Information processing device
The information processing device addresses the issue of multifunction device shutdowns by allowing unaffected functions to operate post-virus detection, ensuring usability and efficiency through targeted virus management and function restoration.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- SHARP KK
- Filing Date
- 2022-03-18
- Publication Date
- 2026-07-16
- Estimated Expiration
- Not applicable · inactive patent
Smart Images

Figure 0007891348000001 
Figure 0007891348000002 
Figure 0007891348000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, and more particularly to an information processing apparatus such as an image forming apparatus having a number of functions, which restricts executable functions when a computer virus is detected.
Background Art
[0002] Conventionally, image forming apparatuses (also called multifunction printers) having a number of functions such as a printing function, a document reading function, a function of transmitting read image data, a FAX transmission / reception function, an e-mail transmission / reception function, an image data acquisition function, and a character recognition function have been used. Such an image forming apparatus having a number of functions may also be infected with a computer virus, similar to electronic devices such as a personal computer connected to a network. Therefore, in order to cope with the infection of a computer virus, some image forming apparatuses are equipped with a program that executes a computer virus detection function, a removal function, etc.
[0003] For example, Patent Document 1 describes a network facsimile apparatus that notifies a PC that a computer virus has been detected when a computer virus is detected in a file attached to a received e-mail, adds a warning to a facsimile image when an instruction to transmit a facsimile via a public switched telephone network is given, attaches the text of a warning message to an e-mail when an instruction to transmit a facsimile via the Internet is given, or prohibits transmission via a LAN and a public switched telephone network.
[0004] Furthermore, Patent Document 2 describes a computer system that, in a computer such as a POS terminal, obtains a list of processes that are actually running, creates a whitelist including the corresponding process name and executable file name, stores the whitelist on a server, distributes it from the server to each computer terminal, and when a process is created on each computer terminal, obtains the process name and executable file name of the created process, detects whether the obtained process name and executable file name exist in the whitelist, and if they do not exist, stops the startup of the created process and generates an alarm. [Prior art documents] [Patent Documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2003-259066 [Patent Document 2] Japanese Patent Publication No. 2016-181074 [Overview of the project] [Problems that the invention aims to solve]
[0006] As with the device described in Patent Document 1, the spread of computer virus infections can be prevented by prohibiting transmission via LAN and public network. However, with information processing devices that have multiple functions, such as multifunction printers, if all functions are stopped due to the detection of a computer virus, it can prevent the spread of the virus infection, but it also presents a problem: functions that are not directly related to the spread of the infection and would not spread the virus even if started become unusable.
[0007] Furthermore, if administrators are unable to immediately take measures such as virus removal after all functions have been shut down, functions that would not spread the infection may remain unavailable for extended periods, leading to problems such as reduced device uptime and users being unable to use any functions. Furthermore, even after the detected computer virus was removed, it was sometimes unclear whether restarting functions related to the infected program or other components that had been disabled would prevent malfunctions from occurring.
[0008] In the system described in Patent Document 2, if a process not present in the whitelist occurs, the system can detect the possibility of a virus infection before the computer terminal malfunctions by stopping the startup of that process. However, even if the process name of the process that occurs is present in the whitelist, if the program itself with the executable file name corresponding to that process name is already infected with a virus, continuing that process may cause the computer terminal to malfunction and potentially spread the virus infection.
[0009] Therefore, this invention was made in consideration of the above circumstances, and aims to prevent the spread of computer virus infection in an information processing device having multiple functions by allowing the execution of functions unaffected by the detected computer virus after the computer virus has been detected, while also avoiding a situation where all functions of the information processing device become unusable, suppressing a decrease in the operating rate of the information processing device, and ensuring the convenience of users of the information processing device for the functions that can be executed. [Means for solving the problem]
[0010] This invention provides an information processing device comprising: a virus detection unit for detecting computer viruses; a virus information acquisition unit for acquiring virus information that identifies the detected computer virus; a function execution feasibility determination unit for determining which functions should be permitted to execute and which functions should be prohibited from executing using the acquired virus information; a function operation setting unit for setting the execution feasibility of each function based on the determination result made by the function execution feasibility determination unit; and a function execution unit for executing the selected function. The function operation setting unit sets functions determined to be permitted to execute as permitted functions, and functions determined to be prohibited from executing as prohibited functions. Functions set as prohibited functions by the function operation setting unit are prohibited from being executed by the function execution unit until they reach a state where execution should be permitted, and after that state, they become functions that can be executed by the function execution unit.
[0011] Furthermore, the system includes a virus removal unit that removes the detected computer virus, wherein the functions that should be permitted to execute and the functions that should be prohibited from executing, as determined by the function execution feasibility determination unit, differ before and after the removal of the detected computer virus, and the functions that should be permitted to execute after the removal of the detected computer virus are greater than the functions that should be permitted to execute before the removal.
[0012] Furthermore, the system is further equipped with a virus removal unit that removes the detected computer virus, and the state in which execution should be permitted is characterized in that the detected computer virus has been removed by the virus removal unit.
[0013] Furthermore, the system includes a virus removal unit that removes the detected computer virus, and a confirmation request unit that, after the detected computer virus has been removed by the virus removal unit, requests a manager to confirm that there is no impact from the removed computer virus, and the state in which execution should be permitted is characterized in that the manager has confirmed that there is no impact from the removed computer virus.
[0014] Furthermore, the virus information acquisition unit includes a virus type determination unit that determines the type of the detected computer virus and an infection location determination unit that identifies the location where the detected computer virus has infected, and the acquired virus information includes the type of the detected computer virus and the location of the infection.
[0015] Furthermore, the system includes a storage unit that pre-stores function operation permission information, which sets whether each function can be executed in association with the type of computer virus and the location where the computer virus infected the system. The function execution permission determination unit uses the function operation permission information to determine, for each function, whether it should be permitted to be executed or prohibited, based on the function's execution permission status associated with the detected computer virus and the location where the detected computer virus infected the system.
[0016] Furthermore, the system includes a display unit that displays a function selection screen including multiple selection display areas for each function, and an operation unit that performs an input operation to select the selection display area corresponding to a desired function in order to execute that function, wherein the selection display area for a function set as an execution prohibition function by the function operation setting unit is displayed on the function selection screen in such a way that it cannot be selected by the operation unit.
[0017] Furthermore, the information processing device is characterized by being an image forming apparatus having multiple functions.
[0018] Furthermore, this invention provides a method for controlling the function operation of an information processing device, wherein a control unit provided in the information processing device performs a virus detection step of detecting a computer virus, a virus information acquisition step of acquiring virus information that identifies the detected computer virus, a function execution feasibility determination step of using the acquired virus information to determine which functions should be allowed to be executed and which functions should be prohibited from being executed, and a function operation setting step of setting the functions determined to be allowed to be executed as execution-permitted functions and the functions determined to be prohibited from being executed as execution-prohibited functions based on the determination results, and in the function operation setting step, functions set as execution-prohibited functions are prohibited from being executed until they reach a state where execution should be permitted, and after reaching a state where execution should be permitted, they become executable functions.
[0019] Furthermore, the functional operation control method of this invention is characterized in that the virus information acquisition step includes a virus type determination step for determining the type of computer virus detected and an infection location identification step for identifying the location where the detected computer virus has infected, the acquired virus information includes the type of computer virus detected and the location where it has infected, and in the functional execution feasibility determination step, the functional operation feasibility information, which is pre-set in association with the type of computer virus and the location where the computer virus has infected, is used to determine whether each function should be allowed to be executed or prohibited to be executed, based on the function's execution feasibility associated with the type of computer virus detected and the location where the detected computer virus has infected. [Effects of the Invention]
[0020] According to the present invention, there are provided a virus information acquisition unit that acquires virus information for identifying a detected computer virus, a function execution permission determination unit that determines a function to be permitted to execute and a function to be prohibited from executing by using the acquired virus information, and a function operation setting unit that sets whether each function can be executed based on the determination result determined by the function execution permission determination unit. The function operation setting unit sets a function determined to be a function to be permitted to execute as an execution-permitted function, and sets a function determined to be a function to be prohibited from executing as an execution-prohibited function. Therefore, it is possible to prevent the spread of infection of a computer virus, avoid a situation where all functions of the information processing apparatus become unusable when the information processing apparatus is infected with a computer virus, suppress a decrease in the operation rate of the information processing apparatus, and ensure the convenience of a user who uses the information processing apparatus for functions that can be executed even after a computer virus is detected, for example, before the computer virus is removed or during the execution of the removal.
