Interface device with network isolation
Abstract
This record has no abstract on file.
Term
Term ended
Expired 14 May 2022, 4.4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
21 claims: 5 independent, 16 dependent
- 1ネットワーク対応可能な機器とネットワークとを接続するためのインターフェース装置であって、 前記ネットワークに接続可能な第1のポートと、前記ネットワーク対応可能な機器に接続可能な第2のポートと、ネットワーク機能を有する回路基板に接続可能な第3のポートとを含む複数のポートを有し、ネットワーク送信を 前記複数のポートのうちの 一のポートから受信して他のすべてのポートへと中継するよう構成されたハブと、 前記ハブにより中継されるネットワーク送信から前記第1のポートを遮断する ことが 可能な遮断スイッチと、 前記遮断スイッチの操作のための制御信号を受け取る、前記遮断スイッチに対するインターフェースとを備え、 前記回路基板は前記制御信号を供給するための制御機能を有 し、 前記回路基板は、前記第1のポートが前記遮断スイッチにより遮断された後、他のポートに対してデータを送信する ことを特徴とするインターフェース装置。
- 2前記インターフェースは前記第3のポートの一部であることを特徴とする請求項1に記載のインターフェース装置。
- 3前記インターフェースは前記第3のポートとは別個のものであることを特徴とする請求項1に記載のインターフェース装置。
- 4前記回路基板を更に備え、前記回路基板のネットワーク機能により前記ネットワーク対応可能な機器の拡張機能が提供されることを特徴とする請求項1に記載のインターフェース装置。
- 5前記ネットワーク対応可能な機器はプリンタを備え、前記拡張機能は保護印刷のための機能であることを特徴とする請求項4に記載のインターフェース装置。
- 6前記回路基板は、前記ネットワーク対応可能な機器のアドレスと同じアドレスにおいてネットワーク送信の受信待ちをすることを特徴とする請求項4に記載のインターフェース装置。
- 7前記制御機能により、前記アドレスのポート番号に基づいた制御信号が供給されることを特徴とする請求項6に記載のインターフェース装置。
- 8前記制御機能により、前記拡張機能に基づいた制御信号が供給されることを特徴とする請求項6に記載のインターフェース装置。
- 9前記制御機能により、前記回路基板の拡張機能に基づいた制御信号が供給されることを特徴とする請求項4に記載のインターフェース装置。
- 10ハブと回路基板とを有するインターフェース装置を用いてネットワーク対応可能な機器からネットワークを遮断するための方法であって、前記ハブは、前記ネットワークに接続可能な第1のポートと、前記ネットワーク対応可能な機器に接続可能な第2のポートと、ネットワーク機能を有する前記回路基板に接続可能な第3のポートとを含む複数のポートを有し、更に、前記ハブにより中継されるネットワーク送信から前記第1のポートを遮断するために操作できる制御可能な遮断スイッチを有しており、前記方法は、 ネットワーク送信が前記第1のポートへ中継される通過モードに前記遮断スイッチを維持する工程と、 前記ネットワーク対応可能な記器宛のジョブを、前記ネットワーク対応可能な機器が対応しないポート番号において受信する工程と、 前記回路基板上においてネットワーク機能を実行し、前記ネットワーク対応可能な機器宛のネットワーク送信に対応する工程と、 前記ハブが前記第1のポートに対してネットワーク 送信 を中継しない迂回モードに前記遮断スイッチを設定する設定工程と、 前記設定工程により前記迂回モードに設定された後、 前記ネットワーク対応可能な機器が受信待ちするポート上において、前記回路基板から前記ネットワーク対応可能な機器に対してネットワーク送信を行う工程と、 前記ネットワーク対応可能な機器に対するネットワーク送信の完了後、前記遮断スイッチを前記通過モードに切り替える工程とを有することを特徴とする方法。
- 11前記ネットワーク対応可能な機器はプリンタであり、前記回路基板のネットワーク機能により前記プリンタの拡張機能が提供されることを特徴とする請求項10に記載の方法。
- 12前記設定工程において、前記遮断スイッチは、前記拡張機能に基づいて通過モードにセットされることを特徴とする請求項11に記載の方法。
- 13前記拡張機能により保護印刷が実行されることを特徴とする請求項11に記載の方法。
- 14前記ネットワーク対応可能な機器は特定のポート番号上のネットワーク送信を受信待ちすることを特徴とする請求項10に記載の方法。
- 15前記設定工程において、前記遮断スイッチは、前記特定のポート番号上のネットワーク送信に応じて通過モードにセットされることを特徴とする請求項14に記載の方法。
- 16ネットワークに 接続可能な 装置であって、 前記ネットワークに接続可能な第1のポートと、機能を有する装置に接続可能な第2のポートとを含む複数のポートであって、データを 複数のポートのうちの一のポートから 他のポートへ送信するよう構成された複数のポートと、 前記ネットワークに接続可能な第1のポートを、操作のための命令に応じて、一のポート からの データの送信から遮断すべく操作可能な遮断スイッチとを備え、 前記 機能を有する 装置は、前記遮断スイッチの操作のための命令を供給する機能を有 し、 前記機能を有する装置は、前記ネットワークに接続可能な第1のポートが前記遮断スイッチにより遮断された後、他のポートに対してデータを送信する ことを特徴とする装置。
