Safe and environment-friendly printing method, system, program and storage medium

By collecting printing task information, user identity authentication, encrypted transmission and dynamic watermarking, the security and environmental protection problems of printing equipment are solved, the security management and resource optimization of the entire process are achieved, and the security and environmental protection of printing tasks are improved.

CN120296759APending Publication Date: 2025-07-11SHENZHEN TAIMEI MICRO TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510330196.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

Existing printing equipment has security risks and resource waste problems. The existing identity authentication and permission control solutions cannot effectively prevent printing data leakage. Environmental printing technology lacks global monitoring and management methods, and employees' subjective initiative has not been fully mobilized.

Method used

By collecting printing task information, performing user identity authentication, generating evidence forensic verification information, and encrypting data during transmission, correct evidence forensic verification information must be provided when picking up the parts, unlocking the printing file storage device, adding dynamic watermarks, identifying sensitive content and warning or approval, and using multi-factor identity authentication and encryption protocols based on printing equipment information.

Benefits of technology

It improves the security and confidentiality of printing tasks, prevents data leakage, reduces resource waste, realizes security and environmental protection management throughout the process, enhances the traceability and anti-counterfeiting capabilities of printed files, and promotes green office.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296759A_ABST
    Figure CN120296759A_ABST
Patent Text Reader

Abstract

The invention discloses a safe and environment-friendly printing management system and a control method thereof. According to the system, mechanisms such as identity authentication, data encryption, evidence obtaining verification, dynamic watermarking, sensitive content recognition and environmental protection statistics are introduced, and the whole life cycle of printing business is controlled. Before printing, a user identity is confirmed based on multi-factor authentication; during printing, encrypted transmission is performed on printing data, a unique watermark is embedded into a printing document, and sensitive information scanning is performed on document content; and after printing, express delivery can be taken only after identity verification, automatic locking is achieved if the express delivery is not taken overtime, and environmental protection data are automatically counted. According to the method, a deep defense system is constructed from a plurality of links, the confidentiality, integrity and traceability of printing data and printing output are guaranteed to the maximum extent, meanwhile, the consciousness of saving of the whole staff is improved, the use of printing supplies is optimized, and safe compliance and green development of printing services are promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of printing devices, and particularly to a secure and environmentally friendly printing method, system, program, and storage medium. Background Art

[0002] With the rapid development of information technology, printing devices have become an indispensable tool in modern office and production environments. However, the resulting security risks and resource waste problems have become increasingly prominent. Printing data is extremely easy to intercept and tamper with, and printed documents are often illegally copied and spread, posing a huge threat to the information security and business secrets of enterprises. At the same time, unreasonable printing behaviors also cause huge waste of consumables such as paper and ink cartridges, exacerbating the environmental burden.

[0003] Currently, there are already some solutions for printing security and environmental protection in the industry. One category is secure printing solutions based on identity authentication and access control, which control access to printing resources through means such as user identity verification and permission allocation, such as HP's secure printing solution. Another category is to achieve environmentally friendly printing by optimizing printing tasks and improving printing processes, such as Epson's ReadyPrint green printing technology.

[0004] However, there are still some problems with the existing technologies. In terms of security, although the existing identity authentication and access control limit illegal access to a certain extent, there is still a risk of printing data being leaked during network transmission and storage, and there is also a lack of effective tracing means for printed documents. In terms of environmental protection, most of the existing environmentally friendly printing technologies are limited to local optimization of the printing process, lacking global monitoring and management means, and the subjective initiative of employees has not been fully mobilized. Therefore, there is an urgent need for a brand-new secure and environmentally friendly printing management system to fundamentally solve the above problems. Summary of the Invention

[0005] A secure printing management method includes: Collecting printing task information, authenticating the user identity based on the collected user information to obtain user identity authentication information, and generating forensic verification information based on the user identity authentication information and the printing task information; Encrypting the printing task information during the transmission process; Executing a pick-up instruction based on the pick-up verification information to unlock a printing file storage device that conforms to the pick-up verification information.

[0006] By adopting a secure printing management method that collects printing task information, authenticates user identities, generates forensic verification information, and encrypts the transmission process, the security of printing tasks is enhanced. The system first collects printing task information and user information, authenticates the user, ensuring that only authorized users can submit printing tasks. Then, based on the authenticated user identity and printing task information, forensic verification information is generated for subsequent verification of the pick-up person's identity. During the transmission process, the printing task information is encrypted to prevent data interception or tampering. Finally, when picking up the file, the correct forensic verification information needs to be provided to unlock the printing file storage device, ensuring the security of the file. The entire process improves the confidentiality, integrity, and non-repudiation of printing tasks.

