Transmitter firewall
Abstract
Problem to be solved.To prevent a part of intranet users from using a part of some functions of a transmitter on the intranet.
Solution.The transmitter receives a request from the user and sends user message data to a request address of a request network resource on the network. The transmitter determines whether transmission of the request is prohibited or not. From this determination, if the request transmission is determined to be not prohibited, the user message data of the request network resource is sent to the request network address. If the request transmission is determined to be prohibited according to the determination, diagnosis is transmitted.
Copyright (C)2004,JPO
Term
Term ended
Projected expiry passed 16 May 2023, 3.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
10 claims: 3 independent, 7 dependent
- 1Requests on a network Requests for network resources In order to send user message data to a network address, a transmitter capable of sending data on the network, in a step of receiving a request from a user, and in the transmitter. When it is determined whether or not the request transmission is prohibited and the determination determines that the request transmission is not prohibited, the step of sending the user message data to the request network address of the request network resource. And, when it is determined by the determination that the request transmission is prohibited, a computer-executable instruction instructing the computer to execute a method including a step of issuing a diagnosis and a method including the step of issuing a diagnosis at the time of execution on the processor is issued. A computer-readable medium that has. ネットワーク上の要求ネットワーク・リソースの要求ネットワーク・アドレスにユーザ・メッセージ・データを送るために、前記ネットワーク上でデータを送ることのできる送信装置で、ユーザからの要求を受け取るステップと、前記送信装置において、前記要求伝送が禁止されるかどうか判定すると、前記判定により、前記要求伝送が禁止されないと判定されるときには、前記要求ネットワーク・リソースの前記要求ネットワーク・アドレスに前記ユーザ・メッセージ・データを送るステップと、前記判定により、前記要求伝送が禁止されると判定されるときには、診断を発するステップと、を含む方法を、プロセッサ上での実行時に、コンピュータに実施するように指示するコンピュータ実行可能命令を有するコンピュータ読取り可能媒体。
- 6A device capable of sending message data that is configured to optically scan a memory containing an access control list (ACL) and at least one object to form the corresponding scanned object data. A capable scanning mechanism, an input device to the memory that receives user input including a user ID, a logic operably coupled to the memory configured to compare the user ID with the ACL, and said. When the comparison is positive, the first network address is used to address the user message data so that the scanned object data is formed in the user message data. The user message data can be configured to initiate an action to send the user message data to the first network address via at least one network interface, and if the comparison is negative, a diagnosis is made. A device comprising at least one network interface operably coupled to said logic, which can be configured to emit. メッセージ・データを送ることのできる装置であって、アクセス制御リスト(ACL)を含むメモリと、少なくとも1つのオブジェクトを光学的にスキャンして、対応するスキャンされたオブジェクト・データを形成するように構成できるスキャニング機構と、ユーザIDを含むユーザ入力を受け取る、前記メモリへの入力装置と、前記ユーザIDと前記ACLを比較するように構成された、前記メモリに動作可能に結合されたロジックと、前記比較が肯定的であるときには、前記スキャンされたオブジェクト・データを、ユーザ・メッセージ・データの中に形成するように、第1のネットワーク・アドレスを用いて、前記ユーザ・メッセージ・データを宛てるように、前記ユーザ・メッセージ・データを、少なくとも1つのネットワーク・インタフェースを経て、前記第1のネットワーク・アドレスに送る動作を起動するように構成でき、また、前記比較が否定的であるときには、診断を発するように構成できる、前記ロジックに動作可能に結合された少なくとも1つのネットワーク・インタフェースと、を備える装置。
- 10A device capable of sending message data that optically scans and responds to memory containing at least one access control list (ACL) and feature access list (FAL) and at least one object. A group consisting of a scanning mechanism that can be configured to form scanned object data, the user's user ID, the requesting functions performed by the device, the user's email address, delivery list, website address, and file directory. An input device to memory that receives a user input containing at least one request network address selected from, said the user input, and configured to compare at least one of the ACL and the FAL. Using the request network address to form the scanned object data in the user message data when the comparison is positive with the logic operably coupled to the memory. , The user message data can be configured to initiate an action to send the user message