Image forming apparatus

JP7899936B2Active Publication Date: 2026-08-04BROTHER KOGYO KK
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
BROTHER KOGYO KK
Filing Date
2025-10-08
Publication Date
2026-08-04

AI Technical Summary

Benefits of technology

【0009】 本発明によれば、画像形成装置に表示されている操作画面を、遠隔の情報処理装置で表示する場面においても、セキュリティレベルの低下を抑制することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007899936000001
    Figure 0007899936000001
  • Figure 0007899936000002
    Figure 0007899936000002
  • Figure 0007899936000003
    Figure 0007899936000003
Patent Text Reader

Abstract

To suppress a decrease in security level when an operation screen displayed on an image forming apparatus is displayed on a remote information processing apparatus.SOLUTION: The controller 11 in the MFP10 executes remote display control for transmitting remote information to the PC40 via the communication IF16, and the remote information is information for displaying a remote screen reproducing an operation screen displayed in the user IF17 on a browser provided in the PC40. The controller 11 acquires a limit parameter for determining the limit of the display content on the remote screen, and transmits remote information corresponding to the limit parameter to the PC40 in the remote display control, thereby displaying the remote screen with the limited display content on the browser.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technique for displaying an operation screen displayed on an image forming apparatus on a remote information processing apparatus.

Background Art

[0002] Patent Document 1 describes an image forming apparatus that displays a preview screen of an image after reading on a display unit in an image forming apparatus. Further, in the image forming apparatus described in Patent Document 1, for a document with a high security level, the security strength is enhanced by displaying the preview screen in a deteriorated state.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, a function of displaying an operation screen displayed on an image forming apparatus on a remote information processing apparatus is known. In such a function, when remotely displaying an operation screen including an image with a high security level on an information processing apparatus, there is a concern that the desired security level cannot be maintained.

[0005] The present invention Example of an embodiment is made in view of the above problems, and an object thereof is to suppress a decrease in the security level when displaying an operation screen displayed on an image forming apparatus on a remote information processing apparatus.

Means for Solving the Problems

[0006] In order to solve the above problems, the present invention Example of an embodimentThis invention relates to an image forming apparatus comprising a communication interface, a user interface, and a controller. The controller of the image forming apparatus performs remote display control, which transmits remote data to an information processing device via the communication interface. The remote data is data for displaying a remote screen, which reproduces the operation screen displayed on the user interface, in a browser provided by the information processing device. The controller performs an acquisition process to obtain restriction parameters that define the limitations on the display content of the remote screen. In the remote display control, the controller transmits remote data corresponding to the restriction parameters to the information processing device, thereby causing the browser to display a remote screen with limited display content.

[0007] In the above configuration, the controller performs remote display control by sending remote data to the information processing device via a communication interface, thereby displaying a remote screen that replicates the operation screen displayed on the user interface in the information processing device's browser. The remote display control performed by the controller restricts the content of the remote screen displayed in the browser by sending remote data corresponding to the acquired restriction parameters to the information processing device. As a result, even when displaying the operation screen shown on the image forming apparatus on a remote information processing device, the content of the remote screen is restricted, thus preventing a decrease in the security level.

[0008] The present invention can be realized in various forms, and can be realized not only as an invention of an image forming apparatus, but also as an invention of a control program executed by a controller. [Effects of the Invention]

[0009] According to the present invention, even when the operation screen displayed on an image forming apparatus is displayed on a remote information processing device, a decrease in the security level can be suppressed. [Brief explanation of the drawing]

[0010] [Figure 1]A diagram illustrating the configuration of an image forming system. [Figure 2] A flowchart illustrating the steps of the process executed by the MFP controller. [Figure 3] A diagram illustrating the SFL list. [Figure 4] A flowchart illustrating the steps of the process performed in S16 of Figure 2. [Figure 5] A diagram illustrating the EWS screen. [Figure 6] A diagram illustrating the remote screen. [Figure 7] A flowchart illustrating the steps of the process executed in S18 of Figure 2. [Figure 8] A diagram illustrating a remote screen with display restrictions. [Figure 9] A diagram illustrating a remote screen with display restrictions. [Figure 10] A diagram illustrating the remote screen according to the second embodiment. [Figure 11] A flowchart illustrating the steps of the process executed in S18 of Figure 2. [Modes for carrying out the invention]

[0011] (First Embodiment) The image forming system 100 according to this embodiment will be described with reference to the drawings. The image forming system 100 shown in Figure 1 comprises an MFP 10, a general user PC 30, an administrator PC 31, and a service technician PC 40. MFP is an abbreviation for multifunction peripheral. The MFP 10 and PCs 30 and 31 are connected to a LAN 200 and can communicate through the LAN 200. The LAN 200 is connected to the Internet 210, and the service technician PC 40 is connected to the Internet 210. In this embodiment, the MFP 100 is an example of an image forming apparatus. PCs 30, 31, and 40 are examples of information processing devices.

