Information processing device, control method for information processing device, and program
Patent Information
- Application Number
- JP2022085058
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-25
- Publication Date
- 2026-09-14
- Estimated Expiration
- 2042-05-25
AI Technical Summary
【0007】 本発明に係る画像処理装置によれば、ユーザによる情報処理装置の設定変更に基づいて、一括設定を推奨する表示を行う仕組みを提供することができる。
Smart Images

Figure 0007919903000005 
Figure 0007919903000006 
Figure 0007919903000007
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus that collectively performs settings for a plurality of setting items.
Background Art
[0002] Generally, an information processing apparatus has a setting function for performing various settings based on user operations. Information processing apparatuses have come to be installed in various environments such as remote workplaces and public spaces shared by an unspecified number of people, and required settings have become more complicated. Therefore, Patent Document 1 discloses a technique for diagnosing setting contents based on a diagnostic policy that matches the characteristics of management categories of an information processing apparatus in order to respond to changes in usage environments.
Prior Art Document
Patent Document
[0003]
Patent Document 1
Summary of the Invention
Problem to be Solved by the Invention
[0004] By the way, a technique for assisting a user to perform settings suitable for a usage environment on an information processing apparatus has been considered. For example, it is conceivable to provide a mechanism that allows the user to select the usage environment of the information processing apparatus, thereby collectively changing the settings of the information processing apparatus to settings suitable for the selected usage environment. However, in such a mechanism, there may be cases where appropriate collective settings are not performed. For example, this can be caused by the user being unable to appropriately select the usage environment of the information processing apparatus, or by the usage environment changing after selection.
[0005] An object of the present invention is to provide a mechanism for displaying a recommendation for collective settings based on a user's setting change of an information processing apparatus.
Means for Solving the Problem
[0006] To achieve the above objective, the information processing device of the present invention includes a receiving means for receiving an instruction to set a predetermined value in the information processing device, and a display control means that, in accordance with the receipt of the instruction, displays a display recommending a batch setting in which multiple values corresponding to the predetermined value are set in the information processing device. Furthermore, the display control means is characterized by providing a display recommending the batch setting, including a display for receiving an instruction to accept or reject the batch setting. do. [Effects of the Invention]
[0007] The image processing apparatus according to the present invention provides a mechanism that displays a recommendation for batch settings based on changes made by the user to the settings of the information processing apparatus. [Brief explanation of the drawing]
[0008] [Figure 1] This diagram illustrates an example of the usage environment for an information processing device. [Figure 2] This flowchart shows an example of conditions for classifying the usage environment of information processing equipment. [Figure 3] This figure shows an example of the hardware configuration of the MFP101. [Figure 4] This figure shows an example of the software configuration of the MFP101. [Figure 5] This figure shows an example of a screen displayed on the operation unit 320 of the MFP101 in the first embodiment. [Figure 6] This figure shows an example of a screen displayed on the operation unit 320 of the MFP101 in the first embodiment. [Figure 7] This flowchart shows an example of the security settings process performed by the MFP101. [Figure 8] This flowchart shows an example of the security settings process performed by the MFP101. [Figure 9] This figure shows an example of the screen displayed on the operation panel 320 of the MFP101 in a modified example. [Modes for carrying out the invention]
[0009] The following describes embodiments for carrying out the present invention with reference to the drawings. Note that the following embodiments are not intended to limit the invention as defined in the claims, and not all combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0010] <First Embodiment> Figure 1 is a network configuration diagram illustrating the usage environment of an information processing device according to an embodiment of the present invention. MFPs 101 to 104, which are examples of information processing devices in this embodiment, are installed in different usage environments 111 to 114. The usage environments 111 to 114 illustrated in Figure 1 are, respectively, a company intranet environment 111, a direct internet connection environment 112, an internet-restricted environment 113, and a home-based environment 114.
[0011] The company's intranet environment 111 is an environment in which MFPs 101 and PCs 121 are connected via the company's LAN (Local Area Network) 131. A firewall 141 is installed at the boundary between LAN 131 and the internet 100. In other words, communication between each information processing device within the company's intranet environment 111 and the internet 100 is monitored and protected by the firewall 141. Therefore, threats such as attackers from the internet 100 gaining access to each information processing device are greatly reduced in the company's intranet environment 111.
[0012] On the other hand, the direct internet connection environment 112 does not have a firewall installed. The direct internet connection environment 112 is an environment in which the MFP 102 and PC 122 are directly connected to the internet 100 and communicate with it. Therefore, information processing devices such as the MFP 102 and PC 122 need to take measures against threats such as access by attackers from the internet 100, by using the personal firewall function within each information processing device.
[0013] The internet-restricted environment 113 is a closed network environment isolated from other networks such as the Internet 100. Information processing devices such as MFP 103 and PC 123 are connected via LAN 133. In the internet-restricted environment 113, network communication is only possible between information processing devices installed on LAN 133. Each information processing device is not accessible by unspecified users on the Internet 100.
[0014] Home environment 114 is an environment in which the MFP 104 and PC 124 are connected via the home LAN 134. LAN 134 is a private network configured by the home router 144, but it does not have the robust firewall security measures found in the company intranet environment 111. Therefore, information processing devices installed in home environment 114, like those in the direct internet connection environment 112, need to take measures against threats such as access from attackers on the internet 100 by utilizing the personal firewall function within each information processing device.