data to the request network address of the request network resource, and the comparison is negative. When is, it can be configured to initiate an action to send diagnostic message data containing at least one user ID, request function, request network address, to the network address of a network resource that is not the request network address. A device comprising at least one network interface operably coupled to said logic. メッセージ・データを送ることのできる装置であって、アクセス制御リスト(ACL)と機能アクセス・リスト(FAL)の少なくとも1つを含むメモリと、少なくとも1つのオブジェクトを光学的にスキャンして、対応するスキャンされたオブジェクト・データを形成するように構成できるスキャニング機構と、ユーザのユーザID、装置で実施される要求機能、ユーザeメール・アドレス、配信リスト、ウェブサイト・アドレス、ファイル・ディレクトリから成る一群から選択された要求ネットワーク・アドレス、を少なくとも1つ含むユーザ入力を受け取る、メモリへの入力装置と、前記ユーザ入力と、前記ACLと前記FALの少なくとも1つを比較するように構成された、前記メモリに動作可能に結合されたロジックと、前記比較が肯定的であるときには、前記スキャンされたオブジェクト・データを、ユーザ・メッセージ・データの中に形成するように、前記要求ネットワーク・アドレスを用いて、前記ユーザ・メッセージ・データを宛てるように、前記ユーザ・メッセージ・データを、前記要求ネットワーク・リソースの前記要求ネットワーク・アドレスに送る動作を起動するように構成でき、また、前記比較が否定的であるときには、ユーザID、要求機能、要求ネットワーク・アドレス、を少なくとも1つ含む診断メッセージ・データを、前記要求ネットワーク・アドレスでないネットワーク・リソースのネットワーク・アドレスに送る動作を起動するように構成できる、前記ロジックに動作可能に結合された少なくとも1つのネットワーク・インタフェースと、を備える装置。
Independent claims3
93 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates generally to the transmitting device, and more specifically to the security of the transmitting device.
【0002】
[Conventional technology]
Many peripherals in a computer network include scanner components. An example of such a peripheral is an "all-in-one" device, which is also capable of performing multiple functions: scanning, copying, and printing hard copy documents. In that respect, it is also known as a multifunction peripheral device (MFP). As another example, a document from an automated document feeder is scanned, mass-copied, bound, checked for missing pages, folded, stacked, stapled, bound, bordered, and attached. Moreover, there are digital network copiers capable of printing on various typesetting substrates. Each of these peripherals can be described as a transmitter device when interacting with the interconnected network.
【0003】
The transmitting device is a device having a keyboard, a display, and a scanner. This transmitter does not need to have a printer. Digital cameras are some sort of transmitter, however, when compared to the above description, they are not considered useful in processing documents and are generally faster to put information into a repository (storage location) after scanning. And lacks the ability to transfer repeatedly and the resolution. Transmitters are generally distinguishable from devices such as laptop PCs (personal computers) and pocket PCs in terms of their limited purpose and limited user interface or input / output capabilities. For example, a typical user interface for transmitter 102 includes a front menu screen with limited screen space and a limited number of buttons. In addition, the transmitter 102 is typically oriented towards performing common tasks such as scanning. In contrast, devices such as laptops and pocket PCs include full-screen displays, QWERTY keyboards, trackball mice, speakers, microphones, PCMCIA (International Association of Personal Computers and Memory Cards) slots, and portable media. Often provides a number of different input / output means such as drives. These devices can perform a number of functions through the execution of various software applications such as word processing applications, spreadsheet applications, accounting applications, network browsers, and network message applications.
【0004】
In an exemplary digital transmission operation, a hard copy of a document can be presented to the scanner portion of the transmitter. After scanning, the transmitter converts the scanned image into a digital representation of the document, which is then stored in a bitmap data format or a data format such as Portable Document Format (PDF). E-mails allow you to attach a document in data format and send an e-mail (e-mail) from this transmitter. Emails can be sent to recipients on an interconnected network, in which the recipients either manually enter into the transmitter or a defined recipient email address list. Have a user-specified email address using. Similarly, documents can be scanned from transmitters and stored on workstation and corporate intranet servers, or in directories on the general Internet.