- 17前記機能を有する装置は、拡張機能を有する回路基板であることを特徴とする請求項16に記載の装置。
- 18前記機能を有する装置は、プリンタ宛の印刷ジョブを受信し、前記機能を実行して前記遮断スイッチの操作のための命令を供給した後で、前記印刷ジョブを前記プリンタに送信することを特徴とする請求項16に記載の装置。
- 19前記機能を有する装置は、保護印刷ジョブを解読する機能を有することを特徴とする請求項18に記載の装置。
- 20複数のポートを有する装置を用いてネットワークを遮断するための方法であって、前記複数のポートは、ネットワークに接続可能な第1のポートと、機能を有する装置に接続可能な第2のポートとを含み、データを 前記複数のポートのうちの一のポートから 他のポートへ送信するよう構成されており、前記方法は、 前記ネットワークからデータを受信し、 前記機能を有する装置において、その機能を実行し、 一のポート からの データの送信から前記ネットワークに接続可能な 前記第1の ポートを遮断し、 前記ネットワークに接続可能な 前記第1の ポートを遮断した後、前記機能を有する装置から前記複数のポートの少なくとも一に対してデータを送信することを特徴とする方法。
- 21ネットワークに接続可能な装置であって、 前記ネットワークに接続可能な第1のポートと、機能を有する装置に接続可能な第2のポートとを含む複数のポートであって、データを複数のポートのうちの一のポートから他のポートへ送信するよう構成された複数のポートと、 命令に従って、前記ネットワークに接続可能な第1のポートを一のポートからのデータの送信から遮断すべく操作可能な遮断手段とを備え、 前記機能を有する装置は、前記ネットワークに接続可能な第1のポートを一のポートからのデータの送信から遮断するよう前記遮断手段に命令する機能を有し、 前記機能を有する装置は、前記ネットワークに接続可能な第1のポートが前記遮断手段により遮断された後、他のポートに対してデータを送信することを特徴とする装置。
Independent claims21
34 paragraphs, as filed
Background of the Invention [Technical field to which the invention belongs] The present invention relates to an interface device for connecting a network-compatible device and a network, and particularly controls to cut off the network from the network-compatible device. With respect to possible such interface devices.
[0002] [Conventional Technology] One of the characteristics desired for a network-compatible device is the possibility of upgrading the device to provide improved performance, extended functions, and new functions. For example, when connecting to a previously placed device that inherits the legacy of the past (legacy device), such as a network printer, it provides extensions (eg, printing grayscale images) that were not originally provided by the printer. Or, it would be nice to be able to upgrade the functionality of the printer to improve performance (eg, a more efficient printing engine).
[0003] Traditionally, such upgrades have been made through reprogramming of firmware included in legacy equipment. Current technology allows reprogramming of equipment, and also includes technology for reprogramming network equipment directly over the network.
[0004] However, the outcome of the upgrade is severely constrained by the processing power of legacy equipment. That is, there are upgrades that require more processing power and memory, or more electronic circuits than those originally provided for equipment that inherits its legacy. In such cases, some devices cannot be upgraded.