Brief Description of the Drawings
[0021] [Figure 1] It is a configuration block diagram of an embodiment of an image forming apparatus of the present invention. [Figure 2] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 3] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 4] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 5] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 6] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 7] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 8] It is an explanatory diagram of an embodiment of information stored in a storage unit of an image forming apparatus of the present invention. [Figure 9]This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus of this invention. [Figure 10] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus of this invention. [Figure 11] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus of this invention. [Figure 12] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus of this invention. [Figure 13] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus of this invention. [Figure 14] This is a flowchart of one embodiment of the virus detection and functional operation control processing of the image forming apparatus of the present invention. [Figure 15] This is a flowchart of one embodiment of the virus detection and functional operation control processing of the image forming apparatus of the present invention. [Figure 16] This is a flowchart of one embodiment of the virus detection and functional operation control processing of the image forming apparatus of the present invention. [Figure 17] This is a flowchart of one embodiment of the virus detection and functional operation control processing of the image forming apparatus of the present invention. [Figure 18] This is a flowchart of one embodiment of the virus detection and functional operation control processing of the image forming apparatus of the present invention. [Figure 19] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 20] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 21] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 22] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 23] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 24]This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 25] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 26] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 27] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 28] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Figure 29] This is an explanatory diagram of one embodiment of the screen displayed on the display unit of the image forming apparatus of this invention. [Modes for carrying out the invention]
[0022] Embodiments of the present invention will be described below with reference to the drawings. However, the invention is not limited by the following descriptions of embodiments.
[0023] The information processing device of this invention is a device that has the function of detecting computer viruses (hereinafter simply referred to as viruses) that infiltrate via a network or storage device, determining the type of virus detected, and isolating or removing it. Alternatively, the information processing device may be equipped with a dedicated antivirus program capable of detecting and removing viruses.
[0024] In the following embodiments, an image forming apparatus corresponding to an information processing apparatus, which has multiple functions, will be described. However, the information processing device is not limited to an image forming apparatus; it can be any electronic device with multiple functions, such as a personal computer, scanner, display device, recording device, or robotic equipment.
[0025] <Configuration of an image forming apparatus> Figure 1 shows a block diagram of one embodiment of the image forming apparatus of the present invention. A multifunction peripheral (MFP) is a device that processes image data, primarily performing tasks such as input, formation, output, storage, and transfer of image data. The image forming apparatus 1 is also called a multifunction printer, or simply an MFP. Furthermore, the image forming apparatus 1 is an electronic device equipped with functions for processing image data, such as a copying function, a printing function, a document reading (scanning) function, a document editing function, a document storage function, a document transmission / reception function (fax transmission / reception, scanner document transmission), an email transmission / reception function, a file transfer function, and a communication function.
[0026] In the following embodiments, the image forming apparatus 1 of this invention will be described as having, in particular, a copy function, a scanner function, a fax function, an email function, a remote printing function, a file saving (document filing) function, and a file transfer (FTP) function, but it may also have other functions.
[0027] In Figure 1, the image forming apparatus (MFP) 1 of this invention mainly comprises a control unit 11, an operation unit 12, a display unit 13, an image processing unit 14, a communication unit 15, a fax processing unit 16, a virus detection unit 20, a virus information acquisition unit 21, a virus removal unit 24, a function execution feasibility determination unit 25, a function operation setting unit 26, a screen display control unit 27, a function execution prohibition unit 28, a function execution unit 29, a confirmation request unit 30, and a storage unit 50. Here, the image processing unit 14, as will be described later, mainly consists of an image input unit, an image forming unit, and an image output unit. Furthermore, the virus information acquisition unit 21 includes a virus type determination unit 22 and an infection location identification unit 23.
[0028] The control unit 11 controls the operation of each component, such as the display unit 13 and the image processing unit 14, and is mainly implemented by a microcomputer consisting of a CPU, ROM, RAM, I / O controller, timer, etc. The CPU operates various hardware components organically based on control programs pre-stored in non-volatile memory such as ROM, thereby executing the image formation function, virus detection function, and other functions of this invention.
[0029] Furthermore, among the above components, the virus detection unit 20, the virus information acquisition unit 21 (virus type determination unit 22, infection location identification unit 23), the virus removal unit 24, the function execution feasibility determination unit 25, and the function operation setting unit 26 are functional blocks in which the CPU executes its respective processes based on a predetermined program.
[0030] The operation unit 12 is an input device for the user of the image forming apparatus 1 to perform predetermined input operations. For example, it is the part for inputting information such as characters or selecting functions, and a keyboard, mouse, or touch panel may be used. User-operated keys include the start key, function selection key, and settings key. For example, users can initiate document scanning by pressing a touch panel or a key to start the scanning operation, or initiate the transmission of information such as image data to a designated destination by pressing a transmission start key.
[0031] The display unit 13 is the part that displays information, and it displays information necessary for the execution of each function, as well as the results of the execution of the function, in order to inform the user. For example, if an LCD or organic EL display is used and a touch panel is used as the operation unit 12, the display unit 13 and the touch panel are arranged to overlap each other. The display unit 13 displays information such as settings for printing on the image forming apparatus, information necessary for executing functions such as document scanning, a screen for selecting the function to be executed (function selection screen), an operation screen for the selected function, and screens related to detected viruses, using characters, symbols, figures, images, icons, animations, videos, etc.
[0032] Furthermore, in this invention, the display unit 13 displays a function selection screen that includes selection display areas for each of the multiple functions. The user uses the operation unit 12 to perform an input operation to select a selection display area corresponding to the desired function in order to execute that function.
[0033] On this function selection screen, executable and non-executable functions are clearly displayed. For example, as will be described later, the selection display area for a function that has been set as an execution prohibition function by the function operation setting unit 26 may be displayed within the function selection screen in such a way that it cannot be selected by the operation unit 12. Furthermore, the display unit 13 shows screens indicating the virus infection status and removal status, such as virus detection, removal in progress, or removal completed.
[0034] The image processing unit 14 is the part that performs the image forming function, which is the main function of the image forming apparatus 1, and mainly consists of an image input unit, an image forming unit, and an image output unit. Primarily, the image input unit is responsible for inputting predetermined image data, the image forming unit is responsible for converting the input image data into information that can be printed, etc., and the image output unit is responsible for outputting the formed print information, etc., onto printing paper, etc.
[0035] The image input section is where image data of a document containing images, text, graphics, etc., such as print data intended for printing, is input. For example, it is the section that reads a document placed on a document glass or the like. For image input, a scanner (reading device) that reads documents containing information is used. The image forming apparatus 1 includes a document tray on which a document is placed and a document cover that holds the document in place, in order to read the document. Furthermore, the image forming apparatus 1 may be equipped with an automatic document feeder (ADF) that can take multiple documents and automatically transport and scan them one by one.
[0036] There are various methods for inputting image information, but for example, a document containing images can be scanned, and the image data of the document (hereinafter referred to as input image data) can be stored in the storage unit 50.
[0037] Furthermore, an interface for connecting external storage media, such as a USB memory stick, corresponds to the image input section. Alternatively, the desired electronic data files, such as image information to be input, may be saved on an external storage medium such as a USB memory stick. By connecting the USB memory stick to an input interface such as a USB terminal and performing a predetermined input operation on the operation unit 12, the desired electronic data files saved on the USB memory stick can be read and stored in the storage unit 50 as input image data.
[0038] When printing print data onto a recording medium, the image forming unit generally performs the following steps in sequence: charging, exposure, development, transfer, cleaning, static discharge, and fixing, to form the print data on the recording medium. In the development process, toner is supplied from the toner cartridge to the developing device, and the electrostatic latent image formed on the surface of the charged photoreceptor drum is developed, forming a toner image corresponding to the electrostatic latent image. The toner image formed on the surface of the photoreceptor drum is transferred onto the recording medium by a transfer device, and then fixed onto the recording medium by heating by a fixing device. The image forming unit also converts the input image data into information in a format that can be transferred and displayed.
[0039] The image output unit is the part that outputs the formed input image data, and is equivalent to, for example, a printer. However, the output of input image data is not limited to printing; it also includes storing input image data of scanned documents and sending input image data of scanned documents via fax. For example, storing scanned input image data on an external storage medium such as a USB memory stick, transmitting input image data to other information processing devices or servers via a network such as the internet, and classifying and saving it in a specific save folder (document filing) are also considered equivalent to image output.
[0040] The communication unit 15 is the part that communicates data with other communication devices via the network 2. Network 2 shall be able to utilize any existing communication lines, such as WANs (Internet), LANs, telephone lines, and dedicated lines. The connection to Network 2 can utilize any existing communication method, and the communication method can be either wired or wireless.
[0041] For example, the image forming apparatus (MFP) 1 is connected to a management server that stores information about viruses via a network 2, and data communication takes place between the MFP 1 and the management server, and information about existing viruses is obtained from the management server. Alternatively, it connects to a designated mail server and receives emails stored on the mail server or sends emails to the mail server.
