Remote programming of unique and secure supply tags
Through the remote programming system, the use of issuing server and digital signature technology, the security problem of updating the printer supply label information is solved, and safe and convenient information update is achieved in the card personalized machine of the authorized entity.
Patent Information
- Application Number
- CN202080088620.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-11-20
- Filing Date
- 2020-11-20
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2040-11-20
AI Technical Summary
In the prior art, the consumable supply label of the printer is difficult to safely program and update after manufacture and distribution, and the private key is susceptible to unauthorized access, resulting in difficulty in updating information.
Remote programming and update system is adopted to verify the identity of the authorized entity through the issuing server, and use unique authorized entity code and digital signature to protect the supply label data, ensuring that information is effectively updated in the authorized entity's card personalized machine.
It realizes the safe and convenient update of supply label information in the card personalized machine of the authorized entity, ensuring the safety and effectiveness of printer use.
Smart Images

Figure CN114830130B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to remotely programming and / or updating electronic tags associated with consumable supply items of a printer. Background Art
[0002] The use of printing supplies in card personalization machines is well known. In some embodiments, the printing supply may include a supply roll and a take-up roll, on which the spent ribbon material is wound during use of the ribbon supply. It will be appreciated that the printing supply may include a secure supply label that can communicate with the card personalization machine using a secure communication protocol (e.g., private and public key infrastructure). After manufacture and distribution, programming and / or updating the information on the supply label may be difficult because the private key may become vulnerable to unauthorized access by unwanted third parties. Summary of the Invention
[0003] The present disclosure relates to remotely programming and / or updating electronic tags associated with consumable supply items of a printer.
[0004] Embodiments described herein are directed to remote programming of security supply tags for allowing authorized entities to modify the security supply tags.In some embodiments, the security supply tags may be unique.
[0005] Described herein are improved systems, methods, and supply items that can allow an authorized entity (e.g., an authorized partner or distributor) to remotely update one or more data fields or information on a secure label of a supply item. A supply item can include a secure label containing data programmed into the label during the supply item's manufacture. The remote programming disclosed herein provides a convenient and secure method for updating information on the label once the supply item has been distributed to an authorized entity. In some embodiments, first supply information (e.g., an authorized entity code, various attribute data such as optimal printer settings, and combinations thereof) can be received by an issuing server. The issuing server can verify the authenticity of the authorized entity and / or the first supply information and, if successfully authenticated, update one or more data fields to form second or updated supply information and send the second supply information to the authorized entity. In some embodiments, the security label can also include a first digital signature protecting the first supply information. The first digital signature can also be received by the issuing server and used to authenticate the printer vendor. In some embodiments, a second or updated digital signature can be generated and sent by the issuing server along with the second supply information, with the second digital signature protecting the second supply information. In some embodiments, the second digital signature can be based on the second supply information. In one embodiment, the second digital signature may be generated using the private key that generated the first digital signature, while in other embodiments, a different private key may be used to generate the second digital signature.
[0006] In some embodiments described herein, each authorized entity is assigned at least one authorized entity code, which can be programmed onto a supply label of a print supply. The authorized entity code can be a unique identifier for the authorized entity. When the print supply is loaded into a card personalization machine provided by the authorized entity, the card personalization machine verifies that the authorized entity code stored on the supply label is present and correct before allowing the print supply to be used. The supply label also includes various attribute data that the card personalization machine can use to determine, for example, the optimal settings to use when performing a print operation with the print supply, how much print supply is left on the print supply, and the like.
[0007] In some embodiments described herein, the supply labels can be reprogrammed by a user computer (e.g., an authorized entity computer) to include an updated authorized entity code, which can be protected by a new digital signature unique to the supply labels. The card personalization machine (e.g., a desktop card printing device) includes a public key that can verify the new digital signature, thereby verifying that the printed supplies with the updated authorized entity code are authorized for use with the card personalization machine.
[0008] In one embodiment, a method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity is provided. The method includes an issuing server receiving first supply label data of printed supplies including a first digital signature and a first authorized entity code. The method also includes the issuing server updating the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity, and the issuing server issuing a new digital signature based on the second or updated supply label data. The second authorized entity code matches the printed supplies to the authorized entity's card personalization system. The new digital signature protects the updated supply label data including the second authorized entity code.
[0009] In another embodiment, a method for remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity is provided. The method includes an issuing server receiving first supply label data of the printed supplies including a first digital signature and a first authorized entity code, and authenticating the remote programming of the supply label. The method also includes the issuing server updating the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity, and the issuing server issuing a new digital signature based on the updated supply label data. The method also includes the issuing server sending the updated supply label data to the authorized entity for programming onto the supply label along with the new digital signature. The second authorized entity code matches the printed supplies to the authorized entity's card personalization system. The new digital signature protects the updated supply label data including the second authorized entity code.
[0010] In yet another embodiment, a system for remotely programming supply labels for printed supplies for use with a card personalization machine is provided. The system includes an authorized entity computer, an issuing server, and a secure element storage, such as an HSM (hardware security module). The authorized entity computer receives first supply label data from the supply labels for the printed supplies and sends the first supply label data to the issuing server. In some embodiments, the first supply label data may include a first authorized entity code not associated with the card personalization machine. The issuing server authenticates the remote programming of the supply label, receives the first supply label data from the authorized entity computer, updates the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity to form second supply label data, and issues a new digital signature based on the second supply label data. The secure element storage generates a new digital signature for the supply label. The second authorized entity code matches the printed supplies to the authorized entity's card personalization system. The new digital signature protects the second supply label data including the second authorized entity code.
