Methods and systems for selectively preventing component operation

By introducing system control components and monitoring-implementation modules into the system, the operation signals of untrusted components are selectively interrupted, thus solving the reliability problems caused by untrusted components in the system and ensuring the safe and correct operation of the system.

CN116981567BActive Publication Date: 2025-12-30LEXMARK INTERNATIONAL INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180095657.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-03-18
Filing Date
2021-10-11
Publication Date
2025-12-30
Estimated Expiration
2041-10-11

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively prevent untrusted components from operating in electronic systems, leading to system reliability issues and failing to ensure proper system operation.

Method used

By employing system control components and monitoring-implementation modules, the system selectively interrupts component operation signals by receiving security information, ensuring that only trusted components can operate normally.

Benefits of technology

It improves system reliability, prevents malicious behavior from untrusted components, and ensures system security and proper operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116981567B_ABST
    Figure CN116981567B_ABST
Patent Text Reader

Abstract

An imaging system comprising: a system control component having stored thereon host firmware, the system control component including a print head operation module actuatable by the host firmware to transmit a signal to a print head of the imaging system, the signal configured to cause a print head operation; and a monitor-enforcement module including: a monitor interface configured to receive security information from a security device of the imaging system, and an enforcement module configured to selectively interrupt the signal transmitted by the print head operation module based on the security information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims priority and benefit to U.S. Provisional Application No. 63 / 162,861 entitled “Hardware-based Security Monitoring and Enforcement”, filed on March 18, 2021, under 35U.SC 119(e).

[0003] background 1. Technical Field

[0005] This disclosure generally relates to methods and systems for preventing component operation, and more specifically, to methods and systems for preventing component operation within an imaging apparatus.

[0006] 2. Relevant Technical Descriptions

[0007] In electronic systems, it is often desirable to verify the authenticity of the system's components to ensure that the entire system operates as designed. Once a component is determined to be untrustworthy, the corresponding operation of the electronic system is halted to ensure that the untrustworthy component is not used.

[0008] Untrusted components employ various techniques to mimic the behavior of trusted components and / or modify or manipulate electronic systems to enable the system to operate using the untrusted components. This can include copying the circuitry and memory contents of trusted components to replicate authentication algorithms or to enable encrypted communication between the component and the rest of the electronic system. This is particularly important in printing systems where verifying the trustworthiness of the supply components is crucial to ensure proper operation.

[0009] Therefore, there is a need for improved systems and methods, such as preventing the operation of electronic systems when a component is determined to be untrustworthy.

[0010] Overview

[0011] This disclosure provides example methods and systems that can be implemented in any general electronic system or specifically in an imaging / printing device / system to prevent the use of untrusted components.

[0012] An imaging system is provided, comprising:

[0013] The system control unit stores host firmware and includes a printhead operation module actuated by the host firmware to transmit signals to the printhead of the imaging system, the signals being configured to operate the printhead; and

[0014] The monitor-enforce module includes:

[0015] A monitoring interface configured to receive security information from the security equipment of the imaging system, and

[0016] An implementation module is configured to selectively interrupt the signals transmitted by the printhead operation module based on security information.

[0017] Printhead operation can be prevented by interrupting the signals transmitted by the printhead operation module using the monitoring-implementation module. This system is less susceptible to modification or manipulation of the host firmware (e.g., by untrusted suppliers). Even if the host firmware is modified or manipulated, the implementation module will still prevent printhead operation by interrupting the signal.

[0018] In this application, the term selective interruption refers to an interruption that occurs only when one or more conditions are met, such as when no certification of the supplied articles has occurred since the imaging system was started.

[0019] In some embodiments, system control components may include a SoC, processor, memory, and / or integrated circuit (IC), such as an application-specific integrated circuit (ASIC). In some embodiments, the imaging system includes imaging device safety equipment and / or supply items. The supply items may include supply item safety equipment.

[0020] In some implementations, the monitoring-enforcement module is located on the system control unit, and the monitoring-enforcement module includes a hardware block on the system control unit configured to receive security information and selectively interrupt printhead operation.

[0021] In some implementations, the hardware block is a dedicated hardware block. The dedicated hardware block can be configured to perform only the operations of the monitoring-implementation module.

[0022] In some implementations, the hardware block is configured to perform operations to receive security information and / or selectively interrupt printhead operation.

[0023] In some implementations, the implementation module is configured to interrupt signals transmitted by the printhead operation module via a gate. In some implementations, the gate may be on the system control unit, outside the printhead operation module, or within the printhead operation module.

[0024] In some implementations, the monitoring-implementation module is separate from the system control components. In some implementations, the monitoring-implementation module may be an integrated circuit, such as a microcontroller or ASIC. In some implementations, the monitoring-implementation module is a programmable device. In some implementations, the programmable device is lockable or lockable.

[0025] In some implementations, security information includes: the authentication status of one or more supply items of the imaging system, and / or a disable command, and / or authentication information from one or more supply items of the imaging system.

[0026] In some implementations, the authentication information is a response to a challenge. In some implementations, the challenge is input to an encryption operation to be performed on the supplied item. In some implementations, the challenge may include a random value, which may be generated, for example, from a pseudo-random number generator (PRNG) using encryption operations. In some implementations, the response is the result of the encryption operation. The response may be a checksum and / or a signature.

[0027] In some implementations, the monitoring-enforcement module is configured to generate a challenge. The system control component can be configured to read the challenge from the monitoring-enforcement module and send it to the security device for the supplies.

[0028] In some embodiments, the monitoring interface is configured to receive security information from the imaging system's security communication system. In some embodiments, the monitoring interface is configured to periodically check the security communication system to obtain security information. In some embodiments, the security communication system may include a hardware signaling communication system. In some embodiments, the monitoring interface may be a follower component. In some embodiments, the security communication system is a security communication bus, such as I... 2 C-bus. In some implementations, the monitoring interface is configured to receive signals from the secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0029] In some implementations, the secure communication system is configured to allow the monitoring interface of the monitoring-implementation module to receive communications from the security devices of the supply items of the imaging system, and / or the security devices of the imaging equipment and / or the host firmware.

[0030] In some implementations, the monitoring interface is configured to communicate with the host firmware. The host firmware can be configured to send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from a secure communication system.

