Information processing equipment, service systems, and programs

JP7899607B2Active Publication Date: 2026-08-04FUJIFILM BUSINESS INNOVATION CORP
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
FUJIFILM BUSINESS INNOVATION CORP
Filing Date
2022-06-29
Publication Date
2026-08-04

AI Technical Summary

Benefits of technology

【0021】 請求項1に記載の発明によれば、保持させないものの利用可能なデータの存在を、ネットワークの外部に設置されている他の情報処理装置に知らせることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007899607000001
    Figure 0007899607000001
  • Figure 0007899607000002
    Figure 0007899607000002
  • Figure 0007899607000003
    Figure 0007899607000003
Patent Text Reader

Abstract

To notify other information processing devices installed outside a network of the existence of data that is not retained but is usable.SOLUTION: A service system has: a real device 10 within a local network; and a virtual device 20 that provides the same service as the real device 10 outside the local network. During synchronization processing, a synchronization processing unit 13 transmits, to a synchronization processing unit 22, public data stored in a data storage unit 14 that can be retained and used by the virtual device 20 and information on the presence or absence of data local data that cannot be retained but can be used, and does not transmit perfect secrecy data that is not retained nor used. When the data local data exits in the real device 10, a service provision unit 21 acquires the data local data from the real device 10 and merges it with the held public data, and then provides it to a user.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, a service system, and a program.

Background Art

[0002] Recently, attempts have been made to provide cloud services by linking a multifunction device and a virtual device on the cloud corresponding to the multifunction device. As a result, a user can use services such as image processing provided by the multifunction device by accessing the virtual device on the cloud without directly accessing the multifunction device.

[0003] In Patent Document 1, it is possible to switch whether to execute a process in an on-premises environment or in a cloud environment based on the characteristics of data and workflows.

[0004] By the way, among the data handled when providing a service, there may be highly confidential data. From the perspective of security, retaining highly confidential data on the cloud is considered to have a higher risk of data leakage and the like compared to the case of keeping it within an on-premises environment. Therefore, if possible, it is not desirable to leave highly confidential data in the state held by the cloud.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] Traditionally, it has been possible to prevent highly confidential data from being made public, meaning that it cannot be stored or used outside the local network system. On the other hand, it is also possible to make less confidential data public, meaning that it can be stored and used outside the local network system.

[0007] However, some data handled by the service may be in an intermediate position: data that should not be stored outside the local network system, but should be used to provide services equivalent to those within the local network system from outside the local network system.

[0008] However, conventional technologies do not handle such intermediate data from a security standpoint. Therefore, the existence of such intermediate data was not disclosed to anything outside the local network system.

[0009] The present invention aims to inform other information processing devices located outside the network of the existence of usable data that is not to be retained. [Means for solving the problem]

[0010] The information processing apparatus according to the present invention is an information processing apparatus installed inside a local network system that provides services to a user, and comprises a processor, which acquires data used when providing the service and security level information indicating whether the data is first data with a first security level that can be held and used by other information processing apparatuses providing the service outside the local network system, second data with a second security level that can be used but not held, or third data with a third security level that cannot be held or used, associates the acquired data with the security level information of the data and stores it inside the network, and the other information processing apparatus for the usage data, which is usage data used when providing the service and includes one or more of the aforementioned data, Place The system is characterized by transmitting, during synchronization processing, the first data included in the usage data, and information indicating whether the second data is included in the usage data.

[0011] Furthermore, the processor is characterized in that it transmits the second data included in the usage data in response to a data transmission request from the other information processing device.

[0012] Furthermore, when the processor sets security level information for data used when providing the service and data generated when a job is executed, it is characterized by referencing the security level information of data selected by the user from among the data for which security level information has already been set, which is related to the job.

[0013] Furthermore, the processor is characterized by restricting the security level of the data generated by the execution of the job to be the same as or higher than the security level of the data selected by the user.

