Web browsing system and method

JP7927500B2Active Publication Date: 2026-10-01CANON KK
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022126366
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-08
Publication Date
2026-10-01
Estimated Expiration
2042-08-08

AI Technical Summary

Benefits of technology

【0011】 本発明によれば、画像生成サーバを用いてWebページをブラウジングする構成において通信端末の通信環境に準じたブラウジングができるシステムを提供できる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007927500000001
    Figure 0007927500000001
  • Figure 0007927500000002
    Figure 0007927500000002
  • Figure 0007927500000003
    Figure 0007927500000003
Patent Text Reader

Abstract

To provide a system and a communication terminal that can perform browsing conforming to a communication environment of the communication terminal in a configuration for browsing a web page by using an image creation server.SOLUTION: A cloud browser system 12-00 is a web browsing system having an image creation server 1-30, image forming apparatuses 21-01 to 21-03, and image forming apparatuses 31-01 to 31-03, and the image forming apparatuses construct respective tunnels between the image forming apparatuses and the image creation server so as to allow the image creation server to perform communication through respective virtual proxy units provided by the respective image forming apparatuses. The image creation server downloads web contents from a web page server 1-05 through the respective tunnels, and provides a result of rendering based on the web contents to the respective image forming apparatuses.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[[Technical Field]]

[0001] The present invention relates to a communication terminal used in a web browsing system. This communication terminal can be applied to general-purpose information processing devices such as personal computers and mobile terminals, as well as image processing devices including printers, scanners, facsimiles, and multifunction peripherals combining the foregoing functions. [[Background Art]]

[0002] Conventionally, communication terminals such as image processing devices (information processing devices) equipped with a web browser (hereinafter referred to as a browser) and having a function of browsing web pages on the browser are known. A communication terminal that accesses a web page of an external service through a web browser can expand its functions by cooperating with the external service. In addition, when using such a web browser, in order to ensure security in specific environments, a method of applying access restrictions and retaining access histories through a proxy is sometimes used.

[0003] Nowadays, a mechanism called a cloud browser that uses an image generation server that generates rendering results of web pages on a cloud server is under study. Patent Document 1 discloses a system that renders a web page on a virtual machine located on a different network from the communication terminal, and displays the rendering result on the communication terminal. According to such a system, processing with high computational load such as web page analysis processing and execution processing is executed on the server, so the required specifications of the communication terminal can be reduced. [[Prior Art Documents]] [[Patent Documents]]

[0004] [[Patent Document 1]] Japanese Unexamined Patent Application Publication No. 2022-41717 [[Summary of the Invention]] [[Problem to be Solved by the Invention]]

[0005] Patent Document 1 does not consider use in special network environments and therefore has room for improvement. It is desirable that the web browsing system can be used appropriately even under special network environments.

[0006] For example, Patent Document 1 states that when a communication terminal is under proxy management, it is desirable to devise a way for communication by the web browsing system to also conform to proxy management. This is because, when a communication terminal under proxy management uses the cloud browser function, access permission settings are made to the image generation server. In that case, if the communication terminal notifies the image generation server of the URL of a web page that should be restricted from access, this communication is permitted. Furthermore, when the rendering result of the web page is sent from the image generation server to the communication terminal, this communication is also permitted. As a result, the communication terminal may be able to access a web page that should be restricted from access, which can lead to security risks.

[0007] Furthermore, if a communication terminal wants to render a web page from a web server on the local network, it cannot retrieve the web content if the image generation server cannot access the local network.

[0009] This invention has been made in view of the above-mentioned problems, and another objective is to provide a system that enables browsing according to the communication environment of each of multiple communication terminals in a configuration in which a web page is browsed using an image generation server. [Means for solving the problem]

[0010] The present invention relates to a web browsing system comprising a communication terminal equipped with a proxy function and an image generation server that provides rendering results based on web content to the communication terminal, wherein the system comprises: construction means for constructing a predetermined communication path between the communication terminal and the image generation server; management means for managing proxy information of proxies used during communication via the predetermined communication path in the image generation server; and download means for downloading web content from a web server corresponding to a request received from the communication terminal via the predetermined communication path and through a proxy corresponding to the proxy information in the image generation server. of The construction means As the aforementioned communication terminal When a first communication path is established as the predetermined communication path between the first communication terminal and the image generation server, the management means manages the proxy information of the first communication terminal used when communicating via the first communication path, and the construction means As the aforementioned communication terminal, further When a second communication path is established between the second communication terminal and the image generation server as the predetermined communication path, the management means is characterized in that it additionally manages information about the proxy function of the second communication terminal used when communicating via the second communication path, as proxy information. [Effects of the Invention]

[0011] According to the present invention, a system can be provided that enables browsing in accordance with the communication environment of a communication terminal when browsing web pages using an image generation server. [Brief explanation of the drawing]

[0012] [Figure 1] This is a block diagram showing the overall configuration of the cloud browser system. [Figure 2] Figure 2(A) is a block diagram showing the hardware configuration of a virtual machine. Figure 2(B) is a block diagram showing the software configuration of a virtual machine. [Figure 3]Figure 3(A) is a block diagram showing the hardware configuration of the image forming apparatus. Figure 3(B) is a block diagram showing the software configuration of the image forming apparatus. [Figure 4] This figure shows an example of the home screen of an image forming apparatus. [Figure 5] This diagram shows the configuration of the cloud browser screen. [Figure 6] This is a diagram showing the settings screen of a cloud browser. [Figure 7] Figure 7(A) shows an example of virtual proxy information managed by a virtual machine. Figure 7(B) shows an example of session and browser association management information managed by a virtual machine. [Figure 8] This diagram shows the usage sequence of a cloud browser system. [Figure 9] This is a flowchart illustrating the proxy processing of an image forming apparatus. [Figure 10] This is a flowchart illustrating the tunnel construction process between the image forming apparatus and the virtual machine. [Figure 11] Figure 11(A) shows the cloud browser settings screen in another embodiment. Figure 11(B) shows the virtual machine settings screen in another embodiment. [Figure 12] This block diagram shows an example configuration of a cloud browser system that allows image forming machines in multiple networks to access a single virtual machine. [Figure 13] Figure 13(A) shows an example of virtual proxy information managed by a virtual machine. Figure 13(B) shows an example of session and browser association management information managed by a virtual machine. [Modes for carrying out the invention]