[0042] Furthermore, in the image forming apparatus 1 of this invention, the communication unit 15 transmits to a terminal device owned by a manager or the like information that a virus has been detected, information about the detected virus, information about the current infection status, information that the virus could not be removed, information that the virus has been removed, and information requesting permission to restart a stopped function.
[0043] The fax processing unit 16 is the part that performs facsimile functions via the network 2. For example, a device connects to a designated facsimile communication device via a telephone line or the internet, and transmits information such as images, converted into data in a format that can be transmitted via facsimile, to the facsimile communication device. Alternatively, it can respond to incoming calls from facsimile communication devices via telephone lines or the internet, and receive information such as images transmitted from facsimile communication devices.
[0044] The virus detection unit 20 is the part that detects viruses that have entered the image forming apparatus. For example, when an email or image data file to be printed is received, a predetermined virus detection process is performed on the received email or other file. Virus detection can be performed using conventional detection methods. For example, if a file attached to an email contains a pattern specific to a known virus, it will be determined that the email contains that known virus.
[0045] The virus information acquisition unit 21 is the part that acquires information (called virus information) that identifies the detected virus. The virus information obtained includes, for example, the type of computer virus detected and the location where the detected computer virus infected the system. The type of computer virus detected is information determined by the virus type determination unit 22, which will be described later, and will be referred to as the virus type below. The location where the detected computer virus infected the system is information identified by the infection location identification unit 23, which will be described later, and will be referred to as the infection location below. In the following embodiments, it is assumed that at least the virus type and infection location are obtained as virus information; however, the information used to identify the detected virus is not limited to these.
[0046] The virus type determination unit 22 is the part that determines the type of virus detected. As described above, if the virus detected by the virus detection unit 20 is a known virus, its name and type are determined. For example, virus management information 52, as described later, may be stored in advance, and the virus management information 52 may be used to determine the virus name, virus type, and whether or not the virus can be removed, which are associated with known virus patterns.
[0047] Alternatively, you could query a server that manages information about viruses via the network to obtain the virus name and type corresponding to the detected virus pattern.
[0048] Virus types are classifications based on the behavior and characteristics of viruses. For example, viruses are generally classified into several types based on whether they can self-replicate, whether they operate independently, or whether they exist by parasitizing other programs, etc. In the following embodiments of this invention, viruses are primarily classified into the following four types, although they are not limited to these four types.
[0049] (1) Macro type (macro infection type) Macro-type viruses are viruses that infect programs that have macro functionality. They parasitize and infiltrate executable files within those programs. If a file contains a macro-type virus, opening that file will activate the virus and perform malicious actions.
[0050] (2) File type (file infection type) File-type viruses infect executable program startup files, or they infiltrate as executable program files themselves. When these files are executed, they infect stored, healthy files and perform malicious actions such as deletion, modification, or rewriting of those files.
[0051] (3) Trojan type (Trojan horse type) Trojan viruses, also known as Trojan horses, do not self-replicate but can operate independently. For example, they can infiltrate an email as an email attachment, disguised as a harmless program. Initially, they may remain undetected, but later attempt to perform actions such as destroying programs or downloading malicious software.
[0052] (4) Worm type (worm shape) Worm-type viruses can self-replicate and operate independently, possessing the ability to spread and infect other information processing devices connected to the same network, for example.
[0053] As described above, the type of virus identified is used to determine which functions are executable and which functions should be prohibited, as will be explained later.
[0054] The infection location identification unit 23 is responsible for identifying the location and route of infection of the detected virus, for example, by identifying the infected program, file, function, storage medium, etc. For example, if a virus is detected in a file attached to an received email, the infection location is identified as either email or the network. Furthermore, if the virus is detected on a USB memory stick connected to an image forming device, the infection location is identified as the USB memory stick (portable storage device). Alternatively, if the virus is detected in a storage device built into the image forming apparatus, such as a hard disk or SSD, which corresponds to the memory unit 50 of the image forming apparatus, the infection location is identified as the built-in storage device such as the hard disk.
[0055] In the following examples, we will describe the infection locations assuming there are three types: network, USB memory, and internal hard disk. As described above, the identified infection locations are used to determine which functions are executable and which are prohibited, as will be explained later.
[0056] The virus removal unit 24 is the part that removes detected viruses. Once the type of virus detected and the location of the infected file are identified, and if the detected virus can be removed, the virus itself will be deleted using an antivirus program or similar tool. Alternatively, you may delete or quarantine the infected files, delete or stop programs related to the infection location, or perform recovery operations.
[0057] The function execution permission determination unit 25 uses the virus information acquired by the virus information acquisition unit 21 described above to determine which of the numerous functions of the image forming apparatus should be permitted to execute and which should be prohibited from executing. In other words, when a virus is detected, the system determines whether or not each function can be executed based on information about the detected virus, the infection status, and whether or not it has been removed.
[0058] The determination of whether an action can be executed is made, for example, by using function operation status information, which is set to associate the type of virus detected with the infection location, and then, based on the function operation status information, which is associated with the type of virus detected and the location where the virus infected, it is determined whether each function should be allowed to run or should be prohibited.
[0059] For example, if "execution permitted" is set for the copy function in the function operation status information, it is determined that the user can select the copy function on the function selection screen and perform the copy operation (execution permitted). On the other hand, if the email function is set to "execution prohibited" in the function availability information, the user will not be able to select the email function on the function selection screen, and will not be able to send or receive emails (execution prohibited). The information regarding the feasibility of the function operation is stored in the memory unit 50 in advance, as will be described later, and an example of the detailed contents of this information will be described later.
[0060] Furthermore, the functions and other aspects affected by the detected virus are likely to differ significantly before and after the virus has been removed. After removing the detected virus, the functions affected by the virus will be reduced or eliminated, and even if most functions are allowed to run, the likelihood of problems such as the infection spreading will decrease.
[0061] In other words, the functions that should be allowed to execute and those that should be prohibited from executing, as determined by the function execution feasibility determination unit 25, differ before and after the detected virus is removed. The number of functions that should be allowed to execute after the detected virus is removed may be greater than the number of functions that should be allowed to execute before removal. The function availability information described later shows an example where the settings for enabling or disabling each function differ depending on whether the virus has been removed, during the removal process, or after the removal is complete.
[0062] In this way, after removing detected viruses, the operation of functions that were prohibited before removal can be permitted, and the number of functions that should be permitted can be increased, thereby improving the operating rate of the image forming apparatus. This also prevents situations where users are unable to use functions they want to use but which were prohibited, thus ensuring user convenience.
[0063] The function operation setting unit 26 is the part that sets whether or not each function can be executed based on the determination result determined by the function execution feasibility determination unit 25. Functions determined by the function execution feasibility determination unit 25 described above that should be allowed to be executed are set as allowed functions and made executable. On the other hand, functions that are determined to be prohibited from execution are set as prohibited functions, preventing them from being executed. Whether or not each function can be executed is set, for example, in the function execution setting information 55 described later. In the "Execution Permitted" column of the function execution setting information 55, information meaning "Execution Permitted" is set for functions that are permitted to be executed, and information meaning "Execution Prohibited" is set for functions that are prohibited from being executed.
[0064] For functions set in the execution permission function, for example, the user can select that function on a predetermined function selection screen, and if the user selects that function, the function execution unit 29 will execute that function.
[0065] On the other hand, functions that have been set as execution prohibited functions by the function operation setting unit 26 will not be executed, and the user will not be able to select those functions on the function selection screen. However, functions set to the execution prohibition function are prohibited from being executed by the function execution unit 29 until they reach a state where execution should be permitted, and only after reaching that state do they become functions that can be executed by the function execution unit 29.
[0066] The state under which execution should be permitted is, for example, after the detected virus has been removed by the virus removal unit 24. Once the detected virus has been removed, it is generally assumed that the virus will no longer cause malfunctions in the image forming apparatus and that there will be no risk of the virus spreading. Therefore, the previously prohibited function may be permitted to run.
[0067] However, if a higher level of security against viruses is required, after the virus removal unit 24 has removed the detected computer virus, the administrator of the image forming apparatus may be required to confirm that there are no effects from the removed virus. In this case, the condition under which execution should be permitted is after the administrator has confirmed that there are no effects from the removed virus. Even after a detected virus has been removed, if, for example, the infected program or file has been modified by the virus, the image forming apparatus may not function properly, and the effects of the removed virus may still remain. Therefore, in such cases, it is preferable to have the person in charge of management confirm that the image forming apparatus is actually functioning normally and that there is no impact from the removed virus.