[0012] PCs 30, 31, and 40 include a CPU, a memory, a user IF, a display, and a network IF not shown in the figure. IF is an abbreviation of interface. The memory of PC 40 stores an OS and a browser program. The browser program is a program that connects to a web server via the Internet 210 and causes the display to show web page data managed by the web server.

[0013] Among PCs 30, 31, and 40, general user PC 30 is a PC used by a user who uses MFP 10 via LAN 200. Specifically, by operating on any of PCs 30, 31, and 40 and logging in to MFP 10, MFP 10 can be used. Administrator PC 31 is a PC used by an administrator who has the authority to manage MFP 10 on LAN 200. Service technician PC 40 is a PC used by a service technician who provides services such as maintenance and operation support for MFP 10.

[0014] ​​​​​​​​​The printer unit 13 performs a printing operation to print an image on a recording medium such as a sheet or a disk. As the recording method of the printer unit 13, an inkjet method, an electrophotographic method, or the like can be adopted. The scanner unit 14 performs a scanning operation to read an image recorded on a document and generate image data. The FAX unit 15 performs a FAX operation to transmit and receive image data in a manner compliant with the FAX protocol. Further, the MFP 10 may be capable of performing a composite operation combining a plurality of operations. A copy operation combining the print operation by the printer unit 13 and the scan operation by the scanner unit 14 is an example of a composite operation.

[0017] The controller 11 is composed of a CPU, an ASIC (abbreviation for Application Specific Integrated Circuit), etc., and controls the operations of the printer unit 13, scanner unit 14, FAX unit 15, communication IF 16, and user IF 17 that constitute the MFP 10. The memory 12 has a data storage area. The data storage area is an area for storing data necessary for the execution of programs and the like. The memory 12 is configured by combining a RAM, a ROM, an SSD, an HDD, etc. A buffer provided in the controller 11 used during the execution of various programs may also be regarded as a part of the memory 12. Note that the memory 12 may be a storage medium readable by the controller 11. A storage medium readable by the controller 11 is a non-transitory medium. Non-transitory media include recording media such as CD-ROMs and DVD-ROMs in addition to the above examples. Also, non-transitory media are tangible media. On the other hand, an electrical signal that conveys a program downloaded from a server on the Internet 210 or the like is a computer-readable signal medium, which is a kind of computer-readable medium, but is not included in non-transitory computer-readable storage media.

[0018] Memory 12 stores the control program 20 as a program that the controller 11 can execute. In the following description, the controller 11 that executes the program may also be referred to simply by the program name. For example, the phrase "control program 20" means "the controller 11 that executes the control program 20." In this embodiment, the processing of the controller 11 according to the instructions written in the program is mainly shown. That is, the processes such as "judgment," "extraction," "selection," "calculation," "decision," "identification," "acquisition," "reception," and "control" in the following description represent the processing of the controller 11. Note that "acquisition" is used as a concept that does not necessarily require a request. That is, the process of the controller 11 receiving data without a request is also included in the concept of "the controller 11 acquiring data." Also, "data" in this specification is represented by a bit sequence that can be read by the controller. Data that has the same substantial meaning but a different format will be treated as the same data. The same applies to "information" in this specification.

[0019] The control program 20 controls the printer operation using the printer unit 13, the scanner operation using the scanner unit 14, and the fax operation using the fax unit 15. The control program 20 also functions as an EWS (Embedded Web server), which is a web server. By functioning as an EWS, the control program 20 can display a browser screen on the browsers of each PC 30, 31, and 40. Specifically, when a user launches a browser on their PC and enters a URL specifying the control program 20 (i.e., the EWS), they can download the web page data created by the control program 20 and display the EWS screen, which is the browser screen, in their browser. In this embodiment, the web page data is an example of remote data.

[0020] Memory 12 stores the SFL (Secure Function Lock) list L1. The SFL list L1 sets whether or not there are execution restrictions on various operations and functions of the MFP10. Details of the SFL list L1 will be described later.

[0021] Next, we will explain the processes executed by the controller 11, referring to the diagram. Figure 2 is a flowchart showing the steps of the processes executed by the control program 20 of the MFC 10, and the main subject is omitted.

[0022] In S10, a standby screen is displayed to the user IF17. The standby screen includes shortcut icons and unregistered icons as operation icons for specifying various operations of the MFP10. For example, the standby screen includes shortcut icons for specifying "FAX operation," "copy operation," "scan operation," and "2-in-1 copy," as well as a shortcut icon for specifying "specific paper copy." In this embodiment, the specific paper copy is a function to copy invoices. In addition to invoices, the specific paper copy may also be a function to copy documents with a high level of security, such as driver's licenses, passports, and insurance cards. Each shortcut icon is basically not an icon that is pre-installed from the time the MFP10 is shipped, but rather an icon that is placed in place of an unregistered icon when the user arbitrarily performs a registration operation on an unregistered icon.

