Information processing device and image processing system
Patent Information
- Application Number
- JP2022107291
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-01
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2042-07-01
AI Technical Summary
【0029】 本開示によれば、情報処理装置において取得された印刷データに対して所定の感染対策処理を実行してコンピュータウイルスを検出し、実行された感染対策処理に関する設定項目を特定するウイルススキャン情報を生成し、コンピュータウイルスが検出されなかった印刷データにウイルススキャン情報を付加し、取得された印刷データのうち、ネットワークを介して接続された画像形成装置から要求された印刷データを含む印刷情報を生成して、画像形成装置に送信するので、画像形成装置における感染リスクを低減させることができる。 また、たとえば、画像形成装置において印刷等の処理をすべき印刷データが、情報処理装置から画像形成装置に転送される場合に、情報処理装置において、可能なかぎり適切なウイルス感染対策処理が実行された後に、印刷データが画像形成装置に送信されるので、画像形成装置がコンピュータウイルスに感染するおそれを軽減させることができ、画像形成装置において、印刷データに付加されたウイルススキャン情報を利用して、印刷データを印刷するか否かを判定することができる。
Smart Images

Figure 0007917327000001 
Figure 0007917327000002 
Figure 0007917327000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing apparatus and an image processing system, and particularly relates to an image processing system that performs infection countermeasure processing on print data and the like transmitted and received between an information processing apparatus having a virus infection countermeasure function for detecting and removing computer viruses, an information processing apparatus connected via a network, and a plurality of image forming apparatuses. [Background Art]
[0002] Conventionally, image forming apparatuses having a number of functions such as a printing function, a document reading function, a function for transmitting read image data, a function for acquiring image data, and a character recognition function have been used. There is also used an image processing system in which an image forming apparatus (referred to as a parent device) that temporarily stores image data received via a network and has a printing function and the like, and an image forming apparatus (referred to as a child device) having a function of printing the image data acquired from the parent device are connected via a network.
[0003] In some image processing systems, the parent device and the child device have a function of checking whether transmitted image data is infected with a predetermined computer virus (hereinafter also simply referred to as a virus), isolate image data infected with the virus, and print only image data not infected with the virus.
[0004] Furthermore, an image forming system is known in which multiple image forming machines are connected via a network, and each of the multiple image forming machines consists of a storage machine that stores print data and the like transmitted from an information processing terminal, and a client machine that accesses the storage machine and obtains print data from it. The storage machine performs a virus check on the received print data D1, and when a data request for the print data D1 is received from the client machine, it determines whether the virus check on the requested print data D1 has already been completed. If it is determined that the virus check has already been completed and predetermined conditions are met, it adds checked information D3 to the print data D1 and transmits it to the client machine.
[0005] In this system, when a client machine retrieves print data D1 from the storage machine, it checks whether checked information D3 is attached. If checked information D3 is attached, it starts printing without performing a virus check on the print data D1. If checked information D3 is not attached, it performs a virus check on the print data D1, thereby shortening the time it takes for the client machine to start printing. [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Japanese Patent Publication No. 2019-192956 [Overview of the project] [Problems that the invention aims to solve]
[0007] However, while it is preferable for virus checking performed in an image forming apparatus to be carried out using the latest virus scanning engine and the latest virus pattern files, if the virus pattern files used in the virus checking process have not been updated to the latest versions, the virus checking process will be carried out using outdated scanning engines and pattern files, which may result in an incomplete virus check and the inability to detect viruses.
[0008] For example, even if checked information D3 is added to print data D1, it is unknown whether the virus check process performed on the storage machine used the latest virus pattern files, etc., and the print data D1 sent to the client machine is not necessarily safe.
[0009] Furthermore, the checked information D3 only indicates that the print data D1 to which checked information D3 is attached has already undergone virus checking; it does not necessarily prove that the print data D1 is not infected. Print data that has not yet undergone virus checking on the storage device is also sent to the client device, so the risk of the client device becoming infected is not completely eliminated.
[0010] Furthermore, print data that has completed the virus check process but does not meet the specified conditions, or print data for which the virus check process has not been performed, will not have the checked information D3 attached, and the virus check process will be performed on the client machine. In such cases, it may not be possible to shorten the time until print output starts. Moreover, if the virus check process on the client machine does not use the latest virus pattern files, there is a risk of infection from print data that could not be cleaned of viruses.
[0011] Therefore, this disclosure has been made in consideration of the circumstances described above, and aims to reduce the risk of computer virus infection in image forming apparatuses when multiple image forming apparatuses are connected via a network and image data to be processed, such as printing, is transferred from a master unit to a slave unit, by having the master unit or slave unit perform virus infection prevention processing using the newest possible virus scanning engine and new virus pattern files. [Means for solving the problem]
[0012] This disclosure provides an information processing device comprising: a print data acquisition unit that acquires print data; a virus detection unit that performs predetermined infection control processing on the print data and detects computer viruses; a virus scan information generation unit that generates virus scan information that identifies setting items related to the executed infection control processing and adds the virus scan information to print data in which no computer viruses were detected by the virus detection unit; a print information generation unit that generates print information from the acquired print data, including print data requested from an image forming apparatus connected via a network; and a print information transmission unit that transmits the generated print information to the image forming apparatus.
[0013] Furthermore, the print information generation unit is characterized by generating print information that includes print data to which the virus scan information has been added, which is print data requested by the image forming apparatus.
[0014] Furthermore, the infection control process includes a virus scan process that detects known computer viruses using a predetermined virus scan engine and a predetermined virus pattern file, and the virus scan information includes the name and version information of the virus scan engine, the version information of the virus pattern file, and the date information on which the virus pattern file was obtained.
[0015] Furthermore, the information processing device may be an image forming apparatus that temporarily stores the acquired print data and has an image forming function.
[0016] Furthermore, this disclosure relates to an image processing system in which a first image forming apparatus for temporarily storing print data and a second image forming apparatus for printing the print data are connected via a network, wherein the first image forming apparatus includes: a print data acquisition unit for acquiring print data; a storage unit for temporarily storing the acquired print data; a virus detection unit for executing predetermined infection control processing on the print data and detecting computer viruses; a virus scan information generation unit for generating virus scan information that identifies setting items related to the executed infection control processing and for adding the virus scan information to print data in which no computer viruses were detected by the virus detection unit; and a print information generation unit for generating print information from the temporarily stored print data, including print data requested by the second image forming apparatus. The present invention provides an image processing system comprising: a print information transmission unit that transmits the generated print information to the second image forming apparatus; a print data request unit that requests the first image forming apparatus to transmit predetermined print data from the print data temporarily stored in the first image forming apparatus; a print information receiving unit that receives the print information transmitted from the first image forming apparatus; a scan information acquisition unit that acquires virus scan information attached to the print data included in the received print information; a print feasibility determination unit that determines whether or not to print the print data included in the received print information using the acquired virus scan information; and a function execution unit that prints the print data when the print feasibility determination unit determines that the print data should be printed.
[0017] Furthermore, the image processing system is characterized in that the print information generated by the print information generation unit includes print data to which the virus scan information has been added. Furthermore, in the image processing system, the infection control process includes a virus scan process that detects known computer viruses using a first virus scan engine and a first virus pattern file, and the virus scan information includes the name and version information of the first virus scan engine, the version information of the first virus pattern file, and the date information on which the first virus pattern file was acquired.
[0018] Furthermore, if the print information received by the print information receiving unit includes print data with the virus scan information attached and print data without the virus scan information attached, the print permission determination unit determines that the print data with the virus scan information attached should be printed, and that the print data without the virus scan information should not be printed.
[0019] Furthermore, the first image forming apparatus, upon receiving a job list request transmitted from the second image forming apparatus, further comprises a job list processing unit that, when the first image forming apparatus receives a job list request, generates a job list from the print data temporarily stored in the storage unit of the first image forming apparatus that includes the name of the print data requested by the job list request, and if the requested print data is print data to which the virus scan information has been added, also includes the virus scan information, and transmits the generated job list to the second image forming apparatus that sent the job list request.
[0020] Furthermore, the second image forming apparatus further comprises a job list receiving unit that receives the job list transmitted from the first image forming apparatus, and a display unit, wherein when the job list receiving unit receives the job list, it causes the display unit to display the received job list.
[0021] Furthermore, the second image forming apparatus further comprises a second virus detection unit that performs infection control processing on the received print data, including a virus scan process that detects known computer viruses using a second virus scan engine and a second virus pattern file, and a second storage unit that stores scan processing information including the name and version information of the second virus scan engine, the version information of the second virus pattern file, and the date information on which the second virus pattern file was acquired. The printability determination unit compares the virus scan information attached to the received print data with the scan processing information stored in the second storage unit, and determines that the print data should be printed if the virus scan information is newer than the scan processing information, and determines that the print data should not be printed if the virus scan information is older than the scan processing information.
[0022] Furthermore, the printability determination unit compares the date information of the acquisition of the first virus pattern file included in the virus scan information attached to the received print data with the date information of the acquisition of the second virus pattern file included in the scan processing information stored in the second storage unit. If the date information of the acquisition of the first virus pattern file is newer than the date information of the acquisition of the second virus pattern file, the unit determines that the print data should be printed. If the date information of the acquisition of the first virus pattern file is older than the date information of the acquisition of the second virus pattern file, the unit determines that the print data should not be printed.
[0023] Furthermore, the second virus detection unit executes the infection control processing on print data that the printability determination unit has determined not to print, so that print data in which a computer virus is detected is not printed, and print data in which no computer virus is detected is printed.
[0024] Further, the first image forming apparatus further comprises an encryption unit that encrypts the generated virus scan information with a first encryption key, wherein the virus scan information generation unit adds the encrypted virus scan information to the print data, the second image forming apparatus further comprises a decryption unit that decrypts the encrypted virus scan information with a second encryption key, and after the decryption unit decrypts the encrypted virus scan information added to the print data included in the print information received by the print information receiving unit, the scan information acquisition unit acquires the decrypted virus scan information as virus scan information.
[0025] Further, in a case where the print information received by the print information receiving unit includes print data to which the encrypted virus scan information is added, when the decryption unit decrypts the encrypted virus scan information, the print permission / denial determination unit determines that the print data to which the encrypted virus scan information is added is to be printed if the decryption is successfully performed, and determines that the print data to which the encrypted virus scan information is added is not to be printed if the decryption is not successfully performed.
[0026] Further, the first encryption key is a private key of the first image forming apparatus, and the second encryption key is a public key of the first image forming apparatus. Further, the first encryption key is a public key of the second image forming apparatus, and the second encryption key is a private key of the second image forming apparatus.
[0027] Furthermore, the second image forming apparatus further includes a second virus detection unit that performs infection control processing, including virus scanning to detect known computer viruses, on the received print data using a second virus scanning engine and a second virus pattern file, and the second virus detection unit performs the infection control processing on print data that the printability determination unit has determined not to print, so that print data in which a computer virus is detected is not printed, and print data in which no computer virus is detected is printed.
[0028] Furthermore, this disclosure relates to an infection control method for an image processing system in which a first image forming apparatus for temporarily storing print data and a second image forming apparatus for printing the print data are connected via a network, wherein a first control unit provided in the first image forming apparatus performs the following steps: a print data acquisition step for acquiring print data; a storage step for temporarily storing the acquired print data; a virus detection step for executing predetermined infection control processing on the print data and detecting computer viruses; a virus scan information generation step for generating virus scan information that identifies setting items related to the executed infection control processing and adding the virus scan information to print data in which no computer viruses were detected in the virus detection step; and a print information generation step for generating print information from the temporarily stored print data that includes print data requested by the second image forming apparatus. The present invention provides an infection control method for an image processing system, characterized by causing the system to perform a print information transmission step of transmitting generated print information to the second image forming apparatus; a print data request step of causing a second control unit provided in the second image forming apparatus to request the first image forming apparatus to transmit predetermined print data from the print data temporarily stored in the first image forming apparatus; a print information reception step of receiving print information transmitted from the first image forming apparatus; a scan information acquisition step of acquiring virus scan information attached to the print data included in the received print information; a print feasibility determination step of determining whether or not to print the print data included in the received print information using the acquired virus scan information; and a function execution step of printing the print data if it is determined in the print feasibility determination step that the print data should be printed. [Effects of the Invention]
[0029] According to this disclosure, the information processing device performs a predetermined infection control process on the acquired print data to detect computer viruses, generates virus scan information that identifies the setting items related to the executed infection control process, adds the virus scan information to the print data in which no computer viruses were detected, and generates print information from the acquired print data that includes the print data requested by the image forming apparatus connected via the network, and transmits it to the image forming apparatus, thereby reducing the risk of infection in the image forming apparatus. Furthermore, for example, when print data to be processed by an image forming apparatus is transferred from an information processing device to the image forming apparatus, the information processing device performs the most appropriate virus infection prevention processing possible before sending the print data to the image forming apparatus. This reduces the risk of the image forming apparatus being infected with a computer virus, and the image forming apparatus can use the virus scan information attached to the print data to determine whether or not to print the print data. [Brief explanation of the drawing]
[0030] [Figure 1] This is a block diagram of one embodiment of the image processing system disclosed herein. [Figure 2] This is a block diagram of one embodiment of the image processing system disclosed herein. [Figure 3] This is a block diagram of one embodiment of the image processing system disclosed herein. [Figure 4] This is a block diagram of one embodiment of the image forming apparatus (master unit) disclosed herein. [Figure 5] This is a block diagram of one embodiment of the image forming apparatus (slave unit) of the present disclosure. [Figure 6] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus (master unit) disclosed herein. [Figure 7] This is an explanatory diagram illustrating one embodiment of the information stored in the memory unit of the image forming apparatus (slave unit) disclosed herein. [Figure 8]This is an explanatory diagram of one embodiment of the print job list display screen shown in the image forming apparatus (slave unit) of the present disclosure. [Figure 9] This is an explanatory diagram of one embodiment of the scan information detail display screen displayed in the image forming apparatus (slave unit) of the present disclosure. [Figure 10] This diagram illustrates one embodiment of the correspondence between the setting conditions for not encrypting virus scan information in the image processing system disclosed herein and whether printing is possible on the client device. [Figure 11] This diagram illustrates one embodiment of the correspondence between the setting conditions for encrypting and decrypting virus scan information using the master unit's encryption key in the image processing system disclosed herein, and whether printing is permitted on the slave unit. [Figure 12] This diagram illustrates one embodiment of the correspondence between the setting conditions for encrypting and decrypting virus scan information using the encryption key of the client device in the image processing system disclosed herein, and whether or not printing is permitted on the client device. [Figure 13] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 14] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 15] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 16] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 17] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 18]This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 19] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Figure 20] This is a communication sequence of one embodiment of the information communication processing in the image processing system disclosed herein, from infection control processing on print data input to the master unit to the execution of printing processing on the slave unit. [Modes for carrying out the invention]
[0031] Embodiments of this disclosure will be described below with reference to the drawings. However, the description of the following embodiments does not limit this disclosure.
[0032] <Configuration of the image processing system> The image processing system disclosed herein is a system comprising a plurality of information processing devices connected via a network, and in particular, a system in which a first information processing device that temporarily stores print data, etc., and a second information processing device that has the function of acquiring print data, etc., and printing, etc., are connected via a network.