[0011] Furthermore, in another embodiment, a printer supply for a card personalization machine is provided. The printing supply includes a supply roll and a supply label. The supply roll is used in a printing process in the card personalization machine. The supply label is attached to the supply roll and includes a rewritable memory storage device that stores first supply label data and a digital signature. The rewritable memory storage device is programmable to store a new digital signature and an updated authorized entity code, which is provided remotely from, for example, a manufacturing location of a print vendor. The updated authorized entity code matches the printed supply for the card personalization machine, and the updated digital signature protects the date of a second or updated supply label that includes the updated authorized entity code.
[0012] Furthermore, in another embodiment, a method for shipping printed supplies is provided. The method includes shipping the printed supplies with a supply label. The supply label stores a first digital signature and a first authorized entity code. The method also includes allowing a user to remotely reprogram the supply label to include an updated authorized entity code and a new digital signature, the updated authorized entity code matching the printed supplies to a card personalization machine of an authorized entity, and the new digital signature protecting the updated supply label data including the updated authorized entity code.
[0013] In another embodiment, a method for remotely programming a supply label for printed supplies for use with a card personalization system of an authorized entity is provided. The method includes an issuing server authenticating the remote programming of the supply label. The method also includes the issuing server receiving first supply label data and a first digital signature for the printed supplies. Furthermore, the method includes the issuing server updating the first supply label data to obtain second supply label data, and generating a second digital signature based on the second supply data. Furthermore, the method includes the issuing server issuing the second supply label data and the second digital signature. The second digital signature protects the second supply label data.
[0014] In yet another embodiment, a method is provided for remotely programming a supply label for a printed supply for use with a card personalization system of an authorized entity. The supply label includes supply label data and a first digital signature protecting the supply label data. The method includes writing a second digital signature to the supply label, the second digital signature protecting the supply label and / or the printed supply to the authorized entity's personalization device.
[0015] In another embodiment, a method for providing remote programming of a supply label for printed supplies for use with a card personalization system of an authorized entity is provided. The method includes an issuance server authenticating the remote programming of the supply label, receiving first supply label data of the printed supplies including a first digital signature, updating the first supply label data to obtain second supply label data, and issuing a second digital signature based on the second supply label data. The second digital signature protects the second supply label data.
[0016] Furthermore, in another embodiment, a method for remotely programming a supply label for printed supplies for use with a card personalization system of an authorized entity is provided. The method includes an issuance server authenticating the remote programming of the supply label, receiving supply label data for the printed supplies including a first digital signature, and issuing a second digital signature unique to an encryption key of the authorized entity, wherein the first digital signature and the second digital signature are to be simultaneously stored on the supply label. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A supply of print ribbon according to one embodiment is shown;
[0018] Figure 2A-2C A rewritable memory storage device for printing supply labels for supplies for use with an authorized entity's card personalization machine, before and after remote programming, is shown according to three different embodiments.
[0019] Figure 3 A system for remotely programming supply labels for printed supplies used with a card personalization machine is shown according to one embodiment.
[0020] Figure 4 A flow chart illustrating a method for providing remote programming of supply labels for printed supplies for use with a card personalization machine of an authorized entity, according to one embodiment, is shown. DETAILED DESCRIPTION
[0021] The present disclosure relates to remotely programming and / or updating electronic tags associated with consumable supply items of a printer.
[0022] Embodiments described herein are directed to remote programming of a secure supply tag to allow an authorized entity to modify data or applications stored in the secure supply tag.In some embodiments, the secure supply tag may be a unique and secure supply tag.
[0023] The embodiments described herein can be used in card personalization machines. Types of printing devices and subassemblies of printing devices (hereinafter referred to as printing devices) used for card personalization can include, for example, central card issuance systems, desktop card printers, desktop embossers, passport systems, desktop laminators, desktop embossers, smart card readers, input and / or output card hoppers, etc.
[0024] Card personalization machines can be designed for relatively small-scale, individual document personalization and production. In these systems, a single document to be personalized is input into a processor, which typically includes one or two personalization / processing capabilities, such as printing and chip programming. These processors are often referred to as desktop processors because they have a relatively small footprint, allowing the processor to be located on a desktop. Many examples of desktop processors are known, such as the SD or SP series desktop card printers produced by Entrust Datacard, Inc. of Shakopee, Minnesota. Other examples of desktop processors are disclosed in U.S. Patents 7,434,728 and 7,398,972, each of which is incorporated herein by reference in its entirety.
[0025] For high-volume production of personalized documents, organizations often utilize systems that employ multiple processing stations or modules to process multiple documents simultaneously, reducing the total processing time per document. Examples of such systems are disclosed in U.S. Patents 4,825,054, 5,266,781, and its successors 6,783,067 and 6,902,107, all of which are incorporated herein by reference in their entirety. Like desktop document processors, batch processing systems typically also include printing and chip programming capabilities.
[0026] For convenience, the supplies in the embodiments described herein will be described with respect to print ribbon supplies. However, it should be appreciated that the concepts described herein are applicable to other types of print supplies, including, for example, liquid supplies (e.g., ink), laminate supplies, print foil supplies, and the like.
[0027] It should be understood that in some embodiments, the authorized entity may be, for example, a partner of a card personalization machine manufacturer, a dealer, a distributor, etc. The authorized entity may have a distribution or resale region and may wish to update the supply information on the label to be specific to or match the printing systems sold and / or serviced by the authorized entity in that region.
[0028] As used herein, the terms "program" and "programming" may include updating one or more information fields or data stored in a memory on a supply label, including, for example, an authorized entity code, optimal printer setting data, a digital signature, combinations thereof, and the like.