[0068] The screen display control unit 27 is the part that switches the screen displayed on the display unit 13 in accordance with the virus detection status and removal status. Primarily, it generates screens showing the virus detection and removal status, as well as function selection screens, and displays the screen corresponding to the current status on the display unit 13. In particular, on the function selection screen, currently available functions are displayed in a selectable format, but functions that are prohibited may be displayed in a way that indicates they cannot be selected. By clearly distinguishing between executable and disabled functions, users can easily understand which functions are currently available and which are unavailable. Alternatively, to prevent selection errors, only currently available functions may be displayed, and functions that are disabled may not be shown.
[0069] The function execution prohibition unit 28 is a part that prevents the execution of a predetermined function, and if a predetermined function is currently being executed, it stops the execution of that function. For example, if a function has information indicating that execution is prohibited set in the function execution setting information 55, the execution of that function will be prohibited or stopped.
[0070] The function execution unit 29 is the part that executes a predetermined function selected by the user of the image forming apparatus. For example, if a function F has information indicating permission to execute set in the function execution setting information 55, and the user selects that function F, then that function F will be executed.
[0071] The confirmation request unit 30 is the part that, after the virus detected by the virus removal unit 24 described above has been removed, requests the person in charge of managing the image forming apparatus to confirm that there is no impact from the removed virus and to check the operating status of the image forming apparatus.
[0072] Generally, after a detected virus has been removed, it is assumed that the same malfunctions as those experienced during a virus infection will not occur even if previously prohibited functions are executed. However, in the case of Trojan-type viruses or new types of viruses, for safety reasons, it may be advisable to have the image forming equipment administrator confirm that the virus has been completely removed, that there are no problems with restarting previously disabled functions, and that there is no impact on the operation of other functions.
[0073] For example, it may be beneficial for the person in charge of managing the image forming machine to visit the machine's installation site, perform operational checks according to established standards, and use designated inspection tools to confirm that the virus has been completely removed.
[0074] Therefore, confirmation request information is generated indicating the infection status of the image forming machine, whether the detected virus has been removed, and whether the status of the image forming machine needs to be checked. This confirmation request information is then sent to a mobile device or other device carried by the administrator. Furthermore, if a manager is always stationed at the location where the image forming apparatus is installed, the confirmation request information may be displayed on the display unit 13 of the image forming apparatus, or the content of the confirmation request information may be announced by voice. Alternatively, in the event of a virus infection, an LED or other indicator could flash to show that a virus has been detected, or users near the image forming apparatus could be notified via voice message that a virus has been detected, that certain functions are unavailable, and that they should contact the administrator regarding the displayed information.
[0075] If the administrator receives a confirmation request on their mobile device, they should go to the location where the image forming apparatus is installed and perform the confirmation procedure described above. After the verification process is complete, if the administrator determines that it is permissible to resume a previously prohibited function, they may do so by using the operation unit 12 of the image forming apparatus to perform a predetermined input operation that signifies permission to execute the function.
[0076] However, if the administrator cannot immediately go to the location where the image forming apparatus is installed, or if, after reviewing the received confirmation request information, they determine that it is permissible to resume the prohibited functions without having to go to the installation location, they may send a confirmation response from a mobile terminal to the image forming apparatus, for example, granting permission to execute all functions. When an image forming apparatus receives an acknowledgment indicating permission to execute all functions, it can automatically enable all functions to be executed, thereby quickly lifting the execution restriction, improving the operating rate of the image forming apparatus, and ensuring user convenience.
[0077] The memory unit 50 is the part that stores information and programs necessary to perform each function of the image processing apparatus MFP of this invention, and uses semiconductor memory elements such as ROM, RAM, and flash memory, storage devices such as HDDs and SSDs, and other storage media. The memory unit 50 stores, for example, function operation availability information 51, virus management information 52, function restriction level information 53, detected virus information 54, function execution setting information 55, restriction level setting information 56, and so on.
[0078] The function operation availability information 51 is information that, when a virus is detected, sets whether or not each function provided in the image forming apparatus should be made executable (executable or not) in response to the situation after detection, and it is preferable to store this information in advance in the storage unit 50. However, the administrator of the image forming apparatus may be allowed to change the execution status of each function as needed. Specific examples of the functional operation status information 51 will be described later in Figures 2 to 9.
[0079] Virus management information 52 is information about known viruses and is stored in the memory unit 50 in advance. Figure 10 shows an explanatory diagram of one example of the virus management information 52. Figure 10 shows, for example, the virus management information 52, which stores four items (virus name, virus type, whether it can be removed, and virus pattern) associated with each of several known viruses. The items stored to identify the virus are not limited to the four items in Figure 10; for example, they may also include the time of outbreak, region of outbreak, infectivity, self-concealing ability, and destructive power.
[0080] Regarding whether removal is possible, for example, if a virus has just appeared and no removal tool is yet available, it will be set to "Removable," but if a removal tool is obtained, it will be set to "Removable." Virus patterns are primarily used to detect viruses and are obtained from servers or other sources that store information about viruses. For example, files stored in an image forming apparatus, files input or received for printing, and files received as email attachments are compared with the virus patterns in the virus management information 52. Files that have a pattern that matches a specific virus pattern are determined to be infected with a virus that has that virus pattern.
[0081] Figure 10's virus management information 52 shows information about eight known viruses. For example, the first virus has the virus name Vir-M01, the virus type is macrotype, the removal status is "removable", and it has a virus pattern named "VPAT001". However, since new viruses are constantly emerging, it is preferable to periodically obtain the latest information from servers that manage information about viruses and update the virus management information 52 using the obtained information.
[0082] Function restriction level information 53 is information that pre-sets the level at which the functions that can be performed after the detected virus has been removed are restricted. For example, three levels (high, medium, and low) can be pre-set to restrict the functions that can be executed, and information corresponding to each level can also be set. The function limitation level information 53 can, for example, be set by the administrator in charge of the image forming apparatus. However, the function restriction level information 53 and the restriction level setting information 56 described later do not necessarily need to be set, and if this information is not set, it may be assumed that the "medium" level is set by default.
[0083] Figure 11 shows an explanatory diagram of one embodiment of the function restriction level information 53. Figure 11's function restriction level information 53 shows the correspondence between the three restriction levels and whether or not administrator confirmation is required.
[0084] There are three levels of restrictions: "high," "medium," and "low," but these are not the only three levels. "Administrator confirmation" indicates that it is necessary to confirm with the administrator whether or not to allow the execution of a function that is currently prohibited.
[0085] The restriction level "High" represents the highest level of security. When this level is set, a sufficiently high level of security will be maintained even after the virus has been removed, and the execution of many functions will be prohibited. Furthermore, the corresponding "Administrator Verification" is set to "Required." If "Administrator Verification" is set to "Required," the verification request unit 30 described above will send verification request information to the administrator's mobile device. If the administrator responds to the confirmation request with information indicating permission to execute all functions, then all functions, including those that were previously prohibited, will be permitted to execute.
[0086] A restriction level of "Medium" indicates a security level that is slightly lower than that of "High." When this level is set, even after the virus has been removed, a relatively large number of functions will be prohibited in order to maintain a high level of security. Furthermore, the corresponding "Administrator Verification" will be set to "Required." Even at the "medium" restriction level, just like at the "high" restriction level, confirmation request information is sent to the administrator's mobile device.
[0087] The restriction level "Low" represents the lowest level of security. When this setting is selected, after virus removal, administrator confirmation will not be required, and in principle, all functions will be permitted to run. The corresponding "Administrator Confirmation" will be set to "Not Required." If "Administrator Verification" is set to "Not Required," the verification request unit 30 described above will not send verification request information to the administrator's mobile device. Therefore, if the restriction level is set to "low," after the virus has been removed, all functions of the image forming apparatus will be permitted to run immediately without waiting for a confirmation response or input from the administrator. In other words, when the restriction level is set to "low," all functions can be executed without waiting for confirmation from the administrator, thus improving the operating rate of the image forming machine.
[0088] The detected virus information 54 stores information about viruses actually detected by the virus detection unit 20 described above. Figure 12 shows an explanatory diagram of one example of detected virus information 54. The detected virus information 54 in Figure 12 shows information consisting of the detected virus name, virus type, infection location, and removal status. However, this information is not limited to these; other information such as the time of infection and the username used may also be included. If it is not necessary to record the results of removing detected viruses as a history, the removal status may be omitted.
[0089] The detected virus name and virus type are information obtained by the virus type determination unit 22, and the infection location is information obtained by the infection location identification unit 23. The removal status indicates whether or not the virus has been removed. For example, "X: Not removed" is set before the virus has been removed, and "○: Removed" is set when the virus removal is complete. For example, in the first virus in the detected virus information 54 of Figure 12, the detected virus name is Vir-M01, the virus type is macrotype, the infection location is that it entered from the network, and the removal status is that it has already been removed.
