Safety protection method and system for whole working process of printer
By implementing full-process security protection methods in the printer, including security chip measurement, firewall settings, automatic reset and electrical erase cleaning, the problem that traditional printer security protection cannot provide comprehensive and reliable information security guarantees is solved, and the full life cycle security management of printer data is achieved.
Patent Information
- Application Number
- CN202510170197.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-10
AI Technical Summary
Traditional printer work security protection cannot provide comprehensive and reliable information security guarantees, especially in network environments, where network leakage risks are at high risk, and human errors lead to leakage of sensitive information.
By implementing a full-process security protection method in the printer, including security chip measurement at startup, firewall settings and whitelist access system for network ports, automatic reset and emergency stop processing during printing, and electrical erase cleaning after printing.
It realizes strict detection and protection of the core data of the printer system, ensures the security of the data throughout the life cycle, prevents data leakage and illegal acquisition, and improves the security and confidentiality of the printer when processing sensitive information.
Smart Images

Figure CN120122902A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of electronic technology, and specifically to a method and system for comprehensive security protection of the entire printer working process. Background Art
[0002] In today's information age, printers, as important office equipment, are widely used in various fields. However, with the rapid development of information technology, information security issues have become increasingly prominent, and the information security protection of printers also faces severe challenges.
[0003] In the past, the printer market in our country mainly relied on foreign products. Special chips were generally installed inside these foreign-produced printers and their consumables. While these chips realized the product identification function, they had certain data storage and transmission capabilities. This characteristic brought serious security risks while facilitating device management and use. On the one hand, in a network environment, the printer may become a source of information leakage, posing a risk of network information leakage; on the other hand, due to human errors and other factors, such as incorrect operations by users or improper processing of printing data, it is also extremely easy to cause the leakage of sensitive information.
[0004] Currently, most of the traditional comprehensive security protection of the entire printer working process is a single data security management strategy, such as a single software or a single hardware, which is difficult to meet the requirements of complex actual usage scenarios and cannot provide comprehensive and reliable information security protection. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a method and system for comprehensive security protection of the entire printer working process, which solves the problem that the traditional comprehensive security protection of the entire printer working process cannot provide comprehensive and reliable information security protection.
[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A method for comprehensive security protection of the entire printer working process includes the following steps:
[0007] S1. Startup check: When starting up, measure the system core data through a security chip. If the measurement is successful, transfer the control right to the main control SOC and start the printing work. If the measurement fails, stop the startup;
[0008] S2. Communication check: Set a firewall for the printer network port, establish a white list access system, allow printing for the host with the IP address or MAC address that enters the white list, and at the same time conduct communication data security inspection. If illegal data appears, eliminate the data and empty all the data that the host attempts to send;
[0009] S3, Process Strategy: When an exception occurs during printing and there is no human intervention beyond the preset time, the printer automatically resets to destroy the data forgotten by the staff. At the same time, when an emergency occurs during printing, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is erased, the printing traces are destroyed, and the logical power supply to the operation module is cut off;
[0010] S4, End Strategy: After printing is completed, the residual information on the toner cartridge is erased by electrical erasure, and at the same time, the residual information in the memory is cleared.
[0011] Preferably, the measurement in S1 specifically includes the following steps:
[0012] S101. When the system starts, TPCM calculates the power supply of the node SOC and measures the BIOS. When the BIOS measurement meets the expectation, the SOC is powered on and the code is loaded. If it does not meet the expectation, power-on is allowed or not allowed according to the policy;
[0013] S102. Before the BIOS executes the third-party driver code, the behavior of the inserted TSB proxy program is intercepted, and TPCM is notified to measure the third-party driver code. The BIOS decides whether to continue starting the system according to the measurement control result;
[0014] S103. Before the BIOS code executes the Bootloader, the behavior of the inserted TSB proxy program is intercepted and measured according to the parameters to determine whether to execute the Bootloader;
[0015] S104. Before the Bootloader code executes the OS kernel, the behavior of the inserted TSB proxy program is intercepted, and TPCM measures the kernel and the OS startup environment. When the measurement fails, whether to execute the OS memory is allowed or not allowed according to the policy. The Bootloader persists in initramfs, the operating system startup script and programs through TPCM, and the script includes / etc / rc*;
[0016] S105. The TSB proxy program in the BootLoader decides whether to execute the operating system kernel according to the return result. The startup measurement interface sends a startup measurement request from the measurement proxy to TPCM, and the measurement proxy includes BIOS, GRUB, and UBOOT;
[0017] S106. After receiving the request, TPCM actively obtains the measured data to calculate the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and the control code.