[0023] In S11, it is determined whether or not a user operation on user IF17 has been detected. If it is determined that an operation on user IF17 has been detected, the process proceeds to S19. In S19, it is determined whether or not the operation on user IF17 is a login operation to MFP10. If the result of S19 is positive, the process proceeds to S20, and the waiting screen is updated to a screen corresponding to the login operation.

[0024] In S21, the login ID received via user IF17 is obtained. In S22, the SFL list L1 corresponding to the login ID obtained in S21 is read. SFL list L1 contains restriction parameters for each "login ID" that identifies the logged-in user of MFP10, indicating whether there are restrictions on the operations of MFP10, such as "print operation," "copy operation," and "fax operation," and whether there are display restrictions on the function of MFP10, such as "remote display control." In SFL list L1 shown in Figure 3, items indicating operations or functions for which restrictions are set are checked, and items indicating operations or functions for which restrictions are not set are left unchecked. For the logged-in user "User A," since a restriction is set on "copy operation" in SFL list L1, if "User A" is logged into MFP10, MFP10 cannot perform the copy operation. The restriction parameters read from SFL list L1 are temporarily stored. Note that the values ​​of SFL list L1 can be set on the EWS screen described later. In this embodiment, the process executed by the controller 11 in S22 is an example of an acquisition process.

[0025] The controller 11 may also execute acquisition processing in response to operations received via the user interface 17 of the MFP 10. In this case, the controller 11 displays a settings screen for setting the contents of SFL list L1 on the user interface 17 based on the user operation received via the user interface 17. Then, it executes acquisition processing to set the contents of SFL list L1 in response to the user operation received on this settings screen.

[0026] If S22 is completed, or if S19 is determined to be negative, the process proceeds to S23. In S23, it is determined whether the operation performed on the user IF17 is an operation on a shortcut icon. If S23 is determined to be positive, the process proceeds to S24, and the screen displayed on the user IF17 is updated to correspond to the shortcut icon that was operated on. For example, if the user operates a shortcut icon that instructs a "copy operation", the copy operation by MFP10 is executed. If S23 is determined to be negative, the process proceeds to S28, and it is determined whether the screen needs to be updated due to the operation performed on the user IF17. If S28 is determined to be positive, the process proceeds to S29, and the screen is updated according to the operation received via the user IF17. If S28 is determined to be negative, or if the process of S29 is completed, the process returns to S11.

[0027] In S25, it is determined whether the operation performed on user IF17 corresponds to a service request. The service request is a request to a service technician to perform remote display control for remote support of MFP10. Specifically, remote display control is a control that displays a virtual screen, which is a virtual screen that virtually creates and displays the display of user IF17 on MFP10, in a PC browser. With remote display control, if the user performs an operation input on the remote screen displayed on the PC, the result is the same as if the same operation input was performed on user IF17 on MFP10. If the result in S25 is negative, the process returns to S11. In this embodiment, a service request is an example of a support request.

[0028] If S25 is determined to be positive, the process proceeds to S26, where a request transmission process for making a service request is performed. In this embodiment, as a service request, a command to request the start of remote display control for remote support is sent to the service technician's PC 40 via the communication IF 16. If the controller 11 has the service technician's email address stored in memory 12, it may also send the support request via email to this email address. Alternatively, if the controller 11 has the service technician's telephone number stored in memory 12, it may display the service technician's telephone number on the user IF 17 in S26. In this case, the user of the MFP 10 makes a support request to the service technician by calling the telephone number displayed on the user IF 17.

[0029] S27 remembers that a service request has been sent to the service technician.

[0030] Returning to S11, if no user action is detected, proceed to S12 to determine whether or not HTTP(s) communication, i.e., data communication following the HTTP(s) protocol, has been received. If it is determined that no HTTP(s) communication has been received, return to S11.

[0031] In S12, if it is determined that an http(s) communication has been received, the process proceeds to S13 to determine whether the http(s) communication is a display request to display the EWS screen. The EWS screen is a browser screen displayed by the browser using web page data created by the control program 20. A request to display the EWS screen is sent to the control program by entering a URL that specifies the control program 20 in the browser. If the http(s) communication is a request to display the EWS screen, in S14, the web page data to display the EWS screen's home screen is sent to the PC that sent the display request. If S14 is completed, the process returns to S11.

[0032] As a result of the S14 process, for example, when the EWS home screen is displayed on the service technician's PC 40, the user can enter a password in the login password input field on the screen displayed on any of the PCs 30, 31, or 40 and click the login button to receive various functions provided by the control program 20. The functions that can be provided from the EWS screen include remote display control for remotely operating the MFP 10 via the remote screen displayed on each PC 30, 31, or 40, and processing for updating items recorded in the SFL list L1. For example, if a user selects remote display control on the EWS screen after logging in, a remote display control start request is sent to the MFP 10 via http(s) communication.