[0013] Hereinafter, modes for carrying out the present invention will be specifically described with reference to examples and drawings. Note that the scope of the present invention is not limited to the configurations described in the examples. Modifications such as replacement of parts of configurations or parts of processing with equivalents, or omissions thereof, may be made within the scope where similar effects can be obtained.

[0014] (Example) <Cloud Browser System> Figure 1 is a diagram showing the overall configuration of a cloud browser system. The cloud browser system 1-00 is a web browsing system that renders web content on the cloud. The cloud browser system 1-00 includes a plurality of image forming apparatuses 1-01 to 1-03, and an image generation server 1-30 to which these image forming apparatuses are connected. The cloud browser system 1-00 also includes a web page server 1-05 that provides web pages, a local web page server 1-09, and a proxy server 1-04. Figure 1 shows an example where there is one image generation server 1-30, while three image forming apparatuses 1-01 to 1-03 are connected thereto. However, any number of image forming apparatuses may be connected to the image generation server 1-30. Further, the image generation server 1-30 is configured to provide services to a plurality of image forming apparatuses in parallel or in a time-division manner. Therefore, in the cloud browser system 1-00, the number of image generation servers 1-30 is relatively small relative to the number of image forming apparatuses. A plurality of image generation servers may also be arranged in the cloud browser system 1-00 for purposes such as distributing load. Hereinafter, the relationship with the image generation server 1-30 will be described by taking the image forming apparatus 1-01 as an example, representing the plurality of image forming apparatuses.

[0015] The image generation server 1-30 is a cloud-based system that provides a service for alternative rendering of web content. The image generation server 1-30 includes a gateway 1-06 and a virtual machine 1-07. As will be described in detail later, a browser engine, which is a software module, operates on the virtual machine 1-07 of the image generation server 1-30. The browser engine receives the URL transmitted from the image forming apparatus 1-01 via the gateway 1-06. Then, the browser engine accesses the web page corresponding to the received URL via the gateway 1-06, and receives web content such as HTML from the web page. Thereafter, a separately prepared software module for rendering generates a rendering result (rendered image) of the received web content. The rendering result is transmitted to the image forming apparatus 1-01 via the gateway 1-06.

[0016] The image forming apparatus 1-01 is an image processing apparatus (information processing apparatus, communication terminal) having a function of forming (printing) an image on a sheet (paper), or a function of transmitting image data generated by scanning to an arbitrary destination. The image forming apparatus 1-01 may be a printer of either MFP or SFP type. Further, the printing method of the image forming apparatus 1-01 may be either an electrophotographic method or an inkjet method. The image forming apparatus 1-01 of the present embodiment is characterized in that it browses and displays web content on the Internet by using the image generation server 1-30. Details will be described later.

[0017] Further, the image forming apparatus 1-01 exists in the intranet 1-20, and can communicate with other apparatuses in the same intranet. For example, the image forming apparatus 1-01 can access a web page provided by a local web server. Further, the image forming apparatus 1-01 can provide a web page to the user terminal 1-08 by functioning as a web server.

[0018] Proxy server 1-04 is a server that monitors and restricts communication between the inside and outside of intranet 1-20. Proxy server 1-04 performs URL filtering (web filtering) to restrict access to websites. This access restriction is done using a list of websites to be prohibited or a list of websites to be allowed. Each device within intranet 1-20 connects to the internet via or without Proxy server 1-04, according to its own settings. For example, in Figure 1, suppose a user operates image forming apparatus 1-01 and inputs a request to view web page server 1-05. The image forming apparatus 1-01 then sends the address of web page server 1-05 (hereinafter referred to as URL) to image generation server 1-30 via Proxy server 1-04. Note that Proxy server 1-04 is configured within DMZ 1-10. DMZ (Demilitarized Zone) 1-10 is a segment isolated from intranet 1-20 for enhanced security.

[0019] <Virtual Machine> Figure 2(A) is a block diagram showing the hardware configuration of a virtual machine.

[0020] Virtual machine 1-07 includes CPU 2-01, storage 2-02, RAM 2-03, interface 2-04, and communication interface 2-05. Each component is connected via bus 2-06 for communication.

[0021] The CPU (Central Processing Unit) 2-01 executes various processes using computer programs and data stored in storage. In doing so, the CPU 2-01 controls the overall operation of the virtual machine 1-07 and executes or controls the various processes described later, which are performed by the virtual machine 1-07.

[0022] Storage 2-02 stores configuration data for virtual machine 1-07, computer programs and data related to the startup of virtual machine 1-07, computer programs and data related to the basic operation of virtual machine 1-07, etc. RAM 2-03 has an area for storing computer programs and data loaded from storage 2-02, and data received from external devices via communication interface 2-05. RAM 2-03 also has a work area used by CPU 2-01 when executing various processes. In this way, RAM 2-03 can provide various areas (storage areas) as appropriate.

