CN100541414C - Data managing method and device - Google Patents

Data managing method and device Download PDF

Info

Publication number
CN100541414C
CN100541414C CNB200610100112XA CN200610100112A CN100541414C CN 100541414 C CN100541414 C CN 100541414C CN B200610100112X A CNB200610100112X A CN B200610100112XA CN 200610100112 A CN200610100112 A CN 200610100112A CN 100541414 C CN100541414 C CN 100541414C
Authority
CN
China
Prior art keywords
positional information
print data
data
information
authentication secret
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CNB200610100112XA
Other languages
Chinese (zh)
Other versions
CN1892581A (en
Inventor
吴周炫
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Samsung Electronics Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Samsung Electronics Co Ltd filed Critical Samsung Electronics Co Ltd
Publication of CN1892581A publication Critical patent/CN1892581A/en
Application granted granted Critical
Publication of CN100541414C publication Critical patent/CN100541414C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer

Abstract

The method of the data that comprise in a kind of management document is provided, has comprised: extracted the positional information that comprises in the print data file; Determine between the positional information of the positional information of being extracted and input, whether have identical positional information; And if determine to exist identical positional information, then analyze the print data that comprises in the print data file.The method of the data that comprise in a kind of management document is provided, has comprised: come extract location information by reading document; Determine between the positional information of the positional information of being extracted and input, whether have identical positional information; And if determine to exist identical positional information, then duplicate the information that comprises in the document.