【0005】
Enterprises typically configure their corporate networks as one or more intranets to share their resources and information. The intranet is accessible only to members, employees, or other authorized people of the company or organization. Intranet websites refer to and take the place of any other website, but the firewalls surrounding the intranet keep unauthorized access away. The firewall examines each message in and out of the intranet and blocks messages that do not meet certain specified security standards.
【0006】
Network administrators within an organization typically utilize one or more device management applications to manage transmitters on the intranet or corporate intranet. As an example of such a transmitter management application, Hewlett Packard (HP) JetAdmin product and HP WEB JetAdmin product are used by network administrators to connect to a network on an intranet. Consider finding, installing, monitoring, and troubleshooting transmitters.
【0007】
Network administrators typically configure firewalls to filter management protocol packets, such as SNMP packets, or prevent such packets from entering or leaving the intranet or corporate intranet. Blocking management protocol packets in this way prevents unauthorized access and management of transmitters on the corporate intranet. Therefore, the transmitter is protected from unauthorized access from outside the intranet by one or more intranet firewalls.
【0008】
[Problems to be Solved by the Invention]
The transmitter may be a stand-alone device operating on the intranet, or it may be dedicated to a host computer on the intranet. When the user accesses this intranet, the user will be able to use any transmitter on the intranet. The intranet administrator may want to make some intranet users unavailable to some features of some transmitters on the intranet. An intranet firewall will not prevent intranet users from accessing and utilizing transmitters in this way. It would be beneficial to prevent unauthorized access by intranet users to transmitters on the intranet. It may also be important to limit the emails sent to them exclusively for businesses. Finally, it may be important to keep track of where the email is sent and what documents are on the corporate intranet or on disk drives outside the corporate intranet. As a result, there is a need for improved methods, equipment and programs that can provide such capabilities.
【0009】
[Means for solving problems]
The transmitting device receives the request from the user and sends the user message data to the request address of the request network resource on the network. The transmitter decides whether the requested transmission is prohibited. When it is determined from this determination that the request transmission is not prohibited, the user message data of the request network resource is sent to the request network address. When it is determined from this determination that the requested transmission is prohibited, a diagnosis is issued.
【0010】
The above and other features of the present invention will be further fully clarified from the claims described below and together. Alternatively, these features may be acquired by practicing the present invention, as described below.
【0011】
The various methods and devices of the invention can be more fully understood by reference to the following detailed description, with reference to the same components and features throughout, using the same reference numerals.
【0012】
BEST MODE FOR CARRYING OUT THE INVENTION
The methods, devices, and programs described herein relate to the installation and use of a local firewall security management system for transmitting devices. Preferably, the firewall operates inside a transmitter that interacts with the intranet. The intranet administrator can also install and maintain a firewall at the transmitter. Alternatively, the firewall is pre-installed, but may later be configured by an administrator with appropriate security rights.
【0013】
The firewall function provided in the transmitter can be configured to meet the requirements of the intranet administrator. Such a request may be intended to completely prohibit the transmission of a document from the transmitting device to the outside of the intranet. For example, a user may knowingly or inadvertently enter an incorrect unauthorized email (ie, email) address into a transmitter. However, due to the transmitter local firewall security management system, this incorrect address was taken by the transmitter into the transmitter and then sent from the transmitter to an unauthorized email address or network location. The transmission of a set of documents will cause a security breach.
【0014】
The need for security in the transmitting device may also be aimed at imposing individual restrictions on some users on access to the transmitting device and the actions that can be performed on the transmitting device. As an example, this firewall can be used for some transmission within an intranet, or to one or more email addresses in a separate Internet email address list, or to a specific uniform resource locator (URL). Can be provided to prohibit the transmission of. Further, the permission for this kind of transmission may be determined by the ID of the user of the transmitting device.