[0033] For example, a system in which a first image forming apparatus that temporarily stores print data and a second image forming apparatus that has the function of printing the print data are connected via a network, and after infection prevention processing such as virus scanning is performed on image data intended for printing (hereinafter referred to as print data) input to the first image forming apparatus, the second image forming apparatus is made to perform printing processing etc. only on print data that does not pose an infection risk. In the following embodiment, the first image forming apparatus that temporarily stores print data is referred to as the master unit, and the second image forming apparatus that has the function of printing the print data is referred to as the slave unit.
[0034] The following embodiments describe an image processing system including an image forming apparatus, but the information processing apparatus of this disclosure is not limited to an image forming apparatus and can also be applied to other information processing apparatuses and information processing systems capable of performing infection control processing on predetermined input information. In addition to image forming apparatus, other information processing devices may include, for example, personal computers with infection control functions, scanners, information and communication devices, information display devices, NAS, and cloud storage.
[0035] Figures 1, 2, and 3 show a block diagram of one embodiment of the image processing system disclosed herein. The image processing system in Figure 1 mainly consists of one image forming apparatus (master unit) 1 connected to a network 4 and multiple image forming apparatuses (slave units) 2. An information creation device 3 is connected to the network 4 to create information for printing purposes and transmit it to the master unit 1. Network 4 may be a wide-area network (WAN) such as the Internet, or it may be a local area network (LAN). Furthermore, the communication method by which these devices are connected to the network may be either wired communication or wireless communication.
[0036] Image forming apparatus (master unit) 1 and image forming apparatus (slave unit) 2 are devices that process image data, performing tasks such as input, formation, output, storage, and transfer of image data. Image forming apparatuses are also called multifunction peripherals (MFPs), or simply MFPs. Among the image forming apparatuses, the master unit 1 is called an MFP-P, and the slave unit 2 is called an MFP-C. When using this system, one of the multiple image forming machines is pre-configured to act as the master unit, while the other image forming machines are configured as slave units. However, while one master unit is sufficient, if multiple image forming machines form several groups, there may be multiple master units, and within each group, only one image forming machine needs to act as the master unit.
[0037] The information creation device 3 corresponds, for example, to a personal computer owned by a user of the image forming apparatus. The user creates information such as image data using the information creation device 3 and transmits the information intended for printing (print data) to the image forming apparatus (master unit) 1 in order to print the created information. The information creation device 3 is also called a user terminal, or simply a PC.
[0038] Image forming apparatus (slave unit) 2, for example, has a function to print print data, and requests the image forming apparatus (master unit) 1 to transmit print data through a predetermined operation by the user on the slave unit, and prints the print data transmitted from the image forming apparatus (master unit) 1 on a predetermined sheet of paper.
[0039] Image forming apparatus (master unit) 1 is a device that temporarily stores information for printing purposes (print data) transmitted from information creation device (user terminal) 3. When an image forming apparatus (slave unit) requests transmission of the temporarily stored print data, it transmits the temporarily stored print data to the requesting slave unit 2. Furthermore, the master unit 1 is an image forming apparatus that has an image forming function to temporarily store acquired print data and print the temporarily stored print data. When the user performs an operation on the master unit to print desired print data, the master unit 1 prints the temporarily stored print data.
[0040] However, the device that temporarily stores the information for printing purposes (print data) transmitted from the information creation device (user terminal) 3 does not necessarily have to be the master unit 1, but may be an information management device (management server: SV) that has the function of temporarily storing predetermined information. The information management device (management server) does not need to have the function of processing image data, such as an image forming apparatus.
[0041] The image processing system in Figure 2 is configured such that an image forming apparatus (master unit) 1 and multiple image forming apparatuses (slave units) 2 are connected to a network (LAN) 4, and an information creation device 3, which creates information for printing and other purposes and transmits it to the master unit 1, is connected to a network (WAN) 5. In this case as well, instead of the master unit 1, an information management device (management server) may be connected to network (LAN) 4.
[0042] The image processing system in Figure 3 is configured such that multiple image forming devices (slave units) 2 and an information creation device 3 are connected to a network (LAN) 4, and an information management device (management server: SV) 6 is connected to a network (WAN) 5 instead of an image forming device (master unit) 1. Although not shown in the diagram, the connection configuration may also be such that multiple image forming devices (slave units) 2 are connected to the network (LAN) 4, and the information creation device 3 and either the image forming device (master unit) 1 or the information management device (management server: SV) 6 are connected to the network (WAN) 5, or other connection configurations may also be used.
[0043] The image forming apparatus (master unit) 1 or the information management device (management server: SV) 6 pre-stores information about one or more image forming apparatuses (slave units) 2 under its management, and information about an information creation device 3 that can be connected to the master unit 1. For example, the device name, IP address, installation location, administrator information, user information (username, user ID, password, etc.), serial number, and network interface MAC address of each child device 2 are stored.
[0044] Furthermore, in order to enhance the confidentiality of information communicated between the master unit and the slave unit, the master unit and the slave unit may store a pre-configured encryption key and transmit information encrypted with that key. In the embodiments described later, the virus scan information described later is encrypted, but the print data itself may also be encrypted.
[0045] When using a "public-key cryptography scheme" that encrypts data using a public key and a private key, for example, the "private key of the master unit" and the "public key of the master unit" generated by the master unit 1 are stored in the master unit 1, and the "public key of the master unit" is stored in the slave unit 2. The "public key of the master unit" may be transmitted from the master unit 1 to the slave unit 2 via a predetermined highly secure communication method, or it may be stored in the slave unit 2 by other means. Alternatively, the "private key of the child device" and the "public key of the child device" generated by the child device 2 may be stored in the child device 2, and the "public key of the child device" may be stored in the parent device 1.
[0046] In public-key cryptography, for example, a file to be sent is encrypted using the recipient's "public key," then the encrypted file is sent to the recipient's device, and the recipient's device, upon receiving the encrypted file, decrypts it using its own "private key" and obtains the decrypted file itself. Alternatively, the sender could encrypt the transmission file using their own "private key," then send the encrypted file to the recipient's device. The recipient's device, upon receiving the encrypted file, could then decrypt it using the sender's "public key," which it had previously stored, and obtain the decrypted transmission file itself.
[0047] In this disclosure, as a general rule, print data transmitted from the information creation device 3 to the master unit 1 is temporarily stored in the master unit 1. If print data requested by the slave unit 2 is already temporarily stored in the master unit 1, that temporarily stored print data is transmitted from the master unit 1 to the slave unit 2. The slave unit 2, upon receiving the print data, prints the received print data on the designated paper.
[0048] Furthermore, the master unit 1 has a computer virus infection prevention function and will perform a virus scan on all print data transmitted from the information creation device 3. Furthermore, the second sub-unit may or may not have a function to protect against computer virus infections.
[0049] The virus scanning process, for example, uses the latest virus scanning engine and virus pattern files to detect viruses. Furthermore, it performs tasks such as quarantining and deleting any printed data in which viruses are detected, removing viruses, saving logs of virus detection information, and notifying administrators of virus detection.
[0050] It is preferable that print data isolated on master unit 1 is not included in the job list requested by slave unit 2 (described later) and is not sent from master unit 1 to slave unit 2. Alternatively, if slave unit 2 requests the transmission of a job list, the job list sent to slave unit 2 will include only the filenames of print data that are not infected with a virus. In addition to the job list, slave unit 2 may also be notified of the filenames of any print data that were infected with a virus. Furthermore, if the slave unit 2 requests the transmission of desired print data, and that requested print data is infected with a virus, the slave unit may not be sent the print data itself, but may be notified that the print data was infected with a virus.
[0051] <Configuration of image forming apparatus: master unit> Figure 4 shows a block diagram of one embodiment of the image forming apparatus (master unit) of the present disclosure. The image forming apparatus (master unit) 1 is an electronic device equipped with functions for processing image data, such as copying, printing, scanning, editing, saving, sending (fax, scanner, Internet fax), and communication functions. Furthermore, as described above, the master unit 1 has the function of receiving and temporarily storing print data transmitted from the information creation device 3. In the following embodiments, the image forming apparatus 1 of the present disclosure will be described in particular as having a printing function and a document reading function, but it may also have other functions.
[0052] In Figure 4, the main unit (MFP-P) 1 mainly comprises a control unit 11, an operation unit 12, a display unit 13, an image processing unit 14, a communication unit 15, a print data acquisition unit 21, a virus detection unit 22, a virus removal unit 23, a virus scan information generation unit 24, a job list processing unit 25, an encryption unit 29, a print information processing unit 30, and a storage unit 40.
[0053] Here, the image processing unit 14, as will be described later, mainly consists of an image input unit, an image forming unit, and an image output unit. The job list processing unit 25 is a functional block that processes a list of print data (called a job list) temporarily stored in the master unit's memory unit 40, and consists of a job list request receiving unit 26, a job list generation unit 27, and a job list transmission unit 28. The print information processing unit 30 is a functional block that processes print information, including data to be printed, and consists of a print data request receiving unit 31, a print information generation unit 32, and a print information transmission unit 33.
[0054] The control unit 11 controls the operation of each component, such as the display unit 13 and the image processing unit 14, and is mainly implemented by a microcomputer consisting of a CPU, ROM, RAM, I / O controller, timer, etc. The CPU operates various hardware components organically based on control programs pre-stored in non-volatile memory such as ROM, thereby executing the image formation function, virus detection function, and other functions of this disclosure.
[0055] Furthermore, among the above components, the virus detection unit 22, virus removal unit 23, virus scan information generation unit 24, job list generation unit 27, encryption unit 29, and print information generation unit 32 are functional blocks in which the CPU performs its respective processing based on a predetermined program.
[0056] The operation unit 12 is an input device for the user of the master unit 1 to perform predetermined input operations. For example, it is the part for inputting information such as characters or selecting functions, and a keyboard, mouse, or touch panel can be used. User-operated keys include the start key, function selection key, and settings key. For example, users can initiate document scanning by pressing a touch panel or a key to start the scanning operation, or initiate the transmission of information such as image data to a designated destination by pressing a transmission start key.
[0057] The display unit 13 is the part that displays information, and it displays information necessary for the execution of each function, as well as the results of the execution of the function, in order to inform the user. For example, if an LCD or organic EL display is used and a touch panel is used as the operation unit 12, the display unit 13 and the touch panel are arranged to overlap each other. The display unit 13 displays information such as settings for printing on the image forming apparatus, information necessary for executing functions such as document scanning, and operation screens for selected functions, using characters, symbols, figures, images, icons, animations, videos, etc.
[0058] Furthermore, in this disclosure, if a virus is detected, for example, a detection notification screen indicating that a virus has been detected, or a warning screen indicating the file name of the print data in which the virus was detected and that the print data has been quarantined, may be displayed on the display unit 13.
[0059] The image processing unit 14 is the part that performs the image formation function, which is the main function of the master unit 1, and mainly consists of an image input unit, an image formation unit, and an image output unit. Primarily, the image input unit is responsible for inputting predetermined image data, the image forming unit is responsible for converting the input image data into information that can be printed, etc., and the image output unit is responsible for outputting the formed print information, etc., onto printing paper, etc.
[0060] The image input section is where image data of a document containing images, text, graphics, etc., such as print data intended for printing, is input. For example, it is the section that reads a document placed on a document glass or the like. For image input, a scanner (reading device) that reads documents containing information is used. The main unit 1 includes a document tray (document tray) on which the document is placed and a document cover to hold the document in place, for scanning purposes. Furthermore, the master unit 1 may be equipped with an automatic document feeder (ADF) that can take multiple documents and automatically transport and scan them one by one.
[0061] There are various methods for inputting image information, but for example, a document containing images can be scanned, and the image data of the document (hereinafter referred to as input image data) can be stored in the storage unit 40.
[0062] Furthermore, an interface for connecting external storage media, such as a USB memory stick, corresponds to the image input section. Electronic data files, such as image information to be input, may be saved on an external storage medium such as a USB memory stick. By connecting the USB memory stick to an input interface such as a USB terminal and performing a predetermined input operation on the operation unit 12, the desired electronic data files saved on the USB memory stick can be read and stored in the storage unit 40 as input image data.
[0063] For example, when printing print data onto a recording medium, the image forming unit generally performs the following steps in sequence: charging, exposure, development, transfer, cleaning, static discharge, and fixing, to form the print data on the recording medium. In the development process, toner is supplied from the toner cartridge to the developing device, and the electrostatic latent image formed on the surface of the charged photoreceptor drum is developed, forming a toner image corresponding to the electrostatic latent image. The toner image formed on the surface of the photoreceptor drum is transferred onto the recording medium by a transfer device, and then fixed onto the recording medium by heating by a fixing device. The image forming unit also converts the input image data into information in a format that can be transferred and displayed.
[0064] The image output unit is the part that outputs the formed input image data, and is equivalent to, for example, a printer. However, the output of input image data is not limited to printing; it also includes storing input image data of scanned documents and sending input image data of scanned documents via fax. For example, storing scanned document input image data on an external storage medium such as a USB memory stick, transmitting input image data to other information processing devices or servers via a network such as the internet, and classifying and saving them in a specific save folder also constitute image output.
[0065] The communication unit 15 is the part that communicates data with other communication devices via the network 4. For example, as shown in Figure 1, the master unit (MFP-P) 1 is connected to the slave unit (MFP-C) and the information creation device (PC) 3 via the network 4, and data communication takes place.
[0066] The master unit (MFP-P) 1 receives, for example, print data transferred from the information creation device (PC) 3 via the communication unit 15. Alternatively, it receives job list requests and print data requests sent from the slave unit (MFP-C), and sends the job list and print information generated by the master unit (MFP-P) 1 to the slave unit (MFP-C).
[0067] The print data acquisition unit 21 is the part that acquires print data and the like transmitted from the information creation device (PC) 3 via the network 4. The acquired print data is temporarily stored in the storage unit 40 as input print data 44. As a general rule, the input print data 44 is requested by the slave unit 2, and after being transferred to the slave unit, it is deleted from the storage unit 40 of the master unit.
[0068] The virus detection unit 22 is one of the infection control functions and is the part that performs predetermined infection control processing on the stored input print data 44 to detect computer viruses. The infection control process includes a virus scan process that uses a predetermined virus scan engine and a predetermined virus pattern file to detect known computer viruses, and by performing the virus scan process, it checks whether or not the stored input print data 44 is infected with a virus.
[0069] Virus scanning is performed using at least a virus scanning engine and virus pattern files. However, to minimize the chances of missing viruses, it is preferable to always use the latest versions of the virus scanning engine and virus pattern files. The latest virus scanning engines and virus pattern files can be obtained, for example, by regularly accessing a designated infection control management server.
[0070] The acquired virus scan engine is assigned the name of the scan engine (scan engine name) and the version information of the scan engine (engine version), and the acquired virus pattern file is assigned the version information of the pattern file (pattern version) and the date information of when the virus pattern file was acquired (scan pattern acquisition date). The scan pattern acquisition date may be the date the virus pattern file was acquired, or it may be the date the virus pattern file was created on the infection control management server.
[0071] The virus removal unit 23 is the part that removes the input print data 44 that is infected with a virus, and the infected input print data 44 may be isolated in a quarantine area of the storage unit 40 that is normally inaccessible. If it is possible to remove viruses from the input print data, you may remove the viruses and store the virus-free input print data. To prevent the spread of infection, it is preferable that the removed input print data 44 and the isolated input print data 44 are not sent to the slave unit 2 even if a transmission request is made from the slave unit 2.
[0072] The virus scan information generation unit 24 is the part that generates virus scan information when a virus scan process is performed. Virus scan information identifies the settings related to the infection prevention process (for example, the virus scan process) performed on the main unit 1. Virus scan information includes at least the name of the virus scan engine (scan engine name), version information (engine version), version information of the virus pattern file (pattern version), and the date the virus pattern file was obtained (scan pattern acquisition date).