[0007] Furthermore, a preset time is set for the pick-up instruction. When the preset time is exceeded, the pick-up instruction becomes invalid, causing the printing file storage device to lock again.

[0008] By setting a preset time in the pick-up instruction, which automatically becomes invalid and relocks the printing file storage device after the timeout, the risk of unauthorized personnel picking up the file after a long period of inactivity is prevented. When the printing task is completed, the system generates a pick-up instruction and sets a preset time. Within the preset time, the user can unlock the storage device with the pick-up verification information to pick up the file. Once the preset time is exceeded, the pick-up instruction automatically becomes invalid, and the storage device relocks, avoiding the situation of the file being forgotten or left unattended for too long and being leaked. This timeout locking mechanism improves the security of printing output and reduces security risks caused by human negligence.

[0009] Furthermore, a unique dynamic watermark is added to the printed document based on the submission time of the printing task information and the forensic verification information.

[0010] By adding a unique dynamic watermark generated based on the printing task information and the forensic verification information to the printed document, the traceability and anti-counterfeiting of the printed file are achieved. The system generates a unique dynamic watermark according to the submission time of each printing task and the forensic verification information and prints it on the document. This watermark can identify information such as the printing time and the printer of the document. Once the document is leaked, the printing source can be traced. At the same time, since the watermark for each printing is different, pirated or copied documents can be easily identified, playing a role in anti-counterfeiting. The dynamic watermark makes each printed output unique, greatly improving the security and traceability of printed documents.

[0011] Furthermore, the dynamic watermark is printed on the back of the printed document; and / or, in the printed document page, a text area and a watermark area are divided, and the dynamic watermark is printed in the watermark area.

[0012] By printing a dynamic watermark on the back of a printed document or in a specific watermark area, document traceability and anti-counterfeiting are achieved without affecting the main text content. Printing the watermark on the back of the document can ensure the integrity and aesthetics of the front content, and at the same time, the watermark on the back is not easily removed or covered. If there is content on both sides of the document, a dedicated watermark area can be demarcated on the page, and the watermark is printed within this area, which not only does not affect the layout of the main text but also serves the purpose of the watermark. The flexible watermark addition method realizes the security function while maximizing the preservation of the original appearance of the document, providing a printing solution that takes into account both practicality and confidentiality.

[0013] Furthermore, the content of the printed document is recognized. When sensitive content is detected in the printed document, a warning is given and recorded; and / or, a print authorization request message is generated and sent to the account corresponding to the high-authority user information.

[0014] By identifying sensitive information in the content of the printed document and automatically warning, recording, or requiring high-authority approval when sensitive content is detected, the leakage of sensitive information is prevented. The system analyzes the content of the document during the printing process and identifies possible sensitive information contained therein, such as personal privacy, commercial secrets, national secrets, etc. Once sensitive content is found, a warning is immediately triggered and relevant information is recorded to remind the user to handle it with caution. At the same time, the system can also set different approval requirements for different levels of sensitive content, and users with higher authorities are required to authorize before continuing to print, thus preventing sensitive information from leaking through the printing channel at the source. The sensitive content identification and approval mechanism provides a line of defense for printing security and effectively curbs the printing and dissemination of sensitive information.

[0015] Furthermore, the emissions of the printed document are statistically calculated based on the printing device information, where the printing device information includes at least one of paper data, printing device type, and printing settings; and / or, the printing task information includes at least one or a combination of several of document format, printing content, submission time, paper type, and printing layout; and / or, a suitable paper type is matched according to the content of the printed document, where the paper type includes at least one of paper size and paper material.

[0016] By statistically calculating the emissions of printed documents based on printing device information and matching the most suitable paper type according to the document content, the purpose of environmental protection and conservation is achieved. The system records parameters such as the number of sheets of paper used in each printing task, the type of printing device, and the printing settings, and accordingly calculates the carbon emissions, enabling users to intuitively understand the impact of their printing behavior on the environment and enhancing their awareness of conservation. At the same time, the system can also intelligently analyze the content of printed documents, such as text, pictures, tables, etc., and automatically recommend the most suitable paper type, minimizing waste to the greatest extent while meeting the printing requirements, saving printing costs and practicing the environmental protection concept. The combination of quantitative statistics and optimal matching guides users to establish scientific printing habits and promotes the realization of green office work.