【0015】
Other features of the transmitter local firewall security management system, such as access control list (ACL) systems that limit the use of transmitters to some users or some classes of users, are being considered. When the transmitting device may have various functions that can be executed, a function control list (FCL) system that limits the use of the transmitting device to a part of the functions is considered. This system may or may not be determined by the user or one class of users. For example, the ability to scan a document at the highest resolution of a transmitter may be available only to some users. Color scanning, color transmission, and / or color printing may also be restricted based on the ACL / FCL system maintained at the transmitter by the local firewall security management system.
【0016】
One of the functions of the firewall installed in the transmitter is to allow the user of the transmitter to gain unauthorized access to the transmitter or to use the transmitter illegally, which would otherwise be permitted. Send message data to security personnel such as network administrators when attempted. For example, an authorized user of this transmitter may attempt to reconfigure the allowed usage of the transmitter, or otherwise change its usage. If the user does not have a sufficient access level recorded in the ACL / FCL system, the local firewall security management system determines that it has attempted to use the transmitter without proper user permission status. The local firewall security management system then coordinates the transmission of message data from the transmitter to a given security-related email address or other reporting mechanism. Preferably, the message data includes those representing the attempted unauthorized access or use. Transmitter security tracking and control can be configured within intranet management using the transmitter firewall security management system.
【0017】
An exemplary system for configuring a transmitter Figure 1 shows an example of a system environment 100 suitable for implementing a transmitter local firewall security management system for transmitters 102-1 to 102-N on an intranet 101. It is a block diagram which shows. Each transmitter 102-1 to 102-N has its own firewall / security management system 104-1 to 104-N. Transmitters 102-1 to 102-N are exemplified and discussed as digital transmitters, but these transmitters are also analog transmitters or a mixture of digital transmitters and analog transmitters. It should be understood that it may be.
【0018】
The intranet 101 can include its own firewall 107, which also provides access outside the intranet 101 to the host computer (s) 108 and transmitters 102-1 to 102-N. Limited to any resource on the intranet 101, including. The transmitters 102-1 to 102-N communicate with the interconnection network 106 through the communication path 105. A set of host computers (s) 108 interact with the interconnect network 106 both on and outside the intranet 101. The interconnect network 106 represents one or more communication links (either wired or wireless) capable of carrying data between the transmitter 102 and other network resources interacting with the interconnect network 106. ing. In some exemplary embodiments, the interconnect network 106 includes a local area network (LAN), a wide area network (WAN), an intranet, the Internet, or other similar networks. The transmitter (s) 102 is also typically coupled to the host computer (s) 108, either directly or through a network connection.
【0019】
In one embodiment of the invention, the system environment 100 considers local access to the transmitter 102-i via an input device (eg, a touch menu screen) on the transmitter 102-i. The user accesses the input device for the purpose of inputting a user identification name (user ID) and other instructions for the operation performed by the transmission device 102-i. In another embodiment of the invention, the host computer 108 inside the intranet 101 sends instructions for operations performed by transmitter 102-i.
【0020】
As can be seen in FIG. 1, the system 100 is used to manage an intranet 101 having transmitters 102-i to 102-N logically communicating through a communication path 105. The communication path 105 may be a local area network (LAN) or a wide area network (WAN). The firewall 107 for the intranet 101 specifically prevents unauthorized access to resources on the intranet 101 from users of the interconnect network 106 outside the intranet 101. Firewall 107 examines each message in and out of the intranet and blocks messages that do not meet certain specified security standards. In this embodiment, the firewall keeps SNMP messages out of the intranet 101. The firewall can also prevent configuration access to the transmitter 102-i. Firewall 107 is coupled to interconnect network 106.
【0021】
The transmitter 102-i may be a stand-alone device or may interact directly with the host computer 108. Transmitters include devices such as printers, scanners, copiers, fax machines, or multifunction peripheral (MFP) devices that combine two or more transmitters into a single device. Stand-alone equipment includes some transmitters that often function while isolated or isolated from other equipment. Therefore, transmitter 102 includes devices such as standard office copiers, digital network copiers, scanners, fax machines, etc., as shown in FIG.