[0014] The information processing device according to the present invention is an information processing device installed outside a local network system that provides services to a user, and comprises a processor, wherein the processor acquires from another information processing device installed inside the local network system second data presence / absence information indicating whether the usage data includes first data with a first security level that can be retained and used, and second data with a second security level that cannot be retained but is usable, among the data included in the usage data used when providing the service, the processor retains the acquired first data and second data presence / absence information, controls the transmission of a data transmission request for the usage data to the other information processing device according to the content of the second data presence / absence information when providing the service, and provides the service using the data acquired from the other information processing device among the usage data.

[0015] Furthermore, if the second data presence / absence information indicates that the second data is not included, the processor provides the service using the acquired first data without sending the data transmission request.

[0016] Furthermore, the processor is characterized in that, if the content of the second data presence / absence information indicates that the second data is included, it sends the data transmission request to the other information processing device and provides the service using the acquired first data and the second data transmitted in response to the data transmission request.

[0017] The service system according to the present invention is characterized by comprising the information processing device described in claim 1 of this application and the information processing device described in claim 5 of this application.

[0018] Furthermore, the information processing device described in claim 5 of this application is characterized by having a device shadow function of the information processing device described in claim 1 of this application.

[0019] The program according to the present invention has a function to acquire data used when providing the service and security level information indicating whether the data is first data with a first security level that can be held and used by other information processing devices providing the service outside the local network system, second data with a second security level that can be used but not held, or third data with a third security level that cannot be held or used; a function to associate the acquired data with the security level information of the data and store it inside the network; and a function to associate the usage data used when providing the service, which includes one or more of the aforementioned data, with other information processing devices. Place The system provides a function to transmit, during synchronization processing, the first data included in the usage data, and information indicating whether the second data is included in the usage data.

[0020] The program according to the present invention enables a computer included in an information processing device installed outside a local network system that provides services to a user to perform the following functions: acquiring second data presence / absence information from another information processing device installed inside the local network system, which indicates whether the usage data includes first data with a first security level that can be retained and used, and second data with a second security level that cannot be retained but is usable, among the data included in the usage data used when providing the service; a function to retain the acquired first data and the second data presence / absence information; a function to control the transmission of a data transmission request for the usage data to the other information processing device according to the content of the second data presence / absence information when providing the service; and a function to provide the service using the data acquired from the other information processing device among the usage data. [Effects of the Invention]

[0021] According to the invention described in claim 1, the existence of available data that is not to be retained can be notified to other information processing apparatuses installed outside the network.

[0022] According to the invention described in claim 2, second data can be utilized in response to a request.

[0023] According to the invention described in claim 3, security level information can be set for data generated by executing a job by referring to the security level information already set for the data.

[0024] According to the invention described in claim 4, a security level higher than the already set data can be set for data generated by executing a job.

[0025] According to the invention described in claim 5, the existence of available data that is not to be retained can be known from other information processing apparatuses installed inside the network.

[0026] According to the invention described in claim 6, a service can be provided using only the first data.

[0027] According to the invention described in claim 7, a service can be further provided using the second data.

[0028] According to the invention described in claim 8, the existence of available data that is not to be retained can be notified to an information processing apparatus installed outside the network.

[0029] According to the invention described in claim 9, a shadow information processing apparatus can be made to utilize second data included in the utilization data without retaining it.

[0030] According to the invention described in claim 10, the existence of available data that is not to be retained can be notified to other information processing apparatuses installed outside the network.

[0031] According to the invention described in claim 11, the existence of usable data that is not retained can be known from other information processing devices installed within the network. [Brief explanation of the drawing]