[0023] Interface 2-04 is an interface that includes a display unit for displaying the processing results of CPU 2-01 as images or text, an operation unit for the user to perform various operations, and so on. The display unit includes an LCD screen or a touch panel screen. The operation unit includes a user interface such as a keyboard, mouse, or touch panel screen.

[0024] Communication interface 2-05 is an interface for data communication with external devices.

[0025] The configuration shown in Figure 2(A) is merely one example of a configuration applicable to a virtual machine, and is not intended to limit the possibilities to the configuration shown in Figure 2(A). For example, in the configuration shown in Figure 2(A), a memory device may be further connected to bus 2-06. Memory devices include, for example, hard disk drives, USB memory, magnetic cards, optical cards, IC cards, memory cards, and drive devices (drive devices for storage media such as flexible disks (FD), compact disks (CDs), and other optical disks). Virtual machine 1-07 can be configured using so-called virtualization technology, which allows various resources constituting a computer system to be organized into logical units independently of the physical configuration. That is, it is possible to integrate multiple resources to configure virtual machine 1-07, or to divide a single resource and configure one of the parts as virtual machine 1-07. In other words, virtual machine 1-07 can be configured using at least some of the multiple resources (which may be composed of multiple devices) of an information processing system that constitutes a cloud.

[0026] Figure 2(B) shows the software configuration of a virtual machine operating in a cloud browser system. The overall control unit 2-50 is a module that controls the entire virtual machine of the cloud browser system 1-00. The network control unit 2-54 is a module that receives external communications and transmits data through the communication interface 2-05. The network control unit 2-54 receives a rendering request for web content specified by a URL and notifies the overall control unit 2-50 of it. Rendering refers to generating images and other content from abstract, high-level information described in a data description language or data structure. The overall control unit 2-50 receives the rendering request notification and notifies the browser engine 2-51 of the specified URL. The browser engine 2-51 passes the URL to the HTTP client 2-52 in order to obtain the web content indicated by that URL. The HTTP client 2-52 obtains the proxy information set in the proxy setting unit 2-53 and requests the network control unit 2-54 to obtain the web content of the specified URL via that proxy. The network control unit 2-54 accesses the URL via the designated proxy and retrieves the web content. The browser engine 2-51 requests the rendering control unit 2-55 to render the information of the retrieved web content. The overall control unit 2-50 transmits the image data rendered by the rendering control unit 2-55 to an external device through the network control unit 2-54. The virtual proxy unit 3-56 (virtual proxy unit) functions as a proxy that provides a communication environment to the virtual machine 1-07 via the image forming apparatus 1-01. When the virtual proxy unit 3-56 is functioning, the virtual machine 1-07 accesses the internet via the proxy server 1-04 and retrieves web content from the web page server 1-05, etc. Also, when the virtual proxy unit 3-56 is functioning, the virtual machine 1-07 accesses the intranet 1-20 and retrieves web content from the local web page server 1-09, etc.

[0027] <Image forming apparatus> Figure 3(A) shows the hardware configuration of the image forming apparatus. The image forming apparatus 1-01 includes a controller unit 3-00, an operating unit 3-12, a USB storage device 3-14, a scanner 3-70, and a printer 3-95.

[0028] The control unit 3-12 is an operation unit that displays information to the user and accepts user input.

[0029] The control unit 3-12 is comprised of, for example, a display, a touch panel sensor, hard keys, and the like.

[0030] USB Storage 3-14 is an external storage device for storing data. USB Storage 3-14 is detachable from USB Host I / F 3-13.

[0031] Scanner 3-70 is an image reading unit (image reading device, image input device) that reads images from a document.

[0032] Printer 3-95 is an image forming unit (image forming device, image output device) that forms an image on a sheet (paper).

[0033] The controller unit 3-00 is a control unit equipped with a configuration for performing various controls in the image forming apparatus 1-01. For example, the controller unit 3-00 performs controls to realize a copy function that prints image data read by the scanner 37-0 using the printer 3-95.

[0034] The controller unit 3-00 comprises a CPU 3-01, RAM 3-02, ROM 3-03, storage 3-04, and image path I / F 3-05. These components are communicated together via the system bus 3-07.

[0035] Furthermore, the controller unit 3-00 includes an operation interface 3-06, a network interface 3-10, a USB host interface 3-13, an RTC 3-15, a device interface 3-20, a scanner image processing unit 3-80, and a printer image processing unit 3-90. These components are communicated via the image path interface 3-05 and the image path.

[0036] CPU3-01 starts the operating system (OS) using a boot program stored in ROM3-03. CPU3-01 then executes programs stored in storage3-04 on this OS, thereby performing various processes. RAM3-02 is used as the CPU3-01's workspace. RAM3-02 provides both workspace and image memory for temporary storage of image data. Storage3-04 is the storage unit for programs and image data. HDDs, SSDs, and eMMCs can be used as storage3-04.

[0037] The CPU 3-01 is connected to the ROM 3-03 and RAM 3-02, the control unit interface 3-06, the network interface 3-10, the USB host interface 3-13, and the image bus interface 3-05 via the system bus 3-07. The control unit interface 3-06 is the interface with the control unit 3-12 and outputs image data to be displayed on the control unit 3-12. The control unit interface 3-06 also sends information entered by the user on the control unit 3-12 to the CPU 3-01. The network interface 3-10 is the interface for connecting the image forming apparatus to a LAN.

[0038] The USB host interface 3-13 is an interface unit that communicates with the USB storage 3-14. The USB host interface 3-13 is an output unit that stores data stored in storage 3-04 onto the USB storage 3-14. The USB host interface 3-13 also receives data stored in the USB storage 3-14 and transmits it to the CPU 3-01. Multiple USB devices, including the USB storage 3-14, can be connected to the USB host interface 3-13.