[0073] Alternatively, the virus scan information may include information that identifies the parent unit 1 that performed the virus scan (for example, the parent unit ID), and may also include the date on which the virus scan was performed on parent unit 1 (execution date).
[0074] Furthermore, the virus scan information generation unit 24 adds the generated virus scan information to the print data on which the virus scan process has been performed. However, since print data in which a virus is detected is quarantined or removed after the virus scan process is performed, in the following embodiment, the virus scan information generation unit 24 adds virus scan information to print data in which no computer viruses were detected during the virus scan process performed by the virus detection unit 22.
[0075] Therefore, print data with added virus scan information is guaranteed to have undergone a virus scan and no viruses were detected. Furthermore, by examining the contents of the virus scan information, it is possible to find information about the virus scan engine and virus pattern file used. For example, by checking the pattern version and scan pattern acquisition date in the virus scan information, it is possible to determine whether or not the virus scan process was performed using the latest virus pattern file among the currently available virus pattern files.
[0076] On the other hand, print data without virus scan information is data that has not yet undergone virus scanning, and it is unknown whether or not it is infected with a virus; therefore, it will be referred to as an unscanned job below. In the following embodiment, the print data with added virus scan information is sent to the slave unit 2. On the other hand, print data that does not have virus scan information attached may or may not be sent to the sub-unit 2.
[0077] As described above, the job list processing unit 25 is the part that processes the list of print data (called the job list) temporarily stored in the master unit's memory unit 40, and consists of a job list request receiving unit 26, a job list generation unit 27, and a job list transmission unit 28. For example, when the master unit 1 receives a job list request from the slave unit 2, the job list processing unit 25 generates a job list from the print data temporarily stored in the storage unit 40 of the master unit 1 that includes the name of the print data requested by the job list request, and if the requested print data is print data with virus scan information attached, it also includes the virus scan information, and sends the generated job list to the slave unit 2 that sent the job list request.
[0078] The job list request receiving unit 26 is the part that receives job list requests transmitted from the slave unit 2. A job list request is information that requests the master unit 1 to send a list of print data (job list) temporarily stored in the storage unit 40 to the slave unit 2. Since the print data temporarily stored on the master unit 1 may include numerous print data created by different users, the job list request includes the username, and requests a list of print data identified by that username from among the multiple temporarily stored print data.
[0079] The job list generation unit 27 is the part that, upon receiving a job list request, generates a list (job list) containing the names of the print data requested by the job list request. The job list will include at least the print data name that identifies the requested print data. If the requested print data has been scanned for viruses and virus scan information has been added, that virus scan information will also be included in the job list. The job list does not include the file itself that contains the print data.
[0080] The job list request includes the username of the user who requested the list of print data. Therefore, the system selects the input print data containing the username from among the many input print data 44 temporarily stored in the storage unit 40. Furthermore, if the selected input print data has virus scan information attached, the system also retrieves the virus scan information to generate the job list. For example, a job list like the one shown in Figure 6, which will be described later, is generated.
[0081] The job list transmission unit 28 is responsible for transmitting the generated job list to the slave unit 2 that sent the job list request. When the slave unit 2 receives the job list, it displays the job list on its display unit, and selects the print data name desired by the user who requested the job list from among the print data names displayed in the job list.
[0082] The encryption unit 29 is the part that encrypts the generated virus scan information with a predetermined encryption key (referred to as the first encryption key). Alternatively, the print data itself sent to the handset could be encrypted. Encryption can be performed using a "public-key cryptography scheme" predetermined for the master and slave units, as described above. For example, the master unit's private key may be used to encrypt the virus scan information, or the slave unit's public key may be used to encrypt the virus scan information. If the virus scan information is encrypted, the virus scan information generation unit 24 described above adds the encrypted virus scan information (referred to as encrypted virus scan information) to the print data.
[0083] Encryption of virus scan information is not mandatory; encryption is performed only when necessary to enhance the confidentiality of the information being communicated. The option to enable or disable encryption may be pre-configured on the main unit. Furthermore, the master unit may allow users to pre-configure whether or not to encrypt the print data itself.
[0084] As described above, the print information processing unit 30 is the part that processes print information, including the data to be printed, and consists of a print data request receiving unit 31, a print information generation unit 32, and a print information transmission unit 33.
[0085] The print data request receiving unit 31 is the part that receives print data requests transmitted from the slave unit 2. When a user views the displayed job list on slave unit 2 and selects the name of the print data they want to print, information requesting the transmission of that selected print data (print data request) is sent to master unit 1. The received print data request includes the print data name, so the system searches for the print data file with that name among the stored input print data 44.
[0086] The print information generation unit 32 is the part that generates print information, including the print data requested by the slave unit 2, from among the acquired and temporarily stored print data. In response to a print data request received from the slave device as described above, print information is generated in order to send the requested print data itself to slave device 2.
[0087] Upon receiving a print data request, the master unit 1 retrieves the file containing the requested print data name from the input print data 44 temporarily stored in the storage unit 40, and generates print information that includes the retrieved print data file. The print information generated here is called the transmitted print information. If the acquired print data includes virus scan information, that virus scan information will also be included in the transmitted print information.
[0088] The print data requested from handset 2 may or may not have virus scan information added to it. Print data with virus scan information attached is print data in which no viruses were detected and is unlikely to be infected. Therefore, in order to reduce the risk of infection of the slave device, it may be possible to generate print information that includes only print data requested by slave device 2 that has virus scan information attached. The information to be sent for printing is, for example, the information shown in Figure 6, which will be described later.
[0089] The print information transmission unit 33 is the part that transmits the generated print information to the slave device 2 that sent the print data request. If the print data requested by slave device 2 has undergone a virus scan process and virus scan information has been added, then the print data file and the print information containing the virus scan information are sent. On the other hand, if the print data requested from slave unit 2 has not yet undergone a virus scan, the print information including the print data file will be sent because the virus scan information will not be added.
[0090] Upon receiving the print transmission information, the slave unit 2 can determine whether or not a virus scan process has been performed on the received print data based on the presence or absence of virus scan information. For example, as will be explained later, if the received print information contains virus scan information, the virus scan process will be executed, and if no virus is detected, the received print data will be deemed safe and printed.
[0091] On the other hand, if the transmitted print information received by the second handset does not contain virus scan information, it means that the virus scan process has not been performed. Therefore, it can be determined that the received print data is unsafe, and it may be best not to print it. Alternatively, if the second sub-unit has infection control capabilities, it may perform a virus scan on print data that does not contain virus scan information. Print data that does not detect a virus may be printed, while print data that does detect a virus may be quarantined or otherwise excluded from printing.
[0092] The memory unit 40 is a part that stores information and programs necessary to perform each function of the image processing apparatus MFP of the present disclosure, and uses semiconductor memory elements such as ROM, RAM, and flash memory, storage devices such as HDDs and SSDs, and other storage media. The memory unit 40 stores, for example, master unit information 41, slave unit information 42, encryption key information 43, input print data 44, virus scan information 45, job list 46, transmission print information 47, job list request 48, print data request 49, and so on. Figure 6 shows an explanatory diagram of one embodiment of the information stored in the memory unit 40 of the image forming apparatus (master unit).
[0093] The master unit information 41 is information about master unit 1, and for example, as shown in Figure 6, information that identifies the master unit (master unit name, master unit ID) and information for connecting to master unit 1 via the network (IP address) are stored in advance. However, the information stored regarding the master unit 1 is not limited to this; for example, information such as the machine serial number and the MAC address of the network interface may also be stored.
[0094] The child device information 42 is information about child device 2, and for example, as shown in Figure 6, information that identifies the child device (child device name, child device ID) and information for connecting to child device 2 via the network (IP address) are stored in advance. However, the information stored regarding the slave unit 2 is not limited to this; for example, information such as the machine serial number and the MAC address of the network interface may also be stored.
[0095] The encryption key information 43 is information used to encrypt and decrypt information communicated between the master unit and the slave unit. For example, as shown in Figure 6, the encryption keys generated and stored by the master unit 1 include the master unit private key (OYASCK) and the master unit public key (OYAPUK), while the encryption key obtained from the slave unit 2 is the slave unit public key (KOPUK).
[0096] The input print data 44 is print data that was transmitted from the information creation device (PC) 3 to the master unit 1 and acquired. If the information creation device (PC) 3 is a user terminal owned by a specific user, then when sending print data to the master unit 1, information identifying that user and the information creation device (PC) may be added to the print data. In this case, the input print data 44 stores the file name and the username or PC name in association with the print data file itself. For example, as shown in Figure 6, the file name of the print data and the username are associated and stored as input print data 44.
[0097] Alternatively, when sending print data from the information creation device (PC) 3 to the master unit 1, a predetermined user authentication process may be performed. After successful user authentication, the print data may be sent to the master unit 1, and the name of the user who successfully authenticated the received print data may be associated with the file name of the received print data and stored as input print data 44. Although Figure 6 shows only one example of print data, numerous input print data 44, each associated with a print data file name and username, are temporarily stored in the storage unit 40.
[0098] As described above, the virus scan information 45 is information (SC) related to the virus scan process performed on the master unit 1. For example, it is generated when the virus scan process is performed, and the virus scan information is added to print data in which no viruses were detected during the virus scan process. As shown in Figure 6, the virus scan information (SC) 45 includes, for example, the scan engine name, engine version, pattern version, scan pattern acquisition date, and master unit ID.
[0099] By sending a job list containing the print data name and virus scan information 45 to the slave unit 2, the slave unit 2 can confirm whether or not the print data was scanned for viruses on the master unit and no viruses were detected. Furthermore, by checking the contents of the received virus scan information, such as the pattern version and the date the scan pattern was acquired, the sub-unit 2, which has infection control capabilities, can determine whether or not to perform a virus scan on that sub-unit 2.
[0100] The job list 46 is a list of print data temporarily stored in the master unit's memory unit 40. In response to a job list request from the slave unit 2, the job list 46 is generated and sent to the slave unit 2. As described above, if the job list request sent from slave unit 2 includes the username of the requesting user, then a list of print data sent by that user from their user terminal PC to master unit 2 will be generated. In other words, from the input print data 44, the file name (print data name) of the print data associated with the username of the requesting user is obtained and included in the job list. For example, as shown in Figure 6, the job list 46 includes the print data name, virus scan information, source master unit information, and destination slave unit information.
[0101] However, if print data that has not undergone virus scanning is placed in the job list, the virus scan information will not be included in job list 46. The job list 46 shown in Figure 6 contains three print data names. Print data "PRINT01" and "PRINT02" have virus scan information and have therefore undergone virus scanning, but print data "PRINT03" does not have virus scan information and has therefore not undergone virus scanning. Furthermore, the information included in the job list 46 is not limited to this information; it may also include the username of the user who made the job list request, the date and time the job list was requested, and so on.
[0102] As described above, the transmitted print information 47 is information generated by the print information generation unit 32, and is print information that includes the print data itself requested by the slave unit 2. For example, as shown in Figure 6, the transmitted print information 47 consists of source master unit information, destination slave unit information, print data name, and print file which is the actual print data. If a virus scan has been performed on the print data, virus scan information is also included.
[0103] The job list request 48 is information sent from the slave unit 2, and includes, for example, destination master unit information, source slave unit information, and username, as shown in Figure 6. As mentioned above, this username is used to generate the job list.
[0104] The print data request 49 is information transmitted from the slave unit 2, and includes, for example, destination master unit information, source slave unit information, and print data name, as shown in Figure 6. The print data name included in the print data request is used to generate the print information to be sent.
[0105] <Configuration of image forming apparatus: slave unit> Figure 5 shows a block diagram of one embodiment of the image forming apparatus (slave unit) of the present disclosure. The image forming apparatus (slave unit) 2, like the master unit 1, is an electronic device equipped with functions for processing image data, such as copying, printing, scanning, editing, saving, sending (fax, scanner, Internet fax), and communication functions.
[0106] In Figure 5, the image forming apparatus (slave unit) 2 of the present disclosure mainly comprises a control unit 101, an operation unit 102, a display unit 103, an image processing unit 104, a communication unit 105, a virus detection unit 106, a virus removal unit 107, a function execution unit 108, a job list request unit 111, a job list reception unit 112, a print data request unit 113, a print information reception unit 114, a scan information acquisition unit 115, a scan information confirmation unit 116, a decoding unit 117, a print feasibility determination unit 118, and a storage unit 140.
[0107] Here, the image processing unit 104, like the master unit 1, mainly consists of an image input unit, an image forming unit, and an image output unit. Furthermore, in the slave unit 2, a virus detection unit 106 and a virus removal unit 107 are provided only if the slave unit 2 has an infection control function, and a virus scan process is performed. However, if the slave unit 2 does not have an infection control function, the virus detection unit 106 and virus removal unit 107 are not present, and the virus scan process is not performed.
[0108] The control unit 101 controls the operation of each component, such as the display unit 103 and the image processing unit 104, and is mainly implemented by a microcomputer consisting of a CPU, ROM, RAM, I / O controller, timer, etc. The CPU operates various hardware components organically based on control programs pre-stored in non-volatile memory such as ROM, executing functions such as image formation and job list request in the slave unit 2.
[0109] Furthermore, among the above components, the virus detection unit 107, virus removal unit 108, scan information acquisition unit 115, scan information confirmation unit 116, decryption unit 117, printability determination unit 118, etc., are functional blocks in which the CPU performs its respective processing based on a predetermined program.
[0110] Of the functional blocks in the slave unit 2, the operation unit 102, display unit 103, image processing unit 104, and communication unit 105 each perform the same processing as the functional blocks provided in the master unit 1, so their explanation will be omitted.
[0111] The function execution unit 106 is the part that executes functions that can be performed on the slave unit 2. For example, if a user performs a predetermined input operation using the control panel 102 of the sub-unit 2 to execute the copy function, the same content as the original will be copied onto predetermined printing paper. Furthermore, when the required input operation is performed to print the desired print data, that print data will be printed on the designated paper. Furthermore, if the printability determination unit 118, described later, determines that the print data should be printed, the print data is printed.
[0112] The virus detection unit 107, like the virus detection unit 22 of the master unit 1, is one of the infection control functions and checks whether or not the print data contained in the received print information 146 is infected with a virus. For example, the system performs infection control processing on received print data, including a virus scan process that uses a virus scanning engine and virus pattern files to detect known computer viruses, thereby detecting computer viruses.
[0113] The virus scanning process performed on the client device also utilizes at least a virus scanning engine and virus pattern files. However, it is preferable to obtain the latest virus scanning engine and virus pattern files, for example, by periodically accessing a designated infection control management server.
[0114] The acquired virus scan engine is assigned the name of the scan engine (scan engine name) and the version information of the scan engine (engine version), and the acquired virus pattern file is assigned the version information of the pattern file (pattern version) and the date information of when the virus pattern file was acquired (scan pattern acquisition date). These pieces of information (name and version information of the virus scan engine, version information of the virus pattern file, and date information of the acquisition of the virus pattern file) will be stored in the storage unit 140 as scan processing information 144, which will be described later.
[0115] The virus removal unit 108, like the virus removal unit 23 of the master unit 1, is a part that removes virus-infected print data, and the infected print data may be isolated in a quarantine area of the storage unit 140 that is normally inaccessible.