[0032] [Figure 1] This is a configuration diagram showing one embodiment of the service system according to the present invention. [Figure 2] This figure shows an example of a data registration screen in this embodiment. [Figure 3] This figure shows an example of the data structure of the address book that is set and registered in the data storage unit of the actual device in this embodiment. [Figure 4] This figure shows another example of the data registration screen in this embodiment. [Figure 5] This figure shows an example of the data structure of job information that is set and registered in the data storage unit of the actual device in this embodiment. [Figure 6] This is a flowchart showing the synchronization process in the actual device of this embodiment. [Figure 7] This figure shows an example of the data configuration for the address book registered in the data storage unit of the virtual device in this embodiment. [Figure 8] This figure shows an example of the data structure related to job information registered in the data storage unit of the virtual device in this embodiment. [Figure 9] This is a flowchart showing the virtual device-side search process in this embodiment. [Figure 10] Figure 3 shows an example of settings after some of the address book data has been modified. [Figure 11] This figure shows an example of the data configuration for the address book set in the data storage unit of the virtual device after the settings of the address book data have been changed and the synchronization process has been performed in this embodiment. [Figure 12]This figure shows an example of the settings after modifying some of the job information data shown in Figure 5. [Figure 13] This figure shows an example of the data configuration for job information set in the data storage unit of a virtual device after the settings of the job information data have been changed and the synchronization process has been performed in this embodiment. [Figure 14] This figure shows an example of a settings screen for setting the security level for job information generated when the scan transmission service is executed in this embodiment. [Figure 15] This figure shows another example of a settings screen for setting the security level for job information generated when the scan transmission service is executed in this embodiment. [Modes for carrying out the invention]

[0033] Hereinafter, preferred embodiments of the present invention will be described based on the drawings.

[0034] Figure 1 is a configuration diagram showing one embodiment of the service system according to the present invention. It is also a diagram showing the block configuration of each information processing device. Figure 1 shows a service system in which information processing devices 10 and 20 and a user terminal 2 are connected by a network 4 such as the Internet.

[0035] Information processing device 10 is installed inside a local network system, generally referred to as an on-premises environment, of a company that provides services to users. In contrast, information processing device 20 is installed outside the local network system and communicates with information processing device 10 via network 4. As an example of an environment outside the local network system, this embodiment assumes a cloud environment. Of course, the environment outside the local network system is not limited to a cloud environment; for example, it may be installed in the systems of other companies, such as branches or agencies. Although information processing device 20 is another information processing device built separately from information processing device 10, it provides services equivalent to those of information processing device 10. In this embodiment, information processing device 20 has a device shadow function for information processing device 10, and is therefore built as a virtual device of information processing device 10. In the following description, information processing device 10 will also be referred to as a "real device" because it is an actual existing information processing device. Information processing device 20 will also be referred to as a "virtual device" because it is an information processing device virtually built on the cloud.

[0036] User terminal 2 is an information terminal device used by users who utilize the services provided by information processing devices 10 and 20. User terminal 2 can be implemented as, for example, a personal computer (PC), a tablet device, or a smartphone, or any other information terminal device equipped with communication capabilities that can access network 4. Users of user terminal 2 can selectively use the services provided by either information processing device 10 or 20. Although only one user terminal 2 is shown in Figure 1, multiple user terminals 2 may be connected to network 4.

[0037] The information processing device 10 can be implemented using a conventional, general-purpose hardware configuration such as a PC. Specifically, the information processing device 10 includes a CPU, ROM, RAM, storage means such as a hard disk drive (HDD), communication means such as a network interface for accessing the network 4, input means such as a mouse and keyboard, and a user interface including a display means.

[0038] The information processing device 10 includes a data management unit 11, a service provision unit 12, a synchronization processing unit 13, and a data storage unit 14. Components not used in the description of this embodiment are omitted from Figure 1.

[0039] The data management unit 11 performs data management such as registration, updating, and deletion of various data used in the service. The service provision unit 12 provides services to users by executing the service functions of the information processing device 10. The synchronization processing unit 13 performs synchronization processing to synchronize the data used when providing the service between the physical device 10 and the virtual device 20. The data storage unit 14 stores the data used when providing the service. The specific data structure will be described later.

[0040] Each component 11 to 13 of the information processing device 10 is realized through the coordinated operation of the computer forming the information processing device 10 and the program running on the CPU installed in the computer. The data storage unit 14 is realized by an HDD installed in the information processing device 10. Alternatively, RAM or storage means in a local network system may be used via the local network.