[0039] The RTC3-15 controls the current time. The time information controlled by the RTC3-15 is used for recording job submission times, etc.

[0040] Image bus I / F3-05 is a bus bridge that connects system bus 3-07 and image bus 3-08, which transfers image data at high speed, and converts data formats. Device I / F3-20, scanner image processing unit 3-80, and printer image processing unit 3-90 are provided on image bus 3-08. Scanner 3-70 and printer 3-95 are connected to device I / F3-20, and device I / F3-20 performs synchronous / asynchronous conversion of image data. Scanner image processing unit 3-80 performs correction, processing, and editing of input image data. Printer image processing unit 3-90 performs correction, resolution conversion, etc., on print output image data according to printer 3-95.

[0041] Figure 3(B) shows the software configuration of the image forming apparatus.

[0042] In Figure 3(B), the parts shown by solid lines are software modules realized when the CPU 3-01 executes the main program loaded into RAM 3-02. The execution of each module described later is managed and controlled by the OS (Operating System) 3-51.

[0043] The UI control unit 3-52 displays the screen on the operation unit 3-12 and accepts user input through 3-06. It also has the function of notifying other modules and receiving drawing instructions from those modules to control screen updates.

[0044] The job execution control unit 3-53 is a module that receives job execution instructions from the UI control unit 3-52 and controls job processing such as copying, scanning, and printing.

[0045] The NW control unit 3-54 receives communication requests from other modules, controls the network IF 3-10, and controls communication with external devices. It also receives notifications from external devices and notifies other modules of the contents of those notifications.

[0046] The storage control unit 3-55 records and manages the configuration information and job information stored in the storage unit 3-04. Each module located in the OS hierarchy accesses the storage control unit 3-55 to refer to and configure settings.

[0047] The virtual proxy unit 3-56 provides the virtual machine with a communication environment (a predetermined communication path) via the Tunnel.

[0048] The browser control unit 3-60 is a submodule included in OS3-51 and performs cloud browser-specific controls, which will be described later. The number of submodules included in the OS is arbitrary.

[0049] When the browser operation unit 3-62 receives notification of user operation from the UI control unit 3-52, it has the function of notifying the command IF unit 3-64 or the proxy processing unit 3-65 of the details of the user operation.

[0050] The Proxy Processing Unit 3-65 receives a notification from the Browser Operation Unit 3-62 and requests the Storage Control Unit 3-55 to obtain Proxy setting information. Based on the obtained Proxy setting information, if the Proxy setting is valid, it requests communication to the Proxy Server 1-04 via the Network Control Unit 3-54. Furthermore, it has the function of receiving a response to the communication request from the Network Control Unit 3-54, processing the content of that response, and notifying the Browser Display Unit 3-63 or the Command IF Unit 3-64 of the result.

[0051] The command interface unit 3-64 receives notifications from the browser operation unit 3-62 and the proxy processing unit 3-65, and requests communication with the image generation server 1-30 via the network control unit 3-54. This communication request may include the notified information. Notified information includes user operations such as text input, link clicks, scrolling, and zooming. For example, text input includes a URL. When a link is clicked, it includes the click coordinates on the operation unit 3-12, and when scrolling and zooming, it includes the corresponding strings. The network control unit 3-54 also receives communication from the image generation server 1-30. It processes the received information and notifies the image data acquisition unit 3-61 or the browser display unit 3-63.

[0052] The image data acquisition unit 3-61 receives the URL of the storage 2-02 where the rendering results are stored from the command interface unit 3-64. It receives the image from the URL and passes it to the browser display unit 3-63.

[0053] The browser display unit 3-63 receives an image from the image data acquisition unit 3-61 and instructs the UI control unit 3-52 to draw the image. It also receives notifications from the command interface unit 3-64 and the proxy processing unit 3-65 and instructs the display of a screen showing the message corresponding to the notification.

[0054] <System Usage Flow> The following describes the usage flow of the cloud browser system 1-00 with the configuration described above. Figure 8 is a diagram showing the usage sequence of the cloud browser system.

[0055] Figure 8 shows the interactions between the user, browser control unit 3-60, virtual proxy unit 3-56, proxy server 1-04, virtual machine 1-07, and web page servers 1-05 and 1-09 when using the cloud browser system 1-00.

[0056] When using the cloud browser system 1-00, the user activates the cloud browser function by operating the control panel 3-12 of the image forming apparatus 1-01. Figure 4 shows the menu screen displayed on the image forming apparatus. This screen is generated by the execution of the program constituting the UI control unit 3-52 by the CPU 3-01 and is displayed on the control panel 3-12. Button 4-01 is related to the copy function. Button 4-02 is related to the print function. Button 4-03 is related to the cloud browser. Button 4-04 is related to the scan function. When each button is selected, the corresponding function is activated. When button 4-03 is selected, the browser control unit 3-60 is activated and the browser screen 500 is displayed on the control panel 3-12 (S8-010).

[0057] The browser screen 5-00 includes a back button 501, a forward button 5-02, an address bar 5-03, and a settings button 5-04. Below these is a content area 5-05 that displays the rendering results of the web content. These functions are the same as those of existing browsers.

[0058] The browser control unit 3-60 is configured to display nothing in the content area 5-05 from the time it is started until a URL is entered. Alternatively, like existing browsers, it may be configured to allow registration of a default URL in the address bar 5-03, and to display the result of rendering the web content of that URL immediately upon startup. Figure 5 shows an example where the result of rendering some web content obtained from the web page pointed to by the URL "https: / / ***.***.***.*** / " is displayed.

