Information processing device and information processing system
The information processing device and system dynamically execute unset countermeasure items to enhance security in image forming devices, addressing the inadequacies of existing security settings by ensuring security tailored to the actual usage environment.
Patent Information
- Application Number
- PCT/JP2025/026037
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-26
- Filing Date
- 2025-07-23
- Publication Date
- 2026-01-29
AI Technical Summary
Existing security settings in image forming devices may not adequately ensure security depending on the data being handled or the printing method, despite user selection of suitable security functions.
An information processing device and system that dynamically execute unset countermeasure items when predetermined conditions are met during execution of selected security functions, ensuring security suited to the actual usage environment.
Ensures enhanced security by conditionally executing unset countermeasure items, such as printing and communication restrictions, based on data content analysis, thereby protecting confidential information.
Smart Images

Figure JP2025026037_29012026_PF_FP_ABST
Abstract
Description
Information processing device and information processing system
[0001] The present invention relates to an information processing device and an information processing system in which any one of a plurality of security functions is set, and more particularly to a technique for setting additional countermeasure items that are not set in the set security functions.
[0002] For example, an image forming device may include an image reading unit that reads an image on a sheet of paper read by the image reading unit, a communication unit that transmits or receives image data representing the image via a network, an image forming unit that forms the image on a sheet of paper, etc. It is desirable for such an image forming device to be configured by selecting from a plurality of security functions that are suitable for the usage environment of the image forming device.
[0003] In the information processing device described in Patent Document 1, in order to support appropriate security settings for devices (multifunction devices) in accordance with various usage environments, characteristic information of communications made by a first device (multifunction device) of interest is acquired, and a trained model is generated by machine learning based on characteristic information of communications made by a plurality of other second devices (multifunction devices) and setting information of the usage environments of the second devices, and the usage environment of the first device is estimated based on this trained model and the acquired characteristic information of communications related to the first device, and this estimated usage environment of the first device is notified.
[0004] Japanese Patent Application Laid-Open No. 2023-114275
[0005] However, even if a user selects and sets the security functions that he or she thinks are suitable for the usage environment from among multiple types of security functions in the image forming device, security may not actually be ensured depending on the data being handled or the printing means.
[0006] In Patent Document 1, the usage environment of the first device is estimated based on a trained model and characteristic information of communications related to the first device, and this estimated usage environment of the first device is notified to assist in setting up security measures. However, even in this case, security may not actually be ensured depending on the data being handled or the printing method.
[0007] The present invention has been made in consideration of the above circumstances, and aims to ensure security suited to the actual usage environment when one of a plurality of security functions is selected and set.
[0008] An information processing device according to one aspect of the present invention comprises an operation unit into which instructions are input by a user, and a first control unit that executes existing countermeasure items in multiple types of security functions selected by the instructions input to the operation unit, and the first control unit further executes unset countermeasure items when predetermined conditions are satisfied during execution of the selected security function.
[0009] In addition, an information processing system according to one aspect of the present invention comprises an information processing device and a terminal device, wherein the terminal device comprises a second communication unit that performs data communication with the information processing device and a second control unit that causes a data file to be sent from the second communication unit to the information processing device via the network, and the information processing device comprises an operation unit into which instructions are input by a user, and a first control unit that executes existing countermeasure items in multiple types of security functions selected by instructions input to the operation unit, and the first control unit further executes unset countermeasure items when predetermined conditions are met when the selected security function is executed.
[0010] According to the present invention, when one of a plurality of types of security functions is selected and set, the selected and set security function can additionally execute unset countermeasure items.
[0011] Fig. 2B is a block diagram showing the configuration of an information processing system including an image forming apparatus as an information processing apparatus according to an embodiment of the present invention. Fig. 2C is a flowchart showing a process for conditionally executing unset countermeasure items when a set security function is executed in the image forming apparatus. Fig. 2D is a flowchart showing a process following Fig. 2A. Fig. 2E is a diagram showing columns of first to sixth security functions and execution keys displayed on the screen of the display unit of the image forming apparatus. Fig. 2F is a diagram showing a comparison table displayed on the screen of the display unit of the image forming apparatus.