Description

Data managing method and device
Technical field
The present invention relates to data management.More specifically, the present invention relates to a kind of data managing method and device, be used for by only between the positional information of the positional information of extracting from file or document or document and input, existing same position information just to allow to know data that file or document comprises to prevent the illegal outflow of data.
Background technology
Traditional data administrator is created print data file by using cut-and-dried authentication secret encrypted print data.Here, print data can be document data or view data.
Because the print data file that the traditional data management devices is created is encrypted, therefore expectation knows that the third party of print data content must decipher this print data file.In order to decipher this print data file, the third party must know the authentication secret that is used to encrypt.
Unfortunately, if the authentication secret that is used to encrypt is disclosed, then anyone can know the print data content from traditional data administrator, therefore, when when home is removed print data file, can not guarantee the security of print data content, the illegal outflow of print data also is possible.In addition, traditional data administrator did not allow the user to know the content of print data before the deciphering print data file.
By authorization information being inserted print data and being printed the print data of inserting authorization information, can create confidential documents.When a certain document comprised authorization information, authorization information represented to should be noted that safety when removing this a certain document from home.
Authorization information can be inserted into print data by the bar code that adds watermark or show as on the document.Yet authorization information only represents when should be noted that safety when home is removed confidential documents, therefore, unrestrictedly can duplicate the confidential documents that comprises authorization information Anywhere.
Therefore, based on the traditional data management devices, owing to can duplicate confidential documents in the undesirable any position of user of creating confidential documents, therefore when from home migration confidential documents, can not guarantee security, and the document of maintaining secrecy may be easy to illegally remove and duplicate.
Summary of the invention
Embodiments of the invention provide a kind of data managing method, and it is by only existing same position information to allow just to know that the data that comprise the file or document prevent the illegal outflow of data between the positional information of positional information of extracting from file or document and input.
The invention provides a kind of data administrator, it is by only existing same position information to allow just to know that the data that comprise the file or document prevent the illegal outflow of data between the positional information of positional information of extracting from file or document and input.
Embodiments of the invention provide a kind of computer readable recording medium storing program for performing that comprises computer program, are used for by only existing same position information just to allow between the positional information of positional information of extracting from file or document and input to know data that file or document comprises to prevent the illegal outflow of data.
According to an aspect of the present invention, provide a kind of data managing method, having comprised: (a) extracted the positional information that comprises in the print data file; (b) determine between the positional information of the positional information of being extracted and acquisition, whether have identical positional information; If (c) determine to exist identical positional information, then analyze the print data that comprises in the print data file.
The positional information of being extracted can be the positional information of position that can form the image of this print data, and the positional information that is obtained can be the positional information of the position of executable operations (c).
Described method can also comprise: the image that (d) forms print data.Described method can also comprise: if (e) determine not have identical positional information, then notify the user can not analyze print data.
Operation (c) can comprise: if (c1) determine to exist identical positional information, then decipher the private data that comprises in the print data file; (c2) analysis is as the print data of decrypted result, and wherein private data is the print data of encrypting.
In operation (a), carry out extraction by the positional information that deciphering comprises in the print data file, and the positional information that comprises in can the encrypted print data file.
If print data that comprises in the print data file and positional information both are encrypted, then in operation (a), by using the positional information that comprises in first authentication secret deciphering print data file, can carry out extraction, and the positional information of using first authentication secret to comprise in can the encrypted print data file, in operation (c), if determine to exist identical positional information, then use second authentication secret to decipher private data, and the print data that private data is to use second authentication secret to encrypt, second authentication secret can be different from first authentication secret.In print data file, can comprise metadata.Metadata is the data that comprise about the information of print data.
According to a further aspect in the invention, provide a kind of data managing method, having comprised: the positional information that (a) produces the position of the image that can form print data; (b) insert print data and create print data file by the positional information that will be produced.
Can in operation (a), produce private data and positional information, in operation (b), insert the private data that produces and to create print data file, and private data can be the result who obtains by the encrypted print data by the positional information that will be produced.
Operation (a) can also comprise encrypted location information, and in operation (b), the positional information of encryption can be inserted into private data.
In operation (a), the positional information of generation can use first authentication secret to encrypt, and print data can use second authentication secret to encrypt, and first authentication secret can be different with second authentication secret.
Operation (b) can comprise: (b1) positional information that generates is inserted the private data that is generated; (b2) metadata is inserted the result.Metadata is the data that comprise about the information of print data.
According to a further aspect in the invention, provide a kind of data managing method, having comprised: come extract location information by reading document; Whether there is identical positional information between the positional information of definite positional information of being extracted and acquisition; If with determine to exist identical positional information, then duplicate the information that comprises in the document.
According to a further aspect in the invention, provide a kind of data managing method, having comprised: positional information is inserted print data; Inserted the print data of positional information with printing.
According to a further aspect in the invention, provide a kind of data administrator, having comprised: the positional information extraction apparatus is used for extracting the positional information that print data file comprises; Detector is used to determine whether have identical positional information between the positional information of the positional information of being extracted and acquisition; With the print data analyzer, be used for according to determining that the result analyzes the print data that print data file comprises.
According to a further aspect in the invention, provide a kind of data administrator, having comprised: position information generator is used to produce the positional information of the position of the image that can form print data; Insert the unit with positional information, be used for inserting print data and create print data file by the positional information that will be produced.
According to a further aspect in the invention, provide a kind of data administrator, having comprised: the positional information extraction apparatus is used for coming extract location information by reading document; Detector is used to determine whether have identical positional information between the positional information of the positional information extracted and acquisition; And copied cells, if be used for determining to exist identical positional information then duplicate the information that document comprises.
According to a further aspect in the invention, provide a kind of data administrator, having comprised: positional information is inserted the unit, is used for positional information is inserted print data; And image-generating unit, be used to print the positional information of inserting print data.
According to a further aspect in the invention, a kind of computer readable recording medium storing program for performing storage is used to carry out the computer program of data managing method, comprising: extract the positional information that comprises in the print data file; Determine between the positional information of the positional information of being extracted and acquisition, whether have identical positional information; If with determine to exist identical positional information, then analyze the print data that comprises in the print data file.
According to a further aspect in the invention, the storage of a kind of computer readable recording medium storing program for performing is used to carry out the computer program of data managing method, comprising: generation can form the positional information of position of the image of print data; With insert print data by positional information that will be produced and create print data file.
According to a further aspect in the invention, a kind of computer readable recording medium storing program for performing storage is used to carry out the computer program of confidential documents management method, comprising: come extract location information by reading document; Whether there is identical positional information between the positional information of definite positional information of being extracted and acquisition; If with determine to exist identical positional information, then duplicate the information that comprises in the document.
Description of drawings
By the detailed description below in conjunction with accompanying drawing, top and other feature and advantage of exemplary embodiment of the present will become more obvious, wherein:
Fig. 1 is the block scheme that is used to create the data administrator of print data file according to an exemplary embodiment of the present invention;
Fig. 2 and 3 is the reference diagrams that are used for the data administrator of key drawing 1;
Fig. 4 is used to explain the reference diagram of positional information according to an exemplary embodiment of the present invention;
Fig. 5 A to 5D illustrates the exemplary position information that obtains of using the XML type in Fig. 4;
Fig. 6 is the figure that the exemplary meta-data of XML type is used in graphic extension;
Fig. 7 A to 7D is the structural drawing by the exemplary print data file of the data administrator establishment of Fig. 1;
Fig. 8 is according to an exemplary embodiment of the present invention, is used for creating at the data administrator of Fig. 1 the process flow diagram of the method for print data file;
Fig. 9 according to the present invention another exemplary embodiment, be used for creating the process flow diagram of the method for print data file at the data administrator of Fig. 1;
Figure 10 is according to an exemplary embodiment of the present invention, how is used for explaining the block scheme of the data administrator of the data that the managing printing data file comprises;
Figure 11 is the reference diagram that is used to explain the data administrator of Figure 10;
Figure 12 is according to an exemplary embodiment of the present invention, is used for the process flow diagram of the method for the data that comprise in the data administrator managing printing data file of Figure 10;
Figure 13 is according to an exemplary embodiment of the present invention, the block scheme of data administrator how to create classified document is shown;
Figure 14 is the block scheme of the data administrator of the data that how comprise in the administrative security file according to an exemplary embodiment of the present invention of graphic extension;
Figure 15 is according to an exemplary embodiment of the present, is used for creating at the data administrator of Figure 13 the process flow diagram of the method for confidential documents; With
Figure 16 is according to an exemplary embodiment of the present, is used for the process flow diagram of the method for the data that comprise in the data administrator administrative security document of Figure 14.
In the whole accompanying drawing, identical Reference numeral is appreciated that and points to components identical, feature and structure.
Embodiment
Referring now to accompanying drawing exemplary embodiment of the present invention is described in more detail.Data according to exemplary embodiment management of the present invention can be comprised in the file or document of paper type, therefore for example will describe both of these case.
When the data that will be managed are included in the file, will data managing method and device according to an exemplary embodiment of the present invention be described referring to figs. 1 to 12.Here, the data that will be managed can be print datas, and the file that comprises the data of will be managed can be known as print data file.
When the data that will be managed are included in the document, will data managing method and device according to an exemplary embodiment of the present invention be described with reference to figures 13 to 16.As used herein, the data that will be managed will be known as by information of managing, comprise the data document of will be managed and will be known as confidential documents.
Fig. 1 is the block scheme that is used to explain data administrator how to create print data file according to an exemplary embodiment of the present invention.With reference to figure 1, data administrator comprises authentication secret input block 110, file encryption unit 112, position information generator 114, positional information ciphering unit 116, positional information insertion unit 118, element data generator 120, metadata insertion unit 122 and image analyzer 124.
Be meant the file of need to be keep secret by the print data file of data administrator management.More specifically, the print data file of being managed by data administrator is meant the file of creating by the processing print data, thereby the user who only authorizes can visit the content of print data.
Exemplary print data file by the data administrator management comprises positional information and print data.In this case, print data file is meant the print data of having inserted positional information.The positional information of inserting print data is meant that the print data image is authorized to the positional information of the position that will form.For example, when the print data of the positional information of insertion position a, c and d was imported into a certain imaging device, the positional information that is obtained by imaging device must be present in the positional information of inserting print data, so that imaging device is printed this print data.Therefore, if imaging device is positioned at position b, and therefore, if the positional information of b is obtained by the positional information of imaging device as imaging device, then imaging device can not be printed this print data.
As a result, even print data and positional information are all not encrypted, all can not print this print data in any position except position a, c and d.Just, the print data of having inserted positional information can keep safety, and therefore, the print data of having inserted positional information can be known as print data file.