[0041] The information processing device 20 is a virtual information processing device and is implemented on one or more server computers located in the cloud. Of course, since the server computer is a computer, it is equipped with a CPU, ROM, RAM, storage means, communication means, etc.

[0042] Since the information processing device 20 has the same functions as the information processing device 10, it has a data management unit 21, a service provision unit 22, a synchronization processing unit 23, and a data storage unit 24, similar to the components 11 to 14 of the information processing device 10. Of these, the synchronization processing unit 23 performs synchronization processing in cooperation with the synchronization processing unit 13. The data management unit 21 performs data management, such as updating the data stored in the data storage unit 24 with data acquired from the information processing device 10 through synchronization processing. The service provision unit 22 provides services to the user in the same way as the service provision unit 12, but its operation differs slightly from that of the service provision unit 12. This will be explained later. In addition, the data storage unit 24 stores data used when providing services, similar to the data storage unit 14, but the structure of the data it holds differs slightly from that of the data storage unit 14. This will be explained later.

[0043] Each component 21-23 of the information processing device 20 is realized through the coordinated operation of one or more server computers forming the information processing device 20 and programs running on the CPUs installed in the server computers. The data storage unit 24 is realized using an HDD or RAM in the cloud.

[0044] Furthermore, the program used in this embodiment can be provided not only via communication means, but also stored on a computer-readable recording medium such as a USB memory stick. The program provided via communication means or recording medium is installed on the computer, and various processes are realized by the computer's CPU executing the program sequentially.

[0045] Next, we will describe the data used when providing the service in this embodiment.

[0046] Figure 2 shows an example of a data registration screen displayed on a display means such as a display in the actual device 10. Figure 2 shows an example of a screen for registering contacts used in the email function. When the information processing devices 10 and 20 provide an email address search service, the service provider sets the contact information from the contact registration screen shown in Figure 2. In this embodiment, as illustrated in Figure 2, the display name, email address, and security level are set. Of course, other information may also be added. The email address is the address information to which emails are sent, and the display name is information that identifies the individual and is displayed on the screen in place of the email address. The security level is a characteristic piece of information in this embodiment. The data management unit 11 acquires the data set by the service provider from the registration screen shown in Figure 2, and the security level of the data, and sets and registers them in the data storage unit 14.

[0047] Here, we will describe the security level that is a characteristic of this embodiment.

[0048] In this embodiment, three security levels are provided, and the security level is set for each piece of data. As mentioned above, the physical device 10 in this embodiment provides the same services to the virtual device 20, but the first security level is the level at which the virtual device 20 can both hold and use the data. In this embodiment, the first security level will be referred to as "public." The data at the first security level will be referred to as "first data" or "public data." The second security level is the level at which the data is not held by the virtual device 20 but is still usable. In this embodiment, the second security level will be referred to as "data local." The data at the second security level will be referred to as "second data" or "data local data." The third security level is the level at which the virtual device 20 cannot hold or use the data. In this embodiment, the third security level will be referred to as "completely confidential." The data at the third security level will be referred to as "third data" or "completely confidential data."

[0049] As explained above, the security levels of the data are in the order of 1st data < 2nd data < 3rd data. In other words, 3rd data has the highest security level, and 1st data has the lowest. In this embodiment, it is possible to set 2nd data, which is positioned in an intermediate position in terms of security. In this embodiment, for convenience, only the 2nd security level is set as the intermediate security level, but multiple levels may be set.

[0050] Figure 3 shows an example of the data structure of the address book set and registered in the data storage unit 14 in this embodiment. Personal data is set and registered in the address book, which is generated by associating information indicating the security level of the data with data used to provide the service set from the registration screen illustrated in Figure 2 (i.e., display name and email address).