[0031] In some embodiments, the monitoring interface is configured to monitor the secure communication system. In some embodiments, the monitoring-implementation module cannot transmit signals on the secure communication system. In some embodiments, the monitoring-implementation module has an address on the secure communication system. In some embodiments, the system control unit sends a challenge to the security device supplying the article on the secure communication system, and the security device supplying the article returns a response to the challenge on the secure communication system. This response is received by the monitoring-implementation module. In some embodiments, the security device supplying the article returns a response to the challenge to the system control unit on the secure communication system, and the monitoring interface of the monitoring-implementation module receives this response by monitoring the secure communication system.

[0032] In some implementations, the implementation module is configured to interrupt the signals transmitted by the printhead operation module when the response is not authenticated. In some implementations, the implementation module is configured to interrupt the signals transmitted by the printhead operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the imaging system has been started.

[0033] In some implementations, the implementation module is configured not to interrupt the signal when the security information confirms the trustworthiness of the supplied item, and the implementation module is configured to interrupt the signal when the security information does not confirm the trustworthiness of the supplied item.

[0034] In some implementations, the implementation module is configured to interrupt the signal when an error occurs. In some implementations, the implementation module is configured to interrupt the signal when the security information contains a disable command.

[0035] In some implementations, the implementation module is configured to interrupt the signal unless security information confirming the reliability of all supplies in the imaging system has been received in the previous time period. The time period can be preset.

[0036] In some implementations, signals are transmitted by the printhead operation module on multiple channels, each corresponding to a specific function of the printhead, and the implementation module is configured to selectively interrupt each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0037] In some implementations, each channel can be interrupted by a corresponding gating, and the implementation module is configured to selectively interrupt each channel by selectively operating the corresponding gating.

[0038] In some implementations, the security information is a Security Status Packet (SSP). In some implementations, the SSP originates from a supply item security device. In some implementations, the SSP originates from an imaging device security device.

[0039] In some implementations, the printhead operation module is a video output terminal.

[0040] In some implementations, the host firmware is configured to perform functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0041] A method for implementing security on the imaging system described above is also provided, the method comprising: selectively interrupting signals transmitted by the printhead operation module based on security information by an implementation module.

[0042] In some implementations, interruption by the implementation module includes operating the gating.

[0043] In some embodiments, the method further includes receiving security information from the imaging system's security communication system via a monitoring interface. In some embodiments, the method further includes periodically checking the imaging system's security communication system via the monitoring interface to obtain security information.

[0044] In some implementations, the monitoring interface receives signals from the secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0045] In some implementations, security information includes: the authentication status of one or more supply items of the imaging system, and / or a disable command, and / or authentication information from one or more supply items of the imaging system.

[0046] In some implementations, authentication information is a response to a challenge. In some implementations, a challenge is input to an encryption operation to be performed on the supplied item. In some implementations, a challenge may include a random value, which may be generated, for example, from a pseudo-random number generator (PRNG) using encryption operations. In some implementations, the response is the result of an encryption operation. The response may be a checksum and / or a signature.

[0047] In some embodiments, the method further includes: sending a challenge by a system control component to a security device supplying the article to the imaging system via a secure communication system, and receiving authentication information from the security device supplying the article via a monitoring interface via the secure communication system, the authentication information being a response to the challenge.

[0048] In some implementations, the monitoring-enforcement module performs an authentication process on the response to determine whether the supply item is trustworthy. The authentication process may include cryptographic methods such as HMAC or CMAC, or may include signature and / or verification using RSA / ECDSA, or another cryptographic operation. Security information may include an HMAC or CMAC checksum on the security state payload of the security information. The authentication process may include the monitoring-enforcement module calculating the checksum on the security state payload and comparing the result with an HMAC or CMAC checksum. If a signature scheme is used, the security information may include a signature of the security state payload, for example, signed with a private key contained in the supply item's security device. The monitoring-enforcement module may be configured to verify the signature with the corresponding public key during the authentication process.

[0049] In some implementations, the challenge is an cryptographic operation. In some implementations, the response is the result of a cryptographic operation. The response may be a checksum and / or a signature.

[0050] In some implementations, the monitoring interface receives communications from the security device for supplying articles to the imaging system, and / or the security device for the imaging equipment and / or the host firmware via a secure communication system.

[0051] In some implementations, the monitoring interface communicates with the host firmware. The host firmware can send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from the secure communication system.

[0052] In some implementations, the monitoring interface monitors the secure communication system. In some implementations, the monitoring-implementation module cannot transmit signals on the secure communication system. In some implementations, the monitoring-implementation module has an address on the secure communication system.

[0053] In some implementations, the implementation module interrupts the signal transmitted by the printhead operation module when the response is not authenticated. In some implementations, the implementation module interrupts the signal transmitted by the printhead operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the imaging system was started.

[0054] In some implementations, the implementation module does not interrupt the signal when the security information confirms the reliability of the supplied items, and interrupts the signal when the security information does not confirm the reliability of the supplied items.

[0055] In some implementations, a module interrupt signal is implemented when an error occurs. In some implementations, a module interrupt signal is implemented when the security message contains a disable command.

[0056] In some implementations, the module interrupts the signal unless security information confirming the reliability of all supplies in the imaging system has been received within the previous time period. In some implementations, the time period is preset.

[0057] In some implementations, signals are transmitted by the printhead operation module on multiple channels, each corresponding to a specific function of the printhead, and the implementation module selectively interrupts each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0058] In some implementations, the host firmware performs functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0059] An electronic system is also provided, comprising:

[0060] System control unit, which stores host firmware, includes a component operation module actuated by the host firmware to transmit signals to components of the electronic system, the signals being configured to operate the components; and

[0061] The monitoring-implementation module includes:

[0062] A monitoring interface configured to receive security information from security devices in an electronic system, and

[0063] An implementation module is configured to selectively interrupt the signals transmitted by the component operation module based on security information.

[0064] In some implementations, system control components may include a system-on-a-chip (SoC), a processor, memory, and / or an integrated circuit (IC), such as an application-specific integrated circuit (ASIC). In some implementations, the electronic system includes electronic device security devices and / or supply items. Supply items may include supply item security devices.

[0065] In some implementations, the monitoring-implementation module is located on the system control unit, and the monitoring-implementation module includes a hardware block on the system control unit configured to receive security information and selectively interrupt component operation.

[0066] In some implementations, the hardware block is a dedicated hardware block. The dedicated hardware block can be configured to perform only the operations of the monitoring-implementation module. In some implementations, the hardware block is configured to perform operations to receive security information and / or selectively interrupt component operation.