On the other hand, print data file can comprise the positional information of metadata, encryption and the print data of encrypting.Just, in order to keep being perfectly safe, print data that comprises in the print data file and positional information can be the positional information of encryption and the print data of encryption.In this case, can use authentication secret to come in encrypted location information and the print data each.More specifically, can use first authentication secret to come encrypted location information, can use second authentication secret to come the encrypted print data.
Fig. 1 illustrates the example data management devices of the print data file that is used to create positional information that comprises metadata, encryption and the print data of encrypting.Therefore, if data administrator shown in Figure 1 is created the print data file that comprises unencrypted positional information and unencrypted print data, then from the diagram of Fig. 1, can omit authentication secret input block 110, file encryption unit 112, positional information ciphering unit 116, element data generator 120 and metadata and insert unit 122.
Now the assembly shown in Fig. 1 will be described.Just, the explanation of the Fig. 1 that describes below relates to print data and all encrypted print data file of positional information.
At least one that authentication secret input block 110 receives in first authentication secret and second authentication secret.First authentication secret is used for encrypted location information, and second authentication secret is used for the encrypted print data.When the positional information that comprises in the print data file and print data are not encrypted, from data administrator, can omit authentication secret input block 110.
The print data of encrypting is known as private data.
First authentication secret preferably also is used for the deciphering of encrypted location information, and second authentication secret preferably also is used for the deciphering of private data.First authentication secret can be different from second authentication secret.And as will be appreciated, in asymmetric cryptosystem was handled, decruption key can be different from encryption key.
File encryption unit 112 can use by second authentication secret of authentication secret input block 110 inputs and encrypt the input print data.Here, IN1 represents to import print data.Therefore, file encryption unit 112 produces private data.
Position information generator 114 produces the positional information that one or more private datas are authorized to the position that will decipher.For this reason, can be pre-defined or pre-determine the position that wherein private data can be decrypted.Just, position information generator 114 produce define or the positional information of predetermined position.
Position information generator 114 can obtain the positional information of the position that position information generator 114 is positioned, and comes to its output more than a pre-prepd positional information by the positional information that coupling is obtained.Position information generator 114 routes are described in more detail to obtain the be positioned preferred exemplary of positional information of position of position information generator 114 below with reference to Fig. 4.
Positional information ciphering unit 116 uses by first authentication secret of authentication secret input block 110 inputs and encrypts the positional information that is produced by position information generator 114.Just, positional information ciphering unit 116 produces the positional information of encrypting.
Positional information is inserted unit 118 encrypted location information is inserted in the private data that is produced by file encryption unit 112.
Element data generator 120 produces the metadata that will be included in the print data file.Metadata comprises the information about print data.For example, metadata can comprise about the information of the content of print data with about any information of print data management person.
Information about the print data content can comprise for example head, author, creation-time, final modification time, admin number and the signal content of print data, but described information is not limited to these exemplary items.
Gerentocratic information about print data can comprise for example gerentocratic name, telephone number and e-mail address.
Metadata insertion unit 122 is inserted in from the result of positional information insertion unit 118 outputs by the metadata that will be produced and creates print data file.The result who inserts unit 118 outputs from positional information is a private data of having inserted encrypted location information.Here, OUT1 represents the print data file that produced.
When IN1 was not print data but hard copy type document, data administrator can comprise image analyzer 124.
Image analyzer 124 produces view data by scanned document.As used herein, when IN1 was file, print data was meant document data, and when IN1 was hard copy type document, print data was meant view data.
Fig. 2 is the reference diagram that is used for the data administrator of key drawing 1.Reference numeral 210,220 and 230 is represented document data, driver and imaging device respectively.Reference numeral 240,250 and 260 expressions are by the Reference numeral 112,118 of Fig. 1 and the assembly of 122 expressions.
Document data can be the file of any kind, and it can use the file printout function to create.Just, document data can be can be directly from the file of the type of imaging device 230 outputs.Driver 220 can be installed in the main process equipment (not shown) that is connected with imaging device 230.In this case, imaging device 230 is peripheral hardwares of main process equipment.Printer or multifunction peripheral (MFP) can be imaging devices 230.
Document data 210, first and second authentication secrets by authentication secret input block 110 input, the positional information that is produced by position information generator 114 and the metadata that is produced by element data generator 120 all are provided for driver 220.
Driver 220 all offers imaging device 230 with document data 210, first and second authentication secrets, positional information and the metadata that receives.Imaging device 230 can comprise that file encryption unit 240, positional information ciphering unit 116, positional information are inserted unit 250 and metadata is inserted unit 260.
In this case, file encryption unit 240 produces private data by encrypted document data 210, and positional information ciphering unit 116 encrypted location information.Positional information is inserted unit 250 encrypted location information is inserted private data, and metadata is inserted the private data that unit 260 has inserted metadata encrypted location information.
Insert the print data file of creating unit 260 by metadata and be sent to driver 220.Print data can be the file with extension name " prn ", and the print data file that sends can be to have in the file of extension name " eprn (encrypting prn) ".
If the print data file by the data administrator management comprises unencryption positional information and unencryption print data, then first authentication secret, second authentication secret and the metadata of Fig. 2 do not offered driver 220, and the data administrator of Fig. 2 can not comprise that file encryption unit 240 and metadata insert unit 260.
Fig. 3 is another reference diagram that is used for the data administrator of key drawing 1.Reference numeral 310,320,330 and 340 is represented hard copy type document, driver, imaging device and view data respectively.Reference numeral 350,360 and 370 expressions are by the Reference numeral 112,118 of Fig. 1 and the assembly of 122 expressions.
Driver 320 can be installed in the main process equipment (not shown) that is connected with imaging device 330.In this case, imaging device 330 is peripheral hardwares of main process equipment.Printer or multifunction peripheral (MFP) can be imaging devices 330.
First and second authentication secrets by authentication secret input block 110 input, the positional information that is produced by position information generator 114 and the metadata that is produced by element data generator 120 all are provided for driver 320.
First and second authentication secrets, positional information and metadata that driver 320 will receive all offer imaging device 330.Imaging device 330 can comprise that image analyzer 124, file encryption unit 350, positional information ciphering unit 116, positional information are inserted unit 360 and metadata is inserted unit 370.
In this case, image analyzer 124 produces view data 340 by scanned document 310, and file encryption unit 350 produces private data by encrypted image data 340, and positional information ciphering unit 116 encrypted location information.Positional information is inserted unit 360 encrypted location information is inserted private data, and metadata is inserted the private data that unit 370 has inserted metadata encrypted location information.Then, create print data file 380.
If the print data file by the data administrator management comprises unencryption positional information and unencryption print data, then first authentication secret, second authentication secret and the metadata of Fig. 3 do not offered driver 320, and the data administrator of Fig. 3 can not comprise that file encryption unit 350 and metadata insert unit 370.
Fig. 4 is the reference diagram that is used to explain the route that can obtain positional information.As described in Figure 1, the positional information (hereinafter being target position information) of the position that position information generator 114 generation private datas can be decrypted.
More specifically, position information generator 114 can produce the positional information determined by the user as target position information, perhaps can obtain the positional information of the position that position information generator 114 is positioned and produce the positional information obtained as target position information.The positional information of determining or obtaining can be known as initial position message.
Target position information can comprise initial position message and expanding location information.Expanding location information is the positional information in the precalculated position corresponding with initial position message.If the expanding location information of matching initial positional information is deposited in database (databased) in advance, then position information generator 114 not only can produce initial position message, can also produce the expanding location information of matching initial positional information, as target position information.
As described in Fig. 1 to 3, put at main frame and to be equipped with in 450, it comprises driver 220 or 320 and be connected to the imaging device 430 of main process equipment 450 via network, and comprise that position information generator 114, file encryption unit 112, positional information ciphering unit 116, positional information are inserted unit 118 and metadata is inserted unit 122, can generation initial position message as described below.
The positional information of the position of position information generator 114 location is positional informations of imaging device 430.Want the user of the positional information of definite imaging device 430 can determine that the positional information that the user perceives is the positional information of imaging device 430, perhaps can be (for example by the Internet 450, WWW) positional information of search imaging device 430 on network, and use Search Results to determine the positional information of imaging device 430 as shown in Figure 4.
Position information generator 114 can obtain its positional information voluntarily.Just, the imaging device 430 that comprises position information generator 114 can obtain its positional information voluntarily.For this reason, data administrator can comprise positional information creator (not shown).
The positional information creator is created the positional information of imaging device 430.This positional information creator (not shown) can be comprised in GPS (GPS) satellite 410 or the cellular phone antennas 440.
For example, the positional information creator that comprises in the gps satellite 410 correctly detects imaging device 430 position on the ground, and creates the information about detected position.In this case, imaging device 430 can comprise the gps receiver (not shown).Gps receiver receives information about the establishment of detected position as positional information from gps satellite 410, and the positional information that receives is sent to position information generator 114, and subsequent position information generator 114 uses the positional information that receives to produce initial position message.
In this case, gps receiver can be from gps satellite 410 direct receiving position informations, perhaps can be via the antenna 420 that is connected to imaging device 430 from gps satellite 410 receiving position informations.
Similarly, the positional information creator that comprises in the cellular phone antennas 440 correctly detects the position of imaging device 430 in cellular phone network, and creates the information about detected position.Cellular phone network typically is made of a plurality of sub-districts, and the cellular phone antennas that comprises in each sub-district typically has unique sub-district ID.Unique sub-district ID of the positional information creator output sub-district that therefore, comprises in the cellular phone antennas 440 of the sub-district at imaging device 430 places is as the positional information of imaging device 430.Position information generator 114 receiving position informations that comprise in the imaging device 430, and use the positional information that receives to produce initial position message.
If the initial position message that the expanding location information matches produces as mentioned above, then position information generator 114 also produces expanding location information as target position information.So, position information generator 114 can produce the position that can decipher print data file more than one.
For example, if initial position message is the positional information of the imaging device selected at a plurality of imaging devices that are arranged on the 3rd layer of building A by the user, if and initial position message comprises the expanding location information of the positional information of all imaging devices among the positional information that comprises all imaging devices in the building A and the buildings C, then position information generator 114 can produce the target position information of the positional information of all imaging devices among the positional information that comprises all imaging devices in the building A and the buildings C.In this case, suppose that identical company works in building A and C.
Although acquisition also produces in the involved as mentioned above imaging device 430 of position information generator 114 of positional information, position information generator 114 can be comprised in the main process equipment 450 that is connected to imaging device 430.
Fig. 5 A to 5D is the figure as the positional information of initial position message that expression position information generator 114 uses that the XML types obtain.
Shown in Fig. 5 A, the positional information of acquisition can be imaging device 430 positional information on the ground, and it is detected by the positional information creator that comprises in the gps satellite 410.
Shown in Fig. 5 B, the positional information of acquisition can be the positional information of imaging device 430 in the cellular phone network, and its positional information creator that is comprised in cellular phone antennas 440 detects.
Shown in Fig. 5 C, the positional information of acquisition can be the positional information of buildings that comprises imaging device 430 places of position information generator 114.Shown in Fig. 5 D, the positional information of acquisition can be medium Access Control (MAC) address that comprises the imaging device 430 of position information generator 114.