[0059] The browser control unit 3-60 accesses the virtual machine 1-07 via the proxy server 1-04 and requests the establishment of a tunnel between the image forming apparatus 1-01 and the virtual machine 1-07 (S8-020, S8-030). The tunnel described later is established on this communication session. If no proxy is configured, the image forming apparatus 1-01 communicates with the virtual machine 1-07 without going through the proxy server 1-04.

[0060] Next, the browser control unit 3-60 activates the virtual proxy function (S8-025). Details of this virtual proxy function will be described later.

[0061] Upon receiving the Tunnel construction request S8-030, virtual machine 1-07 executes the Server Tunnel construction process S8-040 to build a tunnel over its communication. Meanwhile, the virtual proxy unit 3-56 also executes the Device Tunnel construction process S8-045. Details of these tunnel construction processes will be described later using Figure 10.

[0062] These tunnel construction processes determine the virtual proxy information. An example of virtual proxy information is shown in Figure 7(B). This virtual proxy information consists of session ID 7-40, proxy host 7-41, proxy port 7-42, proxy authentication ID 7-43, and proxy authentication password 7-44 (password). Session ID 7-40 is an ID used to identify the client using virtual machine 1-07. Proxy host 7-41 and proxy port 7-42 indicate information about the virtual proxy accessed through the tunnel constructed by the aforementioned tunnel construction process. Proxy authentication ID 7-43 and proxy authentication password 7-44 indicate the authentication information for the virtual proxy.

[0063] Next, virtual machine 1-07 starts browser engine 2-51 (S8-048).

[0064] Next, virtual machine 1-07 sets proxy information in the proxy settings section 2-53 as configuration information to be used for the started browser engine 2-51. Based on the virtual proxy information described above, the browser engine 2-51 is configured with the proxy's Host, Port, Proxy authentication ID, and Password.

[0065] A typical website contains links to multiple web content elements (such as CSS, JavaScript, and images) within its HTML. Browsers follow these links to access the web content via HTTP. JavaScript that is loaded may also dynamically access the content via HTTP. All of these HTTP accesses also occur in the browser engine 2-51. Therefore, according to the settings in S8-050, all of these HTTP accesses pass through the tunnel between the image forming apparatus 1-01 and the virtual machine 1-07.

[0066] In S8-058, virtual machine 1-07 notifies browser control unit 3-60 of the session ID 7-40 determined in S8-040. Next, in S8-060, browser control unit 3-60 accesses virtual machine 1-07 via proxy server 1-04, notifies it of the URL of the web content to be rendered, and requests rendering (S8-060, S8-070).

[0067] This rendering request includes session ID 9-01 and web content URL 9-02, as shown in Figure 9. This session ID 9-01 is the same ID as session ID 7-40 notified in S8-058. Upon receiving the rendering request, virtual machine 1-07 retrieves the web content of URL 9-02 included in the rendering request using browser engine 2-51 (S8-075).

[0068] The Proxy configuration unit 2-53 issues a Web content retrieval request S8-080 for URL 9-02 to the proxy configured in S8-050. This Web content retrieval request S8-080 passes through the Tunnel constructed in the aforementioned Tunnel construction S8-040 and S8-045 and is notified to the virtual Proxy unit 3-56. Upon receiving the Web content retrieval request S8-080, the virtual Proxy unit 3-56 performs the Proxy processing S8-085, which will be described in detail in Figure 9. In this Proxy processing S8-085, a content retrieval request (S8-090, S8-100) is sent to the Web page server 1-05 specified by the URL. Here again, the configuration switches whether communication is performed via Proxy server 1-04 or directly to Web page server 1-05. Upon receiving this content retrieval request S8-100, the web page server 1-05 sends back the web content at the specified URL (S8-110, S8-120).

[0069] The virtual proxy unit 3-56 sends the received web content back to the virtual machine 1-07 (S8-130). The virtual machine 1-07 renders the received web content using the proxy configuration unit 2-53 and saves the rendered image (S8-140).

[0070] Virtual machine 1-07 returns a URL to access the saved rendered image (S8-150, S8-155).

[0071] The browser control unit 3-60 issues an image acquisition request for the rendered image URL received in S8-155 (S8-160, S8-165).

[0072] Virtual machine 1-07 returns the image corresponding to the URL of the image acquisition request (S8-170, S8-175). Browser control unit 3-60, having acquired the rendered image, displays the rendered image on operation unit 3-12 (S8-180). When the user has finished using the service, they send a termination request to browser control unit 3-60 (S8-190).

[0073] When the browser control unit 3-60 receives a termination request, it requests virtual machine 1-07 to discard the tunnel (S8-200, S8-210). In other words, the tunnel discard request is made when the browser function terminates. Upon receiving the tunnel discard request, virtual machine 1-07 discards the tunnel (S8-220) and terminates the proxy setting unit 2-53 (S8-230).

[0074] As described above, even when the image forming apparatus 1-01 and the image generation server 1-30 are on different networks, the image forming apparatus 1-01 can behave as if it were directly accessing the target web page server. Therefore, communication via the proxy server 1-04 becomes possible, ensuring security. Furthermore, even if the content is provided by a local web page server 1-09 within a private network such as intranet 1-20, the virtual machine can access it, render it, and provide it to the image forming apparatus 1-01.

[0075] <Proxy Settings> Figure 6 shows the system settings screen of the cloud browser. This settings screen can be viewed from external devices by providing it as a web page using the server function of the image forming apparatus 1-01. For example, a user terminal 1-08 connected on the same network line can display the settings screen 4-00 by entering a specific URL into its web browser. Processing S10-01 is performed using this settings screen. Alternatively, the settings screen 6-00 may be displayed directly on the operation unit 3-12 without being converted into web page information.

[0076] The settings screen 6-00 includes items 6-01, 6-02, 6-03, 6-04, and 6-05.