[0051] Figure 4 shows another example of a data registration screen displayed on a display means such as a display in the actual device 10. Figure 4 shows an example of a screen for registering a document to be used with the printing function. When the information processing devices 10 and 20 provide a document printing service, the service provider, etc., sets and registers document information from the document registration screen shown in Figure 4. In this embodiment, as illustrated in Figure 4, the document name, print settings, and security level are set. Of course, other information may also be added. The document name is information that identifies the document to be printed, and the name of the document is set. The print settings contain attribute information for printing. Normally, paper size, color attributes, etc. are set, but these are not a feature of this embodiment, so they are omitted. The security level itself has been described above.

[0052] Figure 5 shows an example of the data structure of job information registered in the data storage unit 14 in this embodiment. Here, a print service is used as an example, so the job information corresponds to the print log information generated when printing is performed. The job information includes the document name, result, host name, user, date and time, and security level. Items other than the security level may be the same as those in existing job information. In this embodiment, the job information corresponding to the data is set with the security level set for the document to be printed from the registration screen shown in Figure 4. For example, referring to the registration screen shown in Figure 4, the document "Invoice.pdf" has a second security level called "Data Local" set, so the job information generated when "Invoice.pdf" is printed will have "Data Local" set as the security level.

[0053] The data shown in Figures 3 and 5 is an example of data that is set and registered in the data storage unit 14 of the physical device 10 as usage data used when providing a service. The virtual device 20 will be synchronized with the physical device 10 through a synchronization process, and here the synchronization process in this embodiment will be explained using the flowchart shown in Figure 6. Note that in Figure 6, the process is illustrated as it occurs on the physical device 10.

[0054] Synchronization processing is performed at predetermined intervals. For example, it may be performed periodically or sequentially whenever new data is registered. The data to be transmitted may, for example, store flag information indicating that unsynchronized data is associated with the data. Alternatively, specific information about unsynchronized data may be registered in a designated unsynchronized file, and this information may be deleted from the unsynchronized file when the data is transmitted.

[0055] The synchronization processing unit 13 first refers to the data storage unit 14 and extracts data with a security level of "public" included in the data being used, i.e., public data (step 101). Next, the synchronization processing unit 13 checks whether there is any data with a security level of "data local", i.e., data local data, in the data being used. If data local data exists (Y in step 102), the data local presence / absence information is set to "Yes" (step 103). If data local data does not exist (N in step 102), the data local presence / absence information is set to "No" (step 104). In this way, the data local presence / absence information corresponds to the second data presence / absence information and functions as flag information indicating whether or not there is data local data in the data being used. Then, the synchronization processing unit 13 sends the extracted public data and data local presence / absence information to the virtual device 20 (step 105).

[0056] The synchronization processing unit 23 in the virtual device 20 acquires data transmitted from the synchronization processing unit 13. The synchronization processing unit 13 and the synchronization processing unit 23 are configured to operate in coordination at predetermined timings, for example, by maintaining a constant synchronization path. Once the synchronization processing unit 23 acquires data, the data management unit 21 stores the acquired data by registering it in the data storage unit 24. In this embodiment, synchronization is achieved between the physical device 10 and the virtual device 20.

[0057] Here, we will explain the above synchronization process in more detail using a diagram.

[0058] Assume that the actual device 10 has data registered as shown in the address book in Figure 3. In other words, the data for users A, B, and C corresponds to the usage data described above. In this case, in step 101, the data for users A and B, which corresponds to the public data, is extracted. Also, since no data local data is set in the address book, "None" is set for the data local presence / absence information.

[0059] When the virtual device 20 receives data transmitted from the physical device 10, it registers it in the data storage unit 24. The structure of the data registered in this data storage unit 24 is shown in Figure 7. As is clear from Figure 7, the address book stored in the data storage unit 24 of the virtual device 20 contains only the public data from the data set in the address book of the physical device 10, in other words, the public data from the above-mentioned usage data. In addition, the data storage unit 24 of the virtual device 20 registers "None" as the data local presence / absence information corresponding to the address book. Note that the data related to the address book refers to the data registered in the address book and the data local presence / absence information associated with the address book.