Fig. 6 is the figure that the exemplary meta-data of XML type is used in graphic extension.
As shown in Figure 6, metadata can comprise about the information of the content of print data with about the gerentocratic information of print data.
Head, author, creation-time (" created "), last modification time (" modified "), admin number (" document ") and the schematic content (" description ") that can comprise as mentioned above, print data about the exemplary information of print data content.
Here, yyyy, mm, dd, hh, mm, ss and nn represent year, month, day, hour, minute, second and numeral respectively.
Gerentocratic exemplary information (" contactinfo ") about print data can comprise gerentocratic name (" docmanager "), telephone number (" telephone ") and e-mail address (" email ").
Fig. 7 A to 7D is that print data file 710 comprises metadata 714, encrypted location information 716 and encrypted print data 718 by the structural drawing of the print data file 710 of the data administrator management of Fig. 1.More specifically, Fig. 7 A is the structural drawing of print data file 710, and Fig. 7 B is the structural drawing of file head (header) 712, and Fig. 7 C is the structural drawing of head 730 of metadata 714 and the structural drawing of the head 740 that Fig. 7 D is encrypted location information 716.
Shown in Fig. 7 A, when print data was document data, print data file 710 comprised file head 712, metadata 714, encrypted location information 716 and private data, and it is the print data 718 of encrypting.
File head 712 preferably includes the information about skew, and described skew is metadata 714, encrypted location information 716 and private data 718 a stored relative address in storer when print data file 710 is stored in the storer.Just, shown in Fig. 7 B, file head 712 comprise about metadata begin to be offset 720 data, about the data of encrypted location information offset 722 with about the data of encrypted document data skew 724.
Shown in Fig. 7 C, the metadata 714 of print data file 710 comprises the head of the data of the length that comprises representation element data 714.
Shown in Fig. 7 D, the positional information 716 of the encryption of print data file 710 comprises the head 740 of the data of the length that comprises expression encrypted location information 716.
Fig. 8 is according to an exemplary embodiment of the present invention, creates the process flow diagram by the method for the print data file of the data administrator management of Fig. 1, and described print data file comprises unencryption positional information and unencryption print data.
In operation 810, position information generator 114 produces the positional information of the position that can print described print data IN1, and in operation 820, positional information is inserted unit 118 and is created print data file by the positional information insertion print data IN1 that will be produced.
Fig. 9 according to the present invention another exemplary embodiment, create process flow diagram by the method for the print data file of the data administrator management of Fig. 1, described print data file comprises the positional information and the encrypted print data of metadata, encryption.Described method comprises: use the first authentication secret encrypted location information; Use the second authentication secret encrypted print data; The positional information of encrypting is inserted the encrypted print data; With create print data file (operation 910 to 924) by metadata being inserted private data.
With reference to figure 9, in operation 910, data administrator receives the order of creating print data file, and is operating in 920 then, and authentication secret input block 110 is opened the authentication secret input window.In operation 914, the user inputs to authentication secret input block 110 by the authentication secret input window with first authentication secret and second authentication secret.
In operation 916, positional information ciphering unit 116 uses first authentication secret to encrypt the positional information that is produced by position information generator 114, and in operation 918, file encryption unit 112 produces private data by using second authentication secret to encrypt the input document data.
In operation 920, positional information is inserted unit 118 encrypted location information is inserted private data, and in operation 922, metadata is inserted unit 122 the metadata insertion that element data generator 120 produces has been inserted in the private data of encrypted location information.In operation 924, the print data file of data administrator management is created by operating 910 to 922.
Figure 10 is according to an exemplary embodiment of the present invention, how is used for explaining the block scheme of the data administrator of the data that the managing printing data file comprises.The data administrator of Figure 10 comprises meta-data extractor 1010, metadata notification unit 1012, authentication secret input block 1014, positional information decryption unit 1016, location information acquiring unit 1018, detector 1020, user interface section 1022, file decryption unit 1024, print data analyzer 1026 and image-generating unit 1028.
Here, IN2 represents the print data file by the data administrator management of current embodiment, more specifically, and the OUT1 of presentation graphs 1.
The data administrator of Figure 10 can receive the print data file that comprises metadata, encrypted location information and encrypted print data, and is printed on the print data that comprises in the print data file that receives.
Therefore, receive at the data administrator of Figure 10 and to comprise the print data file of unencryption positional information and unencryption print data and be printed under the situation of the print data that comprises in the print data file that receives, can from Figure 10, omit meta-data extractor 1010, metadata notification unit 1012, authentication secret input block 1014, positional information decryption unit 1016 and file decryption unit 1024.Assembly shown in Figure 10 is described now in more detail.
Meta-data extractor 1010 is extracted in the metadata that comprises in the print data file that receives from print data file.Metadata notification unit 1012 is given the user with the context notification of the metadata of extraction.For this reason, metadata notification unit 1012 can comprise the user interface of the content of the metadata that is used to show extraction.
In this case, the user interface that comprises in the metadata notification unit 1012 is given the user by showing the content of the metadata of extracting with the schematic context notification of print data.Here, OUT2 represents by the user interface content displayed that comprises in the metadata notification unit 1012.
Authentication secret input block 1014 receives first authentication secret and second authentication secret.Here, IN3 represents first authentication secret or second authentication secret.First authentication secret is used for the positional information of enabling decryption of encrypted, and second authentication secret is used to decipher private data.
Just, the authentication secret that is used for encrypted location information must be identical with first authentication secret with the authentication secret that is used for decrypted positions information, and the authentication secret that is used for the encrypted print data must be identical with second authentication secret with the authentication secret that is used to decipher print data.Here, first authentication secret can be different from second authentication secret.
Positional information decryption unit 1016 is used the positional information of coming enabling decryption of encrypted by first authentication secret of authentication secret input block 1014 inputs.Thus, positional information was obtainable before the encrypted print data are extracted.Just, if it is identical with the authentication secret that is used for encrypted location information of the authentication secret input block 110 that is imported into Fig. 1 to be imported into the authentication secret that is used for the enabling decryption of encrypted positional information of authentication secret input block 1014, then positional information decryption unit 1016 is extracted the positional information that comprises among the print data file IN2.
Therefore, authentication secret input block 1014 and positional information decryption unit 1016 are operating as positional information extraction apparatus (not shown).The positional information of extracting is the unencrypted positional information.If IN2 is the OUT1 of Fig. 1, then the positional information of Ti Quing is to obtain by the encryption target position information that comprises among the deciphering OUT1.
Just, the positional information of being extracted by positional information decryption unit 1016 represents to decipher the positional information of one or more positions of the private data that comprises in the print data file, and this positional information is represented described target position information.
Although meta-data extractor 1010 to positional information decryption unit 1016 can be omitted from the data administrator of current embodiment as described above when the print data file by the management of the data administrator of current embodiment comprises unencryption positional information and unencryption print data, but the positional information extraction apparatus preferably is present in the data administrator, is used for extracting the positional information that print data file comprises.
Location information acquiring unit 1018 obtains the positional information of the position at location information acquiring unit 1018 places.The principle of the position at location information acquiring unit 1018 acquisition location information acquiring unit 1018 places is identical with the principle of the position at position information generator 114 acquisition position information generators 114 places of Fig. 1.
Detector 1020 determines whether there is identical positional information between the positional information that is obtained by location information acquiring unit 1018 and the positional information of being deciphered by positional information decryption unit 1016.
If detector 1020 is determined not have identical positional information, then user interface section 1022 can not be deciphered the private data that comprises in the print data file to user notification.For example, user interface section 1022 can show the message that expression can not be encrypted.Here, OUT3 represents the content that user interface section 1022 is notified.
On the other hand, if detector 1020 determines to exist identical positional information, then file decryption unit 1024 uses by second authentication secret of authentication secret input block 1014 inputs and deciphers the private data that comprises in the print data file.
If what be imported into authentication secret input block 1014 is used to that to decipher the authentication secret of private data identical with the authentication secret that is used for the encrypted print data of the authentication secret input block 110 that is imported into Fig. 1, then file decryption unit 1024 produces print data by the deciphering private data.
Print data analyzer 1026 is analyzed the content of print data.User interface section 1022 can show the content of being analyzed.Image-generating unit 1028 forms image according to the content of being analyzed.Just, image-generating unit 1028 forms the image of print data.Here, OUT4 represents the print data printed.
Yet, if what be imported into authentication secret input block 1014 is used to that to decipher the authentication secret of private data different with the authentication secret that is used for the encrypted print data of the authentication secret input block 110 that is imported into Fig. 1, then private data can not be deciphered to user notification in 1024 command user interface unit 1022, file decryption unit.
Similarly, if it is different with the authentication secret that is used for encrypted location information of the authentication secret input block 110 that is imported into Fig. 1 to be imported into the authentication secret that is used for the enabling decryption of encrypted positional information of authentication secret input block 1014, then positional information decryption unit 1016 command user interface unit 1022 to user notification can not enabling decryption of encrypted positional information.
Figure 11 is the reference diagram that is used to explain the data administrator of Figure 10.Reference numeral 1110 expression print data files, Reference numeral 1120 expression imaging devices.Reference numeral 1112,1118,1122,1124 and 1126 expressions are by the Reference numeral 1010,1016,1020,1022 of Figure 10 and the assembly of 1024 expressions.
Meta-data extractor 1112 is extracted the metadata that comprises in the print data file 1110.Metadata notification unit 1012 is given the user with the context notification of the metadata of extraction.For example, metadata notification unit 1012 can use the user interface 1114 that wherein comprises to show the content of the metadata of being extracted.
Meta-data extractor 112 preferably is comprised in the driver.Driver can be comprised in the main process equipment (not shown) that is connected to imaging device 1120.In this case, imaging device is the peripheral hardware of main process equipment.
Printer or MFP can be the examples of imaging device 1120.Positional information decryption unit 1118, detector 1122 and file decryption unit 1126 can be included in the imaging device 1120.
Authentication secret input block 1014 receives first authentication secret and second authentication secret by the authentication secret input window 1116 that wherein comprises.The positional information decryption unit 1118 that comprises in the driver is used by first authentication secret of authentication secret input block 1014 inputs and is come the enabling decryption of encrypted positional information.
Detector 1122 determines whether there is identical positional information between the positional information that is obtained by location information acquiring unit 1018 and the positional information of being deciphered by positional information decryption unit 1118.
If detector 1122 is determined not have identical positional information, then user interface section 1124 can not be deciphered private data to user notification.User interface section 1124 can be comprised in the driver.
User interface section 1124 can show the details of having asked the user that deciphers.If must use login ID and entry password, then can follow the tracks of the user's who has asked the illegal outflow of print data details for main process equipment.
Just, when detector 1122 was determined not have identical positional information, user interface section 1124 can show the details of login user.In this case, detector 1122 can be informed the print data of the details of login user to the supvr.
If detector 1122 determines to exist identical positional information, then file decryption unit 116 produces print data by the deciphering private data.The imaging device 1120 that comprises file decryption unit 1126 can be printed print data that is produced and/or the content that shows the print data that is produced on user's display unit.
Figure 12 is according to an exemplary embodiment of the present invention, is used for the process flow diagram of the method for the data that comprise in the data administrator managing printing data file of Figure 10.Described method comprises: use the first authentication secret decrypted positions information; Only when mating the positional information that is obtained by location information acquiring unit 1018, the positional information of deciphering just uses second authentication secret deciphering private data (operation 1210 to 1226).
In operation 1210, meta-data extractor 1010 is extracted metadata from print data file, and metadata notification unit 1012 is given the user with the context notification of the metadata extracted.
In operation 1212, the data administrator of Figure 10 is from the order of user's receiving and deciphering, and in operation 1214, authentication secret input block 1014 receives first authentication secret and second authentication secret from the user.