【0022】
An exemplary Embodiment of an Instrument Firewall FIG. 3 shows in more detail an embodiment of System 100 of FIG. According to yet another aspect of the present invention, the transmitter 102 may be included in the multifunction peripheral (MFP) device 319. As the name implies, the MFP device 319 is configured to provide multiple functions. In this example, the functionality provided by the MFP device 319 includes the functionality provided by the transmitter 102 and the printer device 313. As a result, the user of transmitter 102 may also print out a hard copy of any relevant portion of the message data.
【0023】
In general, the host computer 108 can display a menu on which data is stored in the menu document 324 on a display device (not shown). The host computer 108 outputs the host data to the transmission device 102 by using the device driver 320, the server module 322, and the intranet module 324. The output from the host computer 108 to the transmitter 102 may be represented in a driver format suitable for the transmitter 102, such as a PCL or PostScript for the printer device 313. A preferred embodiment of the present invention utilizes the TCP / IP network protocol to interact with the transmitter 102.
【0024】
The peripheral device or transmitter 102 includes a controller 300 that processes data from the host computer 108. The controller 300 typically includes a data processing unit or CPU 302, volatile memory 304 (ie RAM), non-volatile memory 306 (eg ROM, flash). The transmitter 102 also includes a device engine 308 and an input device. Preferably, the input device is locally accessible at the transmitting device 102. By way of example, the input device may be a touch menu screen 310. The touch menu screen 310 serves as a local user interface for transmitter 102 by displaying a menu page and accepting user input based on selectable menu items displayed on the menu page. Useful. The touch menu screen 310 can be used to prompt for the input required to fill firewall 104-i on transmitter 102-i and display a menu page that receives that input. Preferably, this input includes a request for a particular function that is to be performed on the transmitting device 102-i, as well as an incoming email address on the network. By way of example, certain features requested by the user may be grayscale scans, color scans, or scans with a particular image resolution.
【0025】
The CPU 302 is operably coupled to a memory 306, a touch menu screen 310, a scanning mechanism 305, and at least one communication port that connects to the interconnect network 106. When the CPU 302 is included in the MFP device 319, the CPU 302 will also be operably coupled to, for example, the printer device 313. CPU 302 represents any hardware, firmware, and / or software that is configured to perform some functions related to the operation of transmitter 102 and, if applicable, MFP 319. Therefore, as will be appreciated by those skilled in the art, the CPU 302 may include dedicated logic and / or one or more processors configured, for example, by software instructions.
【0026】
Memory 306 represents at least any type of data storage mechanism accessible to CPU 302. Therefore, memory 306 may include, for example, some form of random access memory (RAM), some form of read-only memory (ROM), and / or other similar semiconductor data storage mechanisms. Memory 306 may also include a magnetic and / or optical data storage mechanism. The scanning mechanism 305 represents any optical scanner technique that can be used to generate the scanned object data when scanning an object. Such scanning techniques are well known. The resulting scanned object data is fed to CPU 302 and / or stored in memory 306. Controller 300 manages the functionality of the device by processing host data, controlling device engine 308, and responding to input from the touch menu screen 310. Controller 300 includes software 312 for device drivers that are stored in memory 306 and run on a processor such as CPU (s) 302. Memory 306 also includes server module 314. The server module contains software, firmware, or other logic for implementing a local firewall security management system on transmitter 102. This local firewall security management system contains one or more access control lists (ACLs) and feature control lists (FCLs). The ACL controls access to the transmitter 102, for example, by a user ID. The FCL stores the functions allowed in the transmitter 102. Such permissions may also be determined by the specific user ID contained in each of the ACLs. This firewall security management system also has packet filtering, logging, email addresses, and Wor.
【0027】
Server module 314 is also configured to supply menu document 316 to touch menu screen 310. Therefore, server module 314 is a local server in the sense that it is in the same transmitter 102 that supplies menu document 316. Menu document 316, which is decrypted by server module 314, is configured to display text and graphical information as menu pages on the touch menu screen 310.