[0077] Item 6-01 is a setting item for turning the cloud browser function ON or OFF. Checking the checkbox for item 6-01 turns the cloud browser function ON, and the cloud browser button 4-03 will appear on screen 6-00. Unchecking the checkbox for item 6-01 turns the cloud browser function OFF, and the cloud browser button 4-03 will be removed from screen 6-00. Also, item 6-01 is the first item that is operated on the settings screen 6-00, and checking the checkbox for item 6-01 makes it possible to operate on other items.

[0078] Item 6-02 is a setting item for determining whether or not to use a proxy. In environments where a proxy is used for internet access, check the checkbox for setting item 6-02 and configure the proxy host and port information.

[0079] Item 6-03 is a setting item for configuring proxy authentication information. In environments where authentication is required to use the proxy, check the checkbox for item 6-03 and specify the proxy authentication information (ID, Password).

[0080] Item 6-04 is a setting item for configuring the startup URL. Checking the checkbox for item 6-04 and entering a URL in the input field will cause the cloud browser application to automatically access the specified URL when launched. The information configured here is notified via network interface 3-10 and recorded in storage 3-04.

[0081] Item 6-06, which specifies the HTTP headers used when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30, is specified. When this setting is enabled, the specified HTTP header (the HTTP header for the proxy) is added to the HTTP header when the image forming apparatus 1-01 makes an HTTP request to the image generation server 1-30. This makes it possible to determine which of the HTTP accesses passing through the proxy server 1-04 is an access to the image generation server 1-30. Furthermore, if the proxy server is restricting web access, this can be used to identify which accesses should be restricted, and is expected to have the effect of appropriately restricting access.

[0082] <Control> Figure 10 is a flowchart illustrating the tunnel construction process between the image forming apparatus and the virtual machine. Figure 10 details the ServerTunnel construction S8-040 and DeviceTunnel construction S8-045. Of the processes shown in Figure 10, the processing on the image forming apparatus 1-01 side is implemented by the controller unit 3-00. Specifically, this is achieved by expanding the program stored in ROM 3-03 or storage 3-04 into RAM 302, and then executing it on CPU 3-01. Of the processes shown in Figure 8, the processing on the virtual machine 1-07 side is achieved by expanding the program stored in storage 2-02 into RAM 2-03, and then executing it on CPU 2-01.

[0083] In ServerTunnel construction S8-040, CPU2-01 determines the session ID that manages the Tunnel (S10-010). The session ID determined here is managed in item 7-40, as shown in Figure 7(A). Note that this session ID can be in any format as long as it is unique information.

[0084] Next, in order to determine the authentication information (ID, Password) to be used by the virtual proxy unit 3-56, CPU 2-01 executes the virtual proxy authentication confirmation process (S10-020).

[0085] This authentication information (ID, Password) is generated using a random string or hash function. The generated authentication information is linked to the session ID and managed in items 7-43 and 7-44. Next, CPU 2-01 notifies the image forming apparatus 1-01 of the confirmed authentication information (S10-030).

[0086] Next, CPU2-01 determines the port number for communication with the virtual proxy unit 3-56 (S10-040). This port number is associated with the session ID and managed in item 7-42.

[0087] Next, CPU2-01 listens on the TCP port with the determined port number (S10-050). When this port is accessed, it is configured to communicate with the virtual proxy unit 3-56. This concludes the details of the ServerTunnel construction process S8-040.

[0088] Meanwhile, during the DeviceTunnel construction S8-045, CPU3-01 receives virtual proxy authentication information (ID, Password) (S10-060).

[0089] Next, CPU3-01 sets this authentication information as the authentication information for the virtual proxy (S10-070). Then, it constructs a tunnel so that proxy access from virtual machine 1-07 can be received by the virtual proxy unit 3-56 (S10-080).

[0090] As described above, a tunnel is established between the virtual machine 1-07 and the image forming apparatus 1-01. In this embodiment, the virtual proxy authentication confirmation process S10-020 is executed on the virtual machine 1-07 side, and the virtual proxy information reception process S10-070 is executed on the image forming apparatus 1-01. However, the roles of the virtual machine 1-07 and the image forming apparatus 1-01 could be reversed.

[0091] Next, we will explain the details of S8-085. Figure 9 is a flowchart illustrating the proxy processing of the image forming apparatus. Each process shown in this flowchart is implemented by the controller unit 3-00. More specifically, it is implemented by loading a program stored in ROM 3-03 or storage 3-04 into RAM 302, and then executing it on CPU 3-01.

[0092] Proxy processing S8-085 is a process that is executed when the virtual proxy unit 3-56 receives a request to retrieve web content from the virtual machine 1-07.

[0093] CPU3-01 verifies whether the proxy authentication information attached to the web content retrieval request is correct and whether the proxy authentication information set in S10-070 is correct (S9-010). If the verification is successful, CPU3-01 proceeds to S9-020; if the verification fails, it proceeds to S9-070.

[0094] In S9-020, CPU3-01 checks whether the URL of the Web content acquisition request is a URL (loopback address) that points to the web content of image forming apparatus 1-01. If the URL is for image forming apparatus 1-01, the process proceeds to S9-060; otherwise, it proceeds to S9-030.

[0095] In S9-030, CPU3-01 checks whether proxy usage is enabled. If proxy usage is enabled, the process proceeds to S9-050; otherwise, the process proceeds to S9-040.

[0096] In S9-040, CPU3-01 retrieves the content of the requested URL without going through the proxy, and then terminates the process.

[0097] In S9-050, CPU3-01 forwards the web content retrieval request to the configured proxy and terminates processing.

[0098] In S9-060, CPU3-01 acquires (downloads) the web content provided by the image forming apparatus 1-01 and terminates processing.