In operation 1216, positional information decryption unit 1016 uses first authentication secret that receives to come decrypted positions information, and in operation 1218, the positional information of the position that position that location information acquiring unit 1018 acquisition positional information decryption unit 1016 are positioned or location information acquiring unit 1018 are positioned.
In operation 1220, detector 1020 determines whether there is identical positional information between the positional information of positional information that is obtained and deciphering.If detector 1020 determines to exist identical positional information, then in operation 1222, file decryption unit 1024 produces print data by second authentication secret deciphering private data that use receives.In operation 1224, image-generating unit 1028 is printed the print data that is produced.
If detector 1020 determines not exist identical positional information in operation 1220, then in operation 1226, user interface section 1022 can not be deciphered private data to user notification.
Flow chart description shown in Figure 12 be printed on the exemplary process of the print data that comprises in the print data file that receives, the described print data file that receives comprises metadata, encrypted location information and deciphering print data.
If the print data file that receives comprises unencrypted positional information and unencrypted print data, the processing that then is printed on the print data that comprises in the print data file that receives can comprise: extract location information from the print data file that receives; The positional information of the position that acquisition prints; Determine between the positional information of positional information of extracting and acquisition, whether have identical positional information; If determine to exist identical positional information then print this print data; If with determine not have identical positional information then notify the user can not print described print data.
Figure 13 is the block scheme that is used to explain according to an exemplary embodiment of the present invention, how creates the data administrator of classified document.The data administrator of Figure 13 can comprise positional information input block 1310, positional information insertion unit 1320 and image-generating unit 1330.Image-generating unit 1330 comprises exposing unit 1332, developing cell 1334 and fixation unit 1336.
More specifically, Figure 13 is a more detailed block diagram of creating the confidential documents creation apparatus of the confidential documents of being managed by the data administrator of current embodiment.Here, IN4 represents the print data that receives.
At the main process equipment (not shown) and be connected to via network in the imaging device (not shown) of main process equipment, imaging device can receive the print data IN4 that print data IN4 and printing receive from main process equipment.Here, print result is a document.
Imaging device can be such as printer or have printing device the MTP of printing function.Positional information input block 1310, positional information insert unit 1320 and image-generating unit 1330 can be comprised in the imaging device.
Positional information input block 1310 sends to positional information with positional information and inserts unit 1320.
The confidential documents of being managed by the data administrator of current embodiment comprises input position information.Input position information can comprise the positional information of the position that produces print data IN4 and print in the positional information of position of described print data IN4 at least one.
The positional information that produces the position of print data IN4 can be the positional information of main process equipment.In target device, can produce print data IN4.
The positional information of the position of print print data IN4 can be the positional information of imaging device.Can in target imaging equipment, print this print data IN4.
Input position information can comprise at least one in the positional information (hereinafter being called second definite information) of corresponding position, position of the positional information (hereinafter be called first and determine information) of predetermined and the corresponding position, position that produces print data IN4 and predetermined and this print data of printing IN4.
For example, hypothetical target equipment is to be arranged in of a plurality of main process equipments on the 3rd layer of the building A, and described main process equipment is connected to the main process equipment that is arranged in building B and C via network (WWW).In addition, suppose that the company of working is the subsidiary company of the company of working and is the rival of the company that operates in building A in building B in buildings C.
In this case, first determine information can be target device positional information (hereinafter be called information a), be positioned at a certain main process equipment on the 4th layer of the building A positional information (hereinafter being called information b), be positioned at the positional information (hereinafter being called information c) of the All hosts equipment on third and fourth layer of the building A, perhaps can be information a and information c.
For receiving, positional information input block 1310 comprises the information a of another main process equipment and the positional information of positional information, and can pre-defined predetermined main process equipment for each target device.For example, in order in the positional information that receives by positional information input block 1310, to comprise information a and information b, when target device is the main process equipment that is positioned on the 3rd layer of building A, must pre-definedly be positioned at the main process equipment on the 4th layer of building A according to target device.
Similarly, if when target device is arranged in building A, define a certain main process equipment that is arranged in building B according to target device, then when producing print data IN4 in building A, positional information input block 1310 can send to the positional information that comprises the positional information of the All hosts equipment that is arranged in building B positional information and insert unit 1320.
Therefore, if according to pre-defined other positions, position that also produce print data except the position that produces print data, positional information input block 1310 can send to positional information insertion unit 1320 with comprising the positional information of the position that produces print data and the positional information of other positions.
Determine that about first all descriptions of information can be applied to second definite information in the same manner.Therefore, if according to also carrying out pre-defined other positions, position of printing beyond the position of carry out printing, then positional information input block 1310 can send to positional information with the positional information that comprises the positional information of the positional information of carrying out the position of printing and other positions and insert unit 1320.
The positional information of main process equipment and/or imaging device can be the information about the IP address of main process equipment and/or imaging device.Yet because can easily revise the IP address, so the positional information of main process equipment and/or imaging device is the information preferably about MAC Address.
Positional information input block 1310 can send to the positional information of the positional information that receives or acquisition positional information and insert unit 1320.Just, positional information input block 1310 can be from outside receiving position information, and the positional information that receives is sent to positional information inserts unit 1320.Therefore, positional information input block 1310 is worked as impact damper.
The positional information that receives is the positional information that is directly inputted to positional information input block 1310 by the user.Positional information input block 1310 sends to the position with the positional information that receives and inserts unit 1320.Here, the user can be input to the positional information of target device or target imaging equipment positional information input block 1310 or input position information, and does not consider target device or target imaging equipment.
If the user wishes the positional information of target device or target imaging equipment is input to positional information input block 1310, then the user can be by the Internet 450 at network (WWW: the positional information of ferret out equipment or target imaging equipment WWW), and Search Results is input to positional information input block 1310, as shown in Figure 4.
The positional information that is obtained is the positional information that is obtained from the outside by positional information input block 1310, rather than the positional information of user's input.In order to obtain positional information, the data administrator of current embodiment can comprise positional information creator (not shown) as shown in Figure 4.
The positional information creator is created the positional information of target device or target imaging equipment.The positional information creator can be comprised in gps satellite 410 or the cellular phone antennas 440.
For example, the positional information creator that comprises in the gps satellite 410 correctly detects target device or target imaging equipment position on the ground, and creates the information about detected position.In this case, target device or target imaging equipment can comprise the gps receiver (not shown).Gps receiver receives information about the establishment of detected position as positional information from gps satellite 410, and works as positional information input block 1310, the positional information that receives is sent to positional information insert unit 1320.In this case, gps receiver can from gps satellite 410 direct receiving position informations or via the antenna 420 that is connected to target device or target imaging equipment from gps satellite 410 receiving position informations.
Similarly, the positional information creator that comprises in the cellular phone antennas 440 correctly detects the position of target device or target imaging equipment in cellular phone network, and creates the information about detected position.Cellular phone network is made of a plurality of sub-districts, and the cellular phone antennas that comprises in each sub-district has its unique sub-district ID.Unique sub-district ID of the positional information creator output sub-district that therefore, comprises in the cellular phone antennas 440 of the sub-district at target device or target imaging equipment place is as the positional information of target device or target imaging equipment.The positional information input block 1310 that comprises in target device or the target imaging equipment receives the positional information of being created, and the positional information that receives is sent to positional information insertion unit 1320.
Even the positional information creator that comprises in gps satellite 410 or the cellular phone antennas 440 is created the positional information of target device or target imaging equipment, positional information input block 1310 can send to the positional information of creating positional information and positional information that comprises other main process equipments or imaging device positional information and insert unit 1320.For this reason, can pre-defined other main process equipments according to each target device.Similarly, can pre-defined other imaging devices according to each imaging device.
For example, if have positional information (hereinafter being called expanding location information) corresponding to the predefined position, position that produces print data IN4 for the positional information (hereinafter being called initial position message) of the position that produces print data IN4, if and expanding location information and initial position message are deposited in database and are stored in advance, even when the positional information of positional information creator establishment only comprised initial position message, positional information input block 1310 can send to expanding location information positional information and insert unit 1320.Expanding location information can maybe cannot comprise initial position message.
Positional information is inserted unit 1320 positional information that receives is inserted print data IN4.Here, positional information insertion unit 1320 can use watermark (watermarking) that positional information is inserted print data IN4.Watermark is that a kind of being proposed prevents illegal copies and be used to prevent that the copy that various word contents and digital content are replicated without permission from preventing technology.
In this case, positional information insertion unit 1320 can use the various digital watermarks such as least significant bit (LSB) (LSB) modulation technique.Print data IN4 can be owing to the positional information of inserting is damaged.
Image-generating unit 1330 is printed the print data IN4 that has inserted positional information on print media.Print media is an abundant in content notion, and it comprises paper and overhead projector (OHP) film, and image-generating unit 1330 outputs are as the document of concrete physical object.Here, OUT5 represents document printing.The document is known as confidential documents.
If positional information is added watermark and inserted unit 1320 by positional information and insert print data IN4, then the positional information on the document OUT5 can not be perceiveed by naked eyes.Therefore, can not perceive the positional information of inserting confidential documents even attempt illegally to carry the individual of confidential documents.
If positional information is added watermark and is inserted into, then positional information may reside on the marginal portion of the part that shows print data and confidential documents.Therefore, even the part of confidential documents is torn or cut is arranged, confidential documents also still can have positional information.
Image-generating unit 1330 can comprise exposing unit 1332, developing cell 1334 and fixation unit 1336.Exposing unit 1332 is according to the print data IN4 that has inserted positional information, form electrostatic latent image (electrostatic latent image) by exposure medium being exposed to the open air laser beam, developing cell 1334 is by producing the sub-image of development to formed latent electrostatic image developing, and fixation unit 1336 comes document printing based on the print data IN4 that has inserted positional information by the development sub-image that photographic fixing on print media produced.
Figure 14 is a block scheme of explaining according to an exemplary embodiment of the present invention the data administrator of the data that comprise in the administrative security file how.The data administrator of Figure 14 comprises positional information extraction apparatus 1410, location information acquiring unit 1420, positional information fallout predictor 1430, positional information storage unit 1440, detector 1450, copied cells 1460 and user's receiving element 1470.
Copied cells 1460 comprises Copy Info record cell 1462, output image generator 1464, image-generating unit 1465 and print unit 1468.Copied cells 1460 can be by laser printer (LBP), ink-jet printer, add thermal printer (thermal printer) or any other suitable equipment is realized.Image-generating unit 1465 generally includes exposing unit 1466 and developing cell 1467.
Positional information extraction apparatus 1410 to all parts in the user interface section 1470 can be included in the imaging device.Particularly, they can be comprised among duplicating machine, scanner or the MFP.Here, MFP can have duplicating or scan function.Therefore, because the common function of duplicating machine, scanner and MFP is the function of duplicating the information that comprises in the document, can be known as information reproduction equipment so have the imaging device of copy function.