【0028】
On the intranet 101 of FIG. 1, the host computer 108 can make a request to the transmitter 102-i. The request from the host computer 108 will preferably include a user ID or something else that identifies the user's characteristics on the host computer 108, and as mentioned above, the server of transmitter 102 as seen in FIG. Handled by the local firewall security management system in module 314.
【0029】
The graphical keys or buttons presented on the menu page displayed by the touch menu screen 310 provide selectable menu items described with textual information. Menu document 316, which drives the menu page, contains embedded script code associated with the graphical keys. When you press a graphical key on the touch menu screen 310 and select a menu item, an event occurs, which causes the "Virtual Machine" 318 to decrypt the script code associated with that selected graphical key. And then run. Therefore, virtual machine 318 may be a software module stored in memory 306, which runs on CPU (s) 302 and server module 314 of transmitter 102. Decodes and executes script code that contains code related to enabling the local firewall security management system in. This code is written in JavaScript code and is Java Virtual It can also be script code that is decrypted and executed on the Machine (JVM) 318. This script code can also be written in Chai Server code, which is decrypted and executed on the Chai Virtual Machine. This script code can also be written in other script code languages such as VBScript or Perl. However, this code can also be written in other software or machine languages, including (but not limited to) C ++ or C #. Alternatively, such algorithms are machine resident and may be programmed with any common embedded processor code.
【0030】
The script code associated with the selectable menu item (ie, graphical key or button) can be configured to perform the task of receiving a user ID and a request for a function performed on the transmitter 102. When such a receipt occurs, the script code associated with the selectable menu item will look up the relevant ACL and FCL information and compare that information. The script code executed on CPU 302 of the transmitter 102 can determine whether the requesting user is accessing and accepting the user's request.
【0031】
Host computer 108 includes processor 328, volatile memory 330 (ie, RAM), and non-volatile memory 332 (eg, ROM, hard disk, floppy disk, CD-ROM, etc.). The host computer 108 may be implemented as a general purpose computer such as a desktop personal computer, a laptop computer, a server, or the like. The host computer 108 implements one or more software-based device drivers 320 that are stored in non-volatile memory 332 and run on processor 328 to format the data appropriately (eg, PCL, PCL,). The formatted data may be output to the transmitter 102 as a postscript or the like).
【0032】
When an event occurs, the digital transmitter 102-i sends an e-mail message to a server such as a host computer 108 on or outside the intranet 101 to perform file transfer of a document or notification message. It is configured in. For example, one such event is to receive input from an unauthorized user ID, or otherwise an authorized user, with a request to perform an unauthorized function. In one embodiment, the notification message includes such specific user ID, requested function, and information that clearly identifies the digital transmitter for which the request was made. The digital transmitter can then deliver an e-mail message to the server for each digital transmitter 102-i for the purpose of storing unauthorized access logs.
【0033】
An exemplary embodiment of the transmit device firewall method The CPU 302 is configured to perform the above-mentioned processing. As a further example, a flow diagram is shown in FIG. 4 to illustrate some exemplary functions that can be performed using the CPU 302 and other resources within the transmitter 102. Process 400 is provided herein.
【0034】
In step 402, the digital transmitter 102 activates a function performed by its local firewall security management system. In step 404A, a request to activate this function can be made by the user by directly accessing the digital transmitter 102, such as by inputting on the touch menu screen 310. With the touch menu screen 310, you can enter input data such as user ID, recipient (s) email address information, email subject, email text or body, etc. , Can be prompted to the user. Next, the user inputs the user ID, the recipient address data to which the fax of the set of documents is to be sent, and the like on the touch menu screen 310. This recipient address data may be, for example, an email address, or a destination website, local file folder, or other similar location. In step 404B, when this function is activated by the host computer 108 on the intranet 101, the request sent from the host computer 108 to the digital transmitter 102 will also include the user ID.
【0035】
For either of the functions invoked in step 404A or 404B, the ACL associated with the digital transmitter, in particular the ACL for the input user ID, is obtained in step 406. In step 408, the user ID of this request is compared with the ACL. If this user ID is allowed in the ACL, another comparison is made between the request function and the FCL in step 408, and the allowed user ID is the specific request issued to the digital transmitter 102. It is also determined whether or not the user has privileges.