[0067] In some implementations, the implementation module is configured to interrupt signals transmitted by the component operation module via gating. In some implementations, the gating can be on the system control component, outside the component operation module, or within the component operation module.

[0068] In some implementations, the monitoring-implementation module is separate from the system control components. In some implementations, the monitoring-implementation module may be an integrated circuit, such as a microcontroller or ASIC. In some implementations, the monitoring-implementation module is a programmable device. In some implementations, the programmable device is lockable or lockable.

[0069] In some implementations, security information includes: the authentication status of one or more supply items of the electronic system, and / or a disable command, and / or authentication information from one or more supply items of the electronic system.

[0070] In some implementations, authentication information is a response to a challenge. In some implementations, a challenge is input to an encryption operation to be performed on the supplied item. In some implementations, a challenge may include a random value, which may be generated, for example, from a pseudo-random number generator (PRNG) using encryption operations. In some implementations, the response is the result of an encryption operation. The response may be a checksum and / or a signature.

[0071] In some implementations, the monitoring interface is configured to receive security information from the electronic system's security communication system. In other implementations, the monitoring interface is configured to periodically check the security communication system to obtain security information.

[0072] In some implementations, the secure communication system may include a hardware signaling communication system. In some implementations, the monitoring interface may be a follower component. In some implementations, the secure communication system is a secure communication bus, such as I... 2 C bus.

[0073] In some implementations, the monitoring interface is configured to receive signals from a secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0074] In some implementations, the secure communication system is configured to allow the monitoring interface of the monitoring-implementation module to receive communications from the security devices of the supply items of the electronic system, and / or the security devices and / or host firmware of the electronic equipment.

[0075] In some implementations, the monitoring interface is configured to communicate with the host firmware. The host firmware can be configured to send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from a secure communication system.

[0076] In some embodiments, the monitoring interface is configured to monitor the secure communication system. In some embodiments, the monitoring-implementation module cannot transmit signals on the secure communication system. In some embodiments, the monitoring-implementation module has an address on the secure communication system. In some embodiments, the system control unit sends a challenge to the security device supplying the article on the secure communication system, and the security device supplying the article returns a response to the challenge on the secure communication system. This response is received by the monitoring-implementation module. In some embodiments, the security device supplying the article returns a response to the challenge to the system control unit on the secure communication system, and the monitoring interface of the monitoring-implementation module receives this response by monitoring the secure communication system.

[0077] The implementation module can be configured to interrupt signals transmitted by the component operation module when a response is not authenticated. In some embodiments, the implementation module is configured to interrupt signals transmitted by the component operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the electronic system was started.

[0078] In some implementations, the implementation module is configured not to interrupt the signal when the security information confirms the trustworthiness of the supplied item, and the implementation module is configured to interrupt the signal when the security information does not confirm the trustworthiness of the supplied item.

[0079] In some implementations, the implementation module is configured to interrupt the signal when an error occurs. In some implementations, the implementation module is configured to interrupt the signal when the security information contains a disable command.

[0080] In some implementations, the implementation module is configured to interrupt the signal unless security information confirming the reliability of all supplies in the electronic system has been received in the previous time period. The time period can be preset.

[0081] In some implementations, signals are transmitted by a component operation module on multiple channels, each corresponding to a specific function of the component, and the implementation module is configured to selectively interrupt each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0082] In some implementations, each channel can be interrupted by a corresponding gating, and the implementation module is configured to selectively interrupt each channel by selectively operating the corresponding gating.

[0083] In some implementations, the security information is a Security Status Packet (SSP). In some implementations, the SSP originates from a supply article security device. In some implementations, the SSP originates from an electronic device security device.

[0084] In some implementations, the component operation module is a video output terminal.

[0085] In some implementations, the host firmware is configured to perform functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0086] A method for implementing security on an electronic system as described above is also provided, the method comprising:

[0087] Based on security information, the implementation module selectively interrupts signals transmitted by the component operation module.

[0088] In some implementations, interruption by the implementation module includes operating the gating.

[0089] In some embodiments, the method further includes receiving security information from the electronic system's security communication system via a monitoring interface. In some embodiments, the method further includes periodically checking the electronic system's security communication system via the monitoring interface to obtain security information.

[0090] In some implementations, the monitoring interface receives signals from the secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0091] In some embodiments, the method further includes: sending a challenge by a system control component to a security device supplying articles to an electronic system on a secure communication system, and receiving authentication information from the security device supplying articles on a secure communication system by a monitoring interface, the authentication information being a response to the challenge.

[0092] In some implementations, the monitoring-enforcement module performs an authentication process on the response to determine whether the supplied item is trustworthy. The authentication process may include cryptographic methods such as HMAC or CMAC, or may include signature and / or verification using RSA / ECDSA, or another cryptographic operation. Security information may include an HMAC or CMAC checksum on the security state payload of the security information. The authentication process may include the monitoring-enforcement block calculating the checksum on the security state payload and comparing the result with the HMAC or CMAC checksum. If a signature scheme is used, the security information may include a signature of the security state payload, for example, signed with a private key contained in the component security device. The monitoring-enforcement module may be configured to verify the signature with the corresponding public key during the authentication process.

[0093] In some implementations, the challenge is an cryptographic operation. In some implementations, the response is the result of a cryptographic operation. The response may be a checksum and / or a signature.

[0094] In some implementations, the monitoring interface receives communications from the security devices for supplying articles to the electronic system, and / or the security devices and / or host firmware of the electronic equipment, via a secure communication system.

[0095] In some implementations, the monitoring interface communicates with the host firmware. The host firmware can send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from the secure communication system.

[0096] In some implementations, the monitoring interface monitors the secure communication system. In some implementations, the monitoring-implementation module cannot transmit signals on the secure communication system. In some implementations, the monitoring-implementation module has an address on the secure communication system.

[0097] In some implementations, the implementation module interrupts the signal transmitted by the component operation module when the response is not authenticated. In some implementations, the implementation module interrupts the signal transmitted by the component operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the electronic system was started.

[0098] In some implementations, the implementation module does not interrupt the signal when the security information confirms the reliability of the supplied items, and interrupts the signal when the security information does not confirm the reliability of the supplied items.

[0099] In some implementations, a module interrupt signal is implemented when an error occurs. In some implementations, a module interrupt signal is implemented when the security message contains a disable command.

[0100] In some implementations, the module interrupts the signal unless security information confirming the reliability of all supplies in the electronic system has been received within the previous time period. In some implementations, the time period is preset.