[0033] On the other hand, if S13 is determined to be negative, the process proceeds to S15 to determine whether the http(s) communication is a request corresponding to an operation on the EWS screen. If the EWS screen is already displayed on the PC that sent the display request due to the processing in S14, and the user performs an operation on the EWS screen, an http(s) request corresponding to the operation on the EWS screen is sent to the MFP10. Therefore, if S15 is determined to be positive, the process proceeds to S16 to execute the processing corresponding to the operation received on the EWS screen. If S15 is determined to be negative, the process proceeds to S17.

[0034] Figure 4 is a flowchart illustrating the detailed processing performed in S16. In S30, it is determined whether the http(s) request corresponds to a login operation on the EWS screen. If S30 is determined to be positive, the process proceeds to S31, where the web page data necessary to display the updated EWS screen is sent to the requesting PC as part of the login process.

[0035] In S32, the logged-in user who performed the login operation on the EWS screen is temporarily stored in memory 12. Specifically, the user who performed the login operation is stored in memory 12 based on the "username" included in the http(s) request received in conjunction with the login operation on the EWS screen.

[0036] If the process in S32 is terminated or S30 is determined to be negative, the process proceeds to S33. In S33, it is determined whether the http(s) request is a remote display control start request. If S33 is determined to be positive, the process proceeds to S34, where it is determined whether the logged-in user stored in S32 is a service technician. If the logged-in user is a service technician and S34 is determined to be positive, the process proceeds to S35, where it is determined whether a service request has already been sent to the service technician. If a service request has not been sent to the service technician, the received remote display control start request may be a erroneous transmission, so the process in Figure 4 is terminated. In this case, remote display control is not started. On the other hand, if S35 is determined to be positive, the received remote display control start request is valid, so the process proceeds to S36, where the flag indicating to start remote display control is set to enabled. Then, the process proceeds to S17 in Figure 2. Note that the flag set in S36 is changed from enabled to disabled when the operation icon indicating the termination of remote display control is operated on the remote screen.

[0037] In S34, if the logged-in user is not a service technician, i.e., an administrator or a regular user logged into MFP10, the process proceeds to S36, where a flag indicating the start of remote display control is enabled. In other words, if the logged-in user is an administrator or a regular user, it can be determined that remote table control is not for the purpose of remote support, and therefore, the decision of whether or not to send a service request is not made. After the processing in S36 is completed, the process proceeds to S17 in Figure 2.

[0038] In S33, if the http(s) communication is not a remote display start request, the process proceeds to S37 to determine whether remote display control is currently being performed. If the flag indicating the start of remote display control has already been set to enabled by the processing in S36, S37 is affirmed and the process proceeds to S17 in Figure 2. On the other hand, if the flag indicating the start of remote display control is set to disabled, S37 is affirmed and the process proceeds to S38. In S38, it is determined whether an update of the EWS screen is required. If an update of the EWS screen is required in S38, the process proceeds to S39, and the web page data for displaying the updated EWS screen in the browser is sent to the PC that initiated the http(s) communication. If S39 is completed, or if S38 is denied, the process proceeds to S17 in Figure 2.

[0039] Returning to Figure 2, in S17, it is determined whether or not remote display control is currently being performed. Specifically, if the process proceeds to S17 via S36 in Figure 4, or after a positive determination in S37, the flag indicating that remote display control has started is set to enabled, so S17 is determined to be positive and the process proceeds to S18. On the other hand, if the process proceeds to S17 via S38 and S39 after a negative determination in S37, the flag indicating that remote display control has started is set to disabled, so S17 is determined to be negative and the process returns to S11.

[0040] In S18, remote display control is executed. Figure 5 shows the browser screen 300 that is displayed on one of the PCs 30, 31, or 40 when the standby screen is displayed on the user IF17 and remote display control is executed. The browser screen 300 includes an item display area 301 that displays Web page data provided by the control program 20, and a detail display area 302. The item display area 301 is an area that displays items indicating the functions that can be selected on the EWS screen. In Figure 5, since remote display control is selected on the EWS screen, the item "Remote Display Control" indicating remote display control is activated and displayed.

[0041] The detailed display area 302 is the area where the screen corresponding to the selected function is displayed. In Figure 5, the detailed display area 302 displays the remote screen 310, which is an image that reproduces the user interface 17. Specifically, the remote screen 310 includes a panel display image 311 corresponding to the standby screen and virtual key icons 312 corresponding to the operation keys. Therefore, the remote screen 310 includes the same shortcut icons as those displayed on the standby screen.

[0042] The remote screen shown in Figure 6 is the remote screen 310 that appears on any of the PCs 30, 31, or 40 when the user operates the standby screen displayed on the user IF17 to cause the MFP10 to perform a copy operation and display a preview screen of the scanned document on the user IF17. The remote screen 310 includes a preview screen 315 and operation icons 316. The preview screen 315 is a screen that displays the document scanned by the MFP10's scanning operation. The operation icons 316 are icons that accept instructions for processing the document displayed on the preview screen 315, such as zooming in and out, and even inverting it.