[0017] Further, the user identity authentication information includes at least one of user permissions, username and password, face recognition, fingerprint recognition, voiceprint recognition, and mobile phone verification code.

[0018] By adopting multi-factor identity authentication means, the access security of the printing system is improved. Before using the printing service, users need to pass at least one identity authentication, such as username and password, face recognition, fingerprint recognition, voiceprint recognition, or mobile phone verification code. While verifying the user's identity, the system also judges the user's permission level and controls the scope of their access to printing resources. The combination of multiple authentication factors greatly reduces the risk of identity forgery. Even if one authentication method is cracked, other methods can still play a role in checking. At the same time, the application of biometric technology also makes the authentication process more natural and convenient. Strict identity authentication ensures that only legitimate users can enter the printing system, preventing illegal access and operations from the source.

[0019] Further, the encryption adopts any one of the SSL / TLS, IPsec, VPN, SSH, and HTTPS protocols to encrypt the transmission of printing data.

[0020] By adopting mature encryption protocols such as SSL / TLS, IPsec, and VPN during the transmission of printing tasks, the confidentiality and integrity of printing data are ensured. The printing task is in an encrypted channel throughout the process from submission to output. Even if the data is intercepted, it is difficult to be decrypted and tampered with. System administrators can select encryption algorithms of different strengths according to the sensitivity of the data to balance security and performance. End-to-end encrypted transmission constructs a secure tunnel from the user device to the printing device, eliminating the risk of data being transmitted naked in the network and allowing users to submit and print sensitive files with confidence, providing a reliable guarantee for the secure transfer of printing tasks.

[0021] A system for secure printing management, comprising: The user printing module collects printing task information, authenticates the user identity based on the collected user information to obtain user identity authentication information, and generates forensic verification information according to the user identity authentication information and the printing task information; The encryption transmission module encrypts the printing task information during the transmission process; The encryption pick-up module executes the pick-up instruction based on the pick-up verification information to unlock the printing file storage device that conforms to the pick-up verification information.

[0022] By designing a secure printing management system that includes a user printing module, an encryption transmission module, and an encryption pick-up module, a full-process printing security solution is formed. The user printing module is responsible for collecting printing task information, authenticating the user identity, and generating forensic verification information, providing the original data for subsequent operations. The encryption transmission module provides encryption services during the transmission of task information to ensure that the data is not stolen or tampered with. The encryption pick-up module uses the pick-up verification information to control the locking and unlocking of the file storage device, strictly checking the retrieval of files. The three modules cooperate with each other in a well-connected manner, constituting an all-round secure printing ecosystem, greatly enhancing the security of each link from printing task submission to pick-up.

[0023] A computer-readable storage medium stores a command auditing program thereon, and when the command auditing program is executed by a processor, the steps of the method as described are implemented.

[0024] By implementing the secure printing management method as an auditing program stored on a computer-readable storage medium, the printing method has stronger applicability and popularity. Encoding the method steps as computer program instructions and storing them in common storage devices such as disks, optical discs, and USB flash drives enables it to be easily deployed to various computer systems and printers. Users only need to insert the storage medium into the computer and run the program therein to quickly build a secure printing management system without manual configuration, reducing the implementation difficulty and cost. The programmed method steps can also be continuously updated and iterated, introducing new algorithms and strategies, enabling the system to keep up with the times and adapt to the changing security situation. Software-izing the printing security method is an effective way to improve its practical value and popularization. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 Shows the flowchart of the secure printing management method provided in Embodiment 1 of the present invention.

[0026] Figure 2 Shows the flowchart of the secure printing management method provided in Embodiment 3 of the present invention.

[0027] Figure 3 Shows the architecture diagram of the secure printing management system provided in Embodiment 4 of the present invention. Detailed implementation manners

[0028] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0029] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other. Embodiment 1

[0030] As Figure 1 shown, this embodiment provides a secure printing management method, including the following steps: Step S1: Collect print task information, authenticate the user identity based on the collected user information to obtain user identity authentication information, and generate forensic verification information based on the user identity authentication information and the print task information.