[0015] Furthermore, the company intranet environment 111, the direct internet connection environment 112, and the internet-restricted environment 113 are assumed to have sufficient physical security measures in place, such as facility access control, to physically restrict access to each environment. In other words, it is assumed that users can be identified. In addition, environments not shown in the diagram include public space environments where network users cannot be identified, similar to the home environment 114, and highly confidential management environments requiring the protection of highly confidential information. The classification of each environment will be explained in detail using Figure 2.
[0016] In the present embodiment, the usage environments of an information processing apparatus are classified into six categories, and appropriate security settings are provided for each of the categories. FIG. 2 is a flowchart showing the concept of classification when classifying and defining usage environments. Note that the following definitions of usage environments do not limit the present invention, and some or other usage environments exemplified in the present embodiment may be defined. For example, assuming installation in a company, the usage environments may be classified for each industry such as finance and government agencies.
[0017] In the present embodiment, the usage environments of an information processing apparatus are classified into six categories based on the characteristics for classifying usage environments exemplified in steps S201 to S205. In addition, a setting group of security measures to be applied to each usage environment is defined in advance based on threats that can be assumed from the characteristics of the usage environment and can occur in the usage environment. This definition will be described later.
[0018] S201 is a classification whether the environment is for handling highly confidential information. It can be said that an environment handling highly confidential information is an environment where security measures need to be prioritized. Hereinafter, in the present embodiment, this environment where security measures need to be prioritized is defined as a highly confidential information management type.
[0019] In environments that do not handle highly confidential information, the classification of usage environments is further subdivided. As shown in S202, the usage environment is classified based on the user's accessibility to the device. That is, the classification of usage environments is subdivided based on whether or not it is physically possible for an unspecified number of users to access the information processing device. In this embodiment, S202 is a classification based on whether or not it is an access-controlled environment. This is an example of a classification based on whether or not users are restricted from entering the location where the information processing device is installed. Therefore, the classification condition of whether or not it is physically accessible is not limited to this embodiment, and conditions other than access control may also be used as classification conditions. Furthermore, access control in this embodiment is not limited to an access control system using cards. For example, an environment in which only people belonging to the organization work during business hours, effectively limiting the number of people who can enter, and where the doors are locked outside of business hours, is also included in an access-controlled environment.
[0020] When access control is not in place, meaning that an unspecified number of users can physically access the information processing device, the usage environment is subdivided according to the classification conditions shown in S205. S205 is a classification based on whether or not an unspecified number of users share and use the network within the environment. In this embodiment, an environment in which the information processing device is installed in a location where typical access control is not in place and an unspecified number of users share and use the network within the environment is defined as a public space type. Furthermore, an environment in which typical access control is not in place and an unspecified number of users do not share the network within the environment is defined as a home-use type. Note that the difference in network configuration between the home-use type and the public space type lies in whether or not an unspecified number of users share and use the network on which the information processing device is installed. In this embodiment, an environment in which an unspecified number of users do not share the network within the environment, like the home-use type, that is, an environment in which users can be identified, is defined as a private network environment. In other words, in this embodiment, the home-use type is a private network environment, and the public space type is not a private network environment.
[0021] Next, we will explain the classification of usage environments that have accessibility features such as access control. Usage environments classified as having access control in S202 are further subdivided according to the classification conditions shown in S203. S203 is a classification based on whether or not the information processing equipment within the environment is connected to an external network such as the Internet. Environments that are not connected to an external network such as the Internet are defined as Internet-prohibited types. Note that Internet-prohibited types that have access control and are based on a closed network are private network environments.
[0022] If the information processing equipment within the environment is connected to an external network such as the Internet, the usage environment is further subdivided according to the classification conditions shown in S204. S204 is a classification based on whether or not a firewall is installed. An environment with a firewall installed is defined as an internal intranet type. An environment without a firewall is defined as an internet-direct connection type. Note that an internal intranet type, where users can be restricted using the network within the environment by a firewall, is a private network environment.
[0023] Next, Table 1 shows the six usage environments classified according to the concept in Figure 2, and examples of security measures that should be taken for each usage environment.
[0024] [Table 1]
[0025] As shown in Table 1, the security measures that should be implemented for information processing devices vary significantly depending on the operating environment. In this embodiment, based on the security measures that should be implemented for each environment shown in Table 1, we have defined what specific settings should be made and summarized them in Table 2. Below, we will use Table 2 to explain why each security measure is recommended.
[0026] [Table 2]
[0027] Encrypting communication paths is a security measure that prevents information leakage by encrypting the content of communications over a network. One example of a function that enables communication path encryption is TLS (Transport Layer Security). In environments connected to the internet, it is desirable to encrypt communication paths because there is a possibility of third parties eavesdropping on communications. In other words, except in internet-restricted environments (113), it is recommended to encrypt communication paths.
[0028] Disabling legacy protocols is a security measure that prevents impersonation and information leakage by disabling functions that use insecure legacy communication protocols. An example of a legacy protocol is WINS (Windows Internet Name Service). Similar to encrypting communication paths, disabling legacy protocols is desirable in environments connected to external networks such as the internet. In other words, disabling legacy protocols is recommended except in internet-restricted environments (113).