[0018] Preferably, in S2, the printer adopts the zero-interface cache printing technology, and the elimination of data includes the elimination of incomplete data and illegal data.
[0019] Preferably, the anomalies in S3 include paper shortage and paper jams. The operation module includes a CPU and a memory operation module. When an anomaly occurs during the printing process and there is no human intervention beyond the preset time, the printer automatically resets and destroys the data forgotten by the staff. Specifically, the system detects the printer operation timeout status, sends a #RST signal, changes the potential of the memory pin DRSTN from low to high, the RAM chip automatically resets, the cached data is cleared, and the software also clears the cache of the data at the printing port. When an emergency occurs during the printing process, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is eliminated, the printing traces are destroyed, and at the same time, the logic power supply to the operation module is cut off. Specifically, when it is detected that the emergency stop button is pressed, the OSC sends a control signal to control the power supply of the CE pin of the DC module, cut off the power supply to the memory, and hardware-destroy the data and traces during printing. The memory includes 1.35V, Flash 3.3V, and SOC 1.8V.
[0020] A full-process safety protection system for printer operation, comprising:
[0021] Startup check module: used to measure data through a security chip during startup. If the measurement is successful, the control right is transferred to the main control SOC to start the printing work. If the measurement fails, startup is stopped;
[0022] Communication check module: used to set up a firewall for the printer network port, establish a whitelist admission system, allow printing for the host with the IP address or MAC address that enters the whitelist, and at the same time conduct communication data security inspection, eliminate the data, and clear all the data that the host attempts to send;
[0023] Process strategy module: used to automatically reset the printer and destroy the data forgotten by the staff when an anomaly occurs during the printing process and there is no human intervention beyond the preset time. At the same time, when an emergency occurs during the printing process, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is eliminated, the printing traces are destroyed, and at the same time, the logic power supply to the operation module is cut off;
[0024] End strategy module: used to erase the residual information on the toner cartridge by electrical erasure after printing, and at the same time clear the residual information in the memory
[0025] Preferably, the startup check module includes:
[0026] Measurement unit: used to measure data through a security chip during startup;
[0027] Measurement interface unit: used to start the measurement interface to send a start measurement request from the measurement agent to the TPCM; after receiving the request, the TPCM actively obtains the data to be measured, calculates the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and control code.
[0028] Preferably, the measurement unit includes:
[0029] BIOS measurement sub-unit: used for the TPCM to calculate the node SOC power supply when the system starts, measure the BIOS, when the BIOS measurement meets the expectation, power on the SOC, load the code, and when it does not meet the expectation, allow / deny power on according to the policy;
[0030] Third-party measurement sub-unit: used to intercept the behavior of the inserted TSB agent program before the BIOS executes the third-party driver code, and notify the TPCM to measure the third-party driver code, and the BIOS decides whether to continue to start the system according to the measurement control result;
[0031] Pre-Bootloader measurement sub-unit: used to intercept the behavior of the inserted TSB agent program before the BIOS code executes the Bootloader, measure according to the parameters, and judge whether to execute the Bootloader;
[0032] Kernel measurement sub-unit: used to intercept the behavior of the inserted TSB agent program before the Bootloader code executes the OS kernel, and the TPCM measures the kernel and the OS startup environment. When the measurement fails, allow / deny the execution of the OS memory according to the policy;
[0033] System program measurement sub-unit: used for the Bootloader to further persist in the initramfs, the operating system startup script and program through the TPCM;
[0034] Kernel execution control sub-unit: used for the TSB agent program in the BootLoader to decide whether to execute the operating system kernel according to the return result.