[0005] In an effort to solve such a situation, it has been considered to provide an extension function and an upgrade in an interface device intervening between a network-compatible device and a network. Figures 1A and 1B show the situation of being connected to a network-compatible printer. As shown in FIG. 1A, the legacy printer 10 connected to network 11 is subject to processing power and electronic circuit constraints that make upgrade impossible. As shown in FIG. 1B, the interface device 12 is interposed between the network 11 and the printer 10. The interface device contains the requested upgrade content, functions to intercept the network transmission content to and from the printer 10, and processes the transmission content according to the upgraded function. Retransmit the transmission to printer 10 in a format understood by the legacy printer. This interface device allows the functionality of the printer 10 to be extended and upgraded, even if the printer 10 is constrained to not be able to provide the functionality of the printer itself.
[0006] FIG. 2 shows the interface device 12 in more detail. As shown in FIG. 2, the interface device 12 includes a hub 14 and a circuit board 15 including the extended functions required for the printer 10 that inherits the legacy of the past. The hub 14 includes a first port A to which the network 11 is connected, a port B to which the printer 10 is connected, and a port C to which the circuit board is connected. According to the standard functionality of the hub, transmissions received on any one port are relayed to all other ports, as indicated by the double-headed arrow in Figure 2.
[0007] The standard function of a conventional hub causes one problem because the network transmission received from one port is relayed to all other ports. In particular, there is an undesired situation in which the transmission intended from the circuit board 15 on port C to the printer 10 is also relayed to network 11 on port A. One such situation is related to the case where the extension provided by the substrate 15 is a protective printing function. In this case, the board receives the encrypted print job from the network, decrypts the print job, and sends the decrypted "plaintext" print job to the printer 10. When such a transmission that was intended to be directed only to printer 10 is also relayed to network 11 on port A, the "plaintext" of the potentially confidential print job that was intended to be directed only to printer 10. The version will be received on all networks.
[0008] [Outline of the Invention] Therefore, one object of the present invention is to provide an interface device between a network-compatible device and a network that can block the network from communication.
[0009] According to one aspect, the interface device includes multiple ports, which are configured to relay work transmissions received on one port to all other ports. ing. A cutoff switch is provided for one of these ports. The cutoff switch is controllable and can be operated to cut off the port from network transmissions relayed by the hub. The cutoff switch is controlled by a circuit board connected to the hub. The circuit board preferably includes extensions for network-enabled equipment.
[0010] Since the hub includes a cutoff switch that can be controlled to cut off the network from network transmissions relayed by the hub, the network does not receive the transmission content that would otherwise be the case. For example, in a situation where a circuit board provides a protective printing function for a legacy printer, the circuit board has a cutoff switch in a "pass" mode in which the data transmitted by that board is relayed to all ports of the hub. Switch between "bypass" mode, where the network is blocked. During "pass" mode, if the circuit board detects a protected print job, it decrypts the protected print job and then switches the cutoff switch to "bypass" mode to transfer the decrypted plaintext print job to the printer. Send. Since the network is blocked during bypass mode, private communication is established between the board and the printer, thus ensuring that potentially sensitive information is not broadcast across the network.
[0011] The cutoff switch can also be controlled to cut off the network in situations where it is only desired to reduce network traffic throughout the network. This allows the cutoff switch to switch to "bypass" mode to reduce network traffic on the network, even in situations where the board sends unprotected information to the printer.
[0012] According to a particularly preferred aspect, circuit boards and network-enabled devices can share a common network address. However, each of them listens on the port numbered at its common address. For example, an Internet Protocol (IP) address is given in the form xxx.xxx.xxx.xxx:port. Where xxx.xxx.xxx.xxx is the IP address and port is the port number. In such cases, the circuit board and network-enabled devices will share a common IP address, but will wait for transmission at different port numbers. The circuit board switches the cutoff switch between pass mode and bypass mode based on whether the network transmission is received at a predetermined port number.
[0013] This abstract has been prepared so that the essence of the present invention can be immediately understood. A more complete understanding of the present invention can be obtained by reference to the detailed description of the preferred embodiments that follow, along with the accompanying drawings.