[0012] An information processing apparatus and an information processing system according to an embodiment of the present invention will be described below with reference to the drawings. Fig. 1 is a block diagram showing the configuration of an information processing system including an image forming apparatus as an information processing apparatus according to an embodiment of the present invention. The information processing system Sy includes an image forming apparatus 10 as an information processing apparatus according to an embodiment of the present invention, and a terminal device 30. The image forming apparatus 10 performs data communication with the terminal device 30 via a network N.
[0013] In the information processing system Sy, the image forming apparatus 10 is an MFP (multi-function peripheral) that combines multiple functions such as a copy function and a scanner function. The image forming apparatus 10 includes a display unit 11, an operation unit 12, a touch panel 13, a communication unit 14, an image reading unit 15, an image forming unit 16, a storage unit 18, and a control unit 19. These components transmit and receive data or signals to and from each other via a bus.
[0014] The display unit 11 is configured by a liquid crystal display (LCD) or an organic light-emitting diode (OLED) display.
[0015] The screen of the display unit 11 is equipped with a touch panel 13. The touch panel 13 detects contact (touch) with the user's finger or the like on the touch panel 13, along with the contact position, and outputs a detection signal indicating the coordinates of the contact position to the control unit 21 of the control unit 19. This makes it possible to accept input of instructions according to a GUI (Graphical User Interface) displayed on the screen of the display unit 11 via the touch panel 13. The touch panel 13 is an example of an operation unit in the claims, and functions as an operation unit through which instructions from the user are input to the screen of the display unit 11.
[0016] The operation unit 12 includes hardware keys such as a numeric keypad, a decision key, a start key, etc. The operation unit 12 receives various instructions from the user.
[0017] The image reading unit 15 has a scanner that optically reads an image of a document, and generates image data that represents the image of the document.
[0018] The image forming unit 16 is an image forming mechanism that forms an image on recording paper by a so-called electrophotographic method or an inkjet method, and prints an image represented by the image data on recording paper.
[0019] The communication unit 14 is a communication interface equipped with a communication module such as a LAN chip. The communication unit 14 performs data communication with the terminal device 30 via a network N. The network N is composed of, for example, an intranet connected to the communication unit 14, a wired or wireless LAN, and the Internet connected thereto.
[0020] The storage unit 18 is a large-capacity storage device such as an SSD (Solid State Drive) or an HDD (Hard Disk Drive), and stores various application programs and various data.
[0021] The control unit 19 is composed of a processor, a RAM (Random Access Memory), a ROM (Read Only Memory), etc. The processor is, for example, a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), or an MPU (Micro Processing Unit). The control unit 19 functions as a control unit 21 when a control program stored in the ROM or the storage unit 18 is executed by the processor.
[0022] The control unit 19 is responsible for overall control of the image forming apparatus 10. The control unit 19 is also connected to the display unit 11, the operation unit 12, the touch panel 13, the communication unit 14, the image reading unit 15, the image forming unit 16, and the storage unit 18. The control unit 21 controls each of the above components and transmits and receives signals or data to and from each of the components.
[0023] The control unit 21 functions as a processing unit that executes various processes, and also has the function of controlling the display unit 11 and the communication unit 14.
[0024] The touch panel 13 corresponds to the operation unit in the claims, the communication unit 14 corresponds to the first communication unit in the claims, and the control unit 21 corresponds to the first control unit in the claims.
[0025] In the information processing system Sy, the terminal device 30 is, for example, a smartphone, and includes a display unit 31, a touch panel 33, a communication unit 34, a storage unit 38, and a control unit 39. These components transmit and receive data or signals to and from each other via a bus.
[0026] The display unit 31 is configured with a liquid crystal display, an organic EL display, etc. The touch panel 33 is overlaid on the screen of the display unit 11, and detects contact (touch) of the user's finger or the like with the touch panel 13 together with the contact position, and outputs a detection signal indicating the coordinates of the contact position to the control unit 41 of the control unit 39.
[0027] The communication unit 34 is a communication interface and performs data communication with the image forming apparatus 10 through the network N. The network N is composed of, for example, an intranet connected to the communication unit 34, a wired or wireless LAN, and the Internet connected thereto.
[0028] The storage unit 38 is a large-capacity storage device such as an SSD or HDD, and stores various application programs and various data.