[0101] In some implementations, signals are transmitted by a component operation module on multiple channels, each corresponding to a specific function of the component, and the implementation module selectively interrupts each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0102] In some implementations, the host firmware performs functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0103] An imaging system is also provided, comprising:

[0104] The system control component includes:

[0105] A printhead operation module configured to transmit a signal to the printhead of an imaging system, the signal being configured to operate the printhead; and

[0106] The monitoring-implementation module includes a dedicated hardware block on the system control component.

[0107] include:

[0108] A monitoring interface configured to receive security information from the security equipment of the imaging system, and an implementation module configured to selectively interrupt the signals transmitted by the printhead operation module based on the security information.

[0109] In some embodiments, the system control component has host firmware stored thereon. In some embodiments, the system control component further includes a printhead operation module. In some embodiments, the printhead operation module may be a logic block.

[0110] In some embodiments, system control components may include a SoC, processor, memory, and / or integrated circuit (IC), such as an application-specific integrated circuit (ASIC). In some embodiments, the imaging system includes imaging device safety equipment and / or supply items. The supply items may include supply item safety equipment.

[0111] The dedicated hardware block is configured to perform only the operations of the monitoring-implementation module.

[0112] In some implementations, the hardware block is configured to perform operations to receive security information and / or selectively interrupt printhead operation.

[0113] In some implementations, the implementation module is configured to interrupt signals transmitted by the printhead operation module via gating.

[0114] In some implementations, the gating can be on the system control unit, outside the printhead operation module, or inside the printhead operation module.

[0115] In some implementations, security information includes: the authentication status of one or more supply items of the imaging system, and / or a disable command and / or authentication information from one or more supply items of the imaging system.

[0116] In some implementations, authentication information is a response to a challenge. In some implementations, a challenge is input to an encryption operation to be performed on the supplied item. In some implementations, a challenge may include a random value, which may be generated, for example, from a pseudo-random number generator (PRNG) using encryption operations. In some implementations, the response is the result of an encryption operation. In some implementations, the response is a checksum and / or a signature.

[0117] In some implementations, the monitoring interface is configured to receive security information from the imaging system's security communication system. In other implementations, the monitoring interface is configured to periodically check the security communication system to obtain security information.

[0118] In some implementations, the secure communication system may include a hardware signaling communication system. In some implementations, the monitoring interface may be a follower component. In some implementations, the secure communication system is a secure communication bus, such as I... 2 C bus.

[0119] In some implementations, the monitoring interface is configured to receive signals from a secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0120] In some implementations, the secure communication system is configured to allow the monitoring interface of the monitoring-implementation module to receive communications from the security devices of the supply items of the imaging system, and / or the security devices of the imaging equipment and / or the host firmware.

[0121] In some implementations, the monitoring interface is configured to communicate with the host firmware. The host firmware can be configured to send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from a secure communication system.

[0122] In some embodiments, the monitoring interface is configured to monitor the secure communication system. In some embodiments, the monitoring-implementation module cannot transmit signals on the secure communication system. In some embodiments, the monitoring-implementation module has an address on the secure communication system. In some embodiments, the system control unit sends a challenge to the security device supplying the article on the secure communication system, and the security device supplying the article returns a response to the challenge on the secure communication system. This response is received by the monitoring-implementation module. In some embodiments, the security device supplying the article returns a response to the challenge to the system control unit on the secure communication system, and the monitoring interface of the monitoring-implementation module receives this response by monitoring the secure communication system.

[0123] In some implementations, the implementation module is configured to interrupt the signals transmitted by the printhead operation module when the response is not authenticated. In some implementations, the implementation module is configured to interrupt the signals transmitted by the printhead operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the imaging system has been started.

[0124] In some implementations, the implementation module is configured not to interrupt the signal when the security information confirms the trustworthiness of the supplied item, and the implementation module is configured to interrupt the signal when the security information does not confirm the trustworthiness of the supplied item.

[0125] In some implementations, the implementation module is configured to interrupt the signal when an error occurs. In some implementations, the implementation module is configured to interrupt the signal when the security information contains a disable command.

[0126] In some implementations, the implementation module is configured to interrupt the signal unless security information confirming the reliability of all supplies in the imaging system has been received in the previous time period. The time period can be preset.

[0127] In some implementations, signals are transmitted by the printhead operation module on multiple channels, each corresponding to a specific function of the printhead, and the implementation module is configured to selectively interrupt each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0128] In some implementations, each channel can be interrupted by a corresponding gating, and the implementation module is configured to selectively interrupt each channel by selectively operating the corresponding gating.

[0129] In some implementations, the security information is a Security Status Packet (SSP). In some implementations, the SSP originates from a supply item security device. In some implementations, the SSP originates from an imaging device security device.

[0130] In some implementations, the printhead operation module is a video output terminal.

[0131] In some implementations, the host firmware is configured to perform functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0132] A method for implementing security on the imaging system described above is also provided, the method comprising:

[0133] Based on security information, the implementation module selectively interrupts signals transmitted by the printhead operation module.

[0134] In some implementations, interruption by the implementation module includes operating the gating.

[0135] In some implementations, the method further includes receiving security information from the imaging system's security communication system via a monitoring interface.

[0136] In some implementations, the method further includes periodically checking the imaging system's security communication system via a monitoring interface to obtain security information.

[0137] In some implementations, the monitoring interface receives signals from the secure communication system via the SCL line. In some implementations, the signals may be PWM encoded, or UART, NRZ, Manchester, 8b / 10b, or any other suitable encoded signal.

[0138] In some embodiments, the method further includes: sending a challenge by a system control component to a secure device supplying the article to the imaging system via a secure communication system, and receiving authentication information from the secure device supplying the article via a monitoring interface on the secure communication system, the authentication information being a response to the challenge.

[0139] In some implementations, the implementation module performs an authentication process on the response to determine whether the supply item is trustworthy. The authentication process may include cryptographic methods such as HMAC or CMAC, or may include signature and / or verification using RSA / ECDSA, or another cryptographic operation. Security information may include an HMAC or CMAC checksum on the security state payload of the security information. The authentication process may include a monitoring-implementation block calculating the checksum on the security state payload and comparing the result with an HMAC or CMAC checksum. If a signature scheme is used, the security information may include a signature of the security state payload, for example, signed with a private key contained in the supply item security device. The monitoring-implementation module may be configured to verify the signature with the corresponding public key during the authentication process.