[0029] A personal firewall is a firewall installed and used on an information processing device. Like a regular firewall, it monitors communication between the information processing device and external networks such as the internet. Examples of firewalls include IP filters and port number filters. An IP filter is a security measure that reads the destination and source information of communication packets and allows only pre-configured communication packets. This prevents unauthorized access and information leakage. A port number filter is a security measure that closes unused ports to prevent intrusion through ports. This prevents Denial of Service (DoS) cyberattacks that overload a system and exploit vulnerabilities. In environments connected to an external network and without a firewall installed, there is a possibility of information leakage and DoS attacks, so it is desirable to enable a personal firewall. In other words, except for internet-restricted environments 113 that are not connected to an external network and internal intranet environments 111 where a firewall is installed, enabling a personal firewall is recommended.
[0030] Strengthening authentication security involves measures to combat impersonation, such as prohibiting password caching or specifying a minimum password length. Except for internet-restricted environments (113) connected within isolated networks, there is a possibility of impersonation, making it desirable to strengthen authentication security.
[0031] Physical attack countermeasures are security measures that prevent information from being leaked physically. In MFP101 to 104, temporary data such as print jobs is generated on the hard disk. A complete erasure function is provided that automatically and completely erases the generated temporary data as soon as the job is completed. The complete erasure function described above is an example of physical attack countermeasures for MFP101 to 104. If this function is set, even if the hard disk is physically removed, the temporary data cannot be read. In home environments 114 and public space environments 115, where access control is not in place and physical access to the information processing device cannot be restricted, it is desirable to implement physical attack countermeasures. Furthermore, in highly confidential information management environments 116, where reducing the risk of information leakage is the top priority, it is also desirable to implement physical attack countermeasures.
[0032] The file sharing function allows users to share files over a network within an environment. In environments where unspecified users share the network, it is desirable to disable the file sharing function to prevent information leakage. In other words, it is recommended to disable the file sharing function except in private network environments where specific users share the network. As mentioned above, the private network environments in this embodiment are the company intranet environment 111, the internet-restricted environment 113, and the home-based environment 114. Therefore, it is recommended to disable the file sharing function in environments other than these: the internet-connected environment 112, the public space environment 115, and the highly confidential information management environment 116. An example of a setting related to the file sharing function is the SMB (Server Message Block) server setting.
[0033] Disabling external storage devices means configuring them so that, for example, USB (Universal Serial Base) storage devices cannot be used as external storage devices by the information processing system. This prevents information from being written to external storage devices, thus preventing information leakage. It also prevents computer virus infections via USB storage devices and the resulting information leakage. The threat of information leakage through external storage devices such as USB is common to all installation environments. Therefore, it is desirable to disable them in all installation environments.
[0034] In this embodiment, the recommended settings data defined based on the concept described above is stored in the information processing device, and a mechanism is provided to reflect the appropriate recommended settings data when the user selects an environment.
[0035] The hardware configuration of MFP101, an example of an information processing device in this embodiment, will be explained with reference to Figure 3. Although Figure 3 only describes MFP101, MFP102 to 104, and MFPs installed in public space environments and high-security information management environments (not shown), will have the same configuration as MFP101.
[0036] The MFP101 includes a printer 330 that outputs electronic data to paper media and a scanner 340 that reads paper media and converts it into electronic data. In this embodiment, the MFP101, which has multiple functions, is shown as an example of an information processing device, but it is not limited to this. For example, it may be an image processing device equipped with a single-function printer or scanner. It may also be a device such as a 3D printer or 3D scanner.
[0037] The control unit 310, including the CPU (Central Processing Unit) 311, controls the overall operation of the MFP 101. The ROM (Read Only Memory) 312 is used to store programs executed by the CPU 311. The CPU 311 reads the control programs stored in the ROM 312 and performs various controls of the MFP 101, such as read control and transmit control. The RAM (Random Access Memory) 313 is used as the CPU 311's main memory, work area, and other temporary storage areas. The HDD (Hard Disk Drive) 314 is a storage device that stores image data, various programs, and various setting information. Other storage devices such as an SSD (Solid State Drive) may also be provided. In this way, the hardware such as the CPU 311, ROM 312, RAM 313, and HDD 314 constitute a so-called computer.
[0038] The operation unit interface 315 connects the operation unit 320 and the control unit 310. The operation unit 320 is equipped with a liquid crystal display with touch panel functionality and various hard keys. The operation unit 320 functions as a display unit that shows information to the user and as a reception unit that receives user instructions.
[0039] The printer interface 316 connects the printer 330 and the control unit 310. Image data to be printed by the printer 330 is transferred from the control unit 310 via the printer interface 316. The input image data is output to the recording medium by the printer 330. The scanner interface 317 connects the scanner 340 and the control unit 310. The scanner 340 reads a document placed on a document glass (not shown) and generates image data. The generated image data is input to the control unit 310 via the scanner interface 317.
[0040] A network cable is connected to the network interface 318, allowing it to communicate with external devices on LAN 131. In this embodiment, it is assumed to be a wired communication interface, but it is not limited to this. For example, it may be a wireless communication interface. Although the network interface 318 of MFP 101 is connected to LAN 131, the network to which it is connected will vary depending on the installation environment. For example, MFP 102 is directly connected to the internet 100. MFP 103 and 104 are connected to LAN 133 and 134, respectively.