[0029] The control unit 39 is composed of a processor, RAM, ROM, etc. The control unit 39 functions as a control unit 41 when a control program stored in the ROM or the storage unit 38 is executed by the processor.
[0030] The control unit 39 is responsible for overall control of the terminal device 30. The control unit 39 is also connected to the display unit 31, the touch panel 33, the communication unit 34, the storage unit 38, etc. The control unit 41 controls each of the above components and transmits and receives signals or data to and from each of the components.
[0031] The control unit 41 functions as a processing unit that executes various processes, and also has the function of controlling the display unit 31 and the communication unit 34.
[0032] The communication unit 34 corresponds to the second communication unit in the claims, and the control unit 41 corresponds to the second control unit in the claims.
[0033] In the information processing system Sy configured as described above, it is desirable that the image forming apparatus 10 selects and sets from among a plurality of security functions a function suited to the usage environment of the image forming apparatus 10. The usage environment may be a communication environment such as an intranet, a wired or wireless LAN, or the Internet connected to the communication unit 14 of the image forming apparatus 10, or an installation location environment such as a company, office, store, or private home, and it is desirable to set a security function suited to each environment.
[0034] However, for example, in the image forming device 10, if data communication via the communication unit 34 is not restricted, the data file received by the communication unit 14 will be printed without restriction, and depending on the confidentiality of the contents of the data file, security may not be ensured.
[0035] Therefore, in the information processing system Sy, when any of a plurality of types of security functions is set and executed, not only the countermeasure items included in the set security function but also unset countermeasure items not included in the set security function are executed when preset conditions are met, thereby ensuring security suited to the actual usage environment.
[0036] For example, the control unit 21 determines that a data file or metadata acquired together with the data file satisfies a predetermined condition if security data is included in the data file or metadata acquired together with the data file. When the data file is document data or an image file, the security data is predetermined text data consisting of character strings, codes, or symbols included in the data file or in the file name of the data file. In the case of an image file, the control unit 21 extracts text from the image file by performing OCR processing on the image. When a data file contains such security data, the data file is deemed to be subject to high security protection. In this example, the unspecified countermeasure item is a printing restriction (print prohibition) on received data. The security data is stored in advance in the storage unit 8, or is security data input by the user through the operation unit 12, or security data received from an external device by the communication unit 14, and is stored in the storage unit 18.
[0037] For example, when a data file is received from another device via communication unit 14 and the received data file contains security data, control unit 21 of image forming apparatus 10 determines that the data file satisfies a preset condition and performs a printing prohibition process on the received data file as an unspecified countermeasure. If the received data file does not contain security data, control unit 21 does not perform a printing prohibition process on the received data file, and causes image forming unit 16 to form the data to be printed indicated in the data file on recording paper.
[0038] In the information processing system Sy, the control unit 41 of the terminal device 30 transmits the data file from the communication unit 34 to the image forming device 10 via the network N.
[0039] When the data file is received by the communication unit 14, the control unit 21 of the image forming apparatus 10 determines whether the condition that the data file contains security data is met. If the control unit 21 determines that this condition is met, it implements a data communication restriction as an unset countermeasure. The control unit 21 sets the communication of the communication unit 14 to a predetermined high security level, and in this state, (i) transmits a request to transmit the data file at a high security level (predetermined) corresponding to the high security level set in the image forming apparatus 10 from the communication unit 14 to the terminal device 30 via the network N, or (ii) prohibits the communication unit 14 from transmitting a request to transmit the data file.
[0040] To determine whether the above conditions are met, the control unit 21 receives the data file from the terminal device 30 in parts, and starts determining whether the above conditions are met from the received data file parts (including the file names). When the control unit 21 determines that the above conditions are met, it implements communication restrictions on subsequent data according to (i) or (ii) above as an unspecified countermeasure item.
[0041] When the control unit 41 of the terminal device 30 receives the transmission request (i) above sent from the image forming device 10 at the communication unit 34, the control unit 41 causes the communication unit 34 to transmit the data file to the image forming device 10 via the network N at the high security level indicated by (i) above.
[0042] Next, a process of conditionally executing unset countermeasure items when a set security function is executed in the image forming apparatus 10 will be described with reference to the flowcharts shown in FIGS. 2A and 2B.