[0116] The job list request unit 111 is the part that sends a job list request to the master unit 1. A job list request is sent when a user of the image forming apparatus attempts to print print data stored on the master unit 1 using the slave unit 2. As described above, a job list request is information that requests the master unit 1 to send a list of print data (job list) temporarily stored in the storage unit 40 to the slave unit 2.
[0117] If a user of an image forming apparatus sends image data, documents, or other information they have created to the master unit 1, and then wishes to print the desired information on a slave unit 2 located within the user's office, the user performs a predetermined input operation on the slave unit 2 to display a list of the information stored in the master unit 1. For example, when a user enters a username on the slave unit 2, and after a predetermined user authentication process is successful, they input a key corresponding to a request to display a list of their own information, a job list request including the username is created and sent to the master unit 1.
[0118] The job list receiving unit 112 is the part that receives the job list transmitted from the master unit 1. As described above, when the master unit 1 receives a job list request, it generates a job list containing the print data name of the print data corresponding to the requested user and sends it to the slave unit 2. When the job list receiving unit 112 of the slave unit 2 receives a job list, the received job list is displayed on the display unit 103 of the slave unit 2. For example, as shown in Figure 8 later, a list of print data names included in the job list (print job list) is displayed.
[0119] Furthermore, since the received job list includes virus scan information in addition to the print data name, if a virus scan has been performed, it may also be possible to display information indicating whether or not a virus scan has been performed.
[0120] If the received job list contains multiple print data names, it is preferable to display the print data names so that the user can select the print data they want to print. Figure 8 shows an example of the print job list display screen (G1) shown on the display unit 103 of the slave unit 2. This example shows a case where the received job list contains five print data files, displaying the print data names, their corresponding status ("Print Selected / Not Selected"), and their scanning status ("Scanned / Not Scanned").
[0121] The "Scanned / Not Scanned" column indicates whether or not the corresponding print data has been scanned for viruses by the main unit. For example, in Figure 8, if "○" is displayed in the "Scan Not / Completed" column, it means that a virus scan was performed on the corresponding print data and no viruses were detected. On the other hand, if "-" is displayed in the "Scanned / Not Scanned" column, it means that the corresponding print data has not been scanned for viruses by the main unit, and it is unknown whether or not it is infected with a virus.
[0122] The "Print Selection Available / Not Available" field is where the user enters whether or not they choose to print the corresponding print data. When you select the corresponding print data, an indicator (such as a circle or checkmark) will appear in this field to show that you have selected to print. If nothing is displayed in the "Print Selection Available / Not Available" column, it means that no corresponding print data has been selected.
[0123] In the print job list display screen G1 in Figure 8, two print data files (PDT001 and PDT050) are selected as print targets, with "○" displayed in the "Print Selection Available / Not Available" column. In this display state, if the user selects the area labeled "Print" on display screen G1, the slave unit 2 will execute a process to request the master unit 1 to send two print data files with print data names (PDT001, PDT050).
[0124] Furthermore, in the print job list display screen G1 in Figure 8, the three print data (PDT001, PDT002, PDT050) with "○" displayed in the "Scanning Not / Completed" column are data for which a virus scan has been performed on the master unit, while the two print data (PDT111, PDT200) with "-" displayed in the "Scanning Not / Completed" column are data for which a virus scan has not been performed on the master unit.
[0125] Although not shown in Figure 8, the detailed contents of the virus scan process may also be displayed for print data that has undergone a virus scan on the main unit. For example, if you select and input the display area for the print data name on the display screen shown in Figure 8, you may display the scan information details screen (G2) as shown in Figure 9. Figure 9 is an explanatory diagram of one embodiment of the scan information details display screen (G2). In Figure 9, the detailed contents of the scan information are shown to include the print data name, whether printing is selected or not, whether the scan has been performed or not, the name of the scanning master unit, the name of the scanning engine, the version of the scanning engine, the version of the scanning pattern, and the date the scanning pattern was acquired. By viewing this display screen G2, you can check which base station performed the virus scan, and with what engine and pattern.
[0126] The print data request unit 113 is the part that requests the master unit 1 to send predetermined print data from the print data temporarily stored in the master unit 1 to the slave unit, and sends the print data request to the master unit 1. A print data request is sent when the user of the image forming apparatus selects the desired print data and performs an input operation to initiate printing. As described above, a print data request is information that includes the name of the print data and requests that the print data of that name be sent to the slave device 2. For example, as described above, when input is made to select the area labeled "Print" on the display screen G1 in Figure 8, a print data request including the print data name of the selected print data is generated and sent to the master unit 1.
[0127] The print information receiving unit 114 is the part that receives print information transmitted from the master unit 1. Upon receiving a print data request, the master unit 1 searches its storage unit 40 for the print data whose name is included in the print data request, generates a print transmission information 47 that includes the print file which is the actual print data, and transmits it to the slave unit 2. The slave unit 2 receives this transmitted print information 47 and stores it in the storage unit 140 as received print information 147. The received print information 147 has the same structure as the transmitted print information 47, but as shown in Figure 7 below, it includes the print data name, print file, virus scan information, etc.
[0128] The scan information acquisition unit 115 is the part that acquires virus scan information contained in the information sent from the master unit. For example, if the received job list contains virus scan information, retrieve that virus scan information. This virus scan information is used when displaying the screens shown in Figures 8 and 9 above.
[0129] Additionally, when print information is received, the system retrieves virus scan information attached to the print data contained in the received print information (received print information). As described later, this virus scan information is used to determine whether printable data can be printed, to compare and verify the acquisition date of the scan pattern, and to determine whether or not to perform a virus scan on the client device.
[0130] The scan information confirmation unit 116 is the part that confirms the contents of the acquired virus scan information. Here, we check whether the received information contains virus scan information associated with the print data name. As will be discussed later, the presence or absence of virus scan information may be used to determine whether or not printing is permitted. In particular, if the handset lacks infection control functionality and cannot perform a virus scan, the ability to print is determined by whether or not the received information contains virus scan data.
[0131] Furthermore, if the received print information includes virus scan information, for example, the date the scan pattern was acquired in the received virus scan information is compared with the date the scan pattern was acquired in the scan processing information 144 stored in the storage unit 140 of the slave unit 2, and it is determined which date is more recent. By comparing the scan pattern acquisition dates, it is possible to determine which virus scan process—the one performed on the parent device or the one performed on the child device—is the appropriate one. Generally, using a virus pattern file with a more recent scan pattern acquisition date is considered a more appropriate process because it increases the likelihood of detecting newly emerging viruses.
[0132] For example, if the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the stored scan processing information 144, or if the dates are the same, the virus scan process performed by the master unit is determined to be more appropriate than the virus scan process performed by the slave unit.
[0133] On the other hand, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the stored scan processing information 144, the virus scan process performed by the child device is deemed to be a more appropriate process than the virus scan process performed by the parent device. In this case, even if a virus scan is being performed on the master unit, it is preferable for the slave unit to perform a virus scan using the virus scan engine and virus pattern files stored in the slave unit.
[0134] Furthermore, to verify the contents of the virus scan information, you can use not only the scan pattern acquisition date, but also the engine version of the virus scan engine and the pattern version of the virus pattern file. When using engine versions or pattern versions, you can determine which device's virus scan process is appropriate by checking the version of the received virus scan information against the version of the stored scan processing information 144.
[0135] The decryption unit 117 is the part that decrypts the information sent from the master unit using a predetermined encryption key (referred to as the second encryption key). For example, if the virus scan information is encrypted on the main unit, the encrypted virus scan information is decrypted using a predetermined encryption key. Decryption is performed using a predetermined encryption method between the master and slave units, and decryption is carried out using the encryption key pre-stored in the slave unit. Furthermore, the decryption unit 117 decrypts the encrypted virus scan information attached to the print data contained in the print information received by the print information receiving unit 114, and then the scan information acquisition unit 115 acquires the decrypted virus scan information as virus scan information. This allows the original, unencrypted information to be obtained.
[0136] As described later, if the virus scan information is encrypted using the private key of the master unit, the slave unit will decrypt the encrypted virus scan information using the public key of the master unit. Alternatively, if the virus scan information is encrypted on the master unit using the slave unit's public key, the slave unit decrypts the encrypted virus scan information using its own private key.
[0137] Furthermore, if the print data is encrypted in addition to the virus scan information, the print data will also be decrypted.
[0138] Furthermore, if decryption fails during the decryption process, that is, if the decrypted information is in a format that cannot be recognized as virus scan information, it can be determined that the received encrypted virus scan information is either fraudulent or potentially infected with a virus. Thus, if decryption of encrypted virus scan information fails (or is impossible), the print data transmitted along with the virus scan information is also considered unreliable. Therefore, it is preferable not to print the received print data, to quarantine it, or, if the client device can perform a virus scan, to perform a virus scan.
[0139] The printability determination unit 118 is the part that uses the acquired virus scan information to determine whether or not to print the print data contained in the received print information (received print information). The decision of whether or not to print print data is primarily made using virus scan information. For example, the presence or absence of virus scan information is used to determine whether or not to print the print data file. Furthermore, the decision of whether or not to print the print data may be based not only on the presence or absence of virus scan information, but also on other conditions. As will be described later, this may include whether or not decryption is possible, the content of the virus scan information (for example, the date the scan pattern was acquired), and the results of the virus scan process performed on the child device.
[0140] However, as described later, if the master unit performs a virus scan and sends a job list containing only print data in which no viruses were detected to the slave unit, and then the master unit performs another virus scan and sends print information containing print data in which no viruses were detected and virus scan information to the slave unit, the print data received by the slave unit can be considered safe data that is not infected with a virus, and therefore can be printed without making a decision on whether or not to print it.
[0141] For example, if the print information received by the print information receiving unit 114 includes print data with virus scan information attached and print data without virus scan information attached, the decision of whether or not to print the print data file may be made based on whether or not it contains virus scan information. In this case, the printability determination unit 118 determines that print data with virus scan information attached should be printed, and print data without virus scan information attached should not be printed.
[0142] If virus scan information is included, the print data contained in the received print information is considered safe data as it was scanned for viruses by the main unit and no viruses were detected. Therefore, it is safe to print. On the other hand, if virus scan information is not included, the print data included in the received print information has not been scanned for viruses by the main unit, and it is unknown whether or not it is infected with a virus. Therefore, it cannot be determined that the data is safe, and it is determined not to print.
[0143] Furthermore, if infection control processing (virus scanning) can be performed on the client device, the decision on whether or not to print the print data may be made based on the results of the virus scanning process performed on the client device, in addition to the presence or absence of virus scan information. In this case, the printability determination unit 118 first determines that if the received print information contains virus scan information, it will print the print data. On the other hand, if the received print information does not contain virus scan information, the device will perform a virus scan on the print data included in the received print information. If no virus is detected, it will decide to print the print data; however, if a virus is detected, it will decide not to print the print data.
[0144] Furthermore, if the received print information includes virus scan information, the print eligibility determination unit 118 may compare the virus scan information attached to the received print data with the scan processing information 144 stored in the slave unit's storage unit 140. If the virus scan information is newer than the scan processing information 144, it may determine that the received print data should be printed. If the virus scan information is older than the scan processing information 144, it may determine that the received print data should not be printed.
[0145] In this case, for example, the date information on which the virus pattern file included in the virus scan information attached to the received print data was acquired may be compared with the date information on which the virus pattern file included in the scan processing information 144 stored in the storage unit 140 of the slave unit was acquired to determine whether or not printing is permitted.
[0146] If the date information for acquiring the received virus pattern file is newer than or the same as the date information for acquiring the virus pattern file contained in the scan processing information 144 stored in the slave unit's storage unit 140, it is determined that the print data should be printed. On the other hand, even if the received print information includes virus scan information, if the date information for acquiring the received virus pattern file is older than the date information for acquiring the virus pattern file included in the scan processing information 144 stored in the slave unit's storage unit 140, it is determined that the print data will not be printed.
[0147] Alternatively, if infection prevention processing (virus scanning) can be performed on the sub-unit, the virus detection unit 107 of the sub-unit may perform infection prevention processing (virus scanning) on print data that the printability determination unit 118 has determined not to print, so that print data in which a computer virus is detected is not printed, and print data in which no computer virus is detected is printed.
[0148] In particular, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, instead of uniformly deciding not to print the print data, the slave unit may perform a virus scan on the print data included in the received print information. If no virus is detected, it may be decided to print, but if a virus is detected, it may be decided not to print.
[0149] Furthermore, if the received virus scan information is encrypted, the decision on whether or not to print may be based on whether or not the client device can decrypt it. In other words, if the print information received by the print information receiving unit 114 includes print data with encrypted virus scan information attached, when the decryption unit 117 decrypts the encrypted virus scan information, the print feasibility determination unit 118 may determine to print the print data with the encrypted virus scan information attached if the decryption is successful, or to not print the print data with the encrypted virus scan information attached if the decryption is unsuccessful.
[0150] Furthermore, if the encrypted virus scan information cannot be decrypted, the device may perform a virus scan on the print data included in the received print information. If no virus is detected, it may decide to print; however, if a virus is detected, it may decide not to print.
[0151] Alternatively, if the encrypted virus scan information can be decrypted, the above-described comparison of scan pattern acquisition dates may be performed. In this case, if the scan pattern acquisition date of the received virus scan information is newer than or the same as the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, it is determined to print. However, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, it is determined not to print.
[0152] The above description of the printability determination is just one example, and there are various printability determination patterns depending on the set determination conditions. Figures 10, 11, and 12, described later, illustrate an example of the correspondence between several setting conditions and whether or not printing is possible on the slave unit.
[0153] The memory unit 140 is the part that stores the information and programs necessary to execute each function of the slave unit (MFP-C) 2, and uses semiconductor memory elements such as ROM, RAM, and flash memory, storage devices such as HDDs and SSDs, and other storage media. The memory unit 140 stores, for example, master unit information 141, slave unit information 142, encryption key information 143, scan processing information 144, job list request 145, received job list 146, received print information 147, print data request 148, and so on. Figure 7 shows an explanatory diagram of one embodiment of the information stored in the storage unit 140 of the image forming apparatus (slave unit).
[0154] The master unit information 141 and the slave unit information 142 are the same as the master unit information 41 and the slave unit information 42 stored in the storage unit 40 of the master unit 1 described above. The encryption key information 143 is an encryption key based on an encryption scheme predetermined by the master and slave units. For example, the slave unit's private key, slave unit's public key, and master unit's public key are stored.
[0155] Scan processing information 144 is information stored when the slave device 2 has an infection prevention function, and is information (SC) related to the virus scan process performed on the slave device 2. As shown in Figure 7, the virus scan processing information 144 includes, for example, the scan engine name, engine version, pattern version, and scan pattern acquisition date.
[0156] The job list request 145 and the print data request 148 are the same as the job list request 48 and the print data request 49 stored in the storage unit 40 of the master unit 1, respectively. The received job list 146 corresponds to the job list 46 transmitted from the master unit 1, and the received print information 147 corresponds to the transmitted print information 47 transmitted from the master unit 1.
[0157] <Example of the relationship between the setting conditions for not encrypting virus scan information and the ability to print on the sub-unit> Figure 10 shows an explanatory diagram illustrating one example of the relationship between the setting conditions for not encrypting virus scan information and whether printing is possible on the client device. Here, the following items will be used as setting conditions to determine whether or not printing is possible. (1) Whether or not to include only virus-scanned print data in the job list and print transmission information. (2) Whether or not the sub-unit has an infection control function (scanning engine). (3) Whether or not to determine whether the scan pattern acquisition date is new or old. (4) Results of the virus scan process performed on the sub-unit (whether or not a virus was detected). Furthermore, neither the main unit nor the sub-unit will encrypt or decrypt virus scan information.