[0043] In the remote display control described above, when displaying a remote screen 310 containing high-security images such as certificates or ID cards on the service technician's PC 40, there is a concern that the desired security level for the images may not be maintained. For example, in the example in Figure 6, the remote screen 310 contains an original image M corresponding to an ID card, and there is a concern that displaying the remote screen 310 on the service technician's PC 40 will lower the security level. Therefore, in this embodiment, the reduction in the security level for the original document is suppressed by setting restrictions on the display of the remote screen 310 in the remote display control.

[0044] Next, the procedure for the remote display control process executed in S18 of Figure 2 will be explained using Figure 7.

[0045] In S40, it is determined whether the HTTP(s) communication is an HTTP(s) request with operation coordinates. Operation coordinates are generated in response to the operation of an icon on the remote screen 310 and are information indicating the coordinates of the operation performed on the remote screen 310. If S40 is rejected, the process proceeds to S41, where raster data corresponding to the operation screen currently displayed on the user IF17 is created. Note that if the remote screen 310 is not displayed on the PC that requested remote display control, the user cannot operate the icon on the remote screen 310, so S40 is rejected and the process proceeds to S41.

[0046] In S46, it is determined whether the user currently logged in on the EWS screen is a service technician. In this embodiment, if a service technician is logged in, it is determined that the remote display control is for the purpose of remote support. This is because when the operation of the MFP10 is supported via a remote screen 310 displayed by a remote service technician PC 40, the users on the service technician PC 40 side are an unspecified number of people, and the security level is likely to decrease. In such cases, the content displayed on the remote screen 310 is restricted. Specifically, if the logged-in user stored in S32 in Figure 4 is a service technician, S46 is judged affirmatively, and if the logged-in user stored in S32 is an administrator or a general user, S46 is judged negatively.

[0047] In addition to the above, in S46, if the IP address of the source of the http(s) request is the service technician's PC 40, it may be determined that the display of the remote screen is for the purpose of remote support, and if the IP address is that of a general user's PC 30 or an administrator's PC 31, it may be determined that the display of the remote screen is not for the purpose of remote support. In this embodiment, the login ID indicating the service technician and the IP address of the service technician's PC 40 are examples of the purpose information.

[0048] If S46 is determined to be positive, the process proceeds to S47, where it is determined whether the screen currently displayed on the user IF17 is a preview screen for scanner operation. If it is determined that the screen currently displayed on the user IF17 is a preview screen, the process proceeds to S48. In S48, the raster data created in S41 is modified by adding restrictions based on the restriction parameters read from the SFL list L1, and Web page data including the modified raster data is created. In other words, in this embodiment, display restrictions are applied only to the preview screen. At this time, the restriction parameters read are the restriction parameters read in S21 of Figure 2 according to the logged-in user of MPF10.

[0049] In this embodiment, the presence or absence of display restrictions on the remote screen 310 can be set in three modes by the restriction parameters recorded in the SFL list L1. As shown in Figure 3, "Off mode" is a mode in which, when the preview screen 315 is displayed on the remote screen 310, the original image M is displayed as is, that is, without any restrictions. "On mode" and "blur mode" are modes in which, when the preview screen 315 is displayed on the remote screen 310, the display of the original image M is restricted. Of these, "On mode" is a mode in which the original image M is hidden when the preview screen 315 is displayed on the remote screen 310. Specifically, as shown in Figure 8, in "On mode", the original image M is hidden by being grayed out on the preview screen 315. On the other hand, in "blur mode", when the preview screen 315 is displayed on the remote screen 310, the original image M is displayed in a blurred state. Specifically, as shown in Figure 9, in "blur mode," the original image M is blurred in the preview screen 315, making the original image M invisible.

[0050] For example, the method for recognizing the original image M from raster data can be done using well-known image processing methods such as pattern detection. Furthermore, the method for graying out or blurring the original image M can be done using, for example, well-known image processing methods such as filters.

[0051] If it is determined in S46 that the login is not that of a service technician, the process proceeds to S49. As described above, in this embodiment, if an administrator or a general user is logged in on the EWS screen, it is determined that remote display control for the purpose of remote support is not being performed, and therefore the display of the remote screen 310 is not restricted. For this reason, in S49, web page data is created that includes the created raster data as is. In other words, the web page data created in S49 is web page data that allows the browser to display the remote screen 310 corresponding to the preview screen as is. If it is determined in S47 that the preview screen is not being displayed, the process also proceeds to S49, and web page data is created that does not restrict the display of the remote screen 310.