[0041] The software configuration of the MFP101 will be explained using Figure 4. Each part shown in Figure 4 is realized by the CPU 311 executing the program according to the present invention stored in the ROM 312.
[0042] The operation control unit 401 displays a user-facing screen on the operation unit 320. It also detects user operations and switches screens or updates the display based on the detection results.
[0043] The data storage unit 402 stores data in the HDD 314 and reads data from the HDD 314 in accordance with requests from other control units. For example, if a user wants to change some device settings, the operation control unit 401 detects what the user has entered into the operation unit 320, and the data storage unit 402 saves the setting value to the HDD 314 at the request of the operation control unit 401. The data storage unit 402 stores setting information for determining the operation of the MFP 101, as well as information related to the settings. Specifically, it stores user setting data and recommended setting data. The data storage unit 402 also stores a database for estimating the environment, which will be described later.
[0044] User configuration data is setting information that determines the operation of the MFP101, which can be set by the user via the operation unit 320. Each program on the MFP101 provides various functions by operating based on the settings of the user configuration data.
[0045] The recommended settings data is a set of recommended settings for each usage environment. When a user selects an environment, the information of multiple settings managed by the recommended settings data is overwritten in the user settings data, enabling the MFP101 to operate with the settings recommended for that environment. An example of the recommended settings data in this embodiment is shown in Table 3. The recommended settings data associates multiple setting items and multiple setting values corresponding to those setting items with each usage environment. The setting values are appropriate for each usage environment. In this embodiment, the setting items are items such as TLS settings and WINS settings in Table 3. The setting values are the values indicated as "On," "Off," "Deny," etc. in Table 3. Areas represented by diagonal lines in Table 3 indicate that there are no recommended setting values. In other words, when an environment is selected and batch settings are performed, the setting values in the user settings data for those setting items are not changed, and the setting values from before the setting change are carried over. For example, the TLS setting is set to "On" in environments other than the Internet Prohibition type, but it is not changed in the Internet Prohibition type, and the original setting value is maintained. In this embodiment, the recommended setting data is defined in advance by the MFP101 vendor and stored in the data storage unit 402.
[0046] [Table 3]
[0047] Returning to the explanation of Figure 4, the Job Control Unit 403 controls job execution according to instructions from other control units. The Image Processing Unit 404 processes image data into a format suitable for each application according to instructions from the Job Control Unit 403. The Printing Processing Unit 405 prints and outputs the image onto paper media via the Printer I / F 316 according to instructions from the Job Control Unit 403. The Reading Control Unit 406 reads the placed document via the Scanner I / F 317 according to instructions from the Job Control Unit 403. The Network Control Unit 407 sets network settings such as IP addresses to the TCP / IP Control Unit 408 when the system starts up or when a setting change is detected, according to the setting values stored in the Data Storage Unit 402. The TCP / IP Control Unit 408 performs network packet transmission and reception processing via the Network I / F 318 according to instructions from other control units.
[0048] The security settings control unit 409 performs batch configuration of the MFP101's security functions in accordance with user instructions detected by the operation control unit 401. After managing the correspondence between usage environments such as company LAN, home, and public spaces, and the corresponding security-related settings, it can batch configure the corresponding security-related settings when the user specifies a usage environment. The security settings control unit 409 uses the data storage unit 402 to refer to and change the setting values. The specific control will be described later with reference to Figure 8. Note that the batch configuration in this embodiment is a function that allows the batch configuration of recommended settings for typical security functions defined by the vendor. It is different in nature from a function that applies a security policy edited by the user and prohibits changing the settings for specific security settings to settings that do not conform to the policy.
[0049] Next, the screens displayed on the operation unit 320 of the MFP101 will be explained using Figures 5 and 6. The screen 500 shown in Figure 5 is the recommended security settings screen 500, which the operation control unit 401 displays on the operation unit 320. When a user performs an operation to display screen 500 on a menu screen (not shown), the operation control unit 401 detects the operation and displays screen 500. The environment list 501 is a list for the user to select the usage environment of the MFP101. In this embodiment, the user selects from the six usage environment options shown in Figure 2. The operation control unit 401 of the MFP101 detects the user's operation and transmits information indicating the user's selection result to the security settings control unit 409. The security settings control unit 409 performs the settings of security functions appropriate to the usage environment selected by the user, as received from the operation control unit 401, all at once. As a result, the user can select the usage environment of the MFP101 from the list 501 and press the execute button 503 to perform the recommended security settings for each usage environment all at once. The cancel button 502 is a button used by the user to stop the recommended security settings. When the operation control unit 401 detects that the user has pressed the cancel button 502, it displays a menu screen (not shown) on the operation unit 320.
[0050] The screen 600 shown in Figure 6(a) is a recommended environment type change suggestion screen 600 displayed on the operation unit 320 by the operation control unit 401. In the process shown in Figure 8, which will be described later, screen 600 suggests a recommended environment type to the user based on the user's setting changes and receives instructions from the user on whether or not to change the environment type for batch settings. Screen 600 has a Yes button 601 and a No button 602. The operation control unit 401 receives information indicating the user's selection result for either the Yes button 601 or the No button 602. The operation control unit 401 then transmits information indicating the user's selection result to the security setting control unit 409. If the security setting control unit 409 receives information from the operation control unit 401 that the user has selected the Yes button 601, it batch sets the security functions appropriate for the usage environment recommended on screen 600. If it receives information that the user has selected the No button 602, it does not perform any settings.