[0090] The function execution setting information 55 is information that stores whether each function provided in the image forming apparatus is currently available or unavailable. Figure 13 shows an explanatory diagram of one embodiment of the function execution setting information 55. Figure 13's function execution setting information 55 shows information consisting of function number, function name, and whether or not it can be executed. The function execution setting information 55 is information set by the function operation setting unit 26 based on the determination result of the function execution feasibility determination unit 25. Using the function operation feasibility information 51 described above, the execution permission or prohibition is set for each function based on the content of the execution feasibility information 51 that corresponds to the type of virus and infection location of the detected virus.
[0091] In the function execution setting information 55 shown in Figure 13, it is recorded that, in the current situation, the copy function and scanner function are permitted to be executed, while other functions such as the fax function with function numbers F03 to F07 are prohibited from being executed. By referring to this function execution setting information 55, functions for which "execution permitted" is set are executed by the function execution unit 29, and functions for which "execution prohibited" is set are prohibited from being executed by the function execution prohibition unit 28, and if the function is currently running, its execution is stopped.
[0092] The limit level setting information 56 is information that stores the limit levels set and entered by the administrator of the image forming apparatus from the function limit level information 53 described above. Figure 11 shows an example of the restriction level setting information 56, along with the function restriction level information 53 described above. Figure 11 shows the restriction level setting information 56, which indicates the case where "High" is set as the restriction level.
[0093] The restriction level can be set, for example, by displaying the function restriction level setting screen as shown in Figure 29. The administrator simply needs to select and enter one of the three restriction levels (high, medium, or low) displayed on the function restriction level setting screen.
[0094] Furthermore, while the explanation states that the function restriction level is uniformly selected from high, medium, or low, regardless of the type of virus detected, this is not the only option; different function restriction levels may be set for each of the four virus types mentioned above. For example, if the detected virus is a worm type, the restriction level may be set to "high" because there is a possibility of the infection spreading. Alternatively, if the detected virus is a macro-type virus, only file operations will be affected, so you can set the restriction level to "low".
[0095] Furthermore, the restriction levels in the restriction level setting information 56 should be set by the administrator, taking into consideration the location where the image forming apparatus is installed and the usage status of each function of the image forming apparatus. For example, if a manager wants to tighten the security of an image forming machine and severely restrict the functions it can perform, they can set the function restriction level to "High". Alternatively, if the number of image forming machines connected to the same network is small (for example, if there are only one or two image forming machines), or if the usage situation is such that confirmation and response from the administrator is rarely required, and the goal is to improve the operating rate of the image forming machines, the function restriction level may be set to "low".
[0096] <Example of Functional Operation Status Information 51> Figures 2 to 9 show specific examples of the functional operation status information 51. The functional operation status information 51 shown in these drawings is pre-set information indicating whether to allow or prohibit the execution of each of the seven functions (F01 to F07) of the image forming apparatus. Furthermore, after detecting a virus, different functional operation status information 51 is set according to the type of virus detected, the infection location, and whether or not the virus has been removed. In other words, the system pre-configures which functions can be executed and which cannot be executed based on the type of virus detected and the status of virus removal.
[0097] Note that the execution permission and execution prohibition for each function of the function operation availability information 51 shown in Figures 2 to 9 is just one example and is not limited to the settings of this information. For example, the person in charge of managing the image forming apparatus may change the content of the functional operation status information 51, taking into consideration the location and usage status of the image forming apparatus, the history of virus infection, etc.
[0098] The function operation status information 51 in Figure 2 shows information that sets whether each function can be executed after detecting a virus, identifying the type of virus, and before removing the virus. Furthermore, the types of viruses will be the four types mentioned above (macro type, file type, Trojan type, and worm type), and the infection location will be the network. When the infection location is identified as a network, this refers to cases such as when a file attached to an email received via the network is infected with a virus, or when an image file intended for printing, a document file intended for storage, or a configuration file for setting up a multifunction printer is infected with a virus and received via the network.
[0099] In Figure 2, since the virus has not yet been removed, performing the functions of the image forming apparatus may cause malfunctions in the apparatus or spread the virus. Therefore, it is preferable to prohibit the execution of many functions of the image forming apparatus. However, as shown in Figure 2, the copy function is not a function that performs communication processing over a network, but rather a function that can operate even when the network is disconnected, and is a function that is completed solely within the image forming apparatus. Therefore, if the detected virus type is a macro type or a file type, the execution of the copy function may be permitted. On the other hand, if the detected virus is a Trojan or worm, there is a possibility that the infection has spread to the memory of the image forming device, and that the system may be further destroyed by the virus, so the execution of the copy function will be prohibited. Furthermore, since functions F02 through F07 are network-based and pose a risk of infection spread, their execution will be prohibited regardless of the type of virus detected, as long as the virus has not yet been removed.
[0100] Figure 3's function operation status information 51 shows information that sets whether each function can be executed after the type of virus has been identified, and after virus removal has been initiated and is currently in the process of removal. While virus removal is in progress, macro types and file types have a low probability of secondary infection through binary data in faxes, and even internal storage alone has a low probability of secondary infection. Therefore, compared to before virus removal, it may be possible to allow the execution of functions that were previously prohibited, such as the fax function, which have a low probability of spreading the virus. As shown in Figure 3, for example, regarding the copy function, since it allows for virus removal and reduces the risk of secondary infection, the execution of the copy function is permitted not only for macro-type and file-type viruses, but also when the detected virus type is Trojan or worm-type. Furthermore, regarding the fax and file saving functions, since they reduce the risk of secondary infection, their execution is permitted only when the detected virus type is macro-type or file-type.
[0101] Figure 4's function operation status information 51 shows information that sets whether each function can be executed after the virus removal is complete but before the administrator confirms the removal. Furthermore, this example shows a case where the aforementioned limit level setting information 56 is not set. Once the virus removal is complete, the likelihood of the virus causing an impact is low, and since the virus is not active, the risk of secondary infection is extremely low. Therefore, compared to before and during the virus removal process, the likelihood of malfunctions in the image forming apparatus and the spread of the virus are considered to be lower. Therefore, as a general rule, once the virus removal is complete, all restrictions on functions may be lifted and all functions may be allowed to run. Note that the function operation status information 51 in Figure 4 is the same as the information when "Medium" is set in the restriction level setting information shown in Figure 6, which will be described later, but it is not limited to this.
[0102] However, in the function operation status information 51 in Figure 4, in order to ensure a high level of security, some functions remain prohibited from execution until the administrator confirms their removal. All functions will only be permitted to run after the administrator has confirmed that there are no problems with actually performing the removal and other necessary actions. In the function operation status information 51 of Figure 4, after the virus removal is complete, the scanner function, fax function, and file saving function are permitted to run regardless of the type of virus detected, because the possibility of the virus spreading via the network is low, and these functions create data within the multifunction device, thus reducing the likelihood of infection. Furthermore, regarding the remote printing function, since it is an operation executed from an external source, the system allows the function to run if the detected virus is of the macro or file type, and prohibits its execution if it is of the Trojan or worm type, which may modify the external execution instructions provided by the virus.
[0103] In Figures 5, 6, and 7, the function operation availability information 51 shows information that sets whether each function can be executed after the virus removal is complete, similar to Figure 4, but it shows the case where the restriction level setting information 56 described above is set. Since the virus removal process is complete, the number of functions that are prohibited from running is fewer compared to before and during the virus removal process.
[0104] The function operation availability information 51 in Figure 5 is the information when "High" is set in the restriction level setting information 56, the function operation availability information 51 in Figure 6 is the information when "Medium" is set in the restriction level setting information 56, and the function operation availability information 51 in Figure 7 is the information when "Low" is set in the restriction level setting information 56.
[0105] The function operation availability information 51 in Figure 5 indicates that the restriction level setting information 56 is set to "High," meaning the security level is relatively high and a relatively large number of functions are prohibited from being executed. In the function operation status information 51 of Figure 5, after virus removal is complete, the scanner function and file saving function are permitted to run regardless of the type of virus detected, because they are network input systems. Furthermore, regarding the fax function, since it uses binary data which is less likely to spread infection, the system allows the execution of the function if the detected virus is a macro type or file type, and prohibits its execution if it is a Trojan type or worm type which could potentially destroy the system and render it inoperable. On the other hand, the email function, remote printing function, and file transfer function are prohibited from execution regardless of the type of virus detected, because they involve communication over the network and output of data externally.
[0106] In Figure 6, the function operation availability information 51 indicates that the restriction level setting information 56 is set to "medium," resulting in a lower security level and relatively fewer functions being prohibited compared to the "high" setting. As described above, the settings for the function operation status information 51 in Figure 6 are the same as those in Figure 4.
[0107] The function operation availability information 51 in Figure 7 is set to "Low" in the restriction level setting information 56, so compared to the restriction levels of "Medium" and "High," it has the lowest security level and the fewest functions that are prohibited from being executed. In the function operation status information 51 in Figure 7, most functions are permitted, but in the event that the detected virus is of the worm type, in order to minimize the impact of data output to the outside and prevent the virus from spreading, the execution of only the email function and the file transfer function that transmits information over the network is prohibited.