[0060] The above explanation used an address book as an example, but next we will explain it in more detail using job information. Note that the synchronization process itself is the same, so we will omit the explanation. In the case of job information, as shown in Figure 5, the data "Invoice.pdf", "Specifications.ppt", and "Manual.doc" correspond to the usage data mentioned above. In this case, in step 101, the job information data for "Manual.doc", which corresponds to the public data, is extracted. Since the job information for the data-local data "Invoice.pdf" exists in the usage data, the data-local presence information is set to "Yes".

[0061] When the virtual device 20 receives data transmitted from the physical device 10, it registers it in the data storage unit 24. The structure of the data registered in this data storage unit 24 is shown in Figure 8. As is clear from Figure 8, the job information stored in the data storage unit 24 of the virtual device 20 contains only the public data from the data set in the job information of the physical device 10, in other words, the public data from the above-mentioned usage data. In addition, the data storage unit 24 of the virtual device 20 registers "Yes" for the data local presence / absence information corresponding to the job information. Note that the data related to job information refers to the job information data and the data local presence / absence information associated with the job information.

[0062] In this embodiment, data synchronization is achieved between the physical device 10 and the virtual device 20 as described above. In the synchronization process in this embodiment, public data is held on the virtual device 20. Completely confidential data is not even known to exist on the virtual device 20. Data-local data is not held on the virtual device 20, but its existence is known.

[0063] Next, we will describe the case in which the service system in this embodiment provides a search service to the user in response to a user request. First, we will explain the search process performed by the virtual device 20 using the flowchart shown in Figure 9.

[0064] When the service provider 22 in the virtual device 20 receives a search request from the user sent from the user terminal 2 (step 121), it performs a search on the data storage unit 24 in the virtual device 20 (step 122). Here, if the search target is the address book, as illustrated in Figure 7, data for user A and user B exists, so the search retrieves these two data. Next, the service provider 22 refers to the data local presence / absence information and controls the sending of a request to transmit usage data to the physical device 10 according to the settings of the data local presence / absence information. According to Figure 7, the data local presence / absence information corresponding to the address book is set to "none" ("none" in step 123), so the service provider 22 does not send a request to transmit usage data to the physical device 10. That is, the service provider 22 responds to the user with the data for user A and user B that it has already obtained from the physical device 10 and is holding internally as the search result (step 127). The service provider 22 provides the service to the user in this way.

[0065] In this case, if the search target is job information, as illustrated in Figure 8, the job information data for “Manual.doc” exists, so this single data is obtained by performing the search in step 122. Next, the service provider unit 22 refers to the data local existence information. According to Figure 8, the data local existence information corresponding to the job information is set to “Yes” (as set in step 123), so the service provider unit 22 requests the transmission of usage data. Since the public data has already been obtained, the usage data referred to here is the data local data. In other words, the service provider unit 22 queries the actual device 10 for data local data (step 124).

[0066] The service provision unit 12 on the physical device 10 searches for job information in response to an inquiry from the virtual device 20 (i.e., a request to send usage data). As shown in Figure 5, the job information includes a job for "invoice.pdf" with a security level of "data local," so the service provision unit 12 returns the job information for "invoice.pdf" as a search result.

[0067] When the service provider unit 22 in the virtual device 20 obtains search results from the physical device 10 (step 125), it merges the obtained search results with the results of the search it performed in step 122 (step 126). Then, the service provider unit 22 responds to the user with the job information for “Manual.doc” and the job information for “Invoice.pdf” obtained by merging, as search results (step 127). In this way, the service provider unit 22 provides the service to the user.

[0068] In this embodiment, as described above, the data of the second security level is not stored in the virtual device 20, but it can be used when providing services. The virtual device 20 operates independently to provide services if the data of the second security level does not exist in the physical device 10. On the other hand, if the data of the second security level exists in the physical device 10, the virtual device 20 operates in cooperation with the physical device 10 to provide services.

[0069] Incidentally, if the physical device 10 provides the search service to the user in the same way as the virtual device 20, the search results on the physical device 10 will include completely confidential data, unlike those on the virtual device 20. Therefore, users need to be aware of this before using the service.