[0140] In some implementations, the challenge is an cryptographic operation. In some implementations, the response is the result of a cryptographic operation. The response may be a checksum and / or a signature.

[0141] In some implementations, the monitoring interface receives communications from the security device for supplying articles to the imaging system, and / or the security device for the imaging equipment and / or the host firmware via a secure communication system.

[0142] In some implementations, the monitoring interface communicates with the host firmware. The host firmware can send information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. Communication between the monitoring interface and the host firmware can be separate from the secure communication system.

[0143] In some implementations, the monitoring interface monitors the secure communication system. In some implementations, the monitoring-implementation module cannot transmit signals on the secure communication system. In some implementations, the monitoring-implementation module has an address on the secure communication system.

[0144] In some implementations, the implementation module interrupts the signal transmitted by the printhead operation module when the response is not authenticated. In some implementations, the implementation module interrupts the signal transmitted by the printhead operation module when the monitoring interface has not received security information and / or an authenticated response within a predetermined time period and / or since the imaging system was started.

[0145] In some implementations, the implementation module does not interrupt the signal when the security information confirms the reliability of the supplied items, and interrupts the signal when the security information does not confirm the reliability of the supplied items.

[0146] In some implementations, a module interrupt signal is implemented when an error occurs. In some implementations, a module interrupt signal is implemented when the security message contains a disable command.

[0147] In some implementations, the module interrupts the signal unless security information confirming the reliability of all supplies in the imaging system has been received within the previous time period. In some implementations, the time period is preset.

[0148] In some implementations, signals are transmitted by the printhead operation module on multiple channels, each corresponding to a specific function of the printhead, and the implementation module selectively interrupts each channel based on security information. In some implementations, the security information includes channel security information corresponding to at least one channel.

[0149] In some implementations, the host firmware performs functions including provisioning authentication, provisioning metering, and / or the implementation of authentication processes.

[0150] An electronic system is also provided, comprising:

[0151] The system control component includes:

[0152] A component operation module configured to transmit signals to components of the electronic system, the signals being configured to operate the components; and

[0153] The monitoring-implementation module includes a dedicated hardware block on the system control component.

[0154] include:

[0155] A monitoring interface configured to receive security information from the security devices of the electronic system, and an implementation module configured to selectively interrupt the signals transmitted by the component operation module based on the security information.

[0156] In some embodiments, the system control component has host firmware stored thereon. In some embodiments, the system control component further includes a component operation module. In some embodiments, the component operation module may be a logic block.

[0157] In any implementation / exemplification described herein, components may be transmitted via any shared bus (such as I...). 2 C or peer-to-peer bus connection.

[0158] The methods and systems described above can be used in any combination. The optional features described above also apply to all described methods and systems, and are not limited to the specific method / system used to describe them. A fundamental feature of any described method can be an optional feature of any other described method.

[0159] Based on the foregoing disclosure and the following detailed description of various examples, it will be apparent to those skilled in the art that this disclosure provides significant progress in the field of determining the reliability of components of an electronic system. Additional features and advantages of the various examples will be better understood in light of the detailed description provided below.

[0160] As used herein, the term "leader" is equivalent to the term "master" and can be used interchangeably throughout the text without changing its meaning. Similarly, the term "follower" is equivalent to the term "slave" and can be used interchangeably throughout the text without changing its meaning. The terms "master" and "slave" are used in their usual sense in the art, for example, in official I... 2 The meaning used in the C specification. Brief description of the attached diagram

[0162] The above and other features and advantages of this disclosure, and how they are obtained, will become clearer and better understood from the following description, taken in conjunction with the accompanying drawings. Throughout the specification, the same reference numerals are used to indicate the same elements.

[0163] Figure 1 This is a schematic diagram of the imaging system.

[0164] Figure 2 This is a schematic diagram of the components of the imaging system.

[0165] Figure 3 This is a schematic diagram of the components of the imaging system.

[0166] Figure 4 This is a schematic diagram of the components of the imaging system.

[0167] Detailed description of the attached figures

[0168] It should be understood that this disclosure is not limited to the details of the structure and arrangement of the components set forth in the following description or shown in the accompanying drawings. This disclosure is applicable to other examples and can be practiced or performed in various ways. For example, other examples may combine structural, temporal, procedural, and other variations. The examples merely represent possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of certain examples may be included in or replace parts and features of other examples. The scope of this disclosure includes the appended claims and all available equivalents. Therefore, the following description is not to be considered limiting, and the scope of this disclosure is defined by the appended claims.

[0169] Furthermore, it should be understood that the wording and terminology used herein are for descriptive purposes and should not be considered restrictive. The use of “comprising,” “including,” or “having,” and its variations, herein is intended to include the items listed thereafter and their equivalents, as well as any additional items. Moreover, the use of the terms “a” and “an” herein does not imply a limitation on quantity, but rather indicates the presence of at least one of the mentioned items.

[0170] Furthermore, it should be understood that the examples in this disclosure include hardware and electronic components or modules, which, for the purposes of discussion, may be shown and described as if most of the components were implemented only in hardware.

[0171] It will also be understood that each block in the diagram, as well as combinations of blocks in the diagram, can be implemented individually through computer program instructions. These computer program instructions can be loaded onto a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute on the computer or other programmable data processing apparatus, can create means for implementing the functions of each block or combination of blocks in the diagram, which are discussed in detail in the following description.

[0172] These computer program instructions may also be stored in a non-transitory computer-readable medium that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable medium can produce an article of writing, including instruction means that implement the functions specified in one or more blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus, thereby producing a computer-implemented process, such that the instructions executing on the computer or other programmable apparatus implement the functions specified in one or more blocks.

[0173] Therefore, the blocks in the diagram support combinations of means for performing a specified function, combinations of steps for performing a specified function, and program instruction means for performing a specified function. It will also be understood that each block in the diagram and combinations of blocks in the diagram can be implemented by a dedicated hardware-based computer system or a combination of dedicated hardware and computer instructions for performing the specified function or steps.

[0174] Example systems and methods for determining the reliability of components in electronic systems such as imaging / printer systems are disclosed.

[0175] refer to Figure 1 The diagram illustrates an imaging system 100 used in connection with this disclosure. The imaging system 100 includes an imaging device 105 for printing images on a media sheet. Image data of the image to be printed on the media sheet can be provided to the imaging device 105 from various sources, such as a computer 110, a laptop 115, a mobile device 120, a scanner 125 of the imaging device 105, or a similar computing device. These sources communicate directly or indirectly with the imaging device 105 via wired and / or wireless connections.