[0108] The functional operation status information 51 in Figures 2 to 7 represents information when the virus infection location is identified as a network, but the functional operation status information 51 in Figure 8 represents information when the virus infection location is identified as a USB memory stick. Furthermore, Figure 8 shows information indicating whether or not each function can be executed, divided into four cases for the timing of virus processing. The virus processing process will be divided into four stages: before virus removal, during removal, after removal, and after removal confirmation by the administrator. Here, the USB memory is just one example; any so-called external storage medium that is temporarily connected to the image forming apparatus will suffice, and other infected locations include, for example, SSD storage devices and external hard drives.
[0109] In the function operation status information 51 in Figure 8, for example, before the detection of a virus is removed, only the copy function is made executable, and the other functions (F02 to F07) are prohibited from being executed. Furthermore, while a detected virus is being removed, only the copy and fax functions, which have a low probability of infection, are enabled, while other functions (F02, F04 through F07) are disabled. Furthermore, once the detected virus has been removed and confirmed to have been removed by the administrator, the virus removal is complete, as infection from the USB memory stick alone is considered sufficient, and the possibility of secondary infection is low. Therefore, all functions, including those that were previously prohibited, are made executable.
[0110] Figure 9, function operation status information 51, shows information when the location of the virus infection is identified as the internal hard disk. Furthermore, Figure 9, similar to Figure 8, shows information indicating whether or not each function can be executed, divided into four cases for the virus processing timing. Here, the built-in hard disk is just one example; any storage medium permanently built into the image forming apparatus is acceptable. In addition to the hard disk, other examples of infected locations include built-in SSD storage devices, SD cards, eMMCs, etc.
[0111] In the functional operation status information 51 of Figure 9, for example, before the detection virus is removed, the system is corrupted and it is uncertain whether it will work, so the execution of all functions is prohibited. Furthermore, since all functions use the internal hard disk, both during the removal of detected viruses and after the removal of detected viruses but before confirmation by the administrator, the execution of all functions is prohibited. However, once the detected virus has been removed and confirmed by the administrator, it is assumed that the administrator has confirmed that there are no adverse effects such as system disruption, and therefore all functions are made operational.
[0112] <Examples of virus detection and functional operation control processing for an image forming apparatus> (Example 1) Figures 14 to 17 show flowcharts of one embodiment of the virus detection and functional operation control processing of an image forming apparatus. Here, the function restriction level information 53 and restriction level setting information 56 described above will not be used, and after the virus removal is complete, the function operation availability information 51 in Figure 4 will not be used, but rather in Figure 4.
[0113] In step S1 of Figure 14, the virus detection unit 20 performs a virus detection check. If a virus is detected in step S2, proceed to step S3; otherwise, return to step S1.
[0114] In step S3, all functions of the image forming apparatus are stopped. Furthermore, for all functions in the function execution setting information 55, the execution status is set to execution prohibited (X). In step S4, the screen display control unit 27 displays a screen on the display unit 13 indicating that a virus has been detected and that all functions of the image forming apparatus have been stopped (virus detection screen: G1, Figure 19). For example, as shown in Figure 19, it displays information such as, "A virus has been detected. All functions will be restricted."
[0115] In step S5, the virus type determination unit 22 determines the virus name and type of the detected virus. Here, for example, the virus management information 52 described above is used to obtain the name and type of the known virus corresponding to the detected virus. Additionally, the name and type of virus obtained are stored in the detected virus information 54. In step S6, the screen display control unit 27 displays a screen on the display unit 13 showing the name of the detected virus or the type of virus (screen for determining the type of detected virus: G2, Figure 20). For example, as shown in Figure 20, the "Detected Virus Name" is displayed, and further, to show the currently available functions, a selection area such as "Show Available Functions OK" is displayed.
[0116] In step S7, the infection location identification unit 23 acquires the infection location. Furthermore, the acquired infection location is stored in the detected virus information 54. In step S8, the function execution feasibility determination unit 25 reads the function operation feasibility information 51. Here, since the virus has not yet been removed, if the infection location is a network, the functional operation status information 51 corresponding to "after virus type identification, before removal" is read, as shown in Figure 2 above. Furthermore, if the infection location is not on the network, for example, a USB memory stick or internal hard drive, the functional operation status information 51 shown in Figure 8 or Figure 9 is read.
[0117] In step S9, the function execution feasibility determination unit 25 uses the function operation feasibility information 51 and the detected virus information 54 to determine whether each function can be executed. Here, in the function operation availability information 51, the execution status is determined by the "function execution availability setting" which is set in accordance with the type of virus and infection location stored in the detected virus information 54. In step S10, the function operation setting unit 26 stores the result of the determination of whether or not the function can be executed in the function execution setting information 55. In other words, for each function of the image forming apparatus, a setting is made to enable or disable its execution (permit or prohibit execution).
[0118] In step S11, the suspension of the function that was set to allow execution in the function execution setting information 55 is released. In other words, among the functions whose execution was stopped in step S3, those that were set to allow execution are set to an executable state. In step S12, with screen G2 currently displayed, it is checked whether there is any input from a user who intends to use the image forming apparatus. If there is no user input, step S12 is repeated. On the other hand, if screen G2 is displayed and the user selects the "Display executable functions OK" area, the process proceeds to step S13.
[0119] In step S13, the screen display control unit 27 uses the function execution setting information 55 to display the function selection screen on the display unit 13. Here, the function selection screen displays a distinction between functions that can be executed and functions that are prohibited from being executed. For example, if the function operation status information 51 in Figure 2 is read and the detected virus is of the macro type and the infection location is the network, then only the copy function is permitted to be executed, and the execution of other functions is prohibited. As a result, the function selection screen G3 at the time of virus detection is displayed, as shown in Figure 21.
[0120] In the function selection screen G3 shown in Figure 21, six function selection display areas are displayed. Functions that have a predetermined prohibition mark superimposed on their selection display area indicate functions that cannot be executed. In other words, in Figure 21, only the copy function is selectable, and other functions such as the scanner function are not selectable because a prohibition mark is displayed over them. Alternatively, even if a user makes a selection input in the selection display area for other functions, such as the scanner function, that selection input will be ignored.
[0121] Alternatively, as shown in Figure 22, a function selection screen may be displayed that distinguishes between executable functions and non-executable functions. Note that Figures 21 and 22 show the selection screens for six functions, and the file transfer function (F07) is omitted, but it may also be displayed.
[0122] After step S13, proceed to step S21 in Figure 15. In step S21, it is determined whether or not the detected virus can be removed. For example, if the virus management information 52 shown in Figure 10 above has a setting indicating whether or not removal is possible, this virus management information 52 is used to determine whether or not removal is possible. If the detected virus can be removed in step S22, proceed to step S24; otherwise, proceed to step S23.
[0123] In step S23, since the detected virus cannot be removed, a message is sent to the image forming apparatus administrator stating that the detected virus could not be removed. In this case, the person in charge of managing the image forming equipment would be required to take measures against viruses that cannot be removed. After step S23, you can either proceed to step S53 in Figure 17, or you can terminate the process without waiting for confirmation of a response from the administrator.
[0124] In step S24, since the detected virus can be removed, the virus removal unit 24 starts removing the virus. In step S25, the screen display control unit 27 displays a screen on the display unit 13 indicating that it is performing removal of the detected virus (detected virus removal in progress screen: G4, Figure 23). For example, as shown in Figure 23, messages such as "Virus detection removal has started" and "Virus removal in progress" are displayed, and further, a selection area such as "Display available functions OK" is displayed to show the currently available functions.
[0125] In step S26, similar to step S8, the function execution feasibility determination unit 25 reads the function operation feasibility information 51. In this case, since the virus is being removed, if the infection location is the network, the function operation status information 51, which corresponds to "virus removal in progress," is read, as shown in Figure 3 above. Furthermore, if the infection location is not on the network, for example, a USB memory stick or internal hard drive, the functional operation status information 51 shown in Figure 8 or Figure 9 is read.
[0126] In step S27, similar to step S9, the function execution feasibility determination unit 25 uses the function operation feasibility information 51 and the detected virus information 54 to determine whether each function can be executed. Here, in the function operation availability information 51, the execution status is determined by the "function execution availability setting" which is set in accordance with the type of virus and infection location stored in the detected virus information 54.
[0127] In step S28, similar to step S10, the function operation setting unit 26 stores the result of the determination of whether or not the function can be executed in the function execution setting information 55. In other words, for each function of the image forming apparatus, a setting is made to enable or disable its execution (permit or prohibit execution).