[0043] In the image forming device 10, when a user touches the GUI displayed on the screen of the display unit 11 to receive an instruction to display security functions on the touch panel 13, the control unit 21 displays a display screen G1 including columns R1 to R6 for the first to sixth security functions on the screen of the display unit 11, as shown in the example of Figure 3 (S101).
[0044] The display screen G1 displays columns R1 to R6 for the first to sixth security functions and an execution key K1. Here, six types of security functions are shown as an example, but more or fewer types of security functions may be displayed.
[0045] When the user touches any of the display areas of the first to sixth security functions, an instruction to select the security function displayed in the touched area is received by the operation unit 12 via the touch panel 13 (S102). For example, when the user touches the second security function column R2 and the execution key K1, a selection instruction to select the second security function is received by the operation unit 12. The control unit 21 executes the second security function in accordance with the selection instruction (S103).
[0046] At this time, the control unit 21 reads the data of the list HH stored in the memory unit 18 and performs a highlighting process on the read data of the list HH, highlighting each countermeasure item for the security function selected by the selection instruction, in this case the second security function (S104). The list HH is a table indicating whether or not each countermeasure item is set for each of the first through sixth security functions. For example, the background of each countermeasure item for the second security function is processed to be blue, a color different from the touch panel portion. Next, the control unit 21 displays an image of the list HH that has been highlighted on the screen of the display unit 11 (S105).
[0047] In the list HH shown in Figure 4, the countermeasure items for the security functions are listed in the vertical columns, and the countermeasures and effects and the first through sixth security functions are listed in the horizontal rows. For each of the first through sixth security functions, whether or not each countermeasure item is set is indicated. A "○" indicates that a countermeasure item is set, and no mark indicates that a countermeasure item is not set. The countermeasure items include "device connection restrictions," "printing restrictions on received data," "data communication restrictions," etc.
[0048] For example, for the first security function, two countermeasure items are associated with each "o" and therefore two countermeasure items are set and implemented. Also, for the second security function, three countermeasure items are associated with each "o" and therefore three countermeasure items are set and implemented. Or, for the sixth security function, eight countermeasure items are associated with each "o" and therefore eight countermeasure items are set and implemented.
[0049] The user looks at the list HH displayed on the screen of the display unit 11 and knows that the three countermeasure items associated with the respective "◯" marks in the second security function have been executed.
[0050] Here, for example, assume that a second security function with a lower security level is selected in accordance with a selection instruction input by the user to the operation unit 12, and the control unit 21 sets and executes the second security function. Here, the second security function does not include a printing restriction on received data or a data communication restriction as a countermeasure item. However, even when the second security function is executed, it may be desirable to execute a printing restriction on received data and a data communication restriction on highly confidential data files. In this embodiment, to address such cases, when the second security function is executed, the control unit 21 conditionally executes a printing restriction on received data and a communication restriction on data that is not set in the second security function.
[0051] In the image forming apparatus 10 in which the second security function is set and executed as an example of a security function, when a user places an original on the image reading unit 15 and inputs a copy instruction, scan instruction, or send instruction into the operation unit 12 by the user, the control unit 21 causes the image reading unit 15 to read the image of the original in accordance with the content of the instruction in an environment in which the restrictions on the above three countermeasure items of the second security function are already executed. Alternatively, the communication unit 14 receives (i) only a data file or (ii) a data file accompanied by a metafile from the terminal device 30. The metadata is data indicating file attributes of the data file, which is an object, such as the type (directory, link, etc.), size, creation date, last update date, file owner, and access rights.
[0052] When the control unit 21 acquires a data file, which is an original image obtained by scanning using the image scanning unit 15, or a data file (i) or (ii) received from the terminal device 30, as described above, the control unit 21 determines whether the acquired data is a data file or a metafile (S106). That is, when acquiring a data file from the image scanning unit 15 or the communication unit 14, the control unit 21 acquires only the data file, or both the data file and the metafile. Furthermore, when acquiring both the data file and the metafile, the control unit 21 acquires either the data file or the metafile first. Therefore, in S106, the control unit 21 determines whether the data acquired first is a data file or a metafile.