[0051] The screen 610 shown in Figure 6(b) is a setting change confirmation screen 610 displayed on the operation unit 320 by the operation control unit 410. Screen 610 is a screen used to confirm whether the user wants to proceed with the setting change if the change does not conform to the current environment type. In this embodiment, screen 610 is displayed when the No button 602 is selected on screen 600. Screen 610 has a Yes button 611 and a No button 612. The operation control unit 401 receives information indicating the user's selection result for either the Yes button 611 or the No button 612. The operation control unit 401 then transmits the information indicating the user's selection result to the security setting control unit 409. If the security setting control unit 409 receives information from the operation control unit 401 that the user selected the Yes button 611, it changes the setting. If it receives information that the user selected the No button 612, it does not change the setting.
[0052] In this embodiment, screens 500, 600, and 610 are described as being displayed on the operation unit 320 of the MFP101, but the configuration is not limited to this. For example, the MFP101 can be configured to display similar screens on a web browser of an external information processing device via a web server (not shown), and to be operated via the web browser.
[0053] Next, Figure 7 will explain the process from when the user selects the usage environment on screen 500 until the security functions are configured all at once. Then, Figure 8 will explain the process by which the MFP101 proposes a change in the environment type based on the user's setting changes. Each operation (step) shown in the flowcharts of Figures 7 and 8 is realized by the CPU 311 calling and executing the program for realizing each control unit stored in ROM 312 or HDD 314 from RAM 313.
[0054] When a user performs an operation to display screen 500 on a menu screen (not shown) displayed on the operation unit 320, and the operation control unit 401 detects this operation, the flow shown in Figure 7 is initiated. In S701, the operation control unit 401 displays screen 500 on the operation unit 320. In S702, when the operation control unit 401 detects that the user has selected an environment from list 501 and pressed the execute button 503, the operation control unit 401 sends information indicating the user's selection result to the security setting control unit 409, and the process proceeds to S703. Otherwise, when the operation control unit 401 detects that the user has pressed the cancel button 502, the operation control unit 401 displays a menu screen (not shown) on the operation unit 320 and terminates this flow. If the operation control unit 401 does not detect that the cancel button 502 has been pressed, the flow returns to S702.
[0055] In S703, the security setting control unit 409 reads recommended setting data corresponding to the user-selected usage environment from the data storage unit 402 based on the information received from the operation control unit 401. Then, proceeding to S704, the read recommended setting data overwrites the user setting data. Through this process, when the user selects a usage environment on the screen 500, the security function settings appropriate for that usage environment are set collectively in the MFP 101.
[0056] In S702, when the user selects the operating environment on screen 500, the program that executes the flowchart shown in Figure 8 becomes active. In S801, the operation control unit 401 waits until it receives information from the user indicating an instruction to change the setting value corresponding to the setting item of the MFP101. When it receives information indicating an instruction to change the setting value, it notifies the security setting control unit 409. Upon receiving the notification, the security setting control unit 409 executes S802. Note that the setting change in S801 may be a change to the setting value corresponding to the setting item included in the recommended setting data mentioned above, among the setting items of the MFP101. Alternatively, it may be a change to the setting value corresponding to a setting item specified by the user or vendor.
[0057] In S802, the security setting control unit 409 determines whether the setting change instructed by the user in S801 is compatible with the current environment type. The current environment type refers to the environment type selected in S702. The information on the current environment type is applied to the user setting data in S704 and then stored in the data storage unit 402. In S802, the information on the current environment type stored at that time is read from the data storage unit 402 and used for the determination.
[0058] Table 4 shows a data table used to determine whether the modified setting value instructed by the user is compatible with the current environment type. The data table shown in Table 4 is stored in the data storage unit 402. Table 4 is a data table in which the current environment type, the proposed environment type, and predetermined setting values corresponding to predetermined setting items are stored in association. In Table 4, predetermined setting items are shown in "Applicable Setting Example," and predetermined setting values are shown in "Setting Change Case." If the modified setting value instructed by the user matches a predetermined setting value associated with the current environment type, the security setting control unit 409 determines that the modified setting value is not compatible with the current environment type.
[0059] Furthermore, the security setting control unit 409 also uses Table 4 to determine the recommended environment type in S803. If the changed setting value matches a predetermined setting value, the security setting control unit 409 estimates that the proposed environment type stored in association with the predetermined setting value is the recommended environment type. The following describes the processes performed in S802 and S803 for each current type.
[0060] In S802, the security settings control unit 409 performs the following check if the current environment type is Internet Prohibition type. If the setting value that the user has instructed to change is a function configured by the server and client, and a global IP address is specified in the server's connection destination setting, it determines that the instructed change may not be compatible with the current environment type and executes S803. In this case, in S803, the security settings control unit 409 recommends an environment type other than Internet Prohibition type as the environment type. In this case, S804 may display the recommended security settings screen 500 with Internet Prohibition type unavailable, allowing the user to set the environment type. Specific examples of settings include connection destination settings for SMB and LDAP (Lightweight Directory Access Protocol) servers.