[0029] Figure 1 A printing supply 10 is shown according to one embodiment. The supply 10 includes a print ribbon 12 (e.g., a multi-color print ribbon) and a carrier 24 for holding the print ribbon 12, wherein the print ribbon 12 supplies dye or ink used in the printing process. The ribbon 12 is wound on a cylindrical supply roll 14. The ribbon 12 includes a take-up end 16 that is attached to a drum-shaped take-up roll 18, on which the used ribbon is wound. Figure 1 , an unused ribbon 12 is shown with substantially its entire length wound on a supply roll 14, with the end 16 of the ribbon 12 attached to a take-up roll 18, ready for the used ribbon to be taken up. A cap 28 is attached to one end of the take-up roll 18, and a cap 30 is attached to one end of the take-up roll 14.
[0030] The take-up roller 18 includes a supply label 50 mounted on a cap 50. It should be understood that in other embodiments, the supply label 50 can be located anywhere on the supply 10. The supply label 50 includes rewritable memory to store information about the supply items, as well as other information. The rewritable memory is a read / write memory that allows data to be read from and written to the rewritable memory. In some embodiments, the rewritable memory of the supply label 50 includes at least one digital signature that allows the supply label 50 to securely exchange data with, for example, a card personalization machine, an issuing server, etc., using a public key infrastructure (PKI). Furthermore, the rewritable memory may also include an authorized entity code that matches the supply 10 only for use with the authorized entity's card personalization machine. This authorized entity code may be an update code provided as part of the remote programming process described herein. The rewritable memory may also store information regarding the remaining amount of ribbon remaining on the supply roller. The remaining ribbon information is decremented in the memory device based on the print job using information provided by the controller of the card personalization machine. An example of a memory storage device for a supply tag, such as supply tag 50, is described below with reference to Figure 2A -C is discussed in more detail
[0031] In some embodiments, supply tag 50 is a radio frequency identification tag mounted on cap 28. A suitable RF receiver / transmitter will be located in the card personalization machine, adjacent to the end of take-up roller 18, for reading and writing data to supply tag 50. When printing supplies 10 are loaded into a card personalization machine provided by an authorized entity, the card personalization machine verifies that the authorized entity code stored in supply tag 50 is present and correct (e.g., associated with an authorized entity or a universal code) before allowing use of printing supplies 10. Supply tag 50 also includes various attribute data that the card personalization machine can use to determine, for example, the optimal settings to use when performing a print operation with the printing supply, how much supply is left on the printing supply, etc.
[0032] The use and operation of RF identification tags is known from US Patent 6,099,178. In other embodiments, the supply tag 50 may be a contact chip. It should be understood that the supply tag 50 may be any type of programmable data storage device having read and write capabilities.
[0033] The carrier 24 forms a structure onto which the rollers 14, 18 and the ribbon 12 can be mounted, which can then be inserted into the printing device of a card personalization machine. The carrier 24 includes a handle portion 32 disposed between opposing end regions 34, 36. The handle portion 32 and the end regions 34, 36 are preferably made of plastic to reduce the weight of the carrier 24. The end regions 34, 36 are generally circular and have a diameter greater than the diameter of the cylindrical bodies 14, 18.
[0034] The handle portion 32 includes a connecting plate 38 connecting the end regions 34, 36. A plate 40 extends substantially perpendicularly from the plate 38 and the end regions 34, 36. The plate 40 includes an upwardly curved upper surface and forms a handle by which the carrier 24 can be held in a person's hand.
[0035] Figure 2A -C shows a printed supply for use with an authorized entity's card personalization machine (e.g., Figure 1 Several examples of rewritable memory storage devices for supply tags of supplies 10 are shown.
[0036] In particular, Figure 2AA supplies label 200 is shown before and after one embodiment of remote programming. The supplies label 200 includes a rewritable memory storage device 202. In this embodiment, the rewritable memory storage device 202 before remote programming includes a unique label identifier 204, one or more fields or data 206 containing printer supplies information, and a first digital signature 208 securing the printer supplies information at 206 to the unique label identifier 204. In these embodiments, after remote programming has been completed, the supplies label 200' includes the unique label identifier 204, updated printer supplies information in the fields or data 206' (i.e., one or more data fields or information have been modified), and a new or second digital signature 208' securing the updated printer supplies information at 206' to the unique label identifier 204. Thus, in this embodiment, some or all of the printer supplies data and the digital signature have been updated as part of the remote programming process. The printer supply data may include various attribute data that the card personalization machine may use to determine, for example, optimal settings to use when performing a printing operation with the printing supply, how much supply is remaining on the printing supply, and the like.
[0037] Figure 2BA supplies label 210 is shown before and after another embodiment of remote programming. The supplies label 210 includes a rewritable memory storage device 212. In this embodiment, the rewritable memory storage device 212 before remote programming includes a unique label identifier 214, one or more fields or data 216 containing printer supply information, a first authorization entity code 217, and a first digital signature 218 protecting the printer supply information at 216 and the first authorization entity code 217. In some embodiments, the first authorization entity code 217 can be a generic code (or alternatively, a placeholder value such as zero) that allows the printing supplies to function in any printer produced by the manufacturer. In this embodiment, the supplies label 200 after remote programming can include the unique label identifier 214, one or more fields or data 216 containing printer supply information, a second or updated authorization entity code 217′, and a second or updated digital signature 218′ protecting the printer supply information at 216 and the second authorization entity code 217′ to the unique label identifier 214. In some embodiments, the second authorized entity code 217' can be unique to the authorized entity such that the print offer will only function in printers sold, serviced, distributed by, or otherwise associated with the authorized entity. In these embodiments, as part of the remote programming process, the first authorized entity code 217 and the first digital signature 218 stored in the rewritable memory storage device 212 have been updated with the second authorized entity code 217' and the second digital signature 218'.