[0053] When the control unit 21 determines that the initially acquired data is a data file (not a metafile) (S106 "File"), it determines whether the condition that the security data is included in the data file is satisfied (S107). Security data is, for example, predetermined data such as characters, character strings, symbols, or codes indicating confidentiality. Security data may also be predetermined data such as characters, character strings, symbols, or codes indicating data that is generally not disclosed to the public, such as invoices, contracts, or internal documents of an organization, or may be arbitrary characters, character strings, symbols, or codes set by the user. When the data file is image data, the control unit 21 performs OCR (Optical Character Recognition) processing on the image represented by the image data to recognize text from the image and determine whether the text contains security data. Alternatively, the control unit 21 determines whether the file name of the data file contains security data.
[0054] If the control unit 21 of the image forming device 10 determines that the data file does not contain security data and that the above conditions are not met (S107 "No"), it executes only the countermeasure items included in the security functions set at this time (S108), and does not execute the printing restrictions on received data and the data communication restrictions, which are unset countermeasure items that are executed conditionally.
[0055] Then, the control unit 21 causes the image forming unit 16 to form an image using the print target data indicated by the received data file (S109).
[0056] Furthermore, if the control unit 21 of the image forming apparatus 10 determines that the data file contains security data and that the conditions are met (S107 "Yes"), it implements a printing restriction on the received data, which is a conditionally implemented countermeasure that has not yet been set (S111), and further implements a data communication restriction (S112). That is, the control unit 21 executes the countermeasures included in the security function set at this time, and also performs processing to prevent the image forming unit 16 from forming an image of the acquired data file and to prevent data communication after the reception of the data file. Furthermore, if the control unit 21 sequentially acquires a data file portion by portion and starts determining whether the above conditions are met from the acquired data file portion (including the file name), it suspends reception of the data file at that point and prevents subsequent data communication, even if the data file is not completely received and is still being received.
[0057] Therefore, if the data file contains security data, the security function set in the image forming apparatus 10 is not changed to another security function with a higher level than the previous setting, but the unset countermeasure item is executed. For example, when the unset countermeasure item is executed, the control unit 21 may cause the image forming unit 16 to form an image based on the acquired data file or may lift the data communication restriction when the user inputs a restriction lift instruction or a predetermined password into the operation unit 12.
[0058] On the other hand, when the control unit 21 determines that the initially acquired data is a metafile (not a data file) (S106 "Meta"), it determines whether the condition that the above-mentioned security data is included in the metafile is met (S114).
[0059] If the control unit 21 determines that the metadata does not contain security data ("No" in S114), it determines that the condition that the metadata of the data file contains security data is not met, and executes only the countermeasures included in the security function currently set, in this case the second security function (S115). The control unit 21 does not impose printing restrictions on the received data, nor does it impose communication restrictions on subsequent data. Following the metadata, the control unit 21 receives a data file from the terminal device 30 via the communication unit 14, and causes the image forming unit 16 to form an image based on the data file (S116).
[0060] Furthermore, when the control unit 21 determines that the metadata of the data file includes security data ("Yes" in S114) and determines that the condition that the metadata of the data file includes security data is satisfied, it restricts printing of the received data (S120). The control unit 21 also restricts data communication (S121) and increases the security level of touch panel communication. As a result, the communication unit 14 of the image forming device 10 does not receive the data file following the metadata from the terminal device 30. Therefore, the control unit 21 does not cause the image forming unit to form an image based on the data file.
[0061] For example, if the image forming device 10 and the terminal device 30 each have a short-range communication unit (not shown) such as Bluetooth (registered trademark) or Wi-Fi, and data communication between them is carried out via short-range communication, the control unit 21 of the image forming device 10 controls the short-range communication unit to prohibit the short-range communication unit from receiving data from the terminal device 30.
[0062] Therefore, if the metadata of a data file contains security data, the communication unit 14 of the image forming device 10 will not receive the data file, thereby prohibiting the sending and receiving of data files that may contain confidential information, thereby sufficiently protecting the data file.
[0063] In this way, when the result of S114 is YES, the control unit 21 restricts data communication by prohibiting data communication, thereby increasing the security level of communication by the communication unit 14. However, instead, the control unit 21 may receive a data file from the terminal device 30 after increasing the security level of data communication. For example, the control unit 21 may execute an encryption encoding algorithm to receive an encrypted data file from the terminal device 30, and after receiving the encrypted data file, perform a corresponding decryption process to execute an image formation process based on the data file. In this case, the control unit 21 of the image forming apparatus 10 may send an encryption request to the terminal device 30 via the communication unit 1 and receive the encrypted data file from the terminal device 30.