[0158] Figure 10 shows five printability patterns (A01 to A05). The settings for the main unit (MFP-P) should be configured so that encryption is not enabled and the encryption key is not stored. The job list sent to the sub-unit may include only the names of print data that have been scanned for viruses by the master unit and for which no viruses were detected (scan jobs), or it may include both scan jobs and print data that have not been scanned for viruses (unscan jobs). Furthermore, there are two cases in which the master unit sends print data to the slave unit, including only print data that has been scanned for viruses (scan jobs), and cases in which the master unit sends print data to the slave unit, including both scan jobs and print data that has not been scanned for viruses (unscanned jobs).
[0159] Furthermore, regarding the status of the sub-unit (MFP-C), since decoding is not performed, the feasibility of decoding is not determined, and it is assumed that it may or may not have a scan engine. Furthermore, if the sub-unit (MFP-C) has a scan engine, it may or may not perform a virus scan on the sub-unit, and it may or may not determine whether the scan pattern acquisition date is recent or recent.
[0160] (A01 in Figure 10) For example, in Figure 10, A01 shows a scenario where the master unit is set to "Do not encrypt" and "Send only scan jobs," the slave unit does not have a scan engine, and does not determine whether the scan pattern acquisition date is new or old. In this case, since virus scan information is always attached to the print data received by the slave unit, only print data in which no viruses were detected is sent to the slave unit, and therefore the slave unit decides to print all print data received. The communication sequence corresponding to A01 is shown in Figure 13, which will be described later.
[0161] (A02 in Figure 10) Figure 10, A02, shows a scenario where the master unit is set to "Do not encrypt" and "Send including unscanned jobs," and the slave unit does not have a scan engine and does not determine whether the scan pattern acquisition date is new or old.
[0162] In this case, the print data received by the handset may or may not have virus scan information attached, and the ability to print will differ depending on the type of data. If the print data received by the sub-unit has virus scan information attached, print it in the same way as A01. On the other hand, if print data received by the sub-unit does not have virus scan information attached, it is determined that it may be infected and should not be printed. The communication sequence corresponding to A02 is shown in Figure 14, which will be described later.
[0163] (A03 in Figure 10) In Figure 10, A03, the master unit is set to "Do not encrypt" and "Send including unscanned jobs," while the slave unit has a scan engine and does not determine the age of the scan pattern acquisition date. However, it shows a case where the slave unit performs a virus scan on unscanned jobs.
[0164] In this case as well, the print data received by the handset may or may not have virus scan information attached, and whether or not it can be printed will differ depending on the type of data. If the print data received by the sub-unit has virus scan information attached, print it in the same way as A01.
[0165] On the other hand, if the print data received by the sub-unit does not have virus scan information attached, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print. The communication sequence corresponding to A03 is shown in Figure 15, which will be described later.
[0166] (A04 in Figure 10) Figure 10, A04, shows a scenario where the master unit is set to "Do not encrypt" and "Send only scan jobs," while the slave unit has a scan engine that determines the age of the scan pattern acquisition date. For print data with an older scan pattern acquisition date in the received virus scan information, the slave unit performs a virus scan.
[0167] In this case, all print data received by the sub-unit has virus scan information attached, so the newer and older dates of the scan pattern acquisition are compared and determined. If the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the sub-unit, it is determined to print.
[0168] On the other hand, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave device, the virus scan process is executed on the slave device. If no viruses are detected during the virus scan, the system will decide to print; if viruses are detected, it will decide not to print.
[0169] (A05 in Figure 10) In Figure 10, A05 shows a scenario where the master unit is set to "Do not encrypt" and "Send including unscanned jobs," the slave unit has a scan engine, and for scan jobs with virus scan information, it determines whether the scan pattern acquisition date is new or old. Furthermore, for print data with an old scan pattern acquisition date for the received virus scan information, the slave unit performs a virus scan, and also performs a virus scan on unscanned jobs.
[0170] In this case, for scan jobs containing virus scan information, similar to A04, if the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the slave device, it is determined to print.
[0171] On the other hand, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the sub-unit, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0172] Furthermore, for unscanned jobs that do not have virus scan information, the sub-device performs a virus scan. If no virus is detected, it is decided to print; if a virus is detected, it is decided not to print. The communication sequence corresponding to A05 is shown in Figure 16, which will be described later.
[0173] <Example of the relationship between the setting conditions for encrypting and decrypting virus scan information using the master unit's encryption key and the printability on the slave unit> Figure 11 illustrates one example of the correspondence between the setting conditions for encrypting and decrypting virus scan information using the master unit's encryption key and whether printing is possible on the slave unit. Here, the following items will be used as setting conditions to determine whether or not printing is possible. (1) Whether or not to include only virus-scanned print data in the job list and print transmission information. (2) Whether or not the sub-unit has an infection control function (scanning engine). (3) Whether or not to determine whether the scan pattern acquisition date is new or old. (4) Results of the virus scan process performed on the sub-unit (whether or not a virus was detected). (5) The main unit encrypts the virus scan information using the main unit's encryption key (private key). (6) The child unit decrypts the encrypted virus scan information using the parent unit's encryption key (public key) and determines whether or not decryption is possible.
[0174] Conditions (1) through (4) above are the same as those in Figure 10. The encryption and decryption of virus scan information shall utilize "public-key cryptography," using the private key and public key, which are the encryption keys of the master unit. Furthermore, it is assumed that the master unit's private key is pre-stored in the master unit, and the master unit's public key is transferred from the master unit to the slave unit and pre-stored in the slave unit. If the virus scan information is encrypted using the parent unit's private key, the encrypted virus scan information received by the child unit is decrypted using the parent unit's public key.
[0175] Figure 11 shows four printability patterns (B01 to B04). As a setting requirement for the main unit (MFP-P), the virus scan information is encrypted using the encryption key (private key) stored in the main unit. Furthermore, the job list sent to the slave unit may include only the names of print data that have been scanned for viruses by the master unit and for which no viruses were detected (scan jobs), or it may include the names of print data that have not been scanned for viruses in addition to scan jobs (unscanned jobs).
[0176] Furthermore, the status of the sub-unit (MFP-C) is such that it decrypts the received encrypted virus scan information using the master unit's encryption key (public key), determines whether decryption is possible, and may or may not have a scan engine. Furthermore, if the sub-unit (MFP-C) has a scan engine, it may or may not perform a virus scan on the sub-unit, and it may or may not determine whether the scan pattern acquisition date is recent or recent.
[0177] (B01 in Figure 11) In Figure 11, B01 shows a scenario where the master unit is set to "encrypt" and "send only scan jobs," the slave unit does not have a scan engine, and the slave unit performs decryption and determines whether decryption is possible, but does not determine whether the scan pattern acquisition date is new or old. In this case, first, the master unit always adds virus scan information to the print data, but this virus scan information is encrypted with the master unit's private key, and the print data with this encrypted virus scan information added is sent to the slave unit.
[0178] Print data received by the sub-unit always includes encrypted virus scan information. The sub-unit decrypts this encrypted virus scan information using the public key of the master unit, which is stored in advance, and then determines whether or not decryption is possible. In determining whether decryption is possible, the system checks whether the decrypted virus scan information is legitimate. If it is legitimate (decryption is possible), it decides to print it. If it is invalid virus scan information (decryption is not possible), or if decryption fails, it decides not to print it.
[0179] (B02 in Figure 11) In Figure 11, B02, the master unit is set to "encrypt" and "send including unscanned jobs," while the slave unit does not have a scan engine. The slave unit decrypts scan jobs that contain virus scan information and determines whether decryption is possible, but does not determine whether the scan pattern acquisition date is new or old.
[0180] In this case, the print data received by the handset may or may not have encrypted virus scan information attached, and the printability will differ depending on whether or not this information is attached.
[0181] If the print data received by the sub-unit has encrypted virus scan information attached to it, the encrypted virus scan information is decrypted using the public key of the master unit that is stored in advance, and a decision is made as to whether or not decryption is possible. In determining whether decryption is possible, the system checks whether the decrypted virus scan information is legitimate. If it is legitimate (decryption is possible), it decides to print it. If it is invalid (decryption is not possible), or if decryption fails, it decides not to print it.
[0182] On the other hand, if print data received by the sub-unit does not have virus scan information attached, it is determined that it may be infected and should not be printed. The communication sequence corresponding to B02 is shown in Figure 18, which will be described later.
[0183] (Figure 11, B03) In Figure 11, B03 shows a scenario where the master unit is set to "encrypt" and "send including unscanned jobs," the slave unit does not have a scan engine, and the slave unit decrypts scan jobs that contain virus scan information, determines whether decryption is possible or not, and also determines whether the scan pattern acquisition date is new or old.
[0184] In this case, as with B02, the print data received by the sub-unit may or may not have encrypted virus scan information attached, and the ability to print will differ depending on the type of data.
[0185] Also, similar to B02, if the print data received by the slave unit has encrypted virus scan information attached, the encrypted virus scan information is decrypted using the master unit's public key, which is stored in advance, and a decision is made as to whether or not decryption is possible. In determining whether decryption is possible, the system checks whether the decrypted virus scan information is legitimate or not. If the information is invalid (i.e., decryption is not possible), or if decryption fails, the system decides not to print it.
[0186] On the other hand, if the decryption process determines that the virus scan information is normal (i.e., decryption is possible), the date of acquisition of the scan pattern of the decrypted virus scan information is compared and judged. If the scan pattern acquisition date of the decrypted virus scan information is within a predetermined period and recent compared to the current date and time (△1 in B03 of Figure 11), it is determined to print. However, if the scan pattern acquisition date of the decrypted virus scan information is older than a predetermined period compared to the current date and time (△2 in B03 of Figure 11), it will be determined not to print.
[0187] Furthermore, if the print data received by the sub-unit does not have virus scan information attached, it is determined that it may be infected, similar to B02, and therefore should not be printed. The communication sequence corresponding to B03 is shown in Figure 19, which will be described later.
[0188] (Figure 11, B04) In Figure 11, B04 shows a scenario where the master unit is set to "encrypt" and "send including unscanned jobs," the slave unit has a scan engine, and for scan jobs that contain virus scan information, the slave unit decrypts them and determines whether decryption is possible, and also determines whether the scan pattern acquisition date is new or old. Furthermore, for print data with an old scan pattern acquisition date of the received virus scan information, the slave unit performs a virus scan, and also performs a virus scan on unscanned jobs.
[0189] In this case, similar to B03, if the print data received by the slave unit has encrypted virus scan information attached, the encrypted virus scan information is decrypted using the master unit's public key, which is stored in advance, and a decision is made as to whether or not decryption is possible.
[0190] In determining whether decryption is possible, if the decrypted virus scan information is determined to be normal virus scan information (i.e., decryption is possible), the acquisition date of the scan pattern of the decrypted virus scan information is compared and judged. If the scan pattern acquisition date of the decrypted virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the child device, it is determined to print.
[0191] On the other hand, if the scan pattern acquisition date of the decrypted virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the sub-unit, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0192] Furthermore, in determining whether decryption is possible, if the decrypted virus scan information is invalid (decryption is not possible), or if decryption fails, the child device will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0193] Furthermore, even if the print data received by the sub-unit does not have virus scan information attached, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print. The communication sequence corresponding to B04 is shown in Figure 20, which will be described later.
[0194] <Example of the relationship between the setting conditions for encrypting and decrypting virus scan information using the client device's encryption key and the printability on the client device> Figure 12 illustrates one example of the correspondence between the setting conditions for encrypting and decrypting virus scan information using the client device's encryption key and whether or not printing is possible on the client device. Here, the following items will be used as setting conditions to determine whether or not printing is possible. (1) Whether or not to include only virus-scanned print data in the job list and print transmission information. (2) Whether or not the sub-unit has an infection control function (scanning engine). (3) Whether or not to determine whether the scan pattern acquisition date is new or old. (4) Results of the virus scan process performed on the sub-unit (whether or not a virus was detected). (5) The main unit encrypts the virus scan information using the encryption key (public key) of the child unit. (6) The client device decrypts the encrypted virus scan information using the client device's encryption key (private key) and determines whether or not decryption is possible.
[0195] Conditions (1) through (4) above are the same as those in Figure 10. The encryption and decryption of virus scan information utilizes "public-key cryptography," but differs from the embodiment shown in Figure 11 above in that it uses the private key and public key, which are the encryption keys of the child device. Furthermore, it is assumed that the private key of the child unit is pre-stored in the child unit, and the public key of the child unit is transferred from the child unit to the parent unit and pre-stored in the parent unit. If the virus scan information is encrypted on the master unit using the slave unit's public key, the received encrypted virus scan information is decrypted on the slave unit using the slave unit's private key.
[0196] Figure 12 shows four printability patterns (C01 to C04). The only difference from the embodiment in Figure 11 is that the encryption key of the slave device is used as the encryption key. The state of the slave device and whether printing is possible on the slave device are the same as in the embodiment in Figure 11.
[0197] (C01 in Figure 12) In Figure 12, C01, similar to B01 in Figure 11, the master unit is set to "encrypt" and "send only scan jobs," while the slave unit does not have a scan engine. The slave unit decrypts the data and determines whether decryption is possible, but does not determine whether the scan pattern acquisition date is new or old. In this case, first, the master unit always adds virus scan information to the print data, but this virus scan information is encrypted with the slave unit's public key, and the print data with this encrypted virus scan information added is sent to the slave unit.
[0198] Print data received by the handset always includes encrypted virus scan information. This encrypted virus scan information is decrypted using the handset's pre-stored secret key, and the system determines whether or not decryption is possible. In determining whether decryption is possible, the system checks whether the decrypted virus scan information is legitimate. If it is legitimate (decryption is possible), it decides to print it. If it is invalid virus scan information (decryption is not possible), or if decryption fails, it decides not to print it. The communication sequence corresponding to this C01 is shown in Figure 17, which will be described later.
[0199] (C02 in Figure 12) In Figure 12, C02, similar to Figure 11, B02, the master unit is set to "encrypt" and "send including unscanned jobs," while the slave unit does not have a scan engine. The slave unit decrypts scan jobs that contain virus scan information and determines whether decryption is possible, but does not determine whether the scan pattern acquisition date is new or old.
[0200] In this case, the print data received by the handset may or may not have encrypted virus scan information attached, and the printability will differ depending on whether or not this information is attached.
[0201] If the print data received by the sub-unit has encrypted virus scan information attached to it, the encrypted virus scan information is decrypted using the sub-unit's secret key, which is stored in advance, and a decision is made as to whether or not decryption is possible. In the determination of whether decryption is possible, it is determined whether the decrypted virus scan information is normal virus scan information. If it is normal virus scan information (if decryption is possible), it is determined to print; if it is invalid virus scan information (if decryption is not possible) or if decryption fails, it is determined not to print.
[0202] On the other hand, if the print data received by the slave device is not added with virus scan information, there is a possibility that the print data is infected, so it is determined not to print.
[0203] (C03 in FIG. 12) In C03 of FIG. 12, similarly to B03 of FIG. 11, "encrypt" and "transmit including unscanned jobs" are set in the master device, the slave device does not have a scan engine, and this illustrates a case where for scan jobs with virus scan information, the slave device performs decryption to determine whether decryption is possible, and further determines whether the acquisition date of the scan pattern is new or old.
[0204] In this case, similarly to C02, the print data received by the slave device includes one added with encrypted virus scan information and one not added with encrypted virus scan information, and their printability is different.