[0061] In S802, the security settings control unit 409 performs the following check if the current environment type is anything other than the high-security information management type. If a stronger security setting is enabled, it determines that the setting value that the user has instructed to change may not be compatible with the current environment type and executes S803. In that case, the security settings control unit 409 sets the environment type to the high-security information management type in S803. Examples of stronger security settings include enabling IPSec (Security Architecture for Internet Protocol) or IEEE802.1X settings.
[0062] In S802, the security settings control unit 409 performs the following check if the current environment type is anything other than the internet-blocking type. If a user instructs a change to a weaker algorithm, it determines that the setting value instructed by the user may not be compatible with the current environment type and executes S803. In that case, the security settings control unit 409 sets the environment type to the internet-blocking type in S803. An example of a weak algorithm setting is when a protocol that has already been compromised is selected in the settings for protocols used in TLS, SMB, etc.
[0063] In S802, the security settings control unit 409 performs the following check if the current environment type is home-based or public space type. If a setting that appears to be related to access control is enabled, it determines that the setting value that the user has instructed to change may not be suitable for the current environment type and executes S803. In that case, the security settings control unit 409 recommends an environment type other than home-based or public space type in S803. In this case, in S804, it may display the recommended security settings screen 500 with home-based and public space types unavailable for selection, allowing the user to set the environment type. Specific examples of settings include settings that appear to be related to managing the use of image forming equipment by multiple people, such as card authentication and departmental ID management.
[0064] In S802, the security settings control unit 409 determines that if a setting is enabled that appears to have changed the network configuration or installation location, regardless of the current environment type, the setting value that the user has instructed to change may not be compatible with the current environment type, and executes S803. In that case, in S803, the security settings control unit 409 proposes an environment type different from the current environment type. Specific examples of such changes include the setting of a previously unused secondary line or a change in the device's location information settings. In this case, S804 may display the recommended security settings screen 500, allowing the user to set a different environment type than the current one.
[0065] In S802, if the security setting control unit 409 does not meet the above conditions, it determines that the setting change is suitable for the current environment type and executes S809.
[0066] As described above, the security settings control unit 409 performs S804 after determining the recommended environment type in S803.
[0067] [Table 4]
[0068] Returning to the explanation of Figure 8, in S804, the security setting control unit 409 performs display control to propose the recommended environment type determined in S803 to the user. Specifically, it displays the recommended environment type change proposal screen 600 on the operation unit 320 and performs S805. The screen 600 displayed in S804 displays a recommendation to set a group of setting values suitable for the recommended environment type for multiple setting items of the MFP 101 all at once. Here, the group of setting values suitable for the recommended environment type refers to the recommended setting data stored in the data storage unit 402 in association with the environment type, as shown in Table 3. In other words, the security setting control unit 409 displays a recommendation to set the recommended setting data suitable for the recommended environment type, which is associated with the predetermined setting values shown in "Setting Change Cases" in Table 4, all at once.
[0069] In S805, if the operation control unit 401 detects that the user has pressed the Yes button 601 on screen 600, or if it detects that the user has changed the environment type to a different environment type than the current one, it determines that the proposal has been accepted and proceeds to S806. On the other hand, if the operation control unit 401 detects that the user has pressed the No button 602 on screen 600, or if it does not detect that the user has changed the environment type to a different one than the current one, it determines that the proposal has not been accepted and proceeds to S807.
[0070] In S806, the security setting control unit 409 merges the user setting data stored in the data storage unit 402 with the recommended setting data for the environment type determined in S803, and saves the merged setting value to the user setting data. Specifically, the security setting control unit 409 overwrites the user setting data with the recommended setting data. For a setting item of a security function, if the recommended setting data has a value (corresponding to anything other than a "slash" in Table 3), the setting value in the user setting data is changed to the recommended setting value. If the recommended setting data is blank (corresponding to a slash in Table 3), the setting value in the user setting data remains unchanged. Through the process described above, a batch security setting based on the recommended setting data is performed.
[0071] The method for determining user setting data in S806 is not limited to the method described above. For example, in S702, when the operation control unit 401 detects that the user has selected an environment on screen 500, the default setting data before the recommended setting data is overwritten is stored in the data storage unit 402. In S806, when applying the recommended setting data for the environment type to be changed to the user setting data, the default setting data is read from the data storage unit 402. Then, the new user setting data may be determined by overwriting the default setting data with the recommended setting data. It is also conceivable that the user may change the settings of individual setting items. Individual setting changes by the user may be stored and managed in the data storage unit 402, and when determining user setting data in S806, the individual setting changes by the user may be maintained.
[0072] In S807, the security setting control unit 409 displays a setting change confirmation screen 610 on the operation unit 320 to confirm whether the user wants to proceed with the setting change, even though the change does not conform to the current environment type, and then performs S808. Note that if the recommended environment type proposed in S804 is an arbitrary environment type, this step may be omitted if it is determined that the setting change will not affect the current environment type.
[0073] In S808, the security setting control unit 409 executes S809 if the user presses the Yes button 611 on the screen 610, and terminates the process if the user presses the No button 612.