IN5 represents to be provided for the document of information reproduction equipment (that is, the positional information extraction apparatus 1410).More specifically, IN5 represents the document that will be replicated, and can be or can not be confidential documents.Hereinafter, unclassified document is known as general document.
If common document is provided for information reproduction equipment, then information reproduction equipment can duplicate or can not duplicate the information that comprises in the general document.Yet, if confidential documents is provided for information reproduction equipment, then when information reproduction equipment determined that its positional information is the positional information of position of the information that comprises in the confidential documents of not reproducible, information reproduction equipment did not duplicate the information that comprises in the confidential documents.Now the method for administrative security document according to an exemplary embodiment of the present invention will be described in more detail.
Positional information extraction apparatus 1410 extracts the positional information that comprises among the document IN5 by reading document IN5.If document IN5 is general document, then positional information extraction apparatus 1410 can not extract the positional information of document IN5.Just, as long as document IN5 is confidential documents, promptly comprises the document of positional information, positional information extraction apparatus 1410 just can extract the positional information of document IN5.
Although IN5 can be confidential documents or general document, for convenience, suppose that IN5 is confidential documents OUT5.Positional information extraction apparatus 1410 can read document IN5 by it is scanned.
The positional information of being extracted can be the positional information of the predefined position corresponding with the position of creating document IN5.The position of creating document IN5 is the position that produces the print data IN4 that comprises among the document IN5.Just, the positional information of being extracted can comprise initial position message or have the expanding location information of initial position message.
Location information acquiring unit 1420 obtains its positional information.Just, location information acquiring unit 1420 acquisitions comprise the positional information of the information reproduction equipment of location information acquiring unit 1420.Here, location information acquiring unit 1420 obtains positional information from the outside, rather than imports by the user.
For this reason, aforesaid positional information creator also can be created the positional information of information reproduction equipment.As mentioned above, the positional information creator can be comprised in gps satellite 410 or the cellular phone antennas 440.
For example, the positional information creator that comprises in the gps satellite 410 correctly detects information reproduction equipment position on the ground, and creates the information about the position of being detected.In this case, information reproduction equipment can comprise the gps receiver (not shown).Gps receiver is by obtaining establishment information about detected position as positional information from gps satellite 410, the image information copying equipment is equally worked.
Similarly, the positional information creator that comprises in the cellular phone antennas 440 correctly detects the position of information reproduction equipment in cellular phone network, and creates the information about detected position.Therefore the positional information creator that comprises in the cellular phone antennas 440 of the sub-district at information reproduction equipment place is exported the positional information of unique sub-district ID of this sub-district as information reproduction equipment.The positional information that location information acquiring unit 1420 acquisitions that comprise in the information reproduction equipment are created.
Location information acquiring unit 1420 can obtain positional information, and need not directly import by the user, because may obtain incorrect positional information when location information acquiring unit 1420 is obtained its positional information by user's input.
Positional information fallout predictor 1430 provides the positional information that must be included among the document IN5 to detector 1450, so that the information that comprises among the document IN5 is replicated.Just, 1430 predictions of positional information fallout predictor must be included in the value of the positional information among the document IN5, are replicated so that be input to the information that is included among the document IN5 of positional information extraction apparatus 1410.For this reason, can pre-definedly be predicted to be the positional information that to insert document IN5 by mating each positional information of obtaining.The positional information of the prediction of positional information storage unit 1440 storages and each positional information of obtaining coupling.Yet according to current embodiment, positional information fallout predictor 1430 and positional information storage unit 1440 can not be included in the data administrator of Figure 14.In this case, the positional information of being obtained by location information acquiring unit 1420 is sent straight to detector 1450.
Detector 1450 determines whether there is identical positional information between by positional information extraction apparatus 1410 positional information of extracting and the positional informations of being obtained by location information acquiring unit 1420.For example, if expanding location information is included in the positional information of inserting document IN5, then expanding location information is present in the positional information of being extracted by positional information extraction apparatus 1410, and detector 1450 determines whether the positional information of being obtained is present in the expanding location information.
The positional information of being obtained can comprise the positional information of information reproduction equipment.And the positional information of being obtained can comprise other predefined positional informations corresponding with the positional information of information reproduction equipment.
Copied cells 1460 and user interface section 1470 response detectors 1450 determine that the result operates.More specifically, if determine that the result determines to exist identical positional information, then copied cells 1460 work.Determine not exist identical positional information if determine the result, then user interface section 1470 work.
Copied cells 1460 duplicates the information that comprises among the document IN5.Copied cells 1460 can comprise Copy Info record cell 1462, output image generator 1464, image-generating unit 1465 and print data 1468.
The positional information that 1462 storages of Copy Info record cell are extracted.Yet according to current embodiment, Copy Info record cell 1462 can not be included in the copied cells 1460.Output image generator 1464 produces output images, and this output image is the result's that read by positional information extraction apparatus 1410 a image.
Image-generating unit 1465 forms the image of the output image that produces.Print unit 1468 is printed the image that forms on print media.
If copied cells 1460 is realized that by aforesaid LBP then image-generating unit 1465 can comprise exposing unit 1466 and developing cell 1467.In this case, exposing unit 1466 is by producing electrostatic latent image to the exposure medium scanning laser beam, and developing cell 1467 forms image by the electrostatic latent image that is produced that develops.Print unit 1468 is printed the image of formation as document by the formed image of photographic fixing on print media.
If copied cells 1460 realizes that by ink-jet printer then image-generating unit 1465 can comprise ink nozzle controller (not shown).In this case, the ink nozzle controller produces the control signal of control ink spray volume according to the output image that is produced.Print unit 1468 these control signals of response are printed formed image as document by ejection ink on print media.
If copied cells 1460 realizes that by adding thermal printer then image-generating unit 1465 can comprise heat head (thermal head) controller (not shown).In this case, thermal head controller produces the control signal of control temperature according to the output image that is produced.Print unit 1468 these control signals of response are printed formed image as document by the heating print media.
If comprising the information reproduction equipment of copied cells 1460 is duplicating machine or the MFP with copy function, then copied cells 1460 comes Copy Info by copy document IN5.In this case, OUT6 represents by copying the print media that document IN5 obtains.
If comprising the information reproduction equipment of copied cells 1460 is scanner or the MFP with scan function, then copied cells 1460 comes Copy Info by scanned document IN5.In this case, OUT6 represents to have the scan-data that is included in the information among the document IN5.
More specifically, if comprising the information reproduction equipment of copied cells 1460 is scanner or the MFP with scan function, then copied cells 1460 can comprise scanning element (not shown), scan-data acquiring unit (not shown) and scan-data copy cell (not shown).
Scanning element scanned document IN5, and the scan-data acquiring unit obtains the scan-data that generates by scanned document IN5.The scan-data copy cell can copy the scan-data that is obtained.
User interface section 1470 is notified the user not reproducible document IN5.OUT7 represents the content notified.Illegal copies are attempted the notification unit (not shown) can be connected to user interface section 1470.If detector 1450 determines not exist identical positional information, then illegal copies trial notification unit can notify the main process equipment or the imaging device that are positioned at the position of being represented by the positional information of extracting from document IN5 to attempt illegal copies.
If in addition watermark and insert document IN5 of positional information, then the positional information of Cha Ruing can prevent that document IN5 from being damaged by malice, even because attempt the existence that the people of illegal copies can not aware positional information.
Figure 15 is a process flow diagram of creating the method for classified document according to an exemplary embodiment of the present invention in the data administrator of Figure 13.Described method comprises: positional information is inserted print data; Inserted the print data of positional information with printing.More specifically, Figure 13 is to use the more detailed block diagram of creating the data administrator of confidential documents according to the data managing method of current embodiment.
In operation 1510, positional information input block 1310 receives the positional information of being created by the positional information creator, and the positional information that receives is sent to positional information insertion unit 1320.Yet positional information input block 1310 can send to the positional information that the user directly imports positional information and insert unit 1320.
In operation, positional information is inserted unit 1320 positional information that receives is inserted print data IN4.Image-generating unit 1330 is printed on print media and has been inserted the print data of positional information as document.
More specifically, in operation 1532, the exposing unit 1332 of image-generating unit 1330 forms the electrostatic latent image of the print data of having inserted positional information.In operation 1534, the developing cell 1334 of image-generating unit 1330 produces image by the formed electrostatic latent image that develops.In operation 1536, the image that fixation unit 1336 photographic fixing on print media of image-generating unit 1330 are produced.So, created the confidential documents of managing by according to the data administrator of the embodiment of the invention.
Figure 16 is the process flow diagram of the method for the data that comprise in the administrative security document in the data administrator of Figure 14 according to an exemplary embodiment of the present invention.Described method comprises: determine whether there is identical positional information (operating 1610 to 1650) between the positional information of extracting from document and the positional information of being stored; Determine that with basis the result responds (operation 1660 and 1670).
In operation 1610, for positional information extraction apparatus 1410 is prepared document IN5.When preparing document IN5, in operation 1620, location information acquiring unit 1420 is obtained the positional information of the position of having prepared document IN5.In operation 1630, positional information fallout predictor 1430 reads and the positional information corresponding position information of being obtained from positional information storage unit 1440.
In operation 1640, positional information extraction apparatus 1410 is from document IN5 extract location information, and in operation 1650, and detector 1450 determines whether there is identical positional information between the positional information of being extracted and the positional information that reads.
If determine to exist identical positional information in operation 1650, then in operation 1660, copied cells 1460 duplicates the information that comprises among the document IN5.
If determine not exist identical positional information in operation 1650, then in operation 1670, user interface section 1470 is notified the user not reproducible document IN5.
The present invention also can be specially the computer-readable code on the computer readable recording medium storing program for performing.Computer readable recording medium storing program for performing be can store after by the arbitrary data memory device of the data of computer system reads.The example of computer readable recording medium storing program for performing comprises ROM (read-only memory) (ROM), random-access memory (ram), CD-ROM, tape, floppy disk, light data storage device and the carrier wave data transmission of the Internet (for example, by).Computer readable recording medium storing program for performing also can be distributed in the computer system that network connects, thereby with ways of distribution storage and computer readable code executed.And the prior art programming personnel's decipher easily under the present invention realizes functional programs of the present invention, code and code segment.
As mentioned above, in data managing method and device according to the embodiment of the invention, as long as mate the positional information of being stored from the positional information that print data file extracts, then by deciphering the private data that comprises in the print data file, anyone just can prevent that the print data that comprises in the print data file from illegally outflowing, although can visit this print data file via network.And, in data managing method and device according to the embodiment of the invention, be used for the authentication secret of encrypted location information and the authentication secret of the print data that is used to encode by differentiation, just can guarantee the safety of print data content, even one of these two authentication secrets are illegally carried out.In addition, in according to the data managing method of the embodiment of the invention and device, comprise the print data file of metadata by management, the user can know the schematic information about the print data that comprised in print data file before the deciphering private data.
And, in data managing method and device,, can prevent the illegal outflow of confidential documents by allowing only in the specific region, to duplicate the information that comprises in the confidential documents according to the embodiment of the invention.
Although illustrate and described the present invention with reference to exemplary embodiment of the present invention, but those of ordinary skill in the art is to be understood that, under situation about not deviating from, can make various modifications in form and details by the spirit of the present invention of claims definition and category.