[0038] Figure 2CA supply label 220 is shown before and after another embodiment of remote programming. Supply label 220 includes a rewritable memory storage device 222. In this embodiment, before remote programming, rewritable memory storage device 222 includes a unique label identifier 224, one or more fields or data 226 containing printer supply information, and a first digital signature 227. In some embodiments, this first digital signature 227 can be a factory digital signature provided by the manufacturer at the manufacturing location, which secures the printer supply information at 226 to the unique label identifier 224. In these embodiments, after remote programming, supply label 200 can include the unique label identifier 224, one or more fields or data 226 containing printer supply information, the first digital signature 227, and an authorized entity digital signature 228, which can be a second digital signature securing the label / printer supply to the authorized entity's personalized device. The authorized entity digital signature can be provided or generated by the authorized entity using, for example, the authorized entity's cryptographic key. Thus, after remote programming, rewritable memory storage device 222 of supply tag 220 may store both first digital signature 227 and authorized entity digital signature 228 .
[0039] about Figure 2A -C, memory storage devices 202, 212, 222 include a plurality of registers or fields that can store various types of data related to the printed supplies (e.g., unique label identifier(s), printer supply information, digital signature(s), authorized entity code(s), etc.). It should be understood that each of the memory storage devices 202, 212, 222 has a limited storage capacity, and therefore the amount of data that can be stored in the memory storage devices 202, 212, 222 is limited.
[0040] In these examples, one register may store a serial number and / or part number for a print supply. It will be appreciated that the serial number and / or part number may be unique for each supply label, and that the unique serial number and / or part number may be a unique label identifier. Other registers may store various attributes of the print supply. This may include, for example, the length of the print supply, the color of the print supply, supply-specific settings (offset, temperature, counters, parameters for print control, etc.), and so forth. Additional registers may store a first authorized entity code. Another register may store a first digital signature prior to remote programming. The first digital signature may be an initial digital signature (e.g., a factory digital signature) stored in the supply label 200 during manufacture of the print supply, and may allow the issuing server to verify that the supply label is part of an authenticated print supply that may be remotely programmed.
[0041] Following remote programming of the supply tag, the register of the supply tag may or may not include the first digital signature, depending on how the authorized entity remotely programmed the supply tag. In some embodiments, the supply tag may include the first digital signature and a new or second digital signature. In these embodiments, the authorized entity's card personalization machine may include two public keys, where the first public key is common to all potential users / card personalization machines and the second public key is unique to each authorized entity. Thus, the first public key can be used to verify that the first digital signature accurately reflects the data stored in the supply tag, and the second public key can be used to verify that the supply tag can be used in association with the authorized entity's personalization device. Thus, the print supply will only work in a card personalization machine that has the appropriate public keys for each previously valid digital signature and the new digital signature.
[0042] In some embodiments, the first authorized entity code may be an initial authorized entity code. The first authorized entity code may be a default authorized entity code programmed onto the supply label that allows the supply label to be used with any card personalization machine or other device authorized by the manufacturer. The second authorized entity code may bind the supply label to one or more card personalization machines or devices associated with the authorized entity (e.g., sold, serviced, etc. by the authorized entity) such that only printed supplies with the updated identifier will work in the authorized entity's card personalization machine(s). In some embodiments, the second authorized entity code may be unique to the authorized entity.
[0043] The new digital signature stored in the register of the rewritable memory storage device of the supply tag uses, for example, a public key and a private key infrastructure (PKI) to digitally sign the data stored or to be stored in the supply tag. In some embodiments, the data stored or to be stored in the supply tag can be hashed. The private key is then used to create a digital signature of the hashed data. It should be understood that in some embodiments, the digital signature can be created without hashing the data stored or to be stored in the supply tag. In these embodiments, the private key can be used to create a digital signature of the data stored or to be stored in the supply tag.
[0044] In some embodiments, a new digital signature stored in the rewritable memory storage device can digitally sign entity-specific and / or other data to be stored in the supply tag. The entity-specific data can be data specific to an authorized entity and can be remotely programmed by a user computer.
[0045] In some embodiments, one or more cryptographic algorithms (e.g., one or more elliptic curve algorithms, one or more Rivest-Shamir-Adleman (RSA) algorithms, etc.) may be used to create a digital signature with a private key. The authorized entity's card personalization machine includes a public key that can be used to verify that the digital signature accurately reflects the data stored on supply label 200. Thus, it can be determined that the printed supplies are authorized for use with the authorized entity's card personalization machine.
[0046] Figure 3 A system 300 is shown according to one embodiment for printing supply labels 325 (e.g., Figure 2A -B) for remote programming. System 300 includes a user computer 310, an issuing server 330, and a secure element storage 340.
[0047] User computer 310 may be a portal that allows authorized entities access to provide remote programming of supply labels 325. Specifically, user computer 310 may communicate with issuance server 330 by, for example, logging into the application portal to communicate with issuance server 330 over the Internet. In some embodiments, the application portal may authenticate the user via a Secure Sockets Layer (SSL) encryption protocol, a Transport Layer Security (TLS) encryption protocol, or the like.
[0048] User computer 310 also includes a peripheral device 315 (e.g., a smart card reader, a near field communication (NFC) device, a radio frequency identification (RFID) wand, etc.) that can communicate with supply tags 325 of printed supplies 320. In some embodiments, peripheral device 315 can be a contact reader that can read and / or write to supply tags 325 when peripheral device 315 is in physical contact with supply tags 325. In other embodiments, peripheral device 315 can be a contactless reader that can read and / or write to supply tags 325 without physical contact with supply tags 325. In some embodiments, user computer 310 can read supply tag data from supply tags 325 via peripheral device 315 and transmit the supply tag data to issuance server 330 via, for example, an application portal. Peripheral device 315 can be, for example, an RFID wand. In some embodiments, user computer 310 can receive a new digital signature for supply tags 325 from issuance server 330. In some embodiments, user computer 310 can access the authorized entity code and / or other data to be programmed onto supply tag 325. User computer 310 can also reprogram / store supply tag 325 via peripheral device 315 with a new digital signature and updated data (e.g., authorized entity code).