[0052] When S48 or S49 is completed, the process proceeds to S50. If the process proceeds to S50 via S48, the web page data containing raster data with display restrictions is sent to the service technician's PC40 along with an http(s) response. Upon receiving the web page data along with the http(s) response, the service technician's PC40 parses the web page data. Based on the parse results, it then displays the raster data contained in the web page data in a browser. If the process proceeds to S50 via S49, the web page data containing raster data without display restrictions is sent to one of the destination PCs 30, 31, or 40 along with an http(s) response.

[0053] If the remote screen 310 is already displayed on the PC that requested remote display control due to the processing in S50, the user can operate an icon on the remote screen 310 displayed on the PC, sending a request with operation coordinates to the MFP 10. Therefore, if the http(s) request in S40 is a request with operation coordinates, the process proceeds to S42. In S42, it is analyzed whether the operation coordinates are within the area of ​​the operation icon on the remote screen 310. For example, a table recording the correspondence between the operation coordinates and the area of ​​the operation icon included in the remote screen 310 can be stored in memory 12, and the relationship between the operation coordinates and the area of ​​the operation icon can be analyzed by referring to this table.

[0054] If the operation coordinates are not within the area of ​​any operation icon, the operation on the remote screen 310 is not an operation to update the remote screen 310, so S43 is judged negative and the process in Figure 7 is terminated. On the other hand, if S43 is judged positive, the process proceeds to S44, and the operation screen displayed on the user IF17 is updated according to the operation of the operation icon corresponding to the operation coordinates. That is, the operation screen displayed on the user IF17 of the MFP10 is updated according to the operation of the operation icon on the remote screen 310.

[0055] In S45, raster data corresponding to the operation screen updated in S44 is created. The process proceeds to S46 to determine whether the login to the EWS screen is by a service technician. If S46 is confirmed, the process proceeds to S47 to determine whether the screen currently displayed on user IF17 is a preview screen. If S47 is confirmed, the process proceeds to S48 to modify the raster data created in S45 by restricting its display using restriction parameters, and then creates web page data containing the modified raster data. If S46 or S47 is confirmed negative, the process proceeds to S49 to create web page data containing the raster data created in S45 as is. In S50, the web page data created in S48 or S49 is sent along with an http(s) response to one of the destination PCs 30, 31, or 40.

[0056] The embodiment described above can achieve the following effects. The controller 11 transmits web page data to the service technician's PC 40 via the communication IF 16, thereby performing remote display control to display a remote screen 310 that reproduces the operation screen displayed on the user IF 17 in the browser of the service technician's PC 40. In the remote display control performed by the controller 11, the content displayed on the remote screen 310 in the browser is restricted by transmitting web page data corresponding to the acquired restriction parameters to the service technician's PC 40. As a result, even when the operation screen displayed on the MFP 10 is displayed on a remote PC, the content displayed on the remote screen is restricted, thus suppressing a decrease in the security level.

[0057] In remote display control, the controller 11 creates raster data containing multiple operation icons for displaying the remote screen 310 in the browser of the service technician's PC 40, and sends the web page data containing the raster data to the service technician's PC 40. When the controller 11 receives information from the service technician's PC 40 via the communication IF 16 indicating that an operation icon has been operated, it updates the operation screen displayed on the user IF 17 according to the received information. It creates raster data corresponding to the updated operation screen and sends the web page data containing the created raster data to the service technician's PC 40. As a result, the web page data sent to the service technician's PC 40 contains raster data whose display content is restricted according to restriction parameters, so even in a configuration where the operation screen displayed on the MFP 10 is updated in response to the operation of the remote screen 310 on the service technician's PC 40, the display content of the remote screen 310 displayed on the service technician's PC 40 can be restricted.

[0058] Controller 11 accepts input of restriction parameters from the MFP 10 administrator, but does not accept input of restriction parameters from anyone other than the administrator. In remote display control, it sends web page data corresponding to the accepted restriction parameters to the service technician's PC 40. As a result, the acquisition of restriction parameters is limited to operations performed only by the MFP 10 administrator, thus suppressing a decrease in the security level compared to when restriction parameters are changed by an unspecified number of people.

[0059] The restriction parameters are set in association with identification information that identifies a specific user of the service technician's PC 40. In remote display control, the controller 11 obtains the identification information from the service technician's PC 40 along with the remote display control request. If restriction parameters are set in the obtained identification information, the controller 11 sends web page data corresponding to the set restriction parameters to the service technician's PC 40. This allows restriction parameters to be set only for specific users, thus enabling different security levels for each user accessing the remote screen.

[0060] The controller 11, if the login ID indicates that the user is logged into the MFP 10, sends web page data to the general user PC 30 to display the remote screen 310 in a browser without any restrictions on the displayed content. As a result, the remote screen 310, without any restrictions on the displayed content, is displayed on the service technician PC 40 for the logged-in user of the MFP 10. Therefore, for example, if a user logged into the MFP 10 wants to display the remote screen 310 on the PC 30, the remote screen 310 can be displayed on the PC 30 without any restrictions on the displayed content.