[0070] By the way, while I used a virtual device 20 built on the cloud as an example of an information processing device that provides services equivalent to the physical device 10, it is not necessary to limit ourselves to this. In other words, other information processing devices different from the physical device 10 do not need to be limited to virtual information processing devices. For example, let's consider a case where another information processing device is a physical device installed at a different agency than the location where information processing device 10 is installed. The agency can be domestic or overseas. Although we would like the agency to provide the same level of service as our own company, for security reasons, the agency is basically a third party, so we may not want to provide all of our data. In such cases, it is convenient to be able to set a second security level for the data.

[0071] Figure 10 shows an example of settings after some of the address book data shown in Figure 3 has been changed. The data management unit 11 updates the address book settings according to the actions of the administrator or other user. Figure 10 shows an example where the security level of user B has been changed from "public" to "data local".

[0072] The synchronization processing unit 13 performs synchronization processing by coordinating with the synchronization processing unit 23 at predetermined timings. Figure 11 shows an example of the updated settings for the address book on the virtual device 20 as a result of this synchronization processing. As a result of changing user B's security level from "public" to "data local", user B's data is deleted from the address book on the virtual device 20, as shown in Figure 11, and the data local status information is changed to "yes".

[0073] Figure 12 shows an example of settings after some of the job information data shown in Figure 5 has been changed. The data management unit 11 updates the job information settings in response to operations by administrators, etc. Figure 12 shows an example where the security level of the job information generated when "Invoice.pdf" is printed has been changed from "Data Local" to "Public". As a result of this change, there will be no more data in the job information with a security level of "Data Local".

[0074] The synchronization processing unit 13 performs synchronization processing by coordinating with the synchronization processing unit 23 at predetermined timings. As a result of this synchronization processing, an example of the updated settings for job information on the virtual device 20 is shown in Figure 13. When the job information corresponding to "Invoice.pdf" is changed from "Data Local" to "Public", as shown in Figure 13, data corresponding to "Invoice.pdf" is added to the job information on the virtual device 20, and the data local status information is changed to "None".

[0075] Next, we will explain how to set a security level for job information generated when a scan-to-mail service is executed using the Scan to Mail function, by making effective use of data already registered in the address book.

[0076] Figure 14 shows an example of a settings screen for setting the security level for job information generated when the scan transmission service is executed. In Figure 14, the case where the scan transmission service is executed with User C as the destination is used as an example. As illustrated in Figure 10, User C has "Completely Confidential" set as their security level. Therefore, the job information related to User C should also have "Completely Confidential" set, just like User C. Figure 14 shows an example of a user interface where the security level is set by selecting from a dropdown menu. In this example, the data management unit 11 displays the dropdown menu with "Public" and "Data Local" disabled so that a security level lower than "Completely Confidential" cannot be set.

[0077] Figure 15 shows an example of a settings screen different from Figure 14. In Figure 15, the recipient is set to User B. User B has "Data Local" set as the security level, as illustrated in Figure 10. Therefore, job information related to User B should be set to "Data Local" or "Completely Confidential," which is higher than "Data Local" from a security standpoint, similar to User B. Accordingly, the data management unit 11 displays a dropdown menu where "Public" is unavailable to prevent the setting of a security level lower than "Data Local." In other words, the data management unit 11 displays a dropdown menu where either "Data Local" (the same as User B) or "Completely Confidential," which is a higher security level than "Data Local," can be selected.

[0078] Thus, when setting security level information for job information generated when a job that performs the scan transmission function is executed, the appropriate security level can be set for the job information by referring to the security level information of data selected by the user from among the data of users (users A to C in the above example) for which security level information has already been set in relation to the job (user C's data in Figure 14, user B's data in Figure 15). Then, the job information with the set security level can be used when providing the search service to the user, just like the job information obtained by executing the print service (for example, Figure 5).

[0079] In the above embodiment, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.).