【0036】
If neither the user ID nor the requesting function is allowed by the ACL / FCL comparison in step 408, the digital transmitter does not perform the requesting function and can display the diagnosis to the requesting user. In step 410, message data is generated by the digital transmitter 102. In step 410, this message data is addressed to a security email address, such as a user ID or a touch-sensitive menu screen 310 or other function requested of a digital transmitter. Includes input received from the user on the input device. A similar email is sent when an unauthorized request is received from the host computer 108 on the intranet 101. Process 400 then returns to step 402 to accept additional requests from additional users.
【0037】
If the ACL and FCL authenticate both the user ID and the requesting function performed by the transmitter 102, in step 412a the user can enter the desired destination for this document. This desired destination may consist of an email address, distribution list, website address, file directory, or other similar location data. Then, in step 412b, these addresses are checked against the firewall filter to determine whether the document can be sent or forwarded to their respective destination addresses. The local firewall security management system blocks access to specific addresses so that documents can still be passed to unblocked addresses, or blocks access to all addresses. It can be configured to return to step 402 as described above. If the user ID, feature request, and destination filtering tests all pass, in step 412c, the user touches the prompt to put a set of documents in the sheet feeder device tied to the digital transmitter 102. Display on the formula menu screen 310. The sheet feeder device then physically sends this set of documents to the scanning mechanism 305, one by one. When this set of documents is scanned, the CPU 302 produces a bitmap or other output that digitally represents the scanned document. For example, the scanned object data may be included in the email message data as an attachment. The scanned object data includes Portable Document Format (PDF) format data, tagged image file format (TIFF) format data, and Joint Photographic Experts.
【0038】
In step 414, the message data is addressed by the recipient address data received from the user. This message data may include, for example, email message data from a user of a digital transmitter to a user (s) of a remote device (s). As used herein, the email message will somehow include the scanned object data.
【0039】
According to yet another aspect of the present invention, the CPU 302 may be configured to store at least one recipient address data list in memory 306. This recipient address data list may include multiple recipient addresses associated with multiple potential message data recipients. The CPU 302 may also be configured to selectively modify this recipient address data list based on the recipient address data received from the digital transmitter 102.
【0040】
Thus, although some preferred embodiments of the various methods and devices of the present invention have been illustrated in the accompanying drawings and described in the detailed description above, the present invention is an exemplary embodiment disclosed. Not limited to the examples, provided that a number of relocations, modifications and substitutions are possible without departing from the scope of the invention described and defined in the claims below. I want to be understood.
【0041】
Examples of embodiments of the present invention are listed below. [Phase 1] A step of receiving a request from a user in a transmitting device capable of sending data on the network in order to send user message data to a request network address of a request network resource on the network. When the transmission device determines whether or not the request transmission is prohibited and the determination determines that the request transmission is not prohibited, the user message is sent to the request network address of the request network resource. -Instructs the computer to perform a method including a step of sending data and a step of issuing a diagnosis when the determination determines that the requested transmission is prohibited, at the time of execution on the processor. A computer-readable medium with computer-executable instructions. [Embodiment 2] The steps received by the transmitting device include a step of optically scanning at least one object by the transmitting device to form the corresponding scanned object data, and the user message data. The computer-readable medium according to embodiment 1, further comprising the step of forming the scanned object data in the computer. [Embodiment 3] The computer-readable medium according to embodiment 1, wherein the step of issuing a diagnosis includes a step of sending diagnostic message data to a diagnostic network address of a network resource on the network that is not the requested network address. [Phase 4] In a transmitting device on a network, the step of receiving a request from a user further includes a step of accepting a user input including a request function performed by the transmitting device through the user interface of the transmitting device. Further, the step of determining whether or not the request transmission is prohibited includes the step of searching the function access list from the memory in the transmission device, the request function included in the diagnostic message data, and the FAL. Steps to