[0061] Restriction parameters are set in association with purpose information indicating the purpose of remote display control. In remote display control, the controller 11 obtains purpose information from the service technician's PC 40 along with the remote display control request. If restriction parameters are set in the obtained purpose information, the controller 11 sends web page data corresponding to the set restriction parameters to the service technician's PC 40. This allows the system to switch whether or not to restrict the display of the remote screen depending on the purpose of the remote display control, thus enabling different security levels for each purpose of remote display control.

[0062] The objective information includes objective information indicating that the operation of the MFP10 is to be supported via the remote screen, and the restriction parameters are set in association with the objective information indicating that support is to be provided. As a result, when remote display control is performed for the purpose of supporting the operation of the MFP10 from a remote PC, the content displayed on the remote screen 310 is restricted, which helps to suppress a decrease in the security level, especially in situations where security is required.

[0063] (Modification of the first embodiment) Display restrictions on the remote screen 310 may be performed by processing on the service technician's PC 40. In this case, at S48 in Figure 7, the controller 11 sends information to the service technician's PC 40, along with the raster data, to restrict the display content of the raster data according to the restriction parameters, instead of creating restricted web page data. The browser on the service technician's PC 40 can then analyze the information according to the restriction parameters and perform processing to restrict the display of the raster data according to the analysis results.

[0064] (Second Embodiment) In the second embodiment, the configuration that differs from that of the first embodiment will be mainly described. Note that parts denoted by the same reference numerals as in the first embodiment indicate the same parts, and their descriptions will not be repeated.

[0065] In this embodiment, the restriction parameters are set in accordance with the operation screen displayed on the user IF17. Figure 10 shows the remote screen 310 that corresponds to the standby screen. The remote screen 310 includes a shortcut icon 330 for specifying "FAX operation", a shortcut icon 331 for specifying "copy operation", a shortcut icon 332 for specifying "scan operation", a shortcut icon 334 for specifying "2 in 1 copy", and a shortcut icon 335 for specifying "specific paper copy". In this embodiment, specific paper copy is a function for copying invoices. In addition to invoices, specific paper copy may be a function for copying documents or cards with a high level of security, such as driver's licenses, passports, and insurance cards. The remote screen 310 also includes unregistered icons 333 and 336.

[0066] In this embodiment, when remote display control is performed, the display of the remote screen 310 is restricted when the shortcut icon 335 is operated on the standby screen displayed on the user IF17. In this embodiment, the shortcut icon is an example of a shortcut image.

[0067] Figure 11 shows the detailed procedure of the display permission process performed in S18 of Figure 2 in this embodiment. In S41 or S45, raster data corresponding to the operation screen displayed on user IF17 is created. In S46, it is determined whether the logged-in user for the EWS screen is a service technician, and if so, the process proceeds to S60. In this embodiment as well, if the logged-in user is an administrator or a general user, the process proceeds to S49.

[0068] In S60, it is determined whether the screen updated by the operation of the shortcut icon on the user IF17 is subject to display restrictions on the remote screen 310. In this embodiment, if the shortcut icon 335 that specifies a specific paper copy is operated, S60 is determined to be positive and the process proceeds to S48. In S48, the created raster data is modified to restrict its display according to the restriction parameters, and Web page data containing the modified raster data is created. On the other hand, if S60 is determined to be negative, the process proceeds to S49. In S49, Web page data containing the created raster data as is is created.

[0069] In this embodiment, the SFL list stored in memory 12 records restriction parameters associated with each shortcut icon to be operated on. Therefore, in S48, the restriction parameters associated with the shortcut icon operated on the remote screen 310 are read by referring to the SFL list stored in memory 12. Alternatively, the restriction parameters may be read from the items in the SFL list referenced in S21 of Figure 2, depending on the logged-in user of the MFP 10. In this case, the SFL list stored in memory 12 only needs to record the shortcut icons subject to display restrictions and their control parameters associated with each logged-in user of the MFP 10.

[0070] The embodiment described above can achieve the following effects. The restriction parameters are set in correspondence with the operation screen displayed on the user IF17, and in remote display control, if the restriction parameters are set on the operation screen after switching, the controller 11 sends remote data corresponding to the set restriction parameters to the service technician's PC 40. This makes it possible to restrict the display content to only a predetermined operation screen among the operation screens after switching.

[0071] (Third embodiment) In the third embodiment, the configuration that differs from the first embodiment will be mainly described. Note that parts denoted by the same reference numerals as in the first embodiment indicate the same parts, and their descriptions will not be repeated.

[0072] In the first and second embodiments described above, display restrictions were applied to the remote screen 310 according to the restriction parameters. Alternatively, the areas on the remote screen 310 whose display is restricted will differ according to the restriction parameters. Specifically, the SFL list L1 contains areas on the remote screen 310 whose display is restricted, corresponding to the login ID. In this embodiment, when the address book is displayed as the remote screen 310, the display of the address display area included in the address book is restricted.