[0049] Optionally, user computer 310 may also communicate with secure element storage 340. In these embodiments, user computer 310 may receive a new digital signature for remotely programming supply tag 325 directly from secure element storage 340.
[0050] Issuing server 330 communicates with user computer 310 and with secure element storage 340. In some embodiments, issuing server 330 can authenticate the user at user computer 310 as an authorized entity via, for example, an application portal. Furthermore, issuing server 330 can communicate with secure element storage 340 to obtain a new digital signature and send the new digital signature to user computer 310. In some embodiments, issuing server 330 can provide supply label data to secure element storage 340. In some embodiments, issuing server 330 can also access an updated authorized entity code for a particular user and transmit the updated authorized entity code to user computer 310. In some embodiments, issuing server 330 can authorize user computer 310 to obtain a new digital signature from secure element storage 340 to be stored in supply label 325 along with the previously valid digital signature.
[0051] Secure element storage 340 securely stores private keys and can generate new digital signatures for supply labels 325 based on supply label data provided by issuance server 330. In some embodiments, secure element storage 340 is part of issuance server 330. Furthermore, in some embodiments, secure element storage 340 is a hardware security module (HSM). As defined herein, an HSM refers to a physical computing device that protects and manages cryptographic objects used to store authentication and provide cryptographic processing. It should be understood that by using a private key to generate a new digital signature, the private key can remain securely stored in secure element storage 340 and cannot be transmitted outside of secure element storage 340, including, for example, to an authorized entity. It will also be understood that in some embodiments, the private key used to generate the new digital signature is the same as the private key used to generate the previously valid digital signature. In other embodiments, the private key used to generate the new digital signature can be different from the private key used to generate the previously valid digital signature.
[0052] Refer to the following Figure 4 A method for providing remote programming of supply tags for use with system 300 is described.
[0053] Figure 4 A flow chart illustrating a method 400 according to one embodiment for providing printed supplies for use with a card personalization machine of an authorized entity (e.g., Figure 3Supply labels (e.g., printed supplies 320) are shown Figure 3 Remote programming of the supply tag 325 shown.
[0054] Method 400 begins at 405 whereby an issuing server (e.g., Figure 3 The issuing server 330 shown) sends the user computer (e.g. Figure 3 The user at the user computer 310 (shown as FIG400 ) is authenticated as an authorized entity. When the user is authenticated as an authorized entity, the user may be authorized to provide remote programming of supply labels for printed supplies. In some embodiments, the authorized entity authentication may be performed by the user logging into an application portal to communicate with the issuance server via the Internet. In some embodiments, the application portal may authenticate the user via a Secure Sockets Layer (SSL) encryption protocol, a Transport Layer Security (TLS) encryption protocol, or the like. Method 400 then proceeds to 410.
[0055] At 410, the user computer may read a supply label of a printed supply. In some embodiments, the user computer may have a peripheral device (e.g., Figure 3 The peripheral device 315 shown can read previous supply label data stored in the supply label. The previous supply label data can include, for example, a serial number and / or part number of the printed supply, various attributes of the printed supply (e.g., length of the printed supply, color of the printed supply, etc.), a first authorized entity code, and a first valid digital signature. The first valid digital signature can be a hash of the first supply label data stored in the supply label. In some embodiments, the first supply label data can be default supply label data, which can be programmed onto the supply label, for example, by the manufacturer. Method 410 then proceeds to 415.
[0056] At 415, the user computer transmits the first supply label data, including the first valid digital signature, to the issuing server. In some embodiments, the first valid digital signature can protect the previous supply label data stored in the supply label as a unique label identifier stored in the supply label. In some embodiments, the first valid digital signature can be a factory digital signature. In some embodiments, the first supply label data can also include a first authorized entity code. Method 400 then proceeds to 420.
[0057] At 420, the issuing server authenticates the print supply based on the first valid digital signature. By authenticating the print supply, the issuing server can verify that the print supply is a print supply that was legally obtained by an authorized entity. This helps prevent authorized entities from attempting to program unauthorized print supplies.
[0058] The combination of authenticating the user as an authorized entity at 405 and authenticating the printed supplies at 420 allows the issuing server to authenticate remote programming of the supply labels. That is, if the user or the supply labels are not authenticated, the issuing server can prevent remote programming of the supply labels. Method 400 then proceeds to 430 or, optionally, 425.
[0059] At optional 425 , the issuing server updates the previous supply label data, which may include replacing the first authorized entity code with an updated or second authorized entity code unique to the authorized entity. Method 400 then proceeds to 430 .
[0060] At 430, the issuing server issues a new digital signature. In some embodiments, the new digital signature may be issued based on updated supply label data. In some embodiments, the new digital signature may be issued based on entity-specific data that is remotely programmable by the user computer. The entity-specific data may be data specific to an authorized entity. In these embodiments, the supply label may include both the new digital signature and the previously valid digital signature.
[0061] The new digital signature is stored by a secure element located within or remote from the issuing server (e.g. Figure 3 The issuing server may create a new digital signature based on the updated supply label data, which may include an updated or second authorization entity code. In some embodiments, the issuing server issues a new digital signature by obtaining the new digital signature from the secure element storage and sending the new digital signature to the user computer. Thus, the supply label can be remotely programmed with the new digital signature while ensuring the security of the new digital signature. Furthermore, in some embodiments, the issuing server may send the updated supply label data (including, for example, the updated authorization entity code) along with the new digital signature to the user computer. In other embodiments, the updated authorization entity code may already be stored on the user computer.
[0062] It should also be understood that in some embodiments, the updated supply label data signed with the new digital signature and returned to the user's computer may simply include the updated authorized entity code. In other embodiments, the updated supply label data signed with the new digital signature and returned to the user's computer may include the updated authorized entity code as well as other previous supply label data on the supply label. It should be understood that the updated supply label data may or may not be hashed before being sent to the user's computer.