[0176] Imaging device 105 includes imaging device component 130 and user interface 135. Imaging device component 130 may be referred to as a system control component. Imaging device component 130 may include a processor and associated memory. In some examples, imaging device component 130 may be formed as one or more application-specific integrated circuits (ASICs) or system-on-a-chip (SoCs). The memory may be any memory device for storing data and may be used with or able to communicate with the processor. For example, the memory may be any volatile or non-volatile memory or a combination thereof, such as, for example, random access memory (RAM), read-only memory (ROM), flash memory, and / or non-volatile RAM (NVRAM) for storing data. Optionally, imaging device component 130 may control the processing of print data. Imaging device component 130 includes a printhead operation module that controls the operation of the print engine during the printing of an image onto a media sheet. The print engine may be referred to as a printhead.

[0177] In one example, imaging device 105 may use an electronic authentication scheme to authenticate consumable supplies and / or replaceable units installed in imaging device 105. Figure 1 The image shows representative consumable / replaceable supply items, such as toner cartridge 150 (other consumable / replaceable supply items, such as imaging units and fusers, can also be used in the same way). Supply item 150 can be installed in a corresponding storage area within imaging device 105. To perform authentication of supply item 150, imaging device 105 can utilize imaging device security device 160 and supply item security device 165 incorporated into imaging device 105.

[0178] In one example, the imaging device security device 160 in imaging device 105 may be similar to or the same as the supply item security device 165 in consumable supply item 150. Alternatively, the imaging device security device 160 may be programmed differently from the supply item security device 165. The imaging device security device 160 and the supply item security device 165 may operate in combination with each other to perform authentication functions.

[0179] Figure 2 It shows (such as) Figure 1 The imaging system 200 (shown) includes several components. These components include a supply item 150 (e.g., a toner cartridge), a system control unit 130 storing host firmware 207 thereon, an imaging device safety device 160, and a printhead 203. The system control unit 130 and the imaging device safety device 160 are located in the controller area 204 of the imaging system. The supply item 150 has a supply item safety device 165. Figure 2A comparative example of an imaging system without a monitoring-implementation module is shown.

[0180] The host firmware 207 is configured to actuate the printhead operation module 208 to transmit the video signal 202 to the printhead 203, thereby operating the printhead. The supply safety device 165, system control unit 130, and imaging device safety device 160 all communicate via I... 2 C bus 201 communication ground connection, I 2 The C-bus 201 forms a secure communication system.

[0181] In use, the supply item 150 is authenticated via communication between the supply item security device 165, the imaging device security device 160, and the host firmware. Then, when the supply item 150 is authenticated, the printhead operation module 208 operates the printhead 203. When supply item authentication fails, the host firmware does not operate the printhead 203. Since there is no monitoring-enforcement module, if authentication fails, Figure 2 The system relies on host firmware 207 to disable printing.

[0182] Figure 3 It shows (such as) Figure 1 (As shown) Some components of another imaging system. Figure 3 The imaging system 300 has a system control unit 130, on which host firmware 207 is stored. The system control unit 130 includes a printhead operation module 208, which is actuated by the host firmware 207 to transmit a signal 202 to the printhead 203 of the imaging system. The signal is configured to operate the printhead 203. The imaging system 300 also has a monitoring-implementation module 270, which includes: a monitoring interface configured to receive security information from security devices 160, 165 of the imaging system; and an implementation module configured to selectively interrupt the signal 202 transmitted by the printhead operation module 208 based on the security information.

[0183] By interrupting the signal transmitted by the printhead operation module 208 using the monitoring-implementation module 270, printhead 203 operation can be prevented. This system is less susceptible to modification or manipulation of the host firmware 207 (e.g., by untrusted supply items).

[0184] The components include a supply item 150 (e.g., a toner cartridge) and an imaging equipment safety device 160. The supply item 150 has a supply item safety device 165. The system control component 130 and the imaging equipment safety device 160 are located in the controller area 204 of the imaging system.

[0185] The printhead operation module 208 includes a video output terminal configured to transmit a video signal 202 to the printhead 203 to operate the printhead. The supply safety device 165, system control unit 130, imaging equipment safety device 160, and monitoring interface are all connected via I... 2 C bus 201 communication ground connection, I 2 The C-bus 201 forms a secure communication system.

[0186] In use, the supplied item 150 is authenticated via communication between the supplied item security device 165, the imaging device security device 160, the host firmware 207, and the monitoring interface. The printhead operation module 208 enables the printhead 203 to operate. When supplied item authentication fails, the implementation module interrupts the signal 202 at the gating 275. This means that even if the host firmware 207 is modified or manipulated, the implementation module will still prevent the printhead 203 from operating via the interrupt signal.

[0187] System control unit 130 is a SoC. Monitoring-enforcement module 270 is located on system control unit 130 and includes a hardware block on system control unit configured to receive security information and selectively interrupt printhead operation signal 202. This hardware block is a dedicated hardware block configured to perform only the operations of monitoring-enforcement module 270.

[0188] The gate 275 is located on the system control unit 130, external to the printhead operation module. In other embodiments, the gate 275 may be located within the printhead operation module 208. The system control unit 130 and / or the printhead operation module 208 may have input pins that can be actuated by the implementation module to control the gate 275.

[0189] The security information received by the monitoring interface includes: the authentication status of one or more supply items 150 of the imaging system and a disable command issued by security devices 160, 165 or host firmware 207, as well as authentication information from supply items 150.

[0190] The authentication information includes the response to a challenge, and the challenge is an encrypted operation. The response is the result of an encrypted operation returned by the supply item security device 165. The response may be a checksum and / or a signature.

[0191] The monitoring interface is configured to communicate with the secure communication system forming the imaging system. 2 The C-bus 201 receives security information. The monitoring interface is configured to periodically check the security communication system 201 to obtain security information. The security communication system is a hardware signaling communication system, and the monitoring interface is a follower component.

[0192] The secure communication system is configured to allow the monitoring interface of the monitoring-implementation module 270 to receive communications from the security device 165 of the imaging system supply items, and / or the imaging device security device 160 and / or the host firmware 207.

[0193] The monitoring interface is also configured to communicate with the host firmware 207 via channel 206. The host firmware is configured to send information to the monitoring interface that enables the monitoring-implementation module 270 to determine the trustworthiness of the supply item 150 based on security information. The communication between the monitoring interface and the host firmware 207 via channel 206 is separate from the security communication system 201.