[Embodiments of the Invention] FIG. 3 is a detailed view of the first embodiment of the present invention. In FIG. 3, the interface device 120 connects between the network 110 and a network-enabled device such as the printer 100. As shown in FIG. 3, the interface device 120 includes a hub unit 140 and a circuit board unit 150. Hub 140 has a plurality of ports including a first port A connected to the network 110, a second port B connected to the printer 100, and a third port C connected to the circuit board 150. .. Hub 140 is configured to relay network transmissions received on any one port to all other ports, as represented by the double-headed arrow in FIG. Hub 140 further includes a cutoff switch 141 that controlally cuts off port A from relayed transmissions under the control of a control signal received by hub 140 at interface 142. The break switch 141 is preferably implemented with an electrical latch.
[0015] The circuit board 150 includes an electronic circuit, a microprocessor, and a memory in order to realize at least two functional blocks, that is, an extension function 151 and a control function 152. Extension 151 relates to the extension of functions existing on network-enabled devices. In the present embodiment, since the network-compatible device is composed of the printer 100, the extension function 151 is related to the extension function of the printer, and may include an extension function for achieving protective printing as an example. obtain. Other examples of extensions include access control and job accounting for equipment, remote maintenance, JINI enablement, Internet printing on IPP, and directory enablement.
[0016] The control function 151 operates in cooperation with the extension function 151 so as to supply a control signal for operating the cutoff switch 141.
As shown in FIG. 3, the hub 140 and the circuit board 150 are housed in a common housing. However, another option is possible, the hub 140 can be physically separated from the circuit board 150, or even separable.
[0018] Further, although interface 142 is shown as a separate interface from port C, it is also possible to physically couple interface 142 with electrical terminals within port C. In such cases, the interface is provided through the detection of a special purpose signal transmitted from the circuit board 150 on the hub 140. Although 140 is represented as a hub, other configurations are possible, and the term "hub" operates in such configurations, for example, in broadcast or mirror mode (also known as "indiscriminate" mode). It is considered to include all switches.
[0019] In this embodiment in which the extension 151 relates to a protective printing function for the printer 100, the circuit board 150 is configured to wait for reception at the same network address 154 as the network address 104 of the printer 100. .. However, the circuit board 150 waits for reception on a port numbered differently from that of the printer 100, and in particular, waits for reception on port 631, which is commonly designated as the port address for protected print jobs. do. The circuit board 150 does nothing until the network transmission on port 631 is received, and the control function 152 keeps the cutoff switch 141 in "pass" mode. "Pass" mode is the normal setting for hub 140, and data received on any one port is relayed to all other ports, including port A, which is connected to network 110. After receiving the network transmission on port 631 and recognizing the network transmission as a protected print job, the circuit board 150 executes the extension function of block 151 to decode the print job and executes the control function of block 152. Then switch the cutoff switch 141 to "bypass" mode. In "bypass" mode, hub 140 operates to relay transmissions received on one port to all other ports except port A, which is connected to network 110.
As a result, in "bypass" mode, network 110 is blocked from communication on all other ports on hub 140. Then, while the break switch 141 is maintained in "bypass" mode, the extension function 151 of the circuit board 150 relays the decrypted and plaintext print job to port C, which hub 140 relays to port B. Is sent to the printer 100 via the transmission of.
[0021] The present embodiment is based on switching between a "pass" mode and a "bypass" mode as soon as a network transmission on a particular port is received, but other configurations are also possible. Switching can also be controlled based on the functionality provided by the circuit board 150. For example, if the extension 151 enhances the existing functionality of the printer 101 (eg job accounting), the printer and the board 150 will both listen at the same address. The switching between modes is then controlled as needed by the extension. For example, in order to enable transmission of job accounting information from the board 150 to the printer 101 while the network 110 is blocked, the mode is switched to the "bypass" mode at the end of receiving the print job.
[0022] FIG. 4 shows in more detail the operation of the embodiment of FIG. In steps S401 and S402, the control function 152 sets the cutoff switch 141 to pass mode, and the extension function 151 waits for the reception of network traffic destined for the printer 100. The cutoff switch 141 remains in pass mode until traffic destined for the printer is received, and network traffic received on any port on hub 140 is relayed to all other ports. Upon receiving network traffic destined for printer 100 (step S403), circuit board 150 determines if network traffic was received on protection port 631 (step S404). If network traffic is not received on the protected port, the circuit board 150 does nothing and keeps the cutoff switch 141 in pass mode. As shown in step S405, the network traffic was destined for printer 100 on the unprotected port, so the printer itself will respond.