[0063] In other embodiments, the issuing server issues a new digital signature by obtaining a new digital signature from a third-party issuing server by authorizing the user computer, and the new digital signature will be stored in the data providing label together with the previous valid digital signature. Therefore, the supply label can be remotely programmed with the new digital signature to prevent one or more private keys stored in the HSM from being leaked. In some embodiments, a new digital signature can be issued using a private key unique to a specific authorized entity. The user computer can use a private key unique to a specific authorized entity to sign the updated supply label data with a unique digital signature. It will be understood that the updated supply label data can then include public supply label data that is common to all potential authorized entities. In addition, in some embodiments, the issuing server can send updated supply label data with an updated authorized entity code to the user computer. In other embodiments, the updated authorized entity code may already be stored in the user computer.
[0064] Method 400 then proceeds to 435 .
[0065] At 435, the user computer reprograms the supply tag with the updated supply tag data (including, for example, the updated authorized entity code) and the new digital signature. In some embodiments, the user computer reprograms the supply tag with the updated supply tag data using only the new digital signature. In other embodiments, the user computer reprograms the supply tag with the updated supply tag data using both the new digital signature and the previously valid digital signature. In these embodiments, the user computer can reprogram the supply tag data to add entity-specific data specific to the authorized entity. Furthermore, in these embodiments, the entity-specific data will be protected by the new digital signature.
[0066] In some embodiments, a user computer may use peripheral devices (e.g., Figure 3 The user computer can reprogram the supply labels with updated supply label data (e.g., including an updated authorized entity code) using a peripheral device 315 shown. It should be understood that the user computer can reprogram the supply labels with updated supply label data using, for example, a locally stored program application, a cloud-based program application, etc. Once the supply labels are stored with the updated authorized entity code, the printed supplies can be paired with the authorized entity's card personalization machine so that the printed supplies can only be used with the card personalization machine of one or more authorized entities.
[0067] Based on the above discussion, it will be appreciated that method 400 can be applied in a variety of ways. For example, in one embodiment, a user computer can remotely program supply labels to update supply label data for a particular setup and be provided with a new digital signature associated with the updated supply label data for use in a card personalization machine at an authorized entity(ies). Thus, printed supplies with the updated supply label data and the new digital signature can only function in a card personalization machine(ies) with the appropriate entity setup. In this embodiment, each card personalization machine (among all authorized entities) can include the same common public key for verifying the new digital signature.
[0068] In another embodiment, a user computer can remotely program entity-specific data into the supply label data and protect the entity-specific data with a new digital signature unique to the authorized entity. The supply label data in these embodiments includes the new digital signature and the previously valid digital signature. Thus, the print supply can only operate in a card personalization machine that has the appropriate public keys for both the new digital signature and the previously valid digital signature. In this embodiment, each card personalization machine can include the same public key for verifying the previously valid digital signature and a unique public key unique to the specific authorized entity and used to verify the new digital signature.
[0069] In yet another embodiment, the user computer may be authorized to sign the supply label data common to all supply labels using a new digital signature unique to the authorized entity, the new digital signature being created using a unique private key unique to the authorized entity. In this embodiment, each card personalization machine can include the same common supply label data with a unique new digital signature. Thus, printed supplies can only be operated on a card personalization machine that has the appropriate public key unique to the authorized entity in order to verify the unique new digital signature.
[0070] The aspects described herein may be embodied as a system, method, or computer-readable medium. In some embodiments, the described aspects may be implemented using hardware, software (including firmware, etc.), or a combination thereof. Some aspects may be implemented in a computer-readable medium, including computer-readable instructions executed by a processor. Any combination of one or more computer-readable media may be used.
[0071] Some embodiments may be provided via a cloud computing infrastructure. Cloud computing generally involves providing scalable computing resources as a service over a network (eg, the Internet, etc.).
[0072] Although many methods and systems are described herein, it is contemplated that a single system or method may include more than one of the above-described subject matter. Thus, multiple of the above-described systems and methods may be used together in a single system or method.
[0073] aspect:
[0074] It should be understood that any of aspects 1-9, 10-21, 22-26, 27, 28-31, 32-34, 35 and 36-37 may be combined.
[0075] Aspect 1. A method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity, the method comprising:
[0076] Remote programming of supply labels for issuance server authentication;
[0077] The issuing server receives first supply label data including a first digital signature and a first authorized entity code for a printed supply;
[0078] the issuing server updating the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity to obtain second supply label data, wherein the second authorized entity code matches the printed supplies to a card personalization system of the authorized entity; and
[0079] The issuing server issues a second digital signature based on the second supply label data;
[0080] Wherein the second digital signature protects second supply label data including a second authorized entity code.
[0081] Aspect 2. The method of aspect 1, wherein the second digital signature is generated using a private key different from that of the first digital signature.
[0082] Aspect 3. The method of aspect 1, wherein the first digital signature and the second digital signature are both generated using the same private key.
[0083] Aspect 4. The method of any of aspects 1-3, wherein authenticating remote programming of the supply tag comprises authenticating the user as an authorized entity with the authority to remotely program the supply tag.
[0084] Aspect 5. The method of any of aspects 1-4, wherein authenticating the remote programming of the supply label comprises authenticating the printed supply based on the first digital signature.
[0085] Aspect 6. The method of any of aspects 1-5, wherein the issuing server issuing a second digital signature based on the second supply label data comprises the issuing server obtaining the second digital signature from the secure element store and sending the second digital signature to the authorized entity.
[0086] Aspect 7. The method of any of aspects 1-5, wherein the issuing server issuing a second digital signature based on the second supply label data comprises the issuing server authorizing the authorization entity to obtain the second digital signature from the secure element store to be stored in the supply label along with the first digital signature.