[0035] Preferably, the communication check module includes:
[0036] Zero-interface cache printing unit: used to adopt zero-interface cache printing technology to avoid residual unprinted material information when the printer makes an error;
[0037] Firewall setting unit: used to set up a firewall at the network port, establish a whitelist admission system, and allow hosts with IP addresses or MAC addresses within the whitelist to print;
[0038] Communication data verification unit: used to perform security verification on the communication data, eliminate incomplete data and illegal data, and clear all data that the host attempts to send.
[0039] Preferably, the process strategy module includes:
[0040] Timeout detection unit: used to detect the timeout status of printer operations during the printing process;
[0041] Timeout handling unit: used to send a #RST signal when the operation timeout status is detected, causing the RAM chip to automatically reset, clearing the cached data, and at the same time, the software clears the cache of the print port data;
[0042] Control cut-off unit: used to control the OSC to send a signal when the emergency stop button is pressed, control the power supply of the CE pin of the DC module, cut off the power supply of the memory, and hardware-destroy the data and traces during printing.
[0043] Preferably, the end strategy module includes:
[0044] Trace clearing unit: used to clear the residual information on the toner cartridge by electrical erasure after printing;
[0045] Memory clearing unit: used to clear the residual information in the memory when printing ends.
[0046] The present invention provides a method and system for full-process security protection of printer operation. It has the following beneficial effects:
[0047] 1. Through the security chip measurement at startup, the present invention ensures that the core data of the system is not tampered with. The exception handling mechanism during the working process can timely respond to various emergencies, ensuring the security of data throughout its life cycle, providing users with a comprehensive and reliable data printing environment, greatly enhancing the security and confidentiality of the printer when processing sensitive information, meeting the usage requirements of industries and scenarios with high information security requirements, and thus solving the problem that traditional full-process security protection of printer operation cannot provide comprehensive and reliable information security guarantees.
[0048] 2. By adopting the zero-interface cache printing technology in the interface communication security check link, the present invention ensures that no unprinted material information remains when the printer makes an error, prevents data from being stolen due to caching during transmission, and the firewall and whitelist admission system of the network port strictly limit the access rights of external devices. Only hosts with authorized IP addresses or MAC addresses can perform printing operations. At the same time, security inspection is carried out on the communication data to timely eliminate incomplete and illegal data, ensuring the security and integrity of data transmission.
[0049] 3. By clearing the memory data, the present invention ensures that the data in the memory cannot be illegally obtained. At the same time, hardware measures such as controlling the potential of the memory pins and cutting off the power supply to the operation module further enhance the protection of the memory data, eliminating the possibility of memory leakage from the physical level.
[0050] 4. Through the security policy after printing, the present invention timely clears the residual information in the toner cartridge and the memory, preventing subsequent users from obtaining sensitive information and effectively reducing the risk of leakage caused by human negligence. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a flowchart of a method for the full-process security protection of a printer's operation proposed by the present invention;
[0052] Figure 2 It is a system architecture diagram of a full-process security protection system for a printer's operation proposed by the present invention;
[0053] Figure 3 It is a measurement unit architecture diagram of a full-process security protection system for a printer's operation proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] The technical solutions of the present invention will be clearly and completely described below with reference to the drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0055] Embodiment:
[0056] Please refer to the attached Figure 1 , the embodiment of the present invention provides a method for the full-process security protection of a printer's operation, including the following steps:
[0057] S1. Startup check: When starting up, the system core data is measured through a security chip. If the measurement is successful, the control right is transferred to the main control SOC to start the printing operation. If the measurement fails, the startup is stopped;
[0058] S2. Communication check: A firewall is set for the printer network port, and a whitelist access system is established. Hosts with IP addresses or MAC addresses that enter the whitelist are allowed to print. At the same time, communication data security inspection is carried out. When illegal data appears, the data is eliminated and all the data attempted to be sent by the host side is cleared;
[0059] S3, Process Strategy: When an exception occurs during printing and there is no human intervention beyond the preset time, the printer automatically resets to destroy the data forgotten by the staff. Meanwhile, when an emergency occurs during printing, pressing the emergency stop button immediately stops and deletes the current printing task, erases the memory data, destroys the printing traces, and cuts off the logic power supply to the operation module.