[0073] In this case as well, if the address book is displayed as the remote screen 310 in S47 of Figure 7, the process proceeds to S48. Then, web page data with the display of specific areas restricted according to the restriction parameters set for the logged-in user of the MFP10 is sent to the service technician's PC40. For example, in the address book, areas where addresses are expected to be displayed are grayed out or blurred.

[0074] In the embodiment described above, since it is possible to set areas on the remote screen 310 that restrict display for each user, it is possible to set areas on the remote screen 310 that enhance security for each user.

[0075] (Other embodiments) The present invention is not limited to the embodiments described above, and various modifications are possible without departing from its spirit. In the embodiments described above, the display of the remote screen 310 was restricted when the purpose of remote display control was remote support. Alternatively, the display of the remote screen 310 may be restricted uniformly regardless of the purpose of remote display control. In this case, the process in S46 of Figure 7 can be omitted.

[0076] In the embodiments described above, an MFP10 was used as an example of an image forming apparatus. However, the image forming apparatus is not limited to an MFP10; it may also be a standalone printer, scanner, or copier. [Explanation of symbols]

[0077] 10…MFC, 11…Controller, 12…Memory, 16…Communication Interface, 17…User Interface, 30…General User PC, 31…Administrator PC, 40…Service Technician PC, 100…Image Forming System

Claims

1. An image forming apparatus comprising a communication interface, a user interface, and a controller, The aforementioned controller, Remote display control is performed to transmit remote data to the information processing device via the communication interface, wherein the remote data is data for displaying a remote screen on the information processing device, which is a screen that reproduces the operation screen displayed on the user interface. The aforementioned controller, Among the aforementioned operation screens, it is possible to set restrictions on the remote screen that reproduces the preview screen. Image forming apparatus, in which, when a restriction is set for a remote screen that reproduces the preview screen, the remote display control transmits the remote data to the information processing device for displaying the remote screen in the restricted manner on the information processing device for the remote screen that reproduces the preview screen.

2. The controller is As part of the aforementioned restriction settings, it is possible to configure in which manner the display of the preview is restricted. The image forming apparatus according to claim 1, wherein, in the remote display control, the remote screen that reproduces the preview screen is transmitted to the information processing device to cause the information processing device to display the remote screen that has been restricted in a manner according to the settings.

3. The controller is If the setting of the restriction is to restrict the display of the preview in the manner of not displaying the preview, the remote display control transmits the remote data to the information processing device for displaying the remote screen that has been restricted in the manner of not displaying the preview on the information processing device, for the remote screen that reproduces the preview screen. The image forming apparatus according to claim 1 or 2.

4. The controller is If the setting of the restriction is to restrict the display of the preview by blurring the preview, the remote display control transmits the remote data to the information processing device for displaying the remote screen that has been restricted by blurring the preview on the information processing device, for the remote screen that reproduces the preview screen. The image forming apparatus according to any one of claims 1 to 3.

5. The controller is It is possible to set limitations on the image forming functions of the image forming apparatus, corresponding to each of multiple users. The image forming apparatus is configured to restrict the image forming function according to the settings associated with the user logged in to the image forming apparatus. The image forming apparatus according to any one of claims 1 to 4, wherein the restrictions applied to the remote screen that reproduces the preview screen can be set on the same screen as the screen for setting the restrictions on the image forming functions of the image forming apparatus, with each of the multiple users associated with it.

6. In the remote display control, the controller Raster data for displaying the remote screen on the information processing device, comprising creating raster data including a plurality of operation icons, The data, including the raster data, is transmitted to the information processing device as the remote data. When the information processing device that received the remote data via the communication interface receives information indicating that the operation icon has been operated, the operation screen displayed on the user interface is updated according to the received information. Create raster data corresponding to the updated operation screen, The remote data, including the created raster data, is transmitted to the information processing device. The image forming apparatus according to any one of claims 1 to 5, wherein the remote data includes information that restricts the display content of the raster data, or the raster data with restricted display content.

7. The aforementioned controller, The system accepts input of the restriction from the administrator of the image forming apparatus, and does not accept input of the restriction from anyone other than the administrator. The image forming apparatus according to any one of claims 1 to 6, wherein the remote display control transmits the remote data corresponding to the restriction received as input to the information processing device.

8. The aforementioned controller, A shortcut image that accepts a specified operation for switching the aforementioned operation screen can be set on the operation screen. The aforementioned restrictions are set in correspondence with the shortcut image, The image forming apparatus according to any one of claims 1 to 7, wherein, in the remote display control, if the restriction is set for the specified shortcut image, the remote data corresponding to the set restriction is transmitted to the information processing device.

9. The image forming apparatus according to claim 8, wherein the controller sets the shortcut images on the operation screen for each predetermined purpose in response to an operation received via the user interface.