[0031] Specifically, the print task information may include at least one or a combination of several of the document format, print content, submission time, paper type, and print layout. Among them, the document format may be common formats such as PDF, Word, Excel, JPG, PNG, etc.; the print content may be text, pictures, tables, etc.; the submission time is the timestamp when the user submits the print task; the paper type includes paper size (such as A4, A3, B5, etc.) and paper material (such as plain paper, coated paper, photo paper, etc.); the print layout includes options such as single-sided printing, double-sided printing, and multiple pages in one. After the system receives the user's print request, the above print task information can be obtained.

[0032] The user information may be information such as user ID, IC card number, name, department, etc. that identifies the user identity. The system collects the user information by reading the user's identity medium (such as work card, USBKey, etc.) or requiring the user to input credentials (such as username password, PIN code, etc.).

[0033] User identity authentication is to confirm whether the user submitting the printing task is legitimate. The authentication methods can include at least one of verifying username and password, face brushing, fingerprint brushing, voiceprint recognition, mobile phone verification code, etc. Among them, verifying username and password is the most common method. The user needs to enter the correct username and password to pass the authentication; face brushing, fingerprint brushing and voiceprint recognition belong to biometric recognition, which determines the identity by comparing the user's face, fingerprint, voice with the pre-recorded template; the mobile phone verification code is to send a one-time verification code to the mobile phone bound by the user, and the user enters the received verification code to complete the authentication. The system can adopt a combination of one or more authentication methods to improve the reliability of authentication. After the authentication is passed, the user identity can be determined, and the user identity authentication information (such as user unique ID, user role, etc.) can be obtained.

[0034] After obtaining the user identity authentication information and the printing task information, the system will also generate pick-up verification information as the basis for the user to pick up the print later. The pick-up verification information can be a randomly generated digital or string password, or the user's biometric features, such as fingerprints, irises, etc. The system binds the pick-up verification information with the printing task information and stores them together.

[0035] Step S2: Encrypt the printing task information during transmission.

[0036] Specifically, when data is transmitted over the network, it may be attacked such as eavesdropping and tampering, so encryption protection is required. Common encryption means include SSL / TLS, IPsec, VPN, SSH, HTTPS, etc.: SSL / TLS (Secure Socket Layer / Transport Layer Security): Based on public key encryption, it provides security guarantee at the transport layer and is mainly used for communication encryption between Web browsers and servers.

[0037] IPsec (Internet Protocol Security): Encrypts and authenticates data packets at the network layer to protect the communication of all applications in the network.

[0038] VPN (Virtual Private Network): A private network built on top of a public network. Through encryption and tunneling technologies, it establishes a secure and reliable connection on an untrusted network.

[0039] SSH (Secure Shell): Achieves remote secure access through asymmetric encryption and is often used to provide a secure channel for insecure network services, such as remote login, file transfer, etc.

[0040] HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer): Secure HTTP communication based on SSL / TLS. An encryption layer is introduced into the HTTP protocol stack to achieve encrypted transmission of web page content.

[0041] Which specific encryption method to adopt can be determined according to factors such as the sensitivity of the data and the transmission environment. Through encryption, it is possible to prevent the printing task information from being illegally stolen or tampered with during transmission, ensuring the confidentiality and integrity of the data.

[0042] Step S3: Execute the pick-up instruction based on the pick-up verification information to unlock the printing file storage device that conforms to the pick-up verification information.

[0043] After the printing task is completed, the system generates a pick-up instruction indicating the location of the printed file and the information that needs to be verified. The pick-up instruction can be sent to the user in the form of text, QR code, etc. The user goes to the printer according to the pick-up instruction and enters the pick-up verification information, such as password, fingerprint, etc. The system verifies whether the pick-up verification information matches the stored information. If it matches, it controls the printing file storage device to unlock and allows the user to pick up the printed file; if it does not match, the pick-up request is rejected. Here, the printing file storage device can be the output paper tray of the printer body, or an independent file cabinet, pick-up box, etc. The control method can be an actuator such as an electronic lock, electromagnetic lock, servo motor, etc.

[0044] Through the above steps, the printing method of this embodiment constructs a complete printing security link: identity authentication ensures that only legitimate users can initiate printing; encrypted transmission prevents data leakage; pick-up verification avoids theft by others, ultimately achieving end-to-end printing security. Embodiment 2

[0045] Based on Embodiment 1, this embodiment further details several key steps: In step S1, the generation of the pick-up verification information can be achieved through the following sub-steps: S11: Obtain the biometric (such as fingerprint, face, etc.) template of the user and use it as the pick-up verification information. In this case, for subsequent pick-up, the user needs to provide the biometric on-site for comparison.