Claims (25)

1. data managing method comprises:
Extraction is affixed to the positional information of given print data;
Positional information and the ready positional information extracted are compared; With
If the positional information of being extracted is matched with ready positional information, then print this print data,
Wherein, use first authentication secret to encrypt and be affixed to the positional information of given print data, and in extraction step, carry out described extraction by using the first given authentication secret to decipher the positional information that is affixed to given print data, and
The print data that private data is to use second authentication secret to encrypt, and in printing step, if the positional information of being extracted is matched with ready positional information, then use given second authentication secret decipher private data and
Second authentication secret is different from first authentication secret.
2. the positional information of the method for claim 1, wherein being extracted is to print the positional information in the zone of this print data.
3. the method for claim 1, wherein ready positional information is to carry out the positional information of the position of printing.
4. if the positional information of the method for claim 1, wherein the being extracted ready positional information that do not match then can not be printed described print data.
5. method as claimed in claim 4, wherein, if the positional information of being extracted does not match ready positional information, then described data managing method can not be printed described print data to user notification.
6. the method for claim 1, wherein described print data is a private data of having used encipherment scheme.
7. method as claimed in claim 6, wherein, described printing step comprises:
If the positional information of being extracted is matched with ready positional information, then decipher private data; With
Print the private data of deciphering.
8. method as claimed in claim 7, wherein, by encrypting the safety of the positional information that guarantees to be affixed to given print data.
9. method as claimed in claim 7, wherein, metadata is affixed to given print data, and this metadata comprises any information about given print data.
10. data managing method comprises:
Generation is about the positional information in the zone that can form image; With
The positional information that is generated is appended to print data file,
Wherein, in producing step, use given first authentication secret to encrypt the positional information that is produced, use the second given authentication secret encrypted print data, and first authentication secret is different from second authentication secret.
11. method as claimed in claim 10 wherein, obtains the private data file by positional information is included in the print data file.
12. method as claimed in claim 10, wherein, at least one in print data and the positional information is encrypted.
13. method as claimed in claim 10, wherein, in producing step, produce private data and positional information, and in additional step, insert the private data that is produced by the positional information that will be produced and create print data file, wherein private data obtains by encrypting given print data.
14. method as claimed in claim 13, wherein, described generation step also comprises encrypted location information, and in additional step, the positional information of encrypting is inserted private data.
15. method as claimed in claim 13 also comprises:
Metadata is inserted additional result,
Wherein said metadata comprises any information about print data.
16. a data administrator comprises:
The positional information extraction apparatus is used to extract the positional information that is affixed to given print data;
Detector is used to determine whether the positional information of being extracted mates ready positional information; With
Image-generating unit if the positional information that is used for being extracted is mated ready positional information, is then printed described print data,
Wherein, use first authentication secret to encrypt and be affixed to the positional information of given print data, and in the information extractor of position, carry out described extraction by using the first given authentication secret to decipher the positional information that is affixed to given print data,
In image-generating unit, the print data that private data is to use second authentication secret to encrypt, and if the positional information of being extracted be matched with ready positional information, then use given second authentication secret decipher private data and
Second authentication secret is different from first authentication secret.
17. device as claimed in claim 16, wherein, the positional information of being extracted is to print the positional information in the zone of described print data.
18. device as claimed in claim 16, wherein, ready positional information is the positional information of positioning and imaging cell position.
19. device as claimed in claim 16, wherein, the ready positional information if the positional information of being extracted does not match then can not be printed described print data.
20. device as claimed in claim 19, wherein, if the positional information of being extracted does not match ready positional information, then described data administrator can not be printed described print data to user notification.
21. device as claimed in claim 16, wherein, described print data is a private data of having used encipherment scheme.
22. device as claimed in claim 21 also comprises:
The data of maintaining secrecy if the positional information that is used for being extracted is matched with ready positional information, are then deciphered in the file decryption unit,
Wherein image-generating unit is printed the private data of deciphering.
23. a data administrator comprises:
The positional information generator is used to produce the positional information about the zone that can form image; With
Positional information is inserted the unit, and the positional information that is used for being generated appends to print data file
Wherein, in producing step, use given first authentication secret to encrypt the positional information that is produced, use the second given authentication secret encrypted print data, and first authentication secret is different from second authentication secret.
24. device as claimed in claim 23 wherein, obtains the private data file by positional information is included in the print data file.
25. device as claimed in claim 23, wherein, at least one in print data and the positional information is encrypted.
CNB200610100112XA 2005-06-28 2006-06-28 Data managing method and device Expired - Fee Related CN100541414C (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
KR1020050056501A KR100644704B1 (en) 2005-06-28 2005-06-28 Apparatus and method for managing a secure document
KR56501/05 2005-06-28
KR69669/05 2005-07-29