[0023] On the other hand, if network traffic destined for the printer 100 is received on the protection port 631, the circuit board 150 responds as shown in steps S406 through S409. Because the printer does not implement the function for protective printing and is implemented on the circuit board 150, the printer 100 does not even wait for reception on the protective port 631 and therefore responds to such network traffic. It should be noted that it does not.
[0024] First, as shown in step S406, the circuit board 150 executes the extension function in the block 151 to decode the protective print job. The control function 152 is then executed to generate a control signal that switches the cutoff switch 141 to bypass mode. In bypass mode, network 110 is blocked from receiving what is received by hub 140 and transmitted to its port. While the cutoff switch 141 is in bypass mode, the circuit board 150 sends the decrypted print job to the printer 100 on the unprotected port (step S408). After the decrypted print job is sent to the printer, the control function 152 is executed to control the control signal that switches the cutoff switch 141 to pass mode. The flow then returns to step S402, where board 150 waits for network traffic destined for printer 100.
[0025] As described above in connection with FIG. 4, another alternative operation, such as control under extension 151, is between pass mode and bypass mode on a different basis than the reception of network transmissions on port 631. You can also control the switching of.
[0026] FIGS. 5 and 6 are diagrams showing the second and third embodiments, respectively. One difference between the embodiment shown in FIG. 5 and the embodiment shown in FIG. 3 is that the embodiment shown in FIG. 5 allows access to a network-compatible device (here, a printer 200) from a plurality of different networks 211 and 212. That is. As a result, the hub 240 includes a plurality of ports connected to the network and a cutoff switch 241 that operates to cut off all of these ports in response to a common control signal received from the control function 252.
[0027] One of the differences between the embodiment shown in FIG. 6 and the embodiment shown in FIG. 5 lies in the provision of a plurality of machines (here, printers 301 and 302) capable of supporting different networks. In this embodiment, for network traffic destined for any one of the connected printers, the circuit board 350 waits for reception at addresses 354 and 355 and responds as described above to the protective port. If the network traffic above is destined for any one of the addresses 304 and 305 of printer 301 or 302, it blocks networks 311 and 312.
The present invention has been described with respect to embodiments for a particular description. The present invention is not limited to the above-described embodiments, and various modifications and modifications can be made by a person having ordinary technology belonging to the technical field of the present invention without departing from the spirit and scope of the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS [FIG. 1A] FIG. 1A is a diagram illustrating a conventional network configuration.
FIG. 1B is a diagram illustrating a conventional network configuration.
FIG. 2 is a detailed view of the interface device shown in FIG. 1B.
FIG. 3 is a diagram illustrating a first embodiment of the present invention.
FIG. 4 is a flow chart illustrating the operation of the first embodiment.
[Fig. 5] and [Fig. 6] are diagrams for explaining other embodiments.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN103631180A | Cited by | China | Search report |
| JP08107504A | Cites | Japan | – |
| JP11167537A | Cites | Japan | – |
| JP06037752A | Cites | Japan | – |
| JP2000172597A | Cites | Japan | – |
10 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 09853608 | United States of America | – | |
| 85360801 | United States of America | A | |
| 2001853608 | – | – | – |
| US20010853608 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2002169985A1 | United States of America | A1 | |
| EP1262865A2 | European Patent Office (EPO) | A2 | |
| CN1385993A | China | A | |
| JP2003058289A | Japan | A | |
| JP3689682B2This record | Japan | B2 | |
| US2006013249A1 | United States of America | A1 | |
| US7016358B2 | United States of America | B2 | |
| CN1270495C | China | C | |
| EP1262865A3 | European Patent Office (EPO) | A3 | |
| US7626992B2 | United States of America | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 3689682
- Publication, DOCDB
- 3689682
- Publication, EPODOC
- JP3689682B
- Application
- 138457
- Application, DOCDB
- 2002138457
- Application, EPODOC
- JP20020138457
Titles2
- Japanese
- ネットワークから遮断できるインターフェース装置
- English
- Interface device that can be cut off from the network
Classification
- CPC, 6
- H04L63/0428
- G06F3/1204
- G06F3/1222
- G06F3/1236
- G06F3/1238
- G06F3/1285
- IPC, 4
- G06F3 00
- G06F3 12
- H04L29 06
- H04L29 10