[0060] S4, End Strategy: After printing ends, the residual information on the toner cartridge is erased by electrical erasure, and at the same time, the residual information in the memory is cleared.
[0061] Specifically, during startup, the data is measured by the security chip. If the measurement is successful, the control right is transferred to the main control SOC to start the printing work. If the measurement fails, the startup stops. Thus, at the initial stage of system startup, the core data is strictly detected to ensure the integrity and accuracy of the data, prevent security risks caused by the tampering of the system core data, and achieve the safe and controllable startup of the system. Only when the data measurement is successful, indicating that the system core data has not been illegally modified, is it allowed to start the subsequent printing work, ensuring that the printer is in a safe state from startup, effectively preventing malicious attacks on the printer during the startup phase, and laying a secure foundation for the entire printing work process.
[0062] By setting up a firewall for the printer network port and establishing a white list access system, hosts with IP addresses or MAC addresses that enter the white list are allowed to print. At the same time, communication data security inspection is carried out to eliminate the data and empty all the data attempted to be sent by the host side. Thus, at the network communication level of data interaction between the printer and external devices, multiple means are used to strengthen security protection. The firewall and the white list access system limit the network access rights of the printer, only allowing legitimate IP addresses or MAC address hosts to perform printing operations, preventing the access of illegal devices from the source.
[0063] At the same time, the communication data security inspection mechanism can timely detect and process incomplete or illegal data, prevent bad data from entering the printer system, ensure the standardization and security of data transmission. Thus, it effectively controls the network access scope of the printer, ensures that only authorized devices can interact with the printer, and guarantees the quality and security of the data during the data transmission process, preventing the data from being stolen or tampered with during network transmission, improving the security and stability of the printer in the network environment, and protecting the confidentiality and integrity of the printing data during transmission.
[0064] When an exception occurs during the printing process and there is no human intervention beyond the preset time, the printer automatically resets to destroy the data forgotten by the staff. At the same time, when an emergency occurs during the printing process, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is erased, and the printing traces are destroyed. At the same time, the logical power supply to the operation module is cut off. Thus, effective coping strategies are formulated for two common abnormal situations that may occur during the printing process. For the case of operation timeout, the printer automatically resets. By controlling the potential of the memory pins and cleaning the data of the printing port by software, the sensitive data that may be forgotten is destroyed, avoiding the long-term exposure of the data in an insecure environment. When an emergency occurs, pressing the emergency stop button can not only immediately stop the current printing task, but also cut off the logical power supply of the operation module at the hardware level, erase the memory data, and destroy the printing traces, ensuring that the data cannot be recovered or stolen.
[0065] The real-time protection of data and the rapid response to abnormal situations during the printing work process can take timely measures to protect the security of the printed data, prevent data leakage and illegal access, whether it is due to the long-term lack of human intervention caused by abnormal work processes or sudden emergencies. At the same time, it ensures that the printer can quickly return to a safe state in case of abnormalities, ensuring the data security of the printing work under various complex conditions and enhancing the printer's ability to handle various abnormal situations in actual work.
[0066] After the printing is completed, the residual information on the toner cartridge is erased by electrical erasure, and at the same time, the residual information in the memory is cleared. Thus, after the printing task is completed, the residual information in the toner cartridge and memory during the printing process is promptly cleaned. The toner cartridge is processed by electrical erasure technology to ensure that no information related to the printing task remains on the toner cartridge, avoiding the toner cartridge from becoming a source of information leakage during subsequent processing (such as recycling, replacement). At the same time, the residual information in the memory is cleared to prevent the memory data from being illegally obtained or utilized. Thus, it is ensured that the printer will not leave any traces that may lead to information leakage after completing a printing task, guaranteeing information security from the physical storage medium level, keeping the printer in a safe working state at all times, and preparing for the next printing task, effectively preventing the information from being obtained a second time through the toner cartridge and memory, further improving the information confidentiality and security of the printer, and ensuring the full-life-cycle security management of the printed information.