[0128] In step S29, similar to step S11, the suspension of the function set to allow execution in the function execution setting information 55 is released. In other words, among the functions whose execution was stopped in step S3, those that were set to allow execution are set to an executable state. In step S30, with screen G4 currently displayed, it is checked whether there is any input from a user who intends to use the image forming apparatus. If there is no user input, step S30 is repeated. On the other hand, if the user selects and enters "OK to display executable functions" while screen G4 is displayed, the process proceeds to step S31.
[0129] In step S31, the screen display control unit 27 uses the function execution setting information 55 to display a function selection screen (detection and virus removal in progress: G5, Figure 24) on the display unit 13. Here, the function selection screen displays the functions that can be executed and the functions that are prohibited from being executed, in the same way as in Figure 21. For example, if the function operation status information 51 in Figure 3 is read and the detected virus is a file type and the infection location is a network, the copy function, fax function, and file save function are permitted to be executed, while other functions (scanner function, email function, remote printing function) are prohibited. As a result, the function selection screen G5 during virus removal is displayed, as shown in Figure 24.
[0130] In Figure 24, the function selection screen G5 shows a case where the infection location has been identified as a file attached to a received email. To clearly indicate that the email is the infection location (source), an infection source mark is displayed overlaid on the "Email" selection area. In Figure 24, a mark containing "!" is displayed as the source of infection, but this is not the only option. Any mark different from the prohibition mark is acceptable, and symbols or characters indicating the location of infection may also be displayed. While it is preferable to display such infection source marks to indicate the location of infection, they are not required, or the display of infection source marks may be set by the administrator.
[0131] In step S32, if the virus removal unit 24 has completed removing the virus, the process proceeds to step S33; otherwise, step S32 is repeated. In step S33, the screen display control unit 27 displays a screen on the display unit 13 indicating that the removal of the detected virus has been completed (screen after detection virus removal is complete: G6, Figure 25). For example, as shown in Figure 25, it displays messages such as "Detected virus removed" and "Virus removal complete," and further displays a selection area such as "Show available functions OK" to show currently available functions.
[0132] After step S33, proceed to step S41 in Figure 16. In step S41 of Figure 16, similar to step S8, the function execution feasibility determination unit 25 reads the function operation feasibility information 51. Here, since the virus removal is complete, if the infection location is a network, the functional operation status information 51 corresponding to "after virus removal is complete" is read, as shown in Figure 4 above. Furthermore, if the infection location is not on the network, for example, a USB memory stick or internal hard drive, the functional operation status information 51 shown in Figure 8 or Figure 9 is read.
[0133] In step S42, similar to step S9, the function execution feasibility determination unit 25 uses the function operation feasibility information 51 and the detected virus information 54 to determine whether each function can be executed. Here, in the function operation availability information 51, the execution status is determined by the "function execution availability setting" which is set in accordance with the type of virus and infection location stored in the detected virus information 54.
[0134] In step S43, similar to step S10, the function operation setting unit 26 stores the result of the determination of whether or not the function can be executed in the function execution setting information 55. In other words, for each function of the image forming apparatus, a setting is made to enable or disable its execution (permit or prohibit execution).
[0135] In step S44, similar to step S11, the suspension of the function that was set to be allowed to run is released in the function execution setting information 55. In other words, among the functions whose execution was stopped in step S3, those that were set to allow execution are set to an executable state. In step S45, with screen G6 currently displayed, it is checked whether there is any input from a user who intends to use the image forming apparatus. If there is no user input, step S45 is repeated. On the other hand, if screen G6 is displayed and the user selects the "Display available functions OK" area, the process proceeds to step S46.
[0136] In step S46, the screen display control unit 27 uses the function execution setting information 55 to display a function selection screen (after detection and virus removal is complete: G7, Figure 26) on the display unit 13. Here, the function selection screen displays the functions that can be executed and the functions that are prohibited from being executed, in the same way as in Figure 21. For example, if the function operation status information 51 in Figure 4 is read and the detected virus is of the macro type and the infection location is the network, the copy function, scanner function, fax function, remote printing function, and file saving function are permitted to be executed, and the email function is prohibited. Therefore, as shown in Figure 26, the function selection screen G7 at the time of virus detection is displayed. In the function selection screen G7 shown in Figure 26, a prohibition mark is displayed overlaid on the selection area for "Email," which is prohibited from execution. Furthermore, in the function selection screen G7 shown in Figure 26, an infection source mark indicating the infection location is displayed overlaid on the selection area for "Email," which is the infection location.
[0137] After step S46, proceed to step S51 in Figure 17. In step S51 of Figure 17, the confirmation request unit 30 generates information (confirmation request information) requesting the image forming apparatus manager to confirm the status after virus removal. The information requested for verification should include, for example, the name (model number) of the image forming machine, the installation location of the image forming machine, the name of the detected virus, the type of virus, the infection location, the time of infection, confirmation that removal has been completed, confirmation required after removal, and a list of various settings data for the multifunction printer. In step S52, the confirmation request unit 30 transmits the generated confirmation request information to a mobile terminal or the like held by the administrator.
[0138] In step S53, it is checked whether or not an acknowledgment sent from a mobile device or similar device held by the administrator has been received. Alternatively, the administrator may come to the installation site of the image forming apparatus, and after actually checking the status of the image forming apparatus after virus removal, if it is confirmed that the problem caused by the detected virus has been resolved and that normal operation is possible, the administrator may perform the prescribed input operation in response to the confirmation response. In this case, you only need to check whether or not a confirmation response is entered by the administrator.
[0139] If an acknowledgment is received or entered in step S54, proceed to step S55; otherwise, return to step S53. In step S55, if the received acknowledgment is a response indicating permission to execute all functions, proceed to step S56; otherwise, terminate the process. Alternatively, if the acknowledgment entered by the administrator indicates permission to execute all functions, the process proceeds to step S56.
[0140] In step S56, all functions of the image forming apparatus are set to "execution permitted," and the process is terminated. In other words, in the function execution setting information 55, "execution permitted" is set for the execution status of all functions. Furthermore, after all functions of the image forming apparatus have been set to "permission to execute," when the function selection screen is displayed, a screen will be shown without any prohibition marks in the selection display area for all functions.
[0141] As described above, when a virus is detected, the type of virus detected and the infection location are used to set which functions can be executed and which functions are prohibited, corresponding to the status of virus detection and removal. This prevents the spread of the virus and avoids a situation where all functions become unusable until the virus is removed. Furthermore, even after a virus infection has occurred but before removal is complete, functions that do not affect the operation of the image forming apparatus or the spread of infection are set to be executable. This suppresses a decrease in the operating rate of the image forming apparatus and ensures convenience for users who utilize the image forming apparatus for the executable functions.
[0142] (Example 2) Figure 18 shows a flowchart of one embodiment of the virus detection and functional operation control processing of an image forming apparatus. Here, the function restriction level information 53 and restriction level setting information 56 described above will be used, and after the virus removal is complete, the function operation availability information 51 shown in Figures 5 to 7 will be used. Furthermore, as shown in the function restriction level information 53 in Figure 11, if the restriction level setting information 56 is "high" or "medium", administrator confirmation will be required before all functions can be executed after the virus has been removed. On the other hand, if the restriction level setting information 56 is set to "low," after the virus has been removed, administrator confirmation will not be required, and all functions will be permitted to run.
[0143] In this embodiment, as in Embodiment 1 described above, the same process as shown in the flowcharts in Figures 14 and 15 will be performed, and after step S33 in Figure 15, the process will proceed to step S61 in Figure 18, instead of to Figure 16. The following explanation will omit the description of the processes from step S1 to step S33, which are the same as in Example 1, and will instead describe the processes from step S61 onwards in Figure 18.
[0144] In step S61 of Figure 18, the limit level setting information 56 stored in the memory unit 50 is read. The restriction level setting information 56 shall be one of the following: "High", "Medium", or "Low".
[0145] In step S62, the function operation feasibility information 51 corresponding to the read limit level setting information 56 is read. Here, the function operation status information 51 is information after virus removal is complete, and is, for example, one of the function operation status information 51 corresponding to the restriction level setting information 56 in Figures 5, 6, and 7. In other words, if the restriction level setting information 56 is "high", the function operation feasibility information 51 in Figure 5 is read out; if the restriction level setting information 56 is "medium", the function operation feasibility information 51 in Figure 6 is read out; and if the restriction level setting information 56 is "low", the function operation feasibility information 51 in Figure 7 is read out.
[0146] In step S63, similar to step S9, the function execution feasibility determination unit 25 uses the function operation feasibility information 51 and the detected virus information 54 to determine whether each function can be executed. Here, in the function operation availability information 51, the execution status is determined by the "function execution availability setting" which is set in accordance with the type of virus and infection location stored in the detected virus information 54.