[0074] In S809, the security setting control unit 409 sets the modified setting values instructed by the user in S801 to the user setting data stored in the data storage unit 402.
[0075] Through the above flow, the MFP101 can assist the user in configuring their settings by presenting them with the appropriate environment type.
[0076] In the flow described above, S803 estimates the recommended environment type, and S804 proposes that environment type to the user. However, S803 can be omitted. That is, it is possible to configure the system to not estimate the recommended environment type, but instead recommend batch configuration or notify the user of a change in the environment type. For example, when the secondary line settings or location information settings are changed, as shown in the bottom row of Table 4, the recommended environment type is not determined to be a single type, but it is determined that the environment type has changed. Therefore, S804 can be configured to display a recommendation for batch configuration or to notify the user that the environment type has changed. Alternatively, if the recommended environment type is not determined to be a single type as described above, the system can be configured to display a screen allowing the user to select one environment type from the candidate environment types. In that case, the environment type selected by the user is designated as the recommended environment type, and the system proceeds to S806.
[0077] Furthermore, the database used in S802 may have a different configuration than that shown in Table 4. Table 4 was a data table in which the current environment type, the proposed environment type, and predetermined setting values corresponding to predetermined setting items were stored in association. However, it is also possible to store only predetermined setting values, such as changes to secondary line settings or location information settings, and when a setting change is made to one of these predetermined setting values, a message recommending batch settings or a notification that the environment type has changed may be displayed.
[0078] Other configurations are possible for the database used in S802 and S803. For example, it may be a configuration in which predetermined setting values and predetermined usage environments are stored in association with each other. If the predetermined setting value matches the changed setting value instructed in S801 and is stored in the data storage unit 402, the predetermined usage environment may be estimated as the recommended environment type. If the recommended environment type is different from the current environment type, the system may be configured to display a notification of the recommended environment type and a notification recommending that the set of setting values suitable for the recommended environment type be set all at once. Alternatively, if the changed setting value instructed in S801 is a setting value included in the recommended setting data associated with a usage environment different from the usage environment set in the information processing device, it is also possible to notify in S804 that the environment type has changed.
[0079] As mentioned above, in S702, when the user selects an operating environment on screen 500, the program that executes the flowchart shown in Figure 8 becomes active. However, even when no operating environment has been selected on screen 500, the program that executes the flowchart shown in Figure 8 may still be active.
[0080] Furthermore, if the configuration change received in S801 is a configuration change received through the selection of an environment type for batch configuration, it is possible to configure the system so that processing from S802 onwards is not performed.
[0081] <Second Embodiment> In the first embodiment, a configuration was described in which the processing shown in Figure 8 is performed by the MFP101. However, the same processing may be configured to be performed by an information processing device other than the MFP101. For example, the security setting control unit 409 may be implemented as an application that can be installed and executed on the information processing device. This application is assumed to be a server application (hereinafter referred to as a server app) that manages network devices such as the MFP101. By executing the server app on the information processing device, the processing that was performed by the security setting control unit 409 of the MFP101 in the first embodiment can be realized by the information processing device. Specifically, the security setting control unit of the server app performs the processing described below.
[0082] First, the server application collects information about the configuration values set on the MFP101 from the MFP101 itself. For example, one possible configuration is that when the configuration values of the MFP101 are changed by the user, the configuration information is sent to the server application via the network. Alternatively, the server application could periodically collect the configuration information of the MFP101. A device management protocol such as SNMP (Simple Network Management Protocol) can be used to collect configuration information from the MFP101. In this way, the server application collects information about the configuration values of the MFP101. The collected configuration information includes information about the changed configuration values instructed by the user, as well as information about the usage environment already set on the MFP101.
[0083] When the server application receives the settings from MFP101, it executes the process shown in Figure 8. Note that Figure 8 was also used in the description of the first embodiment, but the subject is different in this embodiment. In S801, the server application receives the modified settings instructed by the user from MFP101. If received, proceed to S802.
[0084] In S802-S804, the server application determines whether the configuration change instructed by the user in S801 is compatible with the current environment type, estimates a recommended environment type, and proposes the recommended environment type to the user. In S802 and S803, the server application performs the determination and estimation using a database stored in the server application. This database is the same as the database described with reference to Table 4 in the first embodiment. In S804, the server application provides a screen similar to screen 600. The server application's screen is provided to a display device connected to its own device or to a web browser running on an external PC.
[0085] In S805, the web browser detects that the user has accepted the suggested environment type on screen 600. Upon receiving information indicating that this operation has been detected, the server application proceeds to S806. In S806, the server application sends the recommended configuration data, which is stored in the server application and is suitable for the recommended environment type, to the MFP101. Upon receiving the recommended configuration data, the MFP101 applies the data to itself.
[0086] In S805, if the server application does not receive information indicating that it has detected an operation to accept the user's suggestion of an environment type, the process proceeds to S807. In S807, the server application provides a screen similar to screen 610. In S808, the web browser receives an instruction from the user to apply the configuration change instructed by the user in S801. If the server application receives information indicating this instruction, the process proceeds to S809. If it does not receive this instruction, the process ends. In S809, the server application sends information indicating the user's configuration change instruction received in S801 to MFP101. Upon receiving the information indicating the configuration change instruction, MFP101 applies the configuration change to MFP101.