[0067] The measurement in S1 specifically includes the following steps:
[0068] S101. When the system starts, the TPCM calculates the power supply of the node SOC and measures the BIOS. When the BIOS measurement meets the expectation, the SOC is powered on and the code is loaded. If it does not meet the expectation, power on is allowed / not allowed according to the policy;
[0069] Specifically, when the system starts up, the TPCM calculates the node SOC power supply, measures the BIOS. When the BIOS measurement meets the expectations, the SOC is powered on and the code is loaded. If it does not meet the expectations, power-on is allowed or not allowed according to the policy, so as to accurately measure this key system component of the BIOS to determine whether it has been tampered with or there are security risks.
[0070] S102. Before the BIOS executes the third-party driver code, intercept the behavior of the inserted TSB proxy program and notify the TPCM to measure the third-party driver code. The BIOS decides whether to continue starting the system according to the measurement control result;
[0071] Specifically, before the BIOS executes the third-party driver code, intercept the behavior of the inserted TSB proxy program and notify the TPCM to measure the third-party driver code. The BIOS decides whether to continue starting the system according to the measurement control result, so as to conduct security review and access control on the third-party driver code, ensuring that only the third-party driver code that has passed the security measurement and meets the expectations can be executed in the system, enabling the BIOS to make an intelligent decision based on the measurement result to decide whether to continue starting the system.
[0072] S103. Before the BIOS code executes the Bootloader, intercept the behavior of the inserted TSB proxy program, measure according to the parameters, and determine whether to execute the Bootloader;
[0073] Specifically, before the BIOS code executes the Bootloader, intercept the behavior of the inserted TSB proxy program, measure according to the parameters, and determine whether to execute the Bootloader, so as to conduct security checks before the Bootloader is executed, preventing unauthorized or tampered Bootloader from being executed, avoiding system startup failures or falling into insecure states due to abnormalities in the Bootloader, and ensuring that the system startup process proceeds along the expected secure path.
[0074] S104. Before the Bootloader code executes the OS kernel, intercept the behavior of the inserted TSB proxy program. The TPCM measures the kernel and the OS startup environment. When the measurement fails, power-on of the OS memory is allowed or not allowed according to the policy. The Bootloader persists in initramfs, the operating system startup scripts and programs through the TPCM. The scripts include / etc / rc*;
[0075] Specifically, before the OS kernel is executed by the Bootloader code, the inserted TSB agent program intercepts the behavior, and the TPCM measures the kernel and the OS startup environment. When the measurement fails, the execution of the OS memory is allowed or not allowed according to the policy. The Bootloader adheres to the initramfs, the OS startup script, and the program through the TPCM, thereby ensuring the security of the kernel and the startup environment at the system core level. At the same time, it comprehensively evaluates the key elements of system startup, controls the execution of the OS memory according to the measurement results, prevents system operation risks caused by insecure kernels or startup environments, and ensures that the system starts up into a safe and stable state.
[0076] S105. The TSB agent program in the BootLoader decides whether to execute the operating system kernel according to the return result. The startup measurement interface sends a startup measurement request from the measurement agent to the TPCM. The measurement agent includes BIOS, GRUB, and UBOOT.
[0077] Specifically, the TSB agent program in the BootLoader decides whether to execute the operating system kernel according to the return result. The startup measurement interface sends a startup measurement request from the measurement agent to the TPCM, so that each key component in the system startup process can work together, make intelligent decisions according to the security measurement results, and ensure that the operating system kernel is executed only when all measurements pass, improving the overall security and reliability of the system.
[0078] S106. After receiving the request, the TPCM actively obtains the measured data, calculates the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and the control code.
[0079] Specifically, after the TPCM receives the request, it actively obtains the measured data, calculates the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and the control code. Thus, by comparing with the pre-stored measurement reference value, the security status of the measured data can be accurately judged. The operations of recording the measurement status, returning the measurement result, and the control code enable other components in the system (such as BIOS, etc.) to make corresponding decisions based on this information, standardize and automate the security measurement of system components, ensure the accuracy and consistency of the measurement results, and at the same time provide an effective security status feedback mechanism for the system, enabling the system to take corresponding security measures (such as allowing or blocking system startup, executing specific code, etc.) in a timely manner according to the measurement results, enhancing the system's response ability to security events and the overall security management level.