[0205] Also, similarly to C02, if the print data received by the slave device is added with encrypted virus scan information, the encrypted virus scan information is decrypted with the pre-stored private key of the slave device, and it is determined whether decryption is possible. In the determination of whether decryption is possible, it is determined whether the decrypted virus scan information is normal virus scan information, and if it is invalid virus scan information (if decryption is not possible) or if decryption fails, it is determined not to print.
[0206] On the other hand, if it is determined in the determination of whether decryption is possible that the virus scan information is normal (if decryption is possible), whether the acquisition date of the scan pattern in the decrypted virus scan information is new or old is compared and determined. If the scan pattern acquisition date of the decrypted virus scan information is within a predetermined period and recent compared to the current date and time (△1 in C03 of Figure 12), it is determined to print. However, if the scan pattern acquisition date of the decrypted virus scan information is older than a predetermined period compared to the current date and time (△2 in C03 of Figure 12), it will be determined not to print.
[0207] Furthermore, if the print data received by the sub-unit does not have virus scan information attached, it is determined that it may be infected, similar to C02, and therefore should not be printed.
[0208] (C04 in Figure 12) In Figure 12, C04, similar to Figure 11, B04, the master unit is set to "encrypt" and "send including unscanned jobs," and the slave unit has a scan engine. The slave unit decrypts scan jobs that contain virus scan information and determines whether decryption is possible, and also determines whether the scan pattern acquisition date is new or old. Furthermore, for print data with an old scan pattern acquisition date of the received virus scan information, the slave unit performs a virus scan process, and also performs a virus scan process on unscanned jobs.
[0209] In this case, similar to C03, if the print data received by the slave device has encrypted virus scan information attached, the encrypted virus scan information is decrypted using the slave device's secret key, which is stored in advance, and a decision is made as to whether or not decryption is possible.
[0210] In determining whether decryption is possible, if the decrypted virus scan information is determined to be normal virus scan information (i.e., decryption is possible), the acquisition date of the scan pattern of the decrypted virus scan information is compared and judged. If the scan pattern acquisition date of the decrypted virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the child device, it is determined to print.
[0211] On the other hand, if the scan pattern acquisition date of the decrypted virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the sub-unit, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0212] Furthermore, in determining whether decryption is possible, if the decrypted virus scan information is invalid (decryption is not possible), or if decryption fails, the child device will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0213] Furthermore, even if the print data received by the sub-unit does not have virus scan information attached, the sub-unit will perform a virus scan. If no virus is detected, it will decide to print; if a virus is detected, it will decide not to print.
[0214] <An example of information and communication processing from the time that infection control measures are applied to the print data entered into the master unit, until the print process is executed on the slave unit.> The following shows a communication sequence of one embodiment of the information communication processing corresponding to the relationship between the setting conditions shown in Figures 10 to 12 and the printability status on the slave unit, from infection control processing on the print data input to the master unit to the execution of the print process on the slave unit.
[0215] The communication sequences in Figures 13 to 16 are examples where virus scan information is not encrypted or decrypted. The communication sequence in Figure 13 corresponds to A01 in Figure 10, the communication sequence in Figure 14 corresponds to A02 in Figure 10, the communication sequence in Figure 15 corresponds to A03 in Figure 10, and the communication sequence in Figure 16 corresponds to A05 in Figure 10.
[0216] The communication sequences in Figures 17 to 20 are examples of cases where virus scan information is encrypted and decrypted. The communication sequence in Figure 17 corresponds to C01 in Figure 12, the communication sequence in Figure 18 corresponds to B02 in Figure 11, the communication sequence in Figure 19 corresponds to B03 in Figure 11, and the communication sequence in Figure 20 corresponds to B04 in Figure 11.
[0217] (Example 1 of information and communication processing: No encryption, A01 in Figure 10) Figure 13 shows a communication sequence of one embodiment of information communication processing, from infection prevention processing on print data input to the master unit, to printing only the print data that has undergone virus scanning on the slave unit. This section shows the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C.
[0218] The master unit will perform a virus scan on the input print data, and the master unit will store a virus scan engine and virus pattern information, and will store virus scan information as shown in Figure 6.
[0219] Furthermore, the system will send a job list containing only the print data names of print data that have undergone virus scanning (scan jobs) to the client device, and will also send only the files of print data that have undergone virus scanning (scan jobs) to the client device. The job list and print data (scan job) files sent to the sub-unit always include virus scan information. The sub-unit does not have a virus scanning engine and is not capable of performing virus scanning. It will only print print data (scan jobs) that contain virus scanning information.
[0220] Therefore, since the print data name of print data that has not undergone virus scan processing (unscanned job) is not included in the job list, the slave device cannot select an unscanned job as a print target, and a file of an unscanned job is never transmitted to the slave device.
[0221] In step A1 of the information creating apparatus (user terminal) PC in FIG. 13, assume that a user creates input print data for printing, assigns a print data name to the input print data, and stores the input print data. There may be one input print data or a plurality of input print data. In step A2, when a user selects an image forming apparatus (master device) MFP-P as a transmission destination of input print data and performs an input operation to transmit the input print data, a file of the input print data to which a print data name is assigned is transmitted to the master device MFP-P.
[0222] In step P1 of the image forming apparatus (master device) MFP-P, input print data 44 is received. In step P2, virus scan processing is executed on the received input print data 44. In the virus scan processing, for example, processing such as virus detection, virus quarantine, and virus removal is performed. Here, it is assumed that print data in which a virus is detected and quarantined print data are not subjected to the following processing and are not included in the job list.
[0223] In step P3, virus scan information 45, which is information related to a virus scan engine and a virus pattern used when executing virus scan processing, is acquired from a storage unit 40. In step P4, virus scan information 45 is added to the input print data 44, and the resultant data is stored in the storage unit 40. The input print data 44 stored with virus scan information 45 added thereto is print data in which no virus was detected. Here, the print data name of the input print data 44, the virus scan information 45, and the file that is the actual input print data 44 are stored in association with each other.
[0224] Suppose a user who created input print data on an information creation device PC goes to a location where an image forming apparatus (slave unit) MFP-C is installed and performs an input operation on the slave unit MFP-C to print the input print data they created, by entering user identification information (username) and requesting a job list. In this case, for example, to perform user authentication, the user ID and password may be entered, and if user authentication is successful, the username may be obtained.
[0225] In step C1 of the image forming apparatus (slave unit) MFP-C, a job list request 145 including the username is generated and sent to the master unit MFP-P. For example, a job list request 145 as shown in Figure 7 above is sent. In step P5 of the master MFP-P, a job list request 48 is received.
[0226] In step P6, a job list 46 is generated. Here, the print data name of the input print data 44 stored in the storage unit 40 is obtained, which is associated with the username included in the received job list request. Furthermore, in this embodiment, a job list consisting only of print data (scan jobs) on which a virus scan process has been performed is sent, so the print data name of the input print data 44 that is associated with the username and to which the virus scan information 45 has been added is obtained. For example, in the job list 46 shown in Figure 6 above, a job list 46 is generated that includes only the print data names of the input print data 44 to which virus scan information 45 has been added.
[0227] In step P7, the generated job list 46 is sent to the MFP-C slave unit. Here, a job list 46 consisting only of scan jobs is sent. In step C2 of the MFP-C sub-unit, the job list (received job list 146) is received.
[0228] In step C3, the received job list 146 is displayed on the display unit 103. For example, display the print job list screen G1 as shown in Figure 8 above. However, in this embodiment, since all the print data in the displayed received job list 146 are scan jobs, the "Scanned / Not Scanned" column will all display "○ (Completed)". Furthermore, in this embodiment, since unscanned jobs are not included in the received job list 146, a notice may be displayed to alert users that print data for which virus scanning has not yet been performed on the master unit is not included in the job list.
[0229] The user looks at this display screen G1 and performs an input operation to select the desired print data they want to print. For example, when an input operation is performed to select the "Print Selection Available / Not Available" field corresponding to the desired print data name displayed on screen G1 in Figure 8, a circle "○" will be displayed in the "Print Selection Available / Not Available" field to indicate that a selection has been made. Furthermore, if the user selects a desired print data name, the scan information details screen G2, as shown in Figure 9, may be displayed.
[0230] In step C4, if the user performs an input operation to select print data, a print data request is generated to request the master unit to send the selected print data. For example, a print data request 148 like the one shown in Figure 7 is generated. In step C5, if the user performs a predetermined input operation to request the master unit to send print data, the generated print data request 148 is sent to the master unit MFP-P. In step P8 of the main unit MFP-P, a print data request 49 is received.
[0231] In step P9, the print data with the print data name included in the print data request is obtained from the master unit's storage unit 40. In step P10, the system generates print information to be sent, which includes a print data file with virus scan information added to the acquired print data. For example, the transmission print information 47 shown in Figure 6 is generated. In step P11, the generated print transmission information 47 is sent to the MFP-C (Multifunction Printer).
[0232] In step C6 of the MFP-C handset, the send print information 47 (received send information 147) is received. In step C7, check whether or not virus scan information is included in the received / transmitted information 147. In step C8, the received print data is printed on the designated paper. In this embodiment, all received print data contains virus scan information, so all print data is printed.
[0233] As described above, the print data sent to the child device is only print data that has been scanned for viruses by the master unit and for which no viruses were detected. Therefore, if the master unit's virus scan process uses the latest virus scanning engine and pattern files, the possibility of virus-infected print data being sent to the child device is low, and the risk of the child device becoming infected with a computer virus can be reduced.
[0234] (Example 2 of information and communication processing: No encryption, A02 in Figure 10) Figure 14 shows a communication sequence of one embodiment of information communication processing, in which infection prevention processing is performed on print data input to the master unit, and then the presence or absence of virus scan information attached to the print data is used to determine whether or not the print processing on the slave unit can be performed, and the print processing is performed on the slave unit for print data that has virus scan information. Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 14, steps that perform the same processing as the steps in Figure 13 are assigned the same step number.
[0235] The master unit will perform a virus scan on the input print data, and the master unit will store a virus scan engine and virus pattern information, and will store virus scan information as shown in Figure 6. However, if the main unit is under heavy processing load, such as immediately after inputting print data or while a job is running, the virus scan process may not have been performed yet. The main unit will perform a virus scan, and print data that does not detect a virus will have virus scan information added to it. However, print data that is scanned for a virus and found to have a virus will not have virus scan information added to it, and print data that has not been scanned for a virus will also not have virus scan information added to it.
[0236] Furthermore, the job list sent to the slave unit shall include the names of the print data for which virus scanning has been performed (scan jobs) and the names of the print data for which virus scanning has not been performed (unscanned jobs). The print information sent to the handset includes both scanned and unscanned job files. Scanned jobs contain virus scan information and are print data where no viruses were detected, while unscanned jobs do not contain virus scan information and it is unknown whether or not they are infected.
[0237] The sub-unit does not have a virus scanning engine and is not capable of performing virus scanning. It will only print print data (scan jobs) that contain virus scanning information.
[0238] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 14, steps P1 to P5 of the image forming apparatus (master unit) MFP-P, and step C1 of the image forming apparatus (slave unit) MFP-C perform the same processing as in Figure 13. In steps A1 and A2 of Figure 14, when the user creates the input print data, the input print data file, which is assigned a print data name, is sent to the master MFP-P.
[0239] In steps P1 to P4 of the image forming apparatus (master unit) MFP-P, when input print data 44 is received, a virus scan process is executed, virus scan information 45 is obtained from the storage unit 40, and the virus scan information 45 is added to the input print data in which no virus was detected. The print data name of the input print data 44, the virus scan information 45, and the file that is the actual input print data 44 are stored in association with each other. On the other hand, virus scan information will not be added to print data that has not yet undergone a virus scan.
[0240] If the user performs an input operation on the sub-unit MFP-C, entering a username and requesting a job list, then in step C1, a job list request 145 including the username is generated and sent to the master unit MFP-P. In step P5 of the master MFP-P, job list request 48 is received.
[0241] After step P5, in step P21, the print data name of the input print data 44 stored in the storage unit 40 is obtained in association with the username included in the received job list request, and a job list 46 is generated. Here, we retrieve the print data names of all 44 input print data entries associated with the username. In other words, the job list 46 includes not only print data for which a virus scan has been performed (scan jobs), but also print data for which a virus scan has not yet been performed (unscanned jobs). In Job List 46, virus scan information is attached to scan jobs, but not to unscanned jobs.
[0242] In step P7, the job list 46, including unscanned jobs, is sent to the MFP-C sub-unit. In step C2 of the slave unit MFP-C, the job list (received job list 146) is received, and then steps C3 to C5 are executed as in Figure 13, followed by steps P8 and P9 of the master unit MFP-P.
[0243] In other words, the print job list display screen G1, which includes the received job list 146, is displayed on the display unit 103. When a user looks at this display screen G1 and performs an input operation to select the desired print data they want to print, a mark "○" indicating that a selection has been made is displayed in the "Print Selection Yes / No" column, a print data request 148 is generated, and if the user performs a predetermined input operation to request the master unit to send the print data, the generated print data request 148 is sent to the master unit MFP-P.
[0244] In this embodiment, the job list on the print job list display screen G1 includes both scanned jobs and unscanned jobs. By checking the "Scanned / Unscanned" column on the display screen G1, it is easy to distinguish whether or not the print data displayed in the job list has undergone a virus scan. Therefore, by checking the "Scanned / Not Scanned" column, users can select only those files that have undergone a virus scan as the data to be printed, or they can, at their own discretion, confirm that a job has not been scanned and then select that job as the data to be printed.
[0245] In step P8 of the master MFP-P, when a print data request 49 is received, in step P9, the master MFP-P retrieves print data from its storage unit 40 that has the print data name included in the print data request.
[0246] After step P9, in step P22, print transmission information 47 containing the requested print data file is generated. Here, the transmitted print information 47 includes not only print data with virus scan information attached, but also print data without virus scan information attached, if the requested print data is an unscanned job.
[0247] In step P11, the generated print transmission information 47 is sent to the MFP-C (Multifunction Printer). Here, the transmitted print information 47 contains a mixture of print data with virus scan information attached and print data without virus scan information attached.
[0248] Subsequently, in step C6 of the MFP-C sub-unit, similar to Figure 13, the transmitted print information 47 (received transmission information 147) is received, and in step C7, it is checked whether or not virus scan information is included in each print data within the received transmission information 147.
[0249] In step C11, if the print data contains virus scan information, the received print data is printed on the designated paper. On the other hand, in step C12, if the print data does not contain virus scan information, the received print data will, in principle, not be printed. However, as mentioned above, if a user confirms in the job list that a job is not yet scanned and selects that job as the data to be printed, the print job may be printed even if the print data does not contain virus scan information.
[0250] (Example 3 of information and communication processing: No encryption, A03 in Figure 10) Figure 15 shows a communication sequence of one embodiment of information communication processing, in which infection prevention processing is performed on print data input to the master unit, and then the presence or absence of virus scan information attached to the print data is used to determine whether or not the print processing on the slave unit can be performed, and for print data without virus scan information, the slave unit performs virus scanning processing. Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 15, steps that perform the same processing as the steps in Figures 13 and 14 are assigned the same step number.
[0251] In this embodiment, as in the embodiment shown in Figure 14, the master unit performs a virus scan on the input print data. The master unit stores a virus scan engine and virus pattern information, and the virus scan information shown in Figure 6 is stored therein. Furthermore, if a virus scan is performed on the main unit and no viruses are detected, virus scan information will be added to the print data. However, if a virus scan is not performed on the print data, virus scan information will not be added.