compare and more The computer-readable medium according to Embodiment 3, which comprises. [Phase 5] A transmitting device capable of sending network messages over a network and having an input device and a processor that executes a computer-executable instruction according to the first embodiment. [Phase 6] A device capable of sending message data, which optically scans a memory containing an access control list (ACL) and at least one object to obtain the corresponding scanned object data. A scanning mechanism that can be configured to form, an input device to the memory that receives user input including a user ID, and an operably coupled to the memory configured to compare the user ID with the ACL. And when the comparison is positive, the user message using the first network address to form the scanned object data in the user message data. The user message data can be configured to initiate an action to send the user message data to the first network address via at least one network interface to direct the data, and the comparison is negative. A device comprising at least one network interface operably coupled to said logic, which in some cases can be configured to issue a diagnosis. [Phase 7] The multifunctional peripheral device further includes a printer device operably coupled to the logic, which selects at least one document corresponding to the user message data for the printer device. The device according to embodiment 6, which is further configured to be printed in a functional manner and is incorporated in the multifunctional peripheral device. [Embodiment 8] The user input further includes user-provided data selected from a group of data consisting of the first network address, subject data, and body data, and the first network address is the user. From email address, distribution list, website address, file directory 4. The logic described in Embodiment 6, selected from the group consisting of, further configured to form the user message data by combining the scanned object data with the user-provided data. apparatus. [Embodiment 9] The apparatus according to embodiment 6, wherein the step of issuing a diagnosis further includes a step of invoking an operation of sending diagnostic message data to a second network address via the at least one network interface. [Phase 10] A device capable of sending message data that optically scans a memory containing at least one of an access control list (ACL) and a functional access list (FAL) and at least one object. A scanning mechanism that can be configured to form the corresponding scanned object data and the user's user ID, requesting functions performed by the device, user email address, distribution list, website address, file. To compare an input device to a memory that receives a user input containing at least one request network address, selected from a group of directories, with the user input and at least one of the ACL and the FAL. The request network to form the configured logic operably coupled to the memory and, when the comparison is positive, the scanned object data in the user message data. The address can be configured to trigger an action to send the user message data to the request network address of the request network resource, just as it would address the user message data. When the comparison is negative, it initiates an operation to send diagnostic message data containing at least one user ID, request function, request network address, to the network address of a network resource that is not the request network address. Operabled to the above logic, which can be configured to
[Simple explanation of drawings]
FIG. 1 is a block diagram showing a computational and communication environment having these transmitters on an intranet and in a system environment suitable for providing local access to a plurality of transmitters.
FIG. 2 shows various transmitters that provide local access and input.
FIG. 3 is a block diagram showing a transmitter that interacts with a host computer in a system as shown in FIG.
FIG. 4 is a flow diagram showing, for example, a method used in a computational / communication environment having a transmitter in the system, as in the case of FIG. 1, according to some exemplary embodiments of the present invention.
[Explanation of symbols]
102 Transmitter 106 Network 302 Processor, Logic 305 Scanning Mechanism 306 Memory 310 Input Device, Touch Menu Screen 319 Multifunctional Peripheral 410 Diagnostic 412a Request Network Address
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2011113355A | Cited by | Japan | Search report |
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 151670 | United States of America | – | |
| 15167002 | United States of America | A | |
| 15167002 | United States of America | A | |
| 2002151670 | – | – | – |
| US20020151670 | – | – | – |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written withdrawal of applicationA761 | A761 | |
| Notification of resignation of power of attorneyRD04 | RD04 | |
| Written request for application examinationA621 | A621 | |
| Notification of acceptance of power of attorneyRD02 | RD02 |
Numbers
- Publication
- 2004046811
- Publication, DOCDB
- 2004046811
- Publication, EPODOC
- JP2004046811
- Application
- 138746
- Application, DOCDB
- 2003138746
- Application, EPODOC
- JP20030138746
Titles2
- Japanese
- 送信装置ファイアウォール
- English
- Transmitter firewall
Classification
- CPC, 2
- H04L63/102
- H04L63/101
- IPC, 7
- G06F13 00
- G06F21 00
- G06F21 55
- G06F21 62
- H04L29 06
- H04N1 00
- H04N1 32