[0087] Aspect 8. The method of any of Aspects 1-7, further comprising the issuing server sending the second supply label data to an authorized entity for programming onto the supply label along with the second digital signature.
[0088] Aspect 9. The method of any one of aspects 1-8, wherein the second authorized entity code is unique to the authorized entity.
[0089] Aspect 10. A system for remotely programming supply labels for printed supplies used with a card personalization machine, the system comprising:
[0090] an authorization entity computer that receives first supply label data from a supply label of a printed supply and transmits the first supply label data to an issuing server, wherein the first supply label data includes a first authorization entity code that is not associated with a card personalization machine;
[0091] the issuing server authenticating remote programming of the supply label, receiving first supply label data from the authorized entity computer, updating the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity to obtain second supply label data, and issuing a new digital signature based on the second supply label data;
[0092] The secure element stores and generates a new digital signature for the supply tag based on the second supply tag data.
[0093] wherein the second authorized entity code matches the printed supplies to the authorized entity's card personalization machine, and
[0094] The new digital signature protects second supply label data including a second authorized entity code.
[0095] Aspect 11. The system of aspect 10, wherein the secure element storage is a hardware security module.
[0096] Aspect 12. The system of any of aspects 10 and 11, further comprising a peripheral device connected to the authorization entity computer, wherein the peripheral device reads and writes on the supply tag.
[0097] Aspect 13. The system of any of aspects 10-12, wherein the supply tag is a radio frequency identification tag.
[0098] Aspect 14. The system of any of aspects 10-13, wherein the secure element store is part of the issuing server.
[0099] Aspect 15. The system of any of aspects 10-14, wherein the issuing server authenticates the remote programming of the supply tags by authenticating the user as an authorized entity with the rights to remotely program the supply tags.
[0100] Aspect 16. The system of any of aspects 10-15, wherein the issuing server authenticates the remote programming of the supply label by authenticating the printed supply based on a previous digital signature.
[0101] Aspect 17. The system of any of aspects 10-16, wherein the issuing server issues the new digital signature by obtaining the new digital signature from the secure element store and sending the new digital signature to the authorized entity computer.
[0102] Aspect 18. The system of any of aspects 10-16, wherein the issuing server issues the new digital signature by authorizing the authorization entity computer to obtain the new digital signature from the secure element storage, the new digital signature being stored in the supply tag along with the previous digital signature.
[0103] Aspect 19. The system of any of aspects 10-18, wherein the authorized entity computer remotely programs the supply tag with the new digital signature and the second authorized entity code.
[0104] Aspect 20. The system of any of aspects 10-19, wherein the issuing server sends the second supply label data including the second authorizing entity code to the authorizing entity computer.
[0105] Aspect 21. The system of any of aspects 10-20, wherein the second authorized entity code is unique to the authorized entity.
[0106] Aspect 22. A printed supply for a card personalization machine, the printed supply comprising:
[0107] Supply rolls used in the printing process of card personalization machines; and
[0108] a supply tag attached to the supply roll, the supply tag including a rewritable memory storage device storing first supply tag data and a digital signature,
[0109] wherein the rewritable memory storage device is programmable to store a new digital signature and an updated authorized entity code, and
[0110] wherein the updated authorized entity code matches a printed supply of the card personalization machine and a new digital signature protects second supply label data including the updated authorized entity code.
[0111] Aspect 23. The printing supply of aspect 22, wherein the printing supply is a printing foil.
[0112] Aspect 24. The printing supply of aspect 22, wherein the printing supply is a liquid supply item.
[0113] Aspect 25. The printed supply of any of Aspects 22-24, wherein the supply label includes a plurality of registers, a first register storing a unique serial number or part number of the printed supply, a second register storing attributes of the printed supply, a third register storing a new digital signature, and a fourth register storing an updated authorized entity code.
[0114] Aspect 26. The printed supply of any of Aspects 22-25, wherein the updated authorized entity code is unique to the authorized entity.
[0115] Aspect 27. A method for shipping printed supplies, the method comprising shipping the printed supplies with a supply label, wherein the supply label stores a first digital signature and a first authorized entity code; and allowing a user to remotely reprogram the supply label to include a second authorized entity code for matching the printed supplies to a card personalization machine of an authorized entity, and a second digital signature protecting the supply label data including the second authorized entity code.
[0116] Aspect 28. A method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity, the method comprising:
[0117] Remote programming of supply labels for issuance server authentication;
[0118] The issuing server receives first supply label data and a first digital signature of a printed supply;
[0119] The issuing server updates the first supply label data to obtain second supply label data and generates a second digital signature based on the second supply data; and
[0120] The issuing server issues second supply label data and a second digital signature;
[0121] The second digital signature protects the second supply tag data.
[0122] Aspect 29. The method of aspect 28, wherein the first supply label data includes a first authorized entity code.
[0123] Aspect 30. The method of any one of Aspects 28 and 29, wherein the second digital signature is generated using a different private key than the first digital signature.
[0124] Aspect 31. The method of any one of Aspects 28 and 29, wherein the first digital signature and the second digital signature are both generated using the same private key.
[0125] Aspect 32. A method for providing remote programming of a supply label for a printed supply for use with a card personalization system of an authorized entity, the supply label comprising supply label data and a first digital signature protecting the supply label data, the method comprising:
[0126] A second digital signature is written to the supply label, the second digital signature securing the supply label and / or printed supplies to the personalization device of an authorized entity.
[0127] Aspect 33. The method of Aspect 32, wherein the second digital signature is generated using a private key different from that of the first digital signature.
[0128] Aspect 34. The method of Aspect 32, wherein the first digital signature and the second digital signature are both generated using the same private key.