[0099] In S9-070, CPU3-01 returns an authentication error and terminates processing.

[0100] Based on the above, the request to retrieve web content from virtual machine 1-07 can be processed appropriately.

[0101] <Remarks> As described above, in this embodiment, even when the image forming apparatus 1-01 and the image generation server 1-30 are on different networks, the image forming apparatus 1-01 can behave as if it were directly accessing the target web page server. Therefore, communication via the proxy server 1-04 becomes possible, and security can be ensured. Furthermore, even if the content is provided by a local web page server 1-09 within a private network such as an intranet 1-20, the virtual machine 1-07 can access it, render it, and provide it to the image forming apparatus 1-01.

[0102] (Example 2) Example 1 described an example where one image forming machine connects to one virtual machine via a tunnel connection. However, given the nature of web browsing, it is unlikely that one image forming machine would constantly request rendering from one virtual machine and fully utilize the virtual machine's resources. Therefore, Example 2 describes an example where multiple image forming machines connect to a single virtual machine via a tunnel connection.

[0103] <Cloud Browser System> Figure 12 is a block diagram showing an example configuration of a cloud browser system in which image forming machines in multiple networks can access a single virtual machine.

[0104] In the cloud browser system 12-00, the web page server 1-05 and the image generation server 1-30 are accessed from multiple intranets (intranet A12-01, intranet B12-02).

[0105] Within intranet A12-01, a proxy server 21-04, image forming apparatuses 21-01 to 21-03, a user terminal 21-08, and a local web page server 21-09 are located. Proxy server 21-04 is configured to correspond to proxy server 1-04. However, in Example 2, proxy server 21-04 is assumed to be located within intranet A12-01. Image forming apparatuses 21-01 to 21-03 are configured to correspond to image forming apparatuses 1-01 to 1-03. User terminal 21-08 is configured to correspond to user terminal 1-08. Local web page server 21-09 is configured to correspond to local web page server 1-09.

[0106] Within intranet B12-02, a proxy server 31-04, image forming apparatuses 31-01 to 31-03, a user terminal 31-08, and a local web page server 31-09 are located. Proxy server 31-04 is configured to correspond to proxy server 1-04. However, in Example 2, proxy server 31-04 is assumed to be located within intranet A12-02. Image forming apparatuses 31-01 to 31-03 are configured to correspond to image forming apparatuses 1-01 to 1-03. User terminal 31-08 is configured to correspond to user terminal 1-08. Local web page server 31-09 is configured to correspond to local web page server 1-09.

[0107] Under normal circumstances, devices within intranet A12-01 can access the local web page server 21-09, but devices outside intranet A12-01 cannot. For example, image forming apparatus 21-01 can access the local web page server 21-09, but image forming apparatus 31-01 and virtual machine 1-07 cannot.

[0108] Similarly, under normal circumstances, devices within intranet B12-02 can access the local web page server 31-09, but devices outside intranet B12-02 cannot. For example, image forming apparatus 31-01 can access the local web page server 31-09, but image forming apparatus 21-01 and virtual machine 1-07 cannot.

[0109] In Example 2, virtual machine 1-07 is configured to simultaneously hold Proxy setting A12-03 and Proxy setting B12-04. Proxy setting A12-03 is, for example, configuration information for Tunnel connection with image forming apparatus 21-01, and Proxy setting B12-04 is, for example, configuration information for Tunnel connection with image forming apparatus 31-01. In this way, virtual machine 1-07 establishes Tunnel connections in parallel with devices on different networks. Therefore, virtual machine 1-07 can accept rendering requests sequentially at the same time.

[0110] <Difference> The system usage flow in Example 2 is substantially the same as that described in Example 1 using Figure 8. However, since it is necessary to launch a different browser for each connected image forming apparatus, browser-specific control is performed in S8-048. Browser-specific control is managed using session IDs. Figure 13(B) shows an example of session and browser linkage management information managed by the virtual machine. As shown in Figure 13(B), the linkage between session IDs and browsers is managed by the session ID column 13-70 and the browser column 13-71. "Session 2" is, for example, the session ID corresponding to the browser for image forming apparatus 21-01, and "Session 3" is, for example, the session ID corresponding to image forming apparatus 31-01. In this way, session IDs are determined in S10-010 so that a unique session ID can be used for each connection destination.

[0111] Each browser, regardless of session ID, connects to a different device, and therefore uses different virtual proxy information. Figure 13(A) shows an example of virtual proxy information managed by a virtual machine. In Example 2, different ports are used for each virtual proxy to distinguish between image forming machines connected via tunnel. Therefore, as shown in the Proxy port column 13-42, different port numbers are used for each session ID. For example, "Proxy port 10001" is the port for tunnel connection to image forming machine 21-01, and "Proxy port 10002" is the port for tunnel connection to image forming machine 31-01. Processing in S10-020, S10-030, and S10-040 is performed so that virtual proxy information and ports for each connection destination become available.

[0112] <Remarks> As described above, in this embodiment, even if the image generation server 1-30 is on a different network from the image forming apparatus 21-01 and the image forming apparatus 31-01, it is possible to make it behave as if the image forming apparatus 21-01 and the image forming apparatus 31-01 were directly accessing the target web page server. Therefore, communication via the respective proxy servers, the proxy server 21-04 and the proxy server 31-04, becomes possible, and security can be individually guaranteed. Furthermore, it becomes possible to construct a usage environment in which web content provided by the local web page server 21-09 within the intranet 12-01 is provided to the image forming apparatus 21-01 but not to the image forming apparatus 31-01.

[0113] (Other examples) The present invention is not limited to the above embodiments, and various modifications (including organic combinations of each embodiment) are possible based on the spirit of the invention, and these are not excluded from the scope of the invention.

