5. A network system according to claim 3 or 4, The image processing device determines whether or not to transmit the security information to the device management system according to a transmission setting indicating whether or not to transmit the security information to the device management system. The device management system instructs the image processing device to set the transmission setting to transmit if the transmission setting received from the device management system is set to not transmit and the display setting is set to allow access. A network system characterized by the following:
6. The network system according to claim 5, The aforementioned transmission settings and display settings are configured for each category of security information. A network system characterized by the following:
7. A network system according to any one of claims 1 to 4, If the device management system does not permit the security information display request based on the authorization information, it transmits information indicating that it is not permitted to the information processing device. The information processing device receives information indicating the "unavailable" status from the device management system and displays a screen in the web browser that includes information indicating that the security information cannot be displayed. A network system characterized by the following:
8. A network system according to any one of claims 1 to 4, The aforementioned security information includes at least one of the following categories: default configuration diagnostics, tampering detection, user authentication lockout detection, and login detection during monitored time periods. The device management system collects at least one category from the image processing device as security information for each device identifier. A network system characterized by the following:
9. A network system according to claim 1, A network system characterized in that the transmission of a security information display request to the device management system and the display of a screen including the security information display information received from the device management system are performed in the web browser and implemented by a script embedded in the display information provided by the service provision system.
10. A method for providing information via a network system including an image processing device, an information processing device having a web browser, a service provision system that provides a website, and a device management system that collects and manages security information received from the image processing device, The information processing device, in response to user operation, logs into the service provision system via the web browser and, upon receiving an instruction to display security information, sends a request for authorization information to the service provision system. Upon receiving authorization information issued by the device management system from the service provision system via the web browser, the information processing device transmits a security information display request to the device management system, which includes the authorization information and the specification of a device identifier. If the device management system grants access to the security information to the user logged into the service provision system based on verification of the authorization information included in the security information display request, it transmits the security information display information associated with the device identifier to the information processing device. The information processing device receives security information display information from the device management system and displays a screen including the security information display information in the web browser. A method for providing information characterized by the following features.