[0252] Furthermore, the job list sent to the slave unit shall include the names of the print data for which virus scanning has been performed (scan jobs) and the names of the print data for which virus scanning has not been performed (unscanned jobs). The print information sent to the handset includes both scanned and unscanned job files. Scanned jobs contain virus scan information and are print data where no viruses were detected, while unscanned jobs do not contain virus scan information and it is unknown whether or not they are infected.
[0253] Furthermore, unlike the embodiments shown in Figures 13 and 14, the slave unit is equipped with a virus scanning engine and performs virus scanning on print data (unscanned jobs) that does not contain received virus scanning information.
[0254] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 15, the processing from steps P1 to P11 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C6 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 14, so their explanation is omitted.
[0255] Similar to Figures 13 and 14, in step C6 of the MFP-C sub-unit, after receiving the transmitted print information 47 (received transmission information 147), in step C7, it is checked whether each print data in the received transmission information 147 contains virus scan information.
[0256] In step C11, if the print data contains virus scan information, the received print data is printed on the designated paper, as in Figure 14.
[0257] On the other hand, in step C21, if the print data does not contain virus scan information, a virus scan process is performed on the received print data. The virus scanning process here is performed using the virus scanning engine and virus pattern files stored in the child device.
[0258] In step C22, if no viruses are detected during the virus scan process, the received print data is printed on the designated paper. On the other hand, in step C23, if a virus is detected during the virus scan process, the received print data will not be printed.
[0259] (Example 4 of information and communication processing: No encryption, A05 in Figure 10) Figure 16 shows a communication sequence of one embodiment of information communication processing, in which, after infection control processing is performed on print data input to the master unit, the system determines whether or not to execute the print process on the slave unit based on the presence or absence of virus scan information attached to the print data and the age of the pattern acquisition date included in the virus scan information attached to the print job, and for print data with an older pattern acquisition date, the slave unit executes the virus scan process.
[0260] Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 16, steps that perform the same processing as the steps in Figures 13, 14, and 15 are assigned the same step number.
[0261] In the embodiment shown in Figure 16, unlike the embodiments shown in Figures 13 to 15, the slave unit, upon receiving print data (scan job) containing virus scan information, checks whether the received virus scan information pattern acquisition date is new or old. In other words, if the received print information includes virus scan information, the date the scan pattern of the received virus scan information is acquired is compared with the date the scan pattern of the scan processing information 144 stored in the slave unit's memory unit 140 is acquired, and it is determined which date is more recent.
[0262] Furthermore, the sub-unit shall be equipped with a virus scan engine and shall perform a virus scan on print data that does not contain received virus scan information (unscanned jobs). In addition, in the comparison of scan pattern acquisition dates, if the scan pattern acquisition date of the received virus scan information is older, the virus scan process shall also be performed.
[0263] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 16, the processing from steps P1 to P11 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C6 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 15, so their explanation is omitted.
[0264] Similar to Figure 15, in step C6 of the MFP-C sub-unit, after receiving the transmitted print information 47 (received transmission information 147), in step C7, it is checked whether or not virus scan information is included in each print data within the received transmission information 147.
[0265] In step C21, if the print data does not contain virus scan information, the slave unit performs a virus scan on the received print data, as in Figure 15. In step C22, if no virus is detected, the received print data is printed on the designated paper. In step C23, if a virus is detected, the received print data is not printed.
[0266] On the other hand, in step C31, if the print data contains virus scan information, the system checks whether the received virus scan information pattern acquisition date is recent or recent. Here, the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140 is read and compared with the scan pattern acquisition date of the received virus scan information.
[0267] In step C32, if the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, the received print data is printed on the designated print paper.
[0268] On the other hand, in step C33, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, a virus scan process is performed on the print data containing the received virus scan information. In step C34, if no virus is detected, the received print data is printed on the designated paper. In step C35, if a virus is detected, the received print data is not printed.
[0269] (Example 5 of information and communication processing: With encryption using the slave device's secret key, C01 in Figure 12) Figure 17 shows a communication sequence of one embodiment of information communication processing, from the time that the print data input to the master unit is subjected to infection prevention processing, to the time that the print data with virus scan information encrypted with the slave unit's public key is sent to the slave unit, and the slave unit performs printing only on the print data that has been scanned for viruses and whose virus scan information can be decrypted with the slave unit's private key.
[0270] Here, similar to the embodiment in Figure 13, the master unit sends a job list containing only the print data names of print data (scan jobs) for which a virus scan has been performed, and sends only the files of print data (scan jobs) for which a virus scan has been performed to the slave unit. The job list and the print data (scan job) files sent to the slave unit will always contain virus scan information.
[0271] However, this differs from the embodiment shown in Figure 13 in that the master unit sends print data to the slave unit with virus scan information encrypted using the slave unit's public key. Furthermore, the client device decrypts encrypted virus scan information using its private key. If decryption is successful, the received print data is printed; however, if decryption fails, the received print data is not printed. The sub-unit does not have a virus scanning engine and is not capable of performing virus scanning. It will only print print data (scan jobs) that contain virus scanning information.
[0272] Figure 17 also shows the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 17, steps that perform the same processing as the steps in Figure 13 are assigned the same step number.
[0273] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 17, the processing from steps P1 to P9 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C5 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 13, so their explanation is omitted.
[0274] In step P9 of the image forming apparatus (master unit) MFP-P, after obtaining the requested print data from the storage unit 40, in step P31, the virus scan information stored in the master unit is encrypted with the public key of the slave unit. In step P32, print data to be sent is generated, which includes print data with encrypted virus scan information (encrypted virus scan information) attached.
[0275] Subsequently, in step P11, the generated print transmission information 47 is sent to the MFP-C. In step C6 of the MFP-C handset, the send print information 47 (received send information 147) is received.
[0276] In step C41, the encrypted virus scan information contained in the received transmitted print information 47 is obtained, and the encrypted virus scan information is decrypted using the slave device's secret key. In step C42, the system checks whether the encrypted virus scan information can be decrypted. In other words, the decryption process checks whether or not the correct virus scan information has been restored. In step C43, if the encrypted virus scan information is successfully decrypted, the received print data is printed on the designated paper. In step C44, if decryption fails, the received print data is not printed.
[0277] Note that in Figure 17, the encryption of virus scan information is performed in step P31, but the acquired virus scan information may also be encrypted with the public key of the child device after step P3, when the virus scan information is acquired. Alternatively, when the scan engine or virus pattern files on the master unit are updated to newer versions, the virus scan information may also be updated to reflect the updated scan engine and virus pattern files, and the updated virus scan information may be encrypted using the master unit's public key. In this case, since the encrypted virus scan information is added to the print data in step P4, encryption is not performed in step P31.
[0278] (Example 6 of information and communication processing: Encryption using the master unit's secret key, B02 in Figure 11) Figure 18 shows a communication sequence of one embodiment of information communication processing, which involves performing infection prevention processing on print data input to the master unit, sending print data to the slave unit with virus scan information encrypted with the master unit's private key attached, determining whether or not to execute the print process on the slave unit based on the presence or absence of virus scan information attached to the print data, and executing the print process on the slave unit only for print data that has undergone virus scan processing and whose virus scan information can be decrypted with the master unit's public key.
[0279] Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 18, steps that perform the same processing as the steps in Figure 17, etc., are assigned the same step number.
[0280] In this embodiment, similar to the embodiment in Figure 14, the master unit performs a virus scan on the input print data. The master unit stores a virus scan engine and virus pattern information, and the virus scan information shown in Figure 6 is stored therein. Furthermore, if a virus scan is performed on the main unit and no viruses are detected, virus scan information will be added to the print data. However, if a virus scan is not performed on the print data, virus scan information will not be added.
[0281] Furthermore, the job list sent to the slave unit shall include the names of the print data for which virus scanning has been performed (scan jobs) and the names of the print data for which virus scanning has not been performed (unscanned jobs). The print information sent to the handset includes both scanned and unscanned job files. Scanned jobs contain virus scan information and are print data where no viruses were detected, while unscanned jobs do not contain virus scan information and it is unknown whether or not they are infected.
[0282] In this embodiment shown in Figure 18, the master unit sends print data to the slave unit with virus scan information encrypted using the master unit's secret key, which is different from the embodiment shown in Figure 17. Furthermore, the client device decrypts encrypted virus scan information using the parent device's public key. If decryption is successful, the received print data is printed; however, if decryption fails, the received print data is not printed.
[0283] Furthermore, the slave unit will not have a virus scanning engine and will not be able to perform virus scanning. It will not print print data that does not contain virus scanning information (unscanned jobs), and will decrypt print data that contains virus scanning information (scanned jobs) using the master unit's public key.
[0284] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 18, the processing from steps P1 to P9 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C5 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 17, so their explanation is omitted.
[0285] In step P9 of the image forming apparatus (master unit) MFP-P, after obtaining the requested print data from the storage unit 40, in step P41, the virus scan information stored in the master unit is encrypted with the master unit's secret key. In step P42, similar to step P32, print data to be transmitted is generated, which includes print data with encrypted virus scan information (encrypted virus scan information) attached.
[0286] Subsequently, in step P11, the generated print transmission information 47 is sent to the MFP-C. In step C6 of the MFP-C handset, the send print information 47 (received send information 147) is received.
[0287] In step C7, check whether each print data in the received / transmitted information 147 contains virus scan information. In step C12, if the print data does not contain virus scan information, the received print data will not be printed. On the other hand, in step C51, if the print data contains virus scan information, the encrypted virus scan information is decrypted using the master unit's public key.
[0288] In step C52, similar to step C42 described above, the ability to decrypt the encrypted virus scan information is checked. In other words, the decryption process checks whether or not the correct virus scan information has been restored. If decryption fails in step C53, the received print data will not be printed. In step C54, if the encrypted virus scan information is successfully decrypted, the received print data is printed on the designated paper.
[0289] In the embodiment shown in Figure 18, instead of encrypting the virus scan information in step P41, the acquired virus scan information may be encrypted with the master unit's secret key after step P3, when the virus scan information is acquired. Alternatively, when the scan engine or virus pattern files on the main unit are updated to newer versions, the virus scan information may also be updated, and the updated virus scan information may be encrypted using the main unit's private key.
[0290] (Example 7 of information and communication processing: Encryption using the master unit's secret key, B03 in Figure 11) Figure 19 shows a communication sequence of one embodiment of information communication processing, from the time that infection countermeasures are applied to the print data input to the master unit, to the time that the print data with virus scan information encrypted with the master unit's private key is attached is sent to the slave unit, and the slave unit determines whether or not to execute the print process based on whether or not virus scan information is attached to the print data, whether or not the virus scan information can be decrypted with the master unit's public key, and whether or not the pattern acquisition date included in the virus scan information attached to the print job is new, and the slave unit executes the print process only for print data that has virus scan information, can be decrypted with the master unit's public key, and has a new pattern acquisition date.
[0291] Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 19, steps that perform the same processing as the steps in Figure 18, etc., are assigned the same step number.
[0292] In this embodiment shown in Figure 19, the master unit sends print data to the slave unit with virus scan information encrypted using the master unit's private key, and the slave unit decrypts the encrypted virus scan information using the master unit's public key, which is the same as in the embodiment shown in Figure 18.
[0293] Furthermore, similar to the embodiment in Figure 18, the slave unit does not have a virus scanning engine and is unable to perform virus scanning. It will not print print data that does not contain virus scanning information (unscanned jobs), and will decrypt print data that contains virus scanning information (scanned jobs) using the master unit's public key.
[0294] Furthermore, as in the embodiment shown in Figure 18, if decryption fails, the received print data will not be printed. However, unlike the embodiment in Figure 18, if decryption is successful, the slave unit will check whether the received virus scan information pattern acquisition date is new or old. In other words, if the received print information includes virus scan information, the date the scan pattern of the received virus scan information is acquired is compared with the date the scan pattern of the scan processing information 144 stored in the slave unit's memory unit 140 is acquired, and it is determined which date is more recent.
[0295] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 19, the processing from steps P1 to P11 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C52 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 18, so their explanation is omitted.
[0296] In step C52, similar to Figure 18, the ability to decrypt encrypted virus scan information is checked. If decryption fails in step C53, the received print data will not be printed, as shown in Figure 18. On the other hand, if the encrypted virus scan information is successfully decrypted in step C61, a check is performed to determine whether the received encrypted virus scan information pattern acquisition date is new or old. Here, the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140 is read and compared with the scan pattern acquisition date of the received virus scan information.
[0297] In step C62, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's memory unit 140, the received print data is not printed.
[0298] On the other hand, in step C63, if the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's storage unit 140, the received print data is printed on the designated print paper.
[0299] (Example 8 of information and communication processing: Encryption using the master unit's secret key, B04 in Figure 11) Figure 20 shows a communication sequence of one embodiment of information communication processing, in which, after infection prevention processing is performed on print data input to the master unit, print data with virus scan information encrypted with the master unit's private key is sent to the slave unit, and the slave unit determines whether or not to execute the print process based on the presence or absence of virus scan information attached to the print data, whether or not the virus scan information can be decrypted using the master unit's public key, and the age of the pattern acquisition date included in the virus scan information attached to the print job. The slave unit then performs a virus scan on print data without virus scan information, print data that could not be decrypted using the master unit's public key, and print data with an old pattern acquisition date.
[0300] Here, we show the communication sequence between the information creation device (user terminal) PC, the image forming apparatus (master unit) MFP-P, and the image forming apparatus (slave unit) MFP-C. In the step numbering in Figure 20, steps that perform the same processing as the steps in Figure 19, etc., are assigned the same step number.
[0301] In the embodiment shown in Figure 20, the master unit sends print data to the slave unit with virus scan information encrypted using the master unit's private key, and the slave unit decrypts the encrypted virus scan information using the master unit's public key, which is the same as in the embodiments shown in Figures 18 and 19. Furthermore, if decryption is successful, the slave device checks the age of the pattern acquisition date of the received virus scan information, similar to the example in Figure 19.
[0302] On the other hand, unlike the embodiment in Figure 19, the slave unit is equipped with a virus scan engine, and the slave unit will perform a virus scan process in the following cases: when the received print data is print data that does not contain virus scan information (unscanned job), when the print data contains virus scan information (scanned job) but the virus scan information cannot be decrypted successfully, or when the virus scan information is decrypted successfully but the pattern acquisition date of the received virus scan information is old.
[0303] Steps A1 and A2 of the information creation device (user terminal) PC in Figure 20, the processing from steps P1 to P11 of the image forming apparatus (master unit) MFP-P, and the processing from steps C1 to C7 of the image forming apparatus (slave unit) MFP-C are the same as those in Figure 19, so their explanation is omitted.
[0304] In step C7, check for the presence or absence of encrypted virus scan information, similar to Figure 19. In step C71, if the print data does not contain encrypted virus scan information, proceed to step C21; if the print data contains encrypted virus scan information, proceed to step C51.
[0305] In step C21, if the print data does not contain virus scan information, the slave unit performs a virus scan on the received print data, as in Figures 15 and 16. In step C22, if no virus is detected, the received print data is printed on the designated paper. In step C23, if a virus is detected, the received print data is not printed.
[0306] On the other hand, in step C51, if the print data contains virus scan information, the encrypted virus scan information is decrypted using the master unit's public key.