[0129] Aspect 35. A method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity, the method comprising:
[0130] Remote programming of supply labels for issuance server authentication;
[0131] The issuing server receives first supply label data for a printed supply including a first digital signature;
[0132] The issuing server updates the first supply label data to obtain second supply label data; and
[0133] The issuing server issues a second digital signature based on the second supply label data;
[0134] The second digital signature protects the second supply tag data.
[0135] Aspect 36. A method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity, the method comprising:
[0136] Remote programming of supply labels for issuance server authentication;
[0137] The issuing server receives supply label data for a printed supply including the first digital signature; and
[0138] The issuing server issues a second digital signature unique to the encryption key of the authorized entity, wherein the first digital signature and the second digital signature are to be stored simultaneously in the supply tag;
[0139] The second digital signature protects the second supply tag data.
[0140] Aspect 37. The method of aspect 36, wherein the first digital signature is a factory digital signature provided by the manufacturer at the location of manufacture of the supply label.
[0141] The present invention may be implemented in other forms without departing from the spirit or essential characteristics of the present invention. The embodiments disclosed in this application are to be considered in all respects as illustrative and not restrictive. The scope of the present invention is indicated by the appended claims rather than the foregoing description; and all changes that come within the meaning and range of equivalents of the claims are intended to be embraced therein.
Claims
1. A method for providing remote programming of supply labels for printed supplies for use with a card personalization system of an authorized entity, the method comprising: an issuing server authenticating remote programming of the supply tag by determining that the entity is an authorized entity, wherein the issuing server is remote from the entity; The issuing server receives from the entity first supply label data for the printed supply including a first digital signature and a first authorized entity code; the issuing server authenticating the printed supply by determining that the first digital signature is valid; upon the issuing server determining that the entity is the authorized entity and the first digital signature is valid, the issuing server updating the first supply label data by replacing the first authorized entity code with a second authorized entity code unique to the authorized entity to obtain second supply label data, wherein the second authorized entity code matches the printed supplies to a card personalization system of the authorized entity; as well as The issuing server issues a second digital signature based on the second supply label data; Wherein the second digital signature protects second supply label data including the second authorized entity code.
2. The method of claim 1 , wherein the second digital signature is generated using a different private key than the first digital signature, and / or wherein the first digital signature and the second digital signature are generated using the same private key, and / or The second authorized entity code is unique to the authorized entity.
3. The method of any one of claims 1-2, wherein the issuing server issuing the second digital signature based on the second supply label data comprises the issuing server obtaining the second digital signature from a secure element store and sending the second digital signature to the authorized entity; and / or Wherein issuing the second digital signature based on the second supply label data by the issuing server includes authorizing the authorized entity by the issuing server to obtain the second digital signature from a secure element store to be stored in the supply label along with the first digital signature.
4. The method of any one of claims 1-2, further comprising the issuing server sending the second supply label data to the authorized entity to be programmed onto the supply label along with the second digital signature.
5. A system for remote programming of supply labels for printed supplies for use with a card personalization machine, the system comprising: an authorization entity computer that receives first supply label data from the supply label of the printed supply and sends the first supply label data to an issuing server, the first supply label data including a first digital signature and a first authorization entity code; The issuing server: authenticating remote programming of the supply tag by determining that the entity using the authorized entity code is an authorized entity, receiving said first supply tag data from said authorized entity computer, authenticating the printed supply by determining that the first digital signature is valid, Upon determining that the entity is the authorized entity and the first digital signature is valid, updating the first supply label data and issuing a new digital signature based on the second supply label data; secure element storage, generating the new digital signature for the supply tag based on the second supply tag data, Wherein the new digital signature protects the second supply tag data.
6. The system of claim 5, wherein the secure element storage is a hardware security module, and / or Wherein the secure element store is part of the issuing server.
7. The system of any one of claims 5 and 6, further comprising a peripheral device connected to the authorization entity computer, wherein the peripheral device reads and writes on the supply tags, and / or The supply tag is a radio frequency identification tag.
8. The system according to any one of claims 5-6, wherein the issuing server issues the new digital signature by obtaining the new digital signature from the secure element storage and sending the new digital signature to the authorized entity computer, and / or The issuing server issues the new digital signature by authorizing the authorization entity computer to obtain the new digital signature from the security element storage, and the new digital signature is to be stored in the supply tag together with the previous digital signature.
9. The system of any one of claims 5-6, wherein the authorized entity computer remotely programs the supply tag with the new digital signature and the second authorized entity code.
10. The system according to any one of claims 5-6, wherein the issuing server sends the second supply label data including the second authorizing entity code to the authorizing entity computer, and / or The second authorized entity code is unique to the authorized entity.
11. A printed supply for a card personalization machine, the printed supply comprising: supply rollers used in the printing process of said card personalization machine; as well as a supply tag attached to the supply roll, the supply tag including a rewritable memory storage device storing first supply tag data and a digital signature, wherein the rewritable memory storage device is programmable to store a new digital signature and an updated authorized entity code when the entity is authenticated as an authorized entity and the digital signature is valid, wherein the updated authorized entity code matches a printed supply of the card personalization machine and the new digital signature protects second supply label data including the updated authorized entity code, and Wherein the supply tag includes a plurality of registers, a first register storing a unique serial number or part number of the printing supply, a second register storing attributes of the printing supply, a third register storing the new digital signature, and a fourth register storing the updated authorized entity code.
12. The print supply according to claim 11, wherein the print supply is a print ribbon, or Wherein the printing supply is a liquid supply item or a laminate.
13. The printed supply of any one of claims 11 and 12, wherein the updated authorized entity code is unique to the authorized entity.
Citation Information
Patent Citations
Method and apparatus for parallel integrated circuit card initialization and embossing
US4825054A
Modular card processing system
US5266781A
Printer with media supply spool adapted to sense type of media, and method of assembling same
US6099178A
Passport production system and method
US6783067B2
Card personalization system and method
US6902107B2