[0064] In the above embodiment, both print restrictions and communication restrictions are adopted as unset countermeasure items that are executed when the pre-set conditions are met, but either print restrictions or communication restrictions may be used, or other countermeasure items (not limited to the countermeasure items shown in Figure 4) may be adopted alone or in combination.
[0065] Furthermore, the unspecified countermeasure items to be executed when the preset conditions are satisfied may be fixed (predetermined) or may be selected by a user instruction. The user instruction may be input to the operation unit 12, or may be received by the communication unit 14 of the image forming apparatus 10 as data input to the touch panel 33 of the terminal device 30 and transmitted by the communication unit 34.
[0066] Furthermore, the control unit 21 of the image forming apparatus 10 may execute the unset countermeasure items, and then complete the job for the data file, thereby completing the execution of the unset countermeasure items.
[0067] Furthermore, the control unit 21 of the image forming apparatus 10 may complete the execution of an unset countermeasure item after a certain time has elapsed since the execution of the unset countermeasure item.
[0068] In this embodiment, multiple security functions are displayed on the screen of the display unit 11, and the countermeasure items included in the security function selected by the user are executed. Furthermore, countermeasure items not set in the selected security function are also executed under certain conditions. This makes it possible to provide appropriate security content according to the contents of the data file, etc., and ensures security that is suitable for the actual usage environment.
[0069] The present invention is not limited to the configuration of the above embodiment, and various modifications are possible. Furthermore, in the above embodiment, the configuration and processing shown in the above embodiment using Figures 1 to 4 are merely one embodiment of the present invention, and it is not intended that the present invention be limited to these configurations and processing.
Claims
1. An information processing device comprising: an operation unit into which instructions are input by a user; and a first control unit that executes existing countermeasure items in multiple types of security functions selected by instructions input to the operation unit, wherein the first control unit further executes unset countermeasure items when predetermined conditions are met when the selected security functions are executed.
2. The information processing device according to claim 1, wherein the first control unit uses, as the predetermined condition, a condition that the data file to be processed contains predetermined security data.
3. An information processing device as described in claim 2, further comprising a first communication unit, wherein the first control unit determines whether the condition that the security data is included in the received data file portion is met when the data file is sequentially received portion by portion by the first communication unit, and from the point in time when it determines that the condition is met, executes communication restrictions on subsequent data as the unset countermeasure item.
4. The information processing device according to claim 1, wherein the first control unit uses, as the predetermined condition, a condition that a metafile accompanying the data file to be processed contains predetermined security data.
5. An information processing device as described in claim 4, further comprising a first communication unit, wherein the first control unit determines whether the condition that the received metafile contains the security data is met when the data file is received sequentially in parts by the communication unit, and if it determines that the condition is met, executes communication restrictions on the data file following the metafile as the unset countermeasure item.
6. An information processing device as described in claim 1, wherein the first control unit selects and executes at least one of the following processes as the unset countermeasure items: a process of prohibiting printing of the data file, a process of prohibiting reception of the data file, and a process of receiving only encrypted data files.
7. The information processing device according to claim 1, wherein the unset countermeasure item is selected by an instruction input to the operation unit.
8. The information processing device according to claim 1, further comprising a first communication unit that receives user instructions from a terminal device, wherein the unset countermeasure items are selected by the instructions received by the first communication unit.
9. An information processing system comprising an information processing device and a terminal device, wherein the terminal device comprises a second communication unit that performs data communication with the information processing device, and a second control unit that causes the second communication unit to send a data file to the information processing device via a network, wherein the information processing device comprises: an operation unit to which instructions are input by a user; and a first control unit that executes existing countermeasure items in multiple types of security functions selected by instructions input to the operation unit, and wherein the first control unit further executes unset countermeasure items when preset conditions are satisfied when the selected security function is executed.
Citation Information
Patent Citations
Apparatus, method and program for managing security of business machine
JP2006196951A
Facsimile machine
JP2007258930A
Information processing system and information processing apparatus
JP2017076364A