[0147] In step S64, similar to step S10, the function operation setting unit 26 stores the result of the determination of whether or not the function can be executed in the function execution setting information 55. In other words, for each function of the image forming apparatus, a setting is made to enable or disable its execution (permit or prohibit execution).
[0148] In step S65, similar to step S11, the suspension of the function set to allow execution in the function execution setting information 55 is released. In other words, among the functions whose execution was stopped in step S3, those that were set to allow execution are set to an executable state.
[0149] In step S66, while screen G6 is currently displayed, it is checked whether there is any input from a user who intends to use the image forming apparatus. If there is no user input, step S66 is repeated. On the other hand, if screen G6 is displayed and the user selects the "Display available functions OK" area, the process proceeds to step S67.
[0150] In step S67, if the content of the function restriction level in the restriction level setting information 56 read is "low", proceed to step S68; otherwise, proceed to step S70. In step S70, if the content of the function restriction level in the restriction level setting information 56 read is "medium", proceed to step S71; otherwise, proceed to step S72. Step S72 is initiated only if the functional limitation level is set to "High".
[0151] In step S68, the screen display control unit 27 uses the function execution setting information 55 to display the function selection screen for when the function restriction level is "low" (after detection and removal of the virus is complete, the function restriction level is low: G9, Figure 28) on the display unit 13. Assuming that the function restriction level is "low," and therefore administrator confirmation is not required and all functions are permitted, then, as shown in Figure 28, all functions will be displayed as selectable in their respective selection areas. In other words, the prohibition mark is not displayed for any function. However, even in the function selection screen G9 shown in Figure 28, the infection source mark indicating the infection location is displayed overlaid on the selection display area for "Email," which is the infection location.
[0152] After step S68, in step S69, similar to step S56, all functions of the image forming apparatus are set to "execution permitted," and the process is terminated. In other words, in the function execution setting information 55, "execution permitted" is set for the execution status of all functions.
[0153] In step S71, the screen display control unit 27 uses the function execution setting information 55 to display the function selection screen for when the function restriction level is "medium" (after detection and removal of the virus is complete, the function restriction level is medium: G7, Figure 26) on the display unit 13, and then proceeds to step S51 in Figure 17. Here, we will use the same screen as the function selection screen displayed in step S46 of Figure 16 above, but a different screen may be used. As already explained, in the function selection screen G7 in Figure 26, a prohibition mark is displayed over the selection area for "Email," which is prohibited from execution. However, the selection areas for the copy function, scanner function, fax function, remote print function, and file save function, which are permitted to be executed, are displayed as selectable.
[0154] In step S72, the screen display control unit 27 uses the function execution setting information 55 to display the function selection screen for when the function restriction level is "high" (after detection and removal of the virus is complete, the function restriction level is high: G8, Figure 27) on the display unit 13, and then proceeds to step S51 in Figure 17. In this function selection screen, as in Figure 21, executable functions and functions that are prohibited from being executed are displayed separately.
[0155] For example, if the function restriction level is set to "high," the function operation availability information 51 in Figure 5 is read. If the detected virus is of the macro type and the infection location is the network, the copy function, scanner function, fax function, and file saving function are permitted, while the email function and remote printing function are prohibited. As a result, the function selection screen G8 after virus detection is complete is displayed, as shown in Figure 27. In the function selection screen G8 shown in Figure 27, a prohibition mark is displayed overlaid on the selection area for "Email" and "Remote Printing Function," which are prohibited from being executed. Furthermore, in the function selection screen G8 shown in Figure 27, an infection source mark indicating the infection location is displayed overlaid on the selection area for "Email," which is the infection location.
[0156] As described above, in Example 2, similar to Example 1, when a virus is detected, the type of virus detected and the infection location are used to set which functions can be executed and which functions are prohibited, corresponding to the status of virus detection and removal. This prevents the spread of the virus and avoids a situation where all functions become unusable until the virus is removed. Furthermore, by utilizing the function operation availability information 51 corresponding to the pre-set function restriction level, instead of uniformly requesting a confirmation response from the administrator after the virus has been removed, the system can avoid requesting a confirmation response from the administrator, as in the case where the function restriction level is "low," thereby suppressing the decrease in the operating rate of the image forming apparatus after the virus removal is complete and ensuring the convenience of users who use the image forming apparatus for the functions that can be executed. [Explanation of symbols]
[0157] 1. Image forming apparatus, 2 networks, 11 Control unit, 12 Operation section, 13 Display section, 14 Image Processing Unit, 15 Communications Department, 16. Fax Processing Section 20 Virus detection unit, 21 Virus Information Acquisition Unit, 22 Virus type determination unit, 23 Infection localization department; 24 Virus removal section, 25 Function execution feasibility determination unit, 26 Function operation setting unit, 27 Screen display control unit, 28 Function execution prohibition section, 29 Function execution unit, 30 confirmation request section, 50 storage section, 51. Functionality information, 52 Virus management information, 53. Functionality restriction level information, 54 Detected virus information, 55 Function execution settings information, 56 Restriction Level Setting Information
Claims
1. A virus detection unit that detects computer viruses, A virus information acquisition unit that acquires virus information to identify the detected computer virus, A function execution permission determination unit determines which functions should be allowed to run and which functions should be prohibited from running, using the acquired virus information. A function operation setting unit sets whether each function can be executed based on the determination result determined by the function execution feasibility determination unit, A function execution unit that performs the selected function, A function execution prohibition unit that prevents the execution of the function, The system includes a virus removal unit that removes the detected computer virus, The function operation setting unit sets functions that have been determined to be permitted to be executed as permitted functions, and functions that have been determined to be prohibited from being executed as prohibited functions. An information processing apparatus characterized in that, for a function set as an execution prohibition function by the function operation setting unit, the function execution prohibition unit prohibits the execution of the function until the function becomes permitted to be executed, and the function execution unit executes the function after the computer virus has been removed by the virus removal unit and the function becomes permitted to be executed.
2. Before removing the detected computer virus and after removing the detected computer virus, the functions that should be permitted to be executed and the functions that should be prohibited from being executed, as determined by the function execution feasibility determination unit, are different. The information processing apparatus according to claim 1, characterized in that the number of functions to be permitted to run after the detected computer virus has been removed is greater than the number of functions to be permitted to run before removal.
3. The system further includes a virus removal unit that removes the detected computer virus, The information processing apparatus according to claim 1, characterized in that the state in which the execution should be permitted is after the detected computer virus has been removed by the virus removal unit.
4. A virus removal unit that removes the detected computer virus, The system further comprises a confirmation request unit that, after the detected computer virus has been removed by the virus removal unit, requests the administrator to confirm that there is no impact from the removed computer virus, The information processing apparatus according to claim 1, characterized in that the state for which the execution should be permitted is after the administrator has confirmed that there is no impact from the removed computer virus.
5. The aforementioned virus information acquisition unit, A virus type determination unit that determines the type of computer virus detected, It includes an infection location identification unit that identifies the location where the detected computer virus has infected, The information processing apparatus according to claim 1, characterized in that the acquired virus information includes the type of computer virus detected and the location of the infection.
6. The system further includes a memory unit that pre-stores function operation status information, which is set to allow or disallow each function in correspondence with the type of computer virus and the location where the computer virus infected the system. The information processing apparatus according to claim 5, wherein the function execution feasibility determination unit uses the function operation feasibility information to determine, for each function, whether it is a function that should be permitted to be executed or a function that should be prohibited to be executed, based on the feasibility of executing the function associated with the type of computer virus detected and the location where the detected computer virus infected.
7. A display unit that displays a function selection screen including selection display areas for each of multiple functions, The system further includes an operation unit that performs an input operation to select the selection display area corresponding to the desired function in order to execute that function, The information processing apparatus according to claim 1, characterized in that the selection display area for a function set as an execution prohibition function by the function operation setting unit is displayed within the function selection screen in such a way that it cannot be selected by the operation unit.
8. The information processing apparatus according to any one of claims 1 to 7, characterized in that the information processing apparatus is an image forming apparatus having multiple functions.
9. A method for controlling the function operation of an information processing device, The control unit provided in the aforementioned information processing device, Virus detection steps for detecting computer viruses, A virus information acquisition step to obtain virus information that identifies the detected computer virus, A function execution permission determination step is performed to determine which functions should be allowed to run and which functions should be prohibited from running, using the virus information obtained above. Based on the determination results, the function operation setting step sets whether each function can be executed by setting the functions determined to be permitted to be executed as permitted functions and the functions determined to be prohibited to be prohibited functions. In the function operation setting step, the step of prohibiting the execution of a function that has been set as an execution prohibition function until it reaches a state where execution should be permitted, The steps include: executing the function after it has reached a state where it should be permitted to run; A method for controlling the functional operation of an information processing device, characterized by causing it to perform a specific action.