[0194] The monitoring interface is configured to monitor the secure communication system 201. The monitoring-implementation module 270 has an address on the secure communication system, but cannot transmit signals on the secure communication system.

[0195] In operation, the system control unit 130 sends a challenge to the supplying safety device 165 via the safety communication system 201, and the supplying safety device responds to the challenge via the safety communication system 201. This response is received by the monitoring-implementation module. The supplying safety device 165 responds to the challenge via the safety communication system 201, and the monitoring interface of the monitoring-implementation module receives this response through monitoring the safety communication system 201.

[0196] The implementation module is configured to interrupt signal 202 transmitted by printhead operation module 208 when the response is not authenticated. The implementation module is also configured to interrupt signal 202 transmitted by printhead operation module 208 when the monitoring interface does not receive security information and / or does not receive an authenticated response within a predetermined time period, and when the monitoring interface has not received an authenticated response since the imaging system was started. This is used to default the system to "implement" and ensure that the protected system is protected from untrusted supplies from startup.

[0197] The implementation module is configured to interrupt signal 202 when the security information fails to confirm the trustworthiness of the supplied item. The implementation module is also configured to interrupt the signal when an error occurs. Furthermore, the implementation module is configured to interrupt the signal when the security information contains a disable command.

[0198] The implementation module is configured to interrupt signal 202 unless security information confirming the reliability of all supplies in the imaging system has been received in the previous time period. The time period can be preset.

[0199] Signal 202 is transmitted by printhead operation module 208 in multiple channels (not in...) Figure 3(As shown in the diagram) the data is transmitted, with each channel corresponding to a specific function of the printhead, such as the channels for each color the printhead can use. The implementation module is configured to selectively interrupt each channel based on safety information. The safety information includes channel safety information corresponding to which channels should be interrupted.

[0200] Each channel can be interrupted by one of the corresponding gates in gate 275, and the implementation module is configured to selectively interrupt each channel by selectively operating the corresponding gate.

[0201] The security information is a Security Status Packet (SSP). The SSP can come from the supply item security device 165 or the imaging equipment security device 160.

[0202] The host firmware is configured to perform functions including supply authentication, supply metering, and / or the implementation of authentication processes.

[0203] The above description will now be presented regarding... Figure 3 The described method involves implementing security on an imaging system. A monitoring interface periodically checks the security communication system 201 of the imaging system to obtain security information and receives such information from the security communication system 201. The implementation module then selectively interrupts the signal 202 transmitted by the printhead operation module 208 via an operation gating 275, based on the security information.

[0204] System control unit 130 sends a challenge to the security device 165 of the supply item 150 of the imaging system via the secure communication system 201. The monitoring interface receives authentication information from the security device 165 of the supply item on the secure communication system 201; this authentication information is a response to the challenge. The implementation module performs an authentication process on the response to determine whether the supply item is trustworthy. The monitoring-implementation module then selects whether to interrupt signal 202 based on the authentication process.

[0205] The monitoring interface also communicates with the host firmware 207 via communication channel 206. The host firmware 207 sends information to the monitoring interface that enables the monitoring-implementation module to determine the trustworthiness of the supplied items based on security information. The communication between the monitoring interface and the host firmware 207 via channel 206 is separate from the security communication system 201.

[0206] Figure 4 It shows (such as) Figure 1 (As shown) Some components of another imaging system 400. Imaging system 400 is used in conjunction with... Figure 3 The imaging system 300 shown is configured in the same way, except for the differences explained below.

[0207] Figure 4The imaging system 400 has a system control unit 130 on which host firmware 207 is stored. The system control unit 130 includes a printhead operation module 208 actuated by the host firmware to transmit a signal 202 to the printhead 203 of the imaging system. The signal is configured to operate the printhead 203. The imaging system 400 also has a monitoring-implementation module 370, which includes: a monitoring interface configured to receive security information from security devices 160, 165 of the imaging system; and an implementation module configured to selectively interrupt the signal 202 transmitted by the printhead operation module 208 based on the security information.

[0208] The monitoring-implementation module 370 is separate from the system control unit 130. The monitoring-implementation module 370 is a lockable or lockable programmable device. Because the monitoring-implementation module is separate from the system control unit 130, it can be locked to prevent modification by external devices, thereby enhancing system security.

[0209] In other embodiments, the monitoring-implementation module 370 is an integrated circuit, such as a microcontroller or an ASIC. In other embodiments, the monitoring-implementation module 370 is a hardware block, such as a dedicated hardware block.

[0210] When the supply item authentication fails, the implementation module interrupts the gate 375 signal 202. This means that even if the host firmware 207 is modified or manipulated, the implementation module will still prevent printhead operation via the interrupt signal.

[0211] The monitoring-implementation module 370 is configured to receive security information and selectively interrupt the printhead operation signal 202 via gating 375. Gating 375 is external to the system control module 130. In other embodiments, gating 375 may be on the system control unit 130. In this case, the system control unit 130 and / or the printhead operation module 208 may have input pins actuated by the implementation module to control gating 375.

[0212] In the above implementation / example, the various components are configured as leader / follower components. This is entirely optional, and other communication buses can be used.

[0213] The relatively obvious advantages of many embodiments include, but are not limited to, providing an authentication system / method that is more difficult to achieve / replicate due to the increased processing power required.

[0214] It will be understood that the example applications described herein are illustrative and should not be considered limiting. It will be appreciated that the actions described and illustrated in the example flowcharts can be performed or executed in any suitable order. It will also be appreciated that the example embodiments based on this disclosure are not intended to pertain to... Figure 3 and Figure 4 All actions described need to be performed, and / or additional actions may be performed according to other example embodiments of this disclosure.

[0215] Those skilled in the art to which these disclosures pertain will conceive of numerous modifications and other embodiments of the disclosures set forth herein, benefiting from the teachings presented in the foregoing description and associated drawings. Therefore, it should be understood that this disclosure is not limited to the specific embodiments disclosed, and that modifications and other embodiments are considered to be included within the scope of the appended claims. Although specific terminology is used herein, it is used only in a general and descriptive sense and not for limiting purposes.

[0216] Further disclosures are provided below.