[0087] As with the first embodiment, the method for estimating the recommended environment type is not limited to the method described above. Furthermore, S804 may choose not to display the recommended environment type, only notifying the user that the environment type has changed, or simply displaying a recommendation for batch configuration.
[0088] Furthermore, although this embodiment describes a configuration in which each of steps S801 to S809 is performed by a server application, it is also possible to configure the system so that some steps are performed by an information processing device other than the MFP101. For example, it is possible to implement some steps using Javascript on a web browser on an external PC. The web browser on the PC, in accordance with the execution of Javascript, queries the MFP101 for information on whether the changed settings instructed to the user's MFP101 are compatible with the already configured usage environment, and for information on recommended environment types. Based on the information received, the web browser on the PC can then display recommended settings on the web browser.
[0089] According to the second embodiment, it is possible to perform at least a portion of the processing shown in Figure 8 using an information processing device other than the MFP101.
[0090] <Variation> In the first embodiment, a configuration was described in which screens 600 and 610 shown in Figure 6 are displayed separately in S804 and S807. However, for example, if a setting other than the internet prohibition type is set in S803 and the setting is changed to a weaker algorithm, screen 900 shown in Figure 9 may be displayed in S804.
[0091] In S804, the operation control unit 401 displays the following message on the operation unit 320: This message indicates that the changed setting value does not conform to the current environment type, that it is recommended to change to the internet-prohibited type, and that the system should be operated disconnected from the internet. When the operation control unit 401 detects that the user has pressed button 901, the security setting control unit 409 does not change the setting value and terminates the process. When the operation control unit 401 detects that the user has pressed button 902, the security setting control unit 409 performs the same process as in S806. Specifically, it merges the recommended setting data suitable for the recommended environment type with the current user setting data and applies it to the MFP101. When the operation control unit 401 detects that the user has pressed button 903, the security setting control unit 409 performs the same process as in S809.
[0092] Through the above process, instead of displaying information on screens 600 and 610 separately, only screen 900 can be displayed, allowing user input to be received. This reduces the burden on the user.
[0093] <Other Embodiments> The present invention can also be realized by supplying a program that implements one or more of the functions of each of the embodiments described above to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC or FPGA) that implements one or more functions. [Explanation of Symbols]
[0094] 101 MFP 401 Operation Control Unit 402 Data Storage Unit 409 Security Settings Control Unit
Claims
1. An information processing device, The information processing device includes a receiving means for receiving instructions to set a predetermined value, In accordance with the receipt of the instruction, a display control means displays a message recommending a batch setting of multiple values corresponding to the predetermined value in the information processing device, An information processing apparatus having a display control means that displays a display recommending the batch setting, including a display for receiving an instruction to accept or reject the batch setting.
2. The system further includes estimation means for estimating the usage environment of the information processing device based on the predetermined value, The information processing apparatus according to claim 1, further characterized in that the display control means performs a display that notifies the estimated usage environment.
3. The information processing device further includes setting means that, when one usage environment is selected from among multiple usage environments, sets a plurality of values corresponding to the selected usage environment. The information processing device according to claim 2, characterized in that the display control means displays a notification of the estimated usage environment based on the fact that the estimated usage environment is different from the selected usage environment, and then displays a notification recommending a batch setting in which the information processing device sets a plurality of values corresponding to a predetermined value, which correspond to the estimated usage environment.
4. The information processing device according to claim 2 or 3, characterized in that the information processing device has storage means for storing the predetermined value in association with a predetermined usage environment.
5. The information processing apparatus according to claim 4, characterized in that the estimation means estimates the predetermined usage environment stored in the storage means in association with the predetermined value as the usage environment of the information processing apparatus, in accordance with the instruction to set the predetermined value.
6. If, in the display recommending the aforementioned batch setting, information indicating that the recommendation is not accepted is received, the display control means further displays a message to confirm whether or not to set the predetermined value in the information processing device. The information processing device according to claim 1, characterized in that, when the display for confirmation receives information indicating an instruction to set the predetermined value in the information processing device, the predetermined value is set in the information processing device.
7. The information processing apparatus according to claim 1, characterized in that the information processing apparatus is an image processing apparatus comprising at least one of a scanner and a printer.
8. The information processing device according to claim 1, further comprising a means for providing a notification indicating that the usage environment of the information processing device has changed based on the predetermined value, in accordance with the receipt of an instruction to set the predetermined value.
9. A method for controlling an information processing device, A receiving step for receiving an instruction to set a predetermined value in the information processing device, A display control step that, in accordance with the receipt of the instruction, displays a message recommending a batch setting of multiple values corresponding to the predetermined value in the information processing device, A control method comprising the following, wherein the display control step includes a display for receiving an instruction to accept or reject the batch setting, and is characterized by providing a display recommending the batch setting.
10. A program for causing a computer to execute the control method described in claim 9.
Citation Information
Patent Citations
Image forming apparatus, security setting method, program, and recording medium
JP2007311873A
Image forming system
JP2011066714A
Image forming apparatus, method for setting the same, and security setting device
JP2011147128A
Information diagnostic system, information diagnostic device, information diagnostic method and program
JP2016095631A
System and control method for the same, and program
JP2021089660A