[0114] In the embodiment, the explanation was given on the premise that the Tunnel function is used when using the cloud browser system. However, the use of the Tunnel function may be made switchable ON / OFF by settings. Figure 11(A) shows the settings screen of the cloud browser in another embodiment. The settings screen includes item 11-01. Item 11-01 is for setting whether or not to build a Tunnel between the image forming apparatus 1-01 and the virtual machine 1-07. When item 11-01 is set to enabled, the system operates as shown in the sequence in Figure 8. Therefore, when the virtual machine 1-07 tries to access the web page server 1-05, by using the Tunnel, it is possible to communicate via the proxy server 1-04, which is normally inaccessible. Also, by using the Tunnel, it becomes possible to access the local web page server 1-09, which is normally inaccessible. When item 11-01 is set to disabled, the processes S8-020 and S8-25 are not executed. Therefore, a tunnel is not established between the image forming apparatus 1-01 and the virtual machine 1-07, and the virtual machine 1-07 directly retrieves web content from the web page server 1-05.

[0115] Furthermore, the embodiment described an example in which proxy authentication for the Tunnel function is performed automatically without user intervention. However, a manual setting method involving user intervention may also be adopted for proxy authentication for the Tunnel function. For example, the image forming apparatus 1-01 generates an ID and password and displays them on the settings screen 11-00. The user then makes a note of this information and enters it into the settings screen 11-50 of the virtual machine 1-07. The exchange of proxy authentication information necessary for Tunnel construction may be performed in this manner.

[0116] The present invention can also be realized by supplying a program that implements one or more of the functions of the above embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.

[0117] The present invention may be applied to a system consisting of multiple devices or to a device consisting of a single device. For example, the functionality may be realized by configuring a part of the software module to run on an external server and obtaining the results processed on the external server.

[0118] The abbreviations used in the examples have the following meanings. ASIC stands for Application Specific Integrated Circuit. CPU stands for Central Processing Unit. EMMC stands for embedded MultiMediaCard. FAX stands for Facsimile. HDD stands for Hard Disk Drive. HTML stands for HyperText Markup Language. HTTP stands for HyperText Transfer Protocol. LAN stands for Local Area Network. MFP stands for Multi-Function Peripheral. OS stands for Operating System. RAM stands for Random-Access Memory. ROM stands for Read Only Memory. SFP stands for Single Function Peripheral. SSD stands for Solid State Drive. UI stands for User Interface. URL stands for Uniform Resource Locator. USB stands for Universal Serial Bus. [Explanation of Symbols]

[0119] 1-00 Cloud Browser System 1-01 Image forming apparatus 1-04 Proxy Server 1-30 Image generation server

Claims

1. A web browsing system comprising a communication terminal equipped with a proxy function and an image generation server that provides rendering results based on web content to the communication terminal, A construction means for establishing a predetermined communication path between the communication terminal and the image generation server, The image generation server includes a management means for managing proxy information of a proxy used when communicating via the predetermined communication path, The image generation server includes a download means that downloads web content from a web server corresponding to a request received from the communication terminal via a predetermined communication path and through a proxy corresponding to the proxy information, If the construction means constructs a first communication path as the predetermined communication path between the first communication terminal and the image generation server as the communication terminal, the management means manages the proxy information of the first communication terminal used when communicating via the first communication path as proxy information. A web browsing system characterized in that, if the construction means further constructs a second communication path as the predetermined communication path between the second communication terminal and the image generation server as the communication terminal, the management means additionally manages information of the proxy function of the second communication terminal used when communicating via the second communication path as the proxy information.

2. The Web browsing system according to claim 1, characterized in that the management means manages information on the proxy function of the first communication terminal and information on the proxy function of the second communication terminal, linked to each session ID that identifies the connection of the first communication path and the second communication path, respectively, as predetermined communication paths.

3. The Web browsing system according to claim 1, further characterized in that the management means manages the port number used when connecting to the first communication terminal and the second communication terminal, respectively, in association with each session ID.

4. The Web browsing system according to claim 1, characterized in that the communication terminal has display means for displaying the rendering results of the Web content provided by the image generation server.

5. The Web browsing system according to claim 1, characterized in that the communication terminal includes an image forming unit that forms an image on a sheet.

6. The Web browsing system according to claim 1, characterized in that the communication terminal includes an image reading unit for reading images from a document.

7. A method in a web browsing system comprising a communication terminal equipped with a proxy function and an image generation server that provides rendering results based on web content to the communication terminal, A construction step is performed in which the communication terminal and the image generation server establish a predetermined communication path between the communication terminal and the image generation server, A management process in which the image generation server manages proxy information of the proxy used when communicating via the predetermined communication path, The process includes a download step in which the image generation server downloads web content from a web server corresponding to a request received from the communication terminal, via the predetermined communication path and through a proxy corresponding to the proxy information, When a first communication path is established between the first communication terminal and the image generation server as the predetermined communication path, the management process manages the proxy information of the first communication terminal used when communicating via the first communication path. The method is characterized in that, if a second communication path is further established between a second communication terminal and the image generation server as the predetermined communication path, the management step additionally manages information of the proxy function of the second communication terminal used when communicating via the second communication path as the proxy information.

Citation Information

Patent Citations

  • Method for establishing communication connection

    JP2002064562A

  • Network system, proxy server, session management method, and program

    JP2007128349A

  • Information processing system, method of controlling the same, information processing apparatus, information providing apparatus, image processing apparatus, and program

    JP2011135314A

  • Information processing system and control method thereof

    JP2022041717A

  • Method and apparatus for distributed script processing

    US20130212462A1