[0080] In S2, the printer adopts the zero-interface cache printing technology to eliminate data, including eliminating incomplete data and illegal data.
[0081] The abnormalities in S3 include paper shortage and paper jams. The operation module includes a CPU and a memory operation module. When an abnormality occurs during the printing process and there is no human intervention beyond the preset time, the printer automatically resets and destroys the data forgotten by the staff. Specifically, the system detects the printer operation timeout status, sends a #RST signal, changes the potential of the memory pin DRSTN from low to high, the RAM chip automatically resets, the cached data is cleared, and the software also clears the cache of the data at the printing port. When an emergency occurs during the printing process, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is eliminated, the printing traces are destroyed, and at the same time, the logic power supply to the operation module is cut off. Specifically, when it is detected that the emergency stop button is pressed, the OSC sends a control signal to control the power supply of the CE pin of the DC module, cut off the memory power supply, and hardware-destroy the data and traces during printing. The memory includes 1.35V, Flash 3.3V, and SOC 1.8V.
[0082] Please refer to the appendix Figure 2 , a full-process security protection system for printer operation, including:
[0083] Startup check module: used to measure data through a security chip during startup. If the measurement is successful, the control right is transferred to the main control SOC to start the printing work. If the measurement fails, the startup is stopped;
[0084] Communication check module: used to set up a firewall for the printer network port, establish a white list access system, allow printing for the host with the IP address or MAC address that enters the white list, and at the same time conduct communication data security inspection, eliminate the data, and empty all the data attempted to be sent by the host side;
[0085] Process policy module: used to automatically reset the printer and destroy the data forgotten by the staff when an abnormality occurs during the printing process and there is no human intervention beyond the preset time. At the same time, when an emergency occurs during the printing process, by pressing the emergency stop button, the current printing task is immediately stopped and deleted, the memory data is eliminated, the printing traces are destroyed, and at the same time, the logic power supply to the operation module is cut off;
[0086] End policy module: used to erase the residual information on the toner cartridge by electrical erasure after printing, and at the same time clear the residual information in the memory.
[0087] The startup check module includes:
[0088] Measurement unit: used to measure data through a security chip during startup;
[0089] Measurement interface unit: used to start the measurement interface to send a startup measurement request from the measurement agent to the TPCM; after receiving the request, the TPCM actively obtains the measured data to calculate the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and control code.
[0090] The communication check module includes:
[0091] Zero-interface cache printing unit: used to adopt zero-interface cache printing technology to avoid residual unprinted material information when the printer malfunctions;
[0092] Firewall setting unit: used to set up a firewall at the network port, establish a whitelist admission system, and allow hosts with IP addresses or MAC addresses within the whitelist to print;
[0093] Communication data verification unit: used to perform security verification on communication data, eliminate incomplete data and illegal data, and clear all data attempted to be sent by the host side.
[0094] The process policy module includes:
[0095] Timeout detection unit: used to detect the timeout status of printer operations during the printing process;
[0096] Timeout handling unit: used to send a #RST signal when the operation timeout status is detected, causing the RAM chip to automatically reset, clearing the cached data, and at the same time the software clears the cache of the printing port data;
[0097] Control cut-off unit: used to control the OSC to send a signal when the emergency stop button is detected to be pressed, control the power supply to the CE pin of the DC module, cut off the memory power supply, and hardware-destroy the data and traces during printing.
[0098] The end policy module includes:
[0099] Trace clearing unit: used to clear the residual information on the toner cartridge by electrical erasure after printing;
[0100] Memory clearing unit: used to clear the residual memory information at the end of printing.