Publications (2)

Publication Number Publication Date
CN1892581A CN1892581A (en) 2007-01-10
CN100541414C true CN100541414C (en) 2009-09-16

Family

ID=37597481

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB200610100112XA Expired - Fee Related CN100541414C (en) 2005-06-28 2006-06-28 Data managing method and device

Country Status (2)

Country Link
KR (1) KR100644704B1 (en)
CN (1) CN100541414C (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101321478B1 (en) 2012-02-22 2013-10-28 숭실대학교산학협력단 Method and Apparatus for controlling application execution

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001306273A (en) * 2000-04-26 2001-11-02 Fuji Xerox Co Ltd Method for controlling image output and device for outputting picture
CN1423206A (en) * 2001-12-05 2003-06-11 佳能株式会社 Safty printing using secrete key after being checked
WO2004022350A1 (en) * 2002-08-30 2004-03-18 Seiko Epson Corporation Printer and print system, data receiving device and data sending/receiving system
CN1489034A (en) * 2002-10-07 2004-04-14 ���ǵ�����ʽ���� Method and apparatus for printing web page
CN1613050A (en) * 2002-06-17 2005-05-04 精工爱普生株式会社 Printer, server and print system, and data receiving device and data sending/receiving system

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001306273A (en) * 2000-04-26 2001-11-02 Fuji Xerox Co Ltd Method for controlling image output and device for outputting picture
CN1423206A (en) * 2001-12-05 2003-06-11 佳能株式会社 Safty printing using secrete key after being checked
CN1613050A (en) * 2002-06-17 2005-05-04 精工爱普生株式会社 Printer, server and print system, and data receiving device and data sending/receiving system
WO2004022350A1 (en) * 2002-08-30 2004-03-18 Seiko Epson Corporation Printer and print system, data receiving device and data sending/receiving system
CN1489034A (en) * 2002-10-07 2004-04-14 ���ǵ�����ʽ���� Method and apparatus for printing web page

Also Published As

Publication number Publication date
CN1892581A (en) 2007-01-10
KR100644704B1 (en) 2006-11-10

Similar Documents

Publication Publication Date Title
JP4055807B2 (en) Document management method, document management system, and computer program
CN101118586B (en) Information processing apparatus, data processing apparatus, and methods thereof
CN1326027C (en) Print data communication with data encryption and decryption
US20080298596A1 (en) Image encryption/decryption system
EP1341367B1 (en) Encryption of image data stored in a digital copier
KR20070028559A (en) Image forming apparatus, image forming method, information processing apparatus, and information processing method
KR20100021965A (en) Document data encryption method and document data encryption system
JP5434322B2 (en) Processing decision device, image processing device, processing decision system, and program
JP2004152263A (en) Document printer
JP2004260750A (en) Document processing apparatus, image forming medium, document restoration apparatus, document management method, and program
JP2007257527A (en) Printing system and control method
JP4629581B2 (en) Output information management system
KR20110027031A (en) Image forming apparatus, method for image processing thereof, and image forming system
JP2004164604A (en) Electronic file management device, program, and file access control method
JP4396377B2 (en) Print control system, server device
US8054482B2 (en) Locality permission based printing
CN100541414C (en) Data managing method and device
JP2004152262A (en) Document print program, document protection program, and document protection system
JP3984951B2 (en) Content usage frequency limiting method, content usage terminal device, content usage system, computer program, and computer-readable recording medium
JP4971847B2 (en) Image processing device
JP2003087458A (en) Image forming system with security protecting function
JP4141445B2 (en) Image forming apparatus
JP4176049B2 (en) Image processing apparatus, image forming apparatus, and wide area printing system
JP4595985B2 (en) Document management method, document management system, and computer program
JP2009199390A (en) Image forming apparatus, electronic device and program

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20170302

Address after: Gyeonggi Do, South Korea

Patentee after: Aisi Printing Solutions Co.,Ltd.

Address before: Gyeonggi Do, South Korea

Patentee before: Samsung Electronics Co.,Ltd.

CP01 Change in the name or title of a patent holder

Address after: Gyeonggi Do, South Korea

Patentee after: HP printer Korea Co., Ltd.

Address before: Gyeonggi Do, South Korea

Patentee before: Aisi Printing Solutions Co.,Ltd.

CP01 Change in the name or title of a patent holder
TR01 Transfer of patent right

Effective date of registration: 20191104

Address after: Texas, USA

Patentee after: HP Development Corporation, Limited Liability Partnership

Address before: Han Guojingjidao

Patentee before: HP printer Korea Co., Ltd.

TR01 Transfer of patent right
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20090916

Termination date: 20210628

CF01 Termination of patent right due to non-payment of annual fee