[0080] Furthermore, the operation of the processor in the above embodiments may not be performed by a single processor, but may be performed by multiple processors located in physically separate locations working together. Also, the order of each processor operation is not limited to the order described in the above embodiments, but may be changed as appropriate. [Explanation of symbols]

[0081] 2 User terminals, 4 Network, 10 Information processing device (physical device), 11,21 Data management unit, 12,22 Service provision unit, 13,23 Synchronization processing unit, 14,24 Data storage unit, 20 Information processing device (virtual device).

Claims

1. In an information processing device installed within a local network system that provides services to users, Equipped with a processor, The aforementioned processor, When providing the said service, the system acquires data used in providing the said service, and security level information indicating whether the data is first data with a first security level that can be retained and used by other information processing devices providing the service outside the local network system, second data with a second security level that can be used but not retained, or third data with a third security level that cannot be retained or used. The acquired data and the security level information of that data are associated and stored within the network. When providing the aforementioned service, the system transmits the first data included in the usage data, and second data presence / absence information indicating whether the usage data includes the second data, during the synchronization process of the usage data, which includes one or more of the aforementioned data, with the other information processing device. An information processing device characterized by the following:

2. The information processing apparatus according to claim 1, characterized in that the processor transmits the second data included in the usage data in response to a data transmission request from the other information processing apparatus.

3. The information processing apparatus according to claim 1, characterized in that when the processor sets security level information for data used when providing the service and data generated when a job is executed, it refers to the security level information of data selected by the user from among data for which security level information has already been set, which is related to the job.

4. The information processing apparatus according to claim 3, characterized in that the processor restricts the security level of the data generated by the execution of the job to be the same as or higher than the security level of the data selected by the user.

5. In an information processing device installed outside a local network system that provides services to users, Equipped with a processor, The aforementioned processor, From another information processing device installed within the local network system, obtain second data presence / absence information indicating whether the usage data includes first data with a first security level that can be retained and used, and second data with a second security level that cannot be retained but is usable, among the data included in the usage data used when providing the service. The acquired first data and the information regarding the presence or absence of the second data are stored. When providing the service, the transmission of a data transmission request for the usage data to the other information processing device is controlled according to the content of the second data presence / absence information. The service is provided using data from the aforementioned usage data that has been acquired from the aforementioned other information processing device. An information processing device characterized by the following:

6. The information processing apparatus according to claim 5, characterized in that, if the processor indicates that the second data presence information does not contain the second data, it provides the service using the acquired first data without sending the data transmission request.

7. The aforementioned processor, If the content of the second data presence / absence information indicates that the second data is included, the data transmission request is sent to the other information processing device. The service is provided using the acquired first data and the second data transmitted in response to the data transmission request. The information processing apparatus according to feature 5.

8. The information processing apparatus according to claim 1, The information processing apparatus according to claim 5, A service system characterized by having the following features.

9. The service system according to claim 8, wherein the information processing device according to claim 5 has a device shadow function of the information processing device according to claim 1.

10. A computer included in an information processing device installed within a local network system that provides services to users, A function to acquire data used when providing the said service, and security level information indicating whether the data is first data with a first security level that can be retained and used by other information processing devices providing the said service outside the local network system, second data with a second security level that can be used but not retained, or third data with a third security level that cannot be retained or used. A function to associate acquired data with the security level information of said data and store it within the network. A function that, when performing the aforementioned service, transmits the first data included in the usage data and second data presence / absence information indicating whether the usage data includes the second data, during synchronization processing of the usage data, which includes one or more of the aforementioned data, with the other information processing device. A program to achieve this.

11. A computer included in an information processing device located outside the local network system that provides services to users, A function to acquire, from other information processing devices installed within the local network system, information regarding the presence or absence of second data, which indicates whether the usage data includes first data with a first security level that can be retained and used, and second data with a second security level that cannot be retained but can be used, among the data included in the usage data used when providing the service. A function to store the acquired first data and the presence or absence information of the second data. A function that controls the transmission of a data transmission request for the usage data to the other information processing device, depending on the content of the second data presence / absence information when providing the service. A function that provides the service using data acquired from other information processing devices among the aforementioned usage data. A program to achieve this.