[0217] Statement 1: An imaging system includes: a system control unit, the system control unit including: a printhead operation module configured to transmit signals to a printhead of the imaging system, the signals being configured to operate the printhead; and a monitoring-implementation module including a dedicated hardware block on the system control unit, the hardware block including: a monitoring interface configured to receive security information from a security device of the imaging system; and an implementation module configured to selectively interrupt the signals transmitted by the printhead operation module based on the security information.

[0218] Statement 2: In the imaging system described in Statement 1, the hardware block is configured to perform operations to receive security information and / or selectively interrupt printhead operation.

[0219] Statement 3: In the imaging system described in Statement 1, the implementation module is configured to interrupt the signal transmitted by the printhead operation module via gating.

[0220] Statement 4: According to the imaging system of Statement 1, the security information includes: the authentication status of one or more supply items of the imaging system, and / or a disable command and / or authentication information from one or more supply items of the imaging system.

[0221] Statement 5: In the imaging system described in Statement 4, the authentication information is a response to an inquiry.

[0222] Statement 6: According to the imaging system described in Statement 5, the response is the result of an encryption operation.

[0223] Statement 7: The imaging system according to Statement 6, wherein the response is a checksum and / or a signature.

[0224] Statement 8: According to the imaging system described in Statement 1, the monitoring interface is configured to receive security information from the security communication system of the imaging system.

[0225] Statement 9: In the imaging system described in Statement 8, the monitoring interface is configured to periodically check the security communication system to obtain security information.

[0226] Statement 10: According to the imaging system of Statement 8, the secure communication system is configured to allow the monitoring interface of the monitoring-implementation module to receive communications from the security devices of the supply items of the imaging system, and / or the security devices of the imaging equipment and / or the host firmware.

[0227] Statement 11: In the imaging system described in Statement 1, the security information is a security status grouping.

[0228] Statement 12: In the imaging system described in Statement 1, the printhead operation module is a video output terminal.

[0229] Statement 13: A method for implementing security in an imaging system according to Statement 1, the method comprising: selectively interrupting signals transmitted by a printhead operation module based on security information by an implementation module.

[0230] Statement 14: According to the method described in Statement 13, interruption by the implementation module includes operating the gating.

[0231] Statement 15: According to the method described in Statement 13, the method further includes receiving security information from the security communication system of the imaging system via a monitoring interface.

[0232] Statement 16: According to the method of Statement 15, the security information includes: the authentication status of one or more supply items of the imaging system, and / or a disable command and / or authentication information from one or more supply items of the imaging system.

[0233] Statement 17: According to the method described in Statement 16, the method further includes: sending a challenge by a system control component to a security device supplying the article to the imaging system on a secure communication system, and receiving authentication information from the security device supplying the article on the secure communication system by a monitoring interface, the authentication information being a response to the challenge.

[0234] Statement 18: The method according to Statement 13, wherein the implementation module interrupts the signal unless security information confirming the reliability of all supplies in the imaging system has been received in the previous time period.

[0235] Statement 19: According to the method described in Statement 13, the printhead operation module is a video output terminal.

[0236] Statement 20: An electronic system includes: a system control component, the system control component including: a component operation module configured to transmit signals to components of the electronic system, the signals being configured to cause the components to operate; and a monitoring-implementation module including a dedicated hardware block on the system control component, the hardware block including: a monitoring interface configured to receive security information from a security device of the electronic system; and an implementation module configured to selectively interrupt the signals transmitted by the component operation module based on the security information.

Claims

1. An imaging system comprising: a system control component having a host firmware stored thereon, the system control component including a printhead operation module that is actuatable by the host firmware to transmit a signal to a printhead of the imaging system, the signal configured to cause the printhead to operate; an imaging device security device; a supply item; a monitor-enforcement module including: a monitor interface configured to receive security information from the imaging device security device, wherein the security information includes an authentication status of one or more supply items of the imaging system and / or authentication information from one or more supply items of the imaging system, the authentication information being a response to a challenge, and an enforcement module configured to selectively interrupt the signal transmitted by the printhead operation module based on the security information; and a secure communication system configured to allow the monitor interface of the monitor-enforcement module to receive communications from the imaging device security device.

2. The imaging system of claim 1, wherein, The monitor-enforcement module is on the system control component and includes a hardware block on the system control component that is configured to receive security information and selectively interrupt printhead operation.

3. The imaging system of claim 1, wherein, The enforcement module is configured to gate interrupt the signal transmitted by the printhead operation module.

4. The imaging system of claim 1, wherein, The monitor-enforcement module is separate from the system control component.

5. The imaging system of claim 4, wherein, The monitor-enforcement module is a programmable device.

6. The imaging system of claim 5, wherein, The programmable device is locked or lockable.

7. The imaging system of claim 1, wherein, The secure communication system is further configured to allow the monitor interface of the monitor-enforcement module to receive communications from: a security device of a supply item of the imaging system, and / or the host firmware.

8. The imaging system of claim 1, wherein, The security information is a security status packet.

9. The imaging system of claim 1, wherein, The printhead operation module is a video output.

10. A method of enforcing security on an imaging system according to claim 1, the method comprising: based on the security information, selectively interrupting, by the enforcement module, a signal transmitted by the printhead operation module.

11. The method of claim 10, wherein, The interrupting by the enforcement module includes operating a gate.

12. The method of claim 10, further comprising receiving, by the monitor interface, the security information from the secure communication system of the imaging system.

13. The method of claim 10, further comprising: sending, by the system control component, a challenge on the secure communication system to a security device of a supply item of the imaging system, receiving, by the monitor interface, the authentication information from the security device of the supply item on the secure communication system, the authentication information being a response to the challenge.

14. The method of claim 10, wherein, The enforcement module interrupts the signal unless security information has been received in a previous time period confirming trustworthiness of all supply items in the imaging system.

15. The method of claim 10, wherein, The printhead operation module is a video output.

16. An electronic system comprising: a system control component having a host firmware stored thereon, the system control component including a component operation module actuable by the host firmware to transmit a signal to a component of the electronic system, the signal configured to cause the component operation; an electronic device security device; a supply item; a monitoring-enforcement module including: a monitoring interface configured to receive security information from the electronic device security device, wherein the security information includes an authentication status of one or more supply items of the electronic system and / or authentication information from one or more supply items of the electronic system, the authentication information being a response to a challenge, and an enforcement module configured to selectively interrupt the signal transmitted by the component operation module based on the security information; and a secure communication system configured to allow the monitoring interface of the monitoring-enforcement module to receive communications from the electronic device security device.

Citation Information

Patent Citations

  • Secure franking machine

    US20040193549A1