[0101] Please refer to the appendix Figure 3 , and the measurement unit includes:
[0102] BIOS measurement sub-unit: used for TPCM to calculate the node SOC power supply when the system starts, measure the BIOS, when the BIOS measurement meets the expectations, power on the SOC, load the code, and when it does not meet the expectations, allow / do not allow power on according to the policy;
[0103] Third-party measurement sub-unit: used to intercept the behavior of the inserted TSB proxy program before the BIOS executes the third-party driver code, and notify the TPCM to measure the third-party driver code. The BIOS decides whether to continue starting the system according to the measurement control result;
[0104] Bootloader pre-measurement unit: Before the BIOS code executes the Bootloader, it intercepts the behavior of the inserted TSB agent program, measures according to parameters, and determines whether to execute the Bootloader;
[0105] Kernel measurement unit: Before the Bootloader code executes the OS kernel, it intercepts the behavior of the inserted TSB agent program, and the TPCM measures the kernel and the OS startup environment. When the measurement fails, it allows / does not allow the execution of the OS memory according to the policy;
[0106] System program measurement unit: Used by the Bootloader to further persist the initramfs, the operating system startup script and programs through the TPCM;
[0107] Kernel execution control unit: Used by the TSB agent program in the BootLoader to decide whether to execute the operating system kernel according to the return result.
[0108] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A printer working whole process safety protection method, characterized in that: The following steps are involved: S1. Startup check: During startup, the core data of the system is measured through the security chip. If the measurement is successful, the control is transferred to the main control SOC and the printing work is started. If the measurement fails, the startup is stopped; S2. Communication check: Set up a firewall for the printer network port, establish a whitelist access system, and allow printing for hosts with IP addresses or MAC addresses that are on the whitelist. At the same time, perform communication data security checks. If illegal data appears, eliminate the data and clear all data that the host attempts to send. S3, process strategy: when an abnormality occurs during the printing process and there is no human intervention beyond the preset time, the printer will automatically reset and destroy the data forgotten by the staff. At the same time, when an emergency occurs during the printing process, the emergency stop button will be pressed to immediately stop and delete the current printing task, eliminate the memory data, destroy the printing traces, and cut off the logic power supply to the computing module; S4, ending strategy: After printing is completed, the residual information on the toner cartridge is cleared by electrical erasure, and the residual information in the memory is also cleared.
2. A printer operation whole process safety protection method according to claim 1, characterized in that: The measurement in S1 specifically includes the following steps: S101, TPCM calculates the node SOC power supply when the system starts, measures the BIOS, and when the BIOS measurement meets expectations, powers on the SOC and loads the code; when it does not meet expectations, the power-on is allowed or not allowed according to the policy; S102, before the BIOS executes the third-party driver code, the BIOS intercepts the behavior of the inserted TSB agent program and notifies the TPCM to measure the third-party driver code. The BIOS decides whether to continue to boot the system according to the measurement control result; S103, before the BIOS code executes the Bootloader, the behavior of the inserted TSB agent program is intercepted, and the behavior is measured according to the parameters to determine whether to execute the Bootloader; S104, before executing the OS kernel, the Bootloader code intercepts the behavior of the inserted TSB agent program, and the TPCM measures the kernel and OS startup environment. When the measurement fails, the execution of OS memory is allowed / disallowed according to the policy. The Bootloader maintains initramfs, operating system startup scripts and programs through TPCM, and the scripts include / etc / rc*; S105, the TSB agent in the BootLoader decides whether to execute the operating system kernel according to the returned result, and the boot measurement interface sends a boot measurement request to the TPCM by the measurement agent, and the measurement agent includes BIOS, GRUB, and UBOOT; S106. After receiving the request, TPCM actively obtains the measured data to calculate the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and control code.
3. A printer operation whole process safety protection method according to claim 1, characterized in that: The printer in S2 adopts zero interface buffer printing technology, and the data elimination includes elimination of incomplete data and illegal data.
4. A printer operation whole process safety protection method according to claim 1, characterized in that: The abnormalities in S3 include paper shortage and paper jam. The operation module includes a CPU and a memory operation module. When an abnormality occurs during the printing process and there is no human intervention beyond the preset time, the printer automatically resets and destroys the data forgotten by the staff. Specifically, the system detects the printer operation timeout state and sends a #RST signal. The potential of the memory pin DRSTN changes from low to high, the RAM chip automatically resets, the cached data is cleared, and the software clears the cache of the print port data at the same time. When an emergency occurs during the printing process, the emergency stop button is pressed to immediately stop and delete the current printing task, eliminate memory data, destroy printing traces, and cut off the logic power supply to the operation module. Specifically, the emergency stop button is detected to be pressed, and the OSC sends a control signal to control the power supply to the CE pin of the DC module, cut off the memory power supply, and hardware destroys the data and traces in the printing. The memory includes 1.35V, Flash3.3V, and SOC 1.8V.