[0307] In step C52, similar to step C42 described above, the ability to decrypt the encrypted virus scan information is checked. In other words, the decryption process checks whether or not the correct virus scan information has been restored. If decryption fails in step C72, proceed to step C21 and perform a virus scan. On the other hand, if the encrypted virus scan information is successfully decrypted in step C61, a check is performed to determine whether the received encrypted virus scan information pattern acquisition date is new or old.
[0308] In Step C73, if the scan pattern acquisition date of the received virus scan information is older than the scan pattern acquisition date of the scan processing information 144 stored in the slave device's memory unit 140, the process proceeds to Step C21 and the virus scan process is executed.
[0309] On the other hand, in step C63, if the scan pattern acquisition date of the received virus scan information is newer than the scan pattern acquisition date of the scan processing information 144 stored in the slave unit's storage unit 140, the received print data is printed on the designated print paper.
[0310] <Other Embodiments> (Other Embodiment 1: Encryption Target) In the above embodiment, the target to be encrypted was primarily described as virus scan information. However, in order to enhance the confidentiality of information transmitted and received between the base unit and the slave unit, and to prevent information leakage or tampering, the encryption target is not limited to virus scan information, but all information transmitted and received between the base unit and the slave unit may be encrypted.
[0311] For example, both the print data acquired by the main unit and the virus scan information may be subject to encryption, or only the acquired print data may be subject to encryption. The master unit performs a virus scan on the acquired print data, and further encrypts the print data that does not contain any viruses, thereby enhancing the security of the print data transmitted to the slave unit.
[0312] (Other Embodiment 2: Transmitted Print Information) In the above embodiment, in order to reduce the possibility of infection on the slave unit, infection prevention processing such as virus scanning is performed on the print data acquired by the master unit, and virus scan information is added to the print data on which no computer viruses were detected. Furthermore, Figure 13 shows that a transmission print information is generated that includes only the print data on which virus scan information has been added, which has been requested by the slave unit, and this information is sent to the slave unit.
[0313] However, if appropriate infection control measures are taken on the sub-unit, it is permissible to send print data in which a computer virus has been detected as a result of infection control measures (virus scan) performed on the main unit to the sub-unit. For example, when a slave unit receives print information sent from a master unit, the slave unit connects to an infection control management server, which is believed to store the latest virus scanning engine and virus pattern files. The slave unit retrieves the latest virus scanning engine and virus pattern files from the infection control management server at the time of connection, and uses the retrieved latest virus scanning engine and virus pattern files to perform infection control processing (virus scanning processing) on print data in which computer viruses are detected. This can further reduce the possibility of infection in the sub-unit.
[0314] (Other embodiment 3: Date of execution of virus scan process on the master unit) In the above embodiment, the virus scan information was described as including the information shown in Figure 6. However, the information included in the virus scan information is not limited to this information and may include other information as well. While each printout acquired by the master unit undergoes a virus scan, printouts temporarily stored on the master unit are not necessarily printed immediately on the slave unit. In some cases, a considerable amount of time may pass after the data is temporarily stored before it is printed on the slave unit.
[0315] Therefore, the date and time (execution date) on which the virus scan process was actually performed on the print data may be included in the virus scan information, and when the print data is temporarily saved to the master unit, the virus scan information including the execution date may be added to the print data. When print data containing virus scan information, including the execution date, is sent to a sub-device, the sub-device may compare the execution date included in the virus scan information with the current date. If the execution date is considerably older than the current date—for example, if the execution date is more than a week ago—the sub-device may perform a virus scan using the latest virus pattern file available at that time. This can further reduce the possibility of infection in the sub-unit.
[0316] (Other Embodiment 4: Sending Unscanned Jobs) In the above embodiment, the job list created by the master unit and sent to the slave unit may include print data for which virus scanning has not yet been performed (unscanned jobs), and a user who checks this job list may select an unscanned job as the data to request for printing.
[0317] In this manner, if an unscanned job is selected, the master unit may perform a virus scan on the unscanned job using the latest virus pattern file, etc., immediately before sending the unscanned job from the master unit to the slave unit. If the base unit performs a virus scan and no viruses are detected, only the print data that did not contain any viruses may be sent to the sub-unit. Furthermore, print data in which a virus has been detected may not be sent to the sub-unit, and a warning indicating that the requested print data was infected with a virus may be sent to the sub-unit and displayed on the sub-unit's display.
[0318] Furthermore, when a user selects an unscanned job as the data to be printed, the slave unit may display a warning before sending the print data request to the master unit, indicating that the selected print data includes print data that has not yet undergone virus scanning (an unscanned job).
[0319] (Other embodiment 5: Job list display screen on the slave unit) In the above embodiment, as shown in Figure 8, a job list consisting of the temporarily stored print data name, whether or not printing is selected, and whether or not a virus scan process has been performed (scan not performed / scanned) is displayed on the display unit 103 of the slave unit. However, other information may be displayed on the print job list screen G1 shown on the sub-unit.
[0320] The job list sent from the master unit to the slave unit includes virus scan information such as the scan pattern acquisition date. Therefore, in addition to simply displaying "Scanned / Completed," the display screen G1 may also display warnings such as, for example, that the job list contains print data with old scan pattern acquisition dates used for virus scanning, or that print data for which virus scan information has not been performed may be infected.
[0321] Furthermore, if the sub-unit does not have infection control functionality, a message may be displayed on screen G1 indicating that print data for which virus scan information has not been performed, or print data with an old scan pattern acquisition date, will not be printed. Alternatively, if the client device can perform infection prevention processing (virus scanning), a message may be displayed on screen G1 indicating that the requested print data may not be printed depending on the results of the virus scanning process performed on the client device.
[0322] (Other Embodiment 6: Settings on the Master and Slave Units) The above embodiment demonstrates that the ability to print on the sub-unit is determined based on factors such as the presence or absence of virus scan information, whether decryption is possible, and the date the scan pattern was acquired. These judgment processes may be pre-programmed into the master and slave units, but it is also possible to define the setting items for the judgment conditions and allow the image forming apparatus administrator or user to pre-set these items before operation begins and change them after operation has started.
[0323] For example, settings for encryption and decryption may be provided, and the master unit and slave unit may be pre-configured and stored to indicate whether or not to perform encryption and decryption. Furthermore, the master unit may be configured to allow users to select whether to send only print data that did not contain viruses after a virus scan, send all print data that has undergone a virus scan, or send all print data requested by the slave unit, including print data that has not undergone a virus scan.
[0324] Furthermore, the sub-unit may be pre-configured and stored whether or not to check the date on which the scan pattern of the received virus scan information was acquired. Also, when determining whether the date on which the scan pattern of the received virus scan information was acquired is new or old, the sub-unit may be pre-configured and stored an arbitrary number of days difference that will be considered new. Furthermore, if the child device can perform infection prevention processing (virus scanning), it may be possible to pre-configure and store whether or not to perform that virus scanning process. Alternatively, if the difference between the date the parent unit's virus pattern was acquired and the date the child unit's virus pattern was acquired is less than a pre-set number of days, it may be pre-configured to determine whether or not to perform a virus scan on the child unit. [Explanation of Symbols]
[0325] 1. Image forming apparatus (master unit), 2 Image forming apparatus (slave unit), 3. Information creation device (user terminal), 4 Networks, 5 Networks, 6. Information management device (management server), 11 Control unit, 12 Operation section, 13 Display section, 14 Image Processing Unit, 15 Communications Department, 21 Print data acquisition unit, 22 Virus detection unit, 23 Virus removal section, 24 Virus scan information generation unit, 25. Job list processing unit, 26 Job list request receiving unit, 27 Job list generation unit, 28 Job list transmission section, 29 Encryption Department, 30 Printing Information Processing Unit, 31 Print data request receiving unit, 32 Print information generation section, 33 Print information transmission unit, 40 storage section, 41. Base unit information, 42. Handset information, 43. Cryptographic key information, 44 Input print data, 45 Virus scan information, 46 Job List, 47. Send print information, 48 Job list request, 49. Print data request, 101 Control unit, 102 Operation section, 103 Display section, 104 Image processing unit, 105 Communications Department, 106 Function execution unit, 107 Virus detection unit, 108 Virus Removal Section, 111 Job List Request Section, 112 Job list receiving unit, 113 Print Data Request Unit, 114 Print information receiving unit, 115 Scan information acquisition unit, 116 Scan information confirmation unit, 117 Decoding unit, 118 Printability determination unit, 140 storage section, 141 Master unit information, 142 Handset information, 143 Cryptographic key information, 144 Scan processing information, 145 Job list request, 146 Received job list, 147 Received print information, 148 Print Data Request
Claims
1. An image processing system comprising a first image forming apparatus for temporarily storing print data and a second image forming apparatus for printing the print data, connected via a network, The first image forming apparatus, A print data acquisition unit that acquires print data, A storage unit for temporarily storing the acquired print data, A virus detection unit that performs a predetermined infection control process on the print data and detects computer viruses, A virus scan information generation unit generates virus scan information that identifies the setting items related to the infection control process that has been executed, and adds the virus scan information to print data in which no computer viruses were detected by the virus detection unit, A print information generation unit generates print information that includes print data requested by the second image forming apparatus from the temporarily stored print data, The system includes a print information transmission unit that transmits the generated print information to the second image forming apparatus, The second image forming apparatus, A print data request unit requests the first image forming apparatus to transmit predetermined print data from among the print data temporarily stored in the first image forming apparatus, A print information receiving unit that receives print information transmitted from the first image forming apparatus, The second virus detection unit performs infection control processing, including a virus scan process to detect known computer viruses, on the print data contained in the received print information, using a second virus scan engine and a second virus pattern file, and detects computer viruses. A second storage unit that stores scan processing information including the date information of the acquisition of the second virus pattern file, A scan information acquisition unit that acquires virus scan information added to the print data contained in the received print information, A printability determination unit that uses the acquired virus scan information to determine whether or not to print the print data contained in the received print information, The system includes a function execution unit that prints the print data when the printability determination unit determines that the print data should be printed, The aforementioned virus scan information includes date information for obtaining the first virus pattern file. The printability determination unit is: The date information on the acquisition of the first virus pattern file included in the virus scan information is compared with the date information on the acquisition of the second virus pattern file included in the scan processing information. If the date information for obtaining the first virus pattern file is newer than the date information for obtaining the second virus pattern file, it is determined that the print data should be printed. An image processing system characterized in that, if the date information for obtaining the first virus pattern file is older than the date information for obtaining the second virus pattern file, it is determined that the print data will not be printed.
2. The image processing system according to claim 1, characterized in that the print information generated by the print information generation unit includes print data to which the virus scan information has been added.
3. The aforementioned infection control process includes a virus scan process that uses a first virus scan engine and a first virus pattern file to detect known computer viruses. The image processing system according to claim 1, characterized in that the virus scan information includes the name and version information of the first virus scan engine and the version information of the first virus pattern file.
4. If the print information received by the print information receiving unit includes print data to which the virus scan information has been added and print data to which the virus scan information has not been added, The printability determination unit is: The image processing system according to claim 1, characterized in that it determines to print print data to which the virus scan information has been added, and determines not to print print data to which the virus scan information has not been added.
5. When the first image forming apparatus receives a job list request transmitted from the second image forming apparatus, The image processing system according to claim 1, further comprising a job list processing unit that generates a job list including the name of the print data requested by the job list request from among the print data temporarily stored in the storage unit of the first image forming apparatus, and if the requested print data is print data to which the virus scan information has been added, generates a job list including the virus scan information, and transmits the generated job list to the second image forming apparatus that sent the job list request.
6. The second image forming apparatus, A job list receiving unit that receives the job list transmitted from the first image forming apparatus, It further includes a display unit, The image processing system according to claim 5, characterized in that when the job list receiving unit receives the job list, it causes the display unit to display the received job list.
7. The second virus detection unit executes the infection control process on print data that the printability determination unit has determined not to print. The image processing system according to claim 1, characterized in that print data in which a computer virus is detected is not printed, and print data in which no computer virus is detected is printed.
8. The first image forming apparatus, The system further includes an encryption unit that encrypts the generated virus scan information with a first encryption key, The virus scan information generation unit adds the encrypted virus scan information to the print data. The second image forming apparatus, The system further includes a decryption unit that decrypts the encrypted virus scan information using a second encryption key. The image processing system according to claim 1, characterized in that the decryption unit decrypts the encrypted virus scan information attached to the print data contained in the print information received by the print information receiving unit, and then the scan information acquisition unit acquires the decrypted virus scan information as virus scan information.
9. If the print information received by the print information receiving unit includes print data to which the encrypted virus scan information has been added, When the decryption unit decrypts the encrypted virus scan information, The printability determination unit is: If the decryption is successful, it is determined that the print data with the encrypted virus scan information added will be printed. The image processing system according to claim 8, characterized in that if the decryption fails, it is determined not to print the print data to which the encrypted virus scan information has been added.
10. The image processing system according to claim 8 or 9, characterized in that the first encryption key is the secret key of the first image forming apparatus, and the second encryption key is the public key of the first image forming apparatus.
11. The image processing system according to claim 8 or 9, characterized in that the first encryption key is the public key of the second image forming apparatus, and the second encryption key is the secret key of the second image forming apparatus.
12. The second virus detection unit executes the infection control process on print data that the printability determination unit has determined not to print. The image processing system according to claim 4 or 9, characterized in that print data in which a computer virus is detected is not printed, and print data in which no computer virus is detected is printed.
13. A method for preventing infection in an image processing system in which a first image forming apparatus for temporarily storing print data and a second image forming apparatus for printing the print data are connected via a network, The first control unit provided in the first image forming apparatus, The print data acquisition step involves acquiring print data, A storage step for temporarily storing the acquired print data, A virus detection step involves performing a predetermined infection control process on the print data to detect computer viruses, A virus scan information generation step that generates virus scan information that identifies the setting items related to the infection control process that was executed, and adds the virus scan information to print data in which no computer virus was detected in the virus detection step, A print information generation step that generates print information including print data requested by the second image forming apparatus from the temporarily stored print data, The generated print information is transmitted to the second image forming apparatus in a print information transmission step, and the apparatus is then configured to perform this step. The second control unit provided in the second image forming apparatus, A print data request step in which the first image forming apparatus is requested to transmit predetermined print data from among the print data temporarily stored in the first image forming apparatus, A print information receiving step of receiving print information transmitted from the first image forming apparatus, The infection control process includes a virus scan process that detects known computer viruses using a second virus scan engine and a second virus pattern file on the print data contained in the received print information, and a second virus detection step that detects computer viruses. The steps include storing scan processing information that includes date information for obtaining the second virus pattern file, A scan information acquisition step, which involves acquiring virus scan information attached to the print data contained in the received print information, A printability determination step that determines whether or not to print the print data contained in the received print information using the acquired virus scan information, If it is determined in the printability determination step that the print data should be printed, the function execution step for printing the print data is executed. The aforementioned virus scan information includes date information for obtaining the first virus pattern file. The printability determination step is: The date information on the acquisition of the first virus pattern file included in the virus scan information is compared with the date information on the acquisition of the second virus pattern file included in the scan processing information. If the date information for obtaining the first virus pattern file is newer than the date information for obtaining the second virus pattern file, it is determined that the print data should be printed. An infection control method for an image processing system, characterized in that if the date information for obtaining the first virus pattern file is older than the date information for obtaining the second virus pattern file, it is determined that the print data will not be printed.
Citation Information
Patent Citations
Transmission control method and reception control method for electronic mail system, and the electronic mail system
JP2000029799A
Information processing device, image formation device, image formation system, and virus check method
JP2019192956A