5. A printer operation whole process safety protection system, characterized by: A printer operation full-process safety protection method for any one of claims 1 to 4, comprising: Startup check module: used to measure data through the security chip at startup. If the measurement is successful, the control is transferred to the main control SOC to start the printing work. If the measurement fails, the startup stops; Communication check module: used to set up a firewall for the printer network port, establish a whitelist access system, allow printing for hosts with IP addresses or MAC addresses that are on the whitelist, and perform communication data security checks, eliminate data, and clear all data that the host attempts to send; Process strategy module: used to automatically reset the printer and destroy the data forgotten by the staff when an abnormality occurs during the printing process and there is no human intervention beyond the preset time. At the same time, when an emergency occurs during the printing process, press the emergency stop button to immediately stop and delete the current printing task, eliminate the memory data, destroy the printing traces, and cut off the logic power supply to the operation module; End strategy module: used to clear the residual information on the toner cartridge by electrical erasure after printing is completed, and to clear the residual information in the memory at the same time.
6. A printer operation full process safety protection system according to claim 5, characterized in that: The startup inspection module comprises: Measuring unit: used to measure data through the security chip at startup; Measurement interface unit: used to start the measurement interface and the measurement agent sends a measurement request to TPCM; after receiving the request, TPCM actively obtains the measured data to calculate the measurement value, compares it with the measurement reference value, records the measurement status, and returns the measurement result and control code.
7. A printer operation full process safety protection system according to claim 6, characterized in that: The measurement unit comprises: BIOS measurement subunit: used by TPCM to calculate the node SOC power supply when the system starts, measure the BIOS, and when the BIOS measurement meets expectations, power on the SOC and load the code; if it does not meet expectations, power on is allowed or not allowed according to the policy; Third-party measurement subunit: used to intercept the behavior of the inserted TSB agent program before the BIOS executes the third-party driver code, and notify the TPCM to measure the third-party driver code. The BIOS decides whether to continue to boot the system based on the measurement control result; Pre-Bootloader Measurement Subunit: It is used to intercept the behavior of the inserted TSB agent program before the BIOS code executes the Bootloader, measure it according to the parameters, and determine whether to execute the Bootloader; Kernel measurement subunit: used to intercept the behavior of the inserted TSB agent before the Bootloader code executes the OS kernel. TPCM measures the kernel and OS boot environment. When the measurement fails, it allows / does not allow the execution of OS memory according to the policy. System program measurement subunit: used by Bootloader to further adhere to initramfs, operating system boot scripts and programs through TPCM; Kernel execution control subunit: The TSB agent used in the BootLoader decides whether to execute the operating system kernel based on the returned result.
8. A printer operation full process safety protection system according to claim 5, characterized in that: The communication checking module comprises: Zero interface buffer printing unit: used to adopt zero interface buffer printing technology to avoid unprinted data information remaining when the printer makes a mistake; Firewall setting unit: used to set up a firewall on the network port, establish a whitelist access system, and allow hosts with IP addresses or MAC addresses in the whitelist to print; Communication data verification unit: used to perform security checks on communication data, eliminate incomplete and illegal data, and clear all data that the host attempts to send.
9. A printer operation full process safety protection system according to claim 5, characterized in that: The process strategy module includes: Timeout detection unit: used to detect the timeout status of printer operation during printing; Timeout processing unit: used to send out #RST signal when the operation timeout state is detected, so that the RAM chip is automatically reset and the cache data is cleared. At the same time, the software clears the cache of the print port data; Control cut-off unit: used to control OSC to send a signal when it detects that the emergency stop button is pressed, control the power supply to the CE pin of the DC module, cut off the power supply to the memory, and destroy the data and traces in the printing by hardware.
10. A printer operation full process safety protection system according to claim 5, characterized in that: The end strategy module includes: Trace cleaning unit: used to clean the residual information on the toner cartridge by electrical erasing after printing; Memory clearing unit: used to clear the residual information in the memory at the end of printing.