[0046] S12: Randomly generate a one-time password (OTP) and use it as the pick-up verification information. The one-time password can be generated using algorithms such as HOTP (HMAC-based OTP) and TOTP (Time-based OTP). At this time, the system sends the one-time password to the user through channels such as text messages and emails, and the user picks up the item with the one-time password. The one-time password becomes invalid after use, which can prevent others from copying and misusing it.

[0047] S13: Combine the printing task information with the user identity authentication information, add salt and perform hashing to generate a digital signature as the pick-up verification information. The "salt" here is a random number, which can prevent rainbow table attacks. The digital signature can verify the identity of the pick-up person on the one hand and ensure the integrity of the printing task information on the other hand.

[0048] The above methods for generating pick-up verification information can be used alone or in combination. In practical applications, an appropriate generation strategy can be selected according to security requirements.

[0049] In step S2, the encryption of the printing task information can be carried out in a block encryption manner to improve the encryption efficiency. Taking SSL / TLS as an example, its basic process is as follows: S21: The sender divides the printing task information into several data groups, and the size of each group is determined by the encryption algorithm and the key length. For example, the block size of AES-128 is 128 bits.

[0050] S22: Encrypt each data group, and the encryption results are concatenated into a ciphertext data stream. The encryption process can adopt various working modes of block ciphers, such as ECB, CBC, CFB, OFB, etc. Among them, the ECB mode is the simplest, and each block is encrypted independently; the CBC mode introduces an initialization vector, so that the same plaintext block will generate different ciphertext blocks; CFB and OFB convert the block cipher into a stream cipher, which is suitable for encrypting data streams.

[0051] S23: The sender sends the encrypted data to the receiver through the channel.

[0052] S24: After receiving the ciphertext data stream, the receiver decrypts the data stream according to the encryption algorithm and key agreed upon with the sender to restore the original printing task information.

[0053] The above encryption process uses the same session key between the sender and the receiver, which belongs to symmetric encryption. The generation and distribution of the session key can be achieved through other mechanisms such as asymmetric encryption.

[0054] In step S3, the pick-up instruction can be set with a validity period. If the pick-up is not made after the validity period expires, the instruction becomes invalid, and it is necessary to regenerate the pick-up verification information. This can prevent the printed documents from being left unattended for a long time and taken away by others. The validity period of the pick-up instruction can be set according to factors such as the sensitivity of the document and the printing environment, usually ranging from dozens of minutes to several hours. When generating the pick-up instruction, the system will simultaneously set a timer. When the timer times out, the system will automatically lock the printing document storage device, and the document cannot be taken away until the user contacts the administrator for handling. Embodiment 3

[0055] This embodiment provides an enhanced secure printing management method. Based on Embodiments 1 and 2, functions such as dynamic watermarking, content recognition, and environmental protection statistics are added to further improve printing security and management efficiency, as Figure 2 shown.

[0056] Between steps S1 and S2, add the following steps: Step S1A: Add a unique dynamic watermark to the printed document based on the submission time of the printing task information and the forensics verification information.

[0057] In specific implementation, the submission timestamp of the printing task can be combined with the forensics verification information (such as a digital signature), and after encryption, encoding, and other processes, a digital watermark pattern is generated. The pattern can be in the form of a QR code, barcode, digital number, text information, etc. The system embeds the digital watermark pattern into the printed document to blend it with the document content. The embedding method can be a visible watermark or an invisible watermark: For a visible watermark, the digital watermark pattern is directly printed on the back of the document or a specially demarcated watermark area, and can be recognized by the user with the naked eye. The advantage is that the warning effect is strong, which can remind the user to pay attention to the confidentiality of the document. The disadvantage is that it will occupy a certain amount of printing space and affect the neatness of the document.

[0058] For an invisible watermark, the digital watermark pattern is printed on the document in a form invisible to the human eye, such as small yellow text, a light pattern close to the background color, etc. The document looks no different from ordinary printed output, but can be revealed by irradiating with a specific instrument (such as an ultraviolet lamp) when needed. The advantage is that it does not affect the document layout, and the disadvantage is that it is invisible to the naked eye and the warning effect is relatively weak.

[0059] In addition to including the printing task information, the watermark can also add management information such as the printer, printing device, printing time, and printing times to form the document DNA exclusive to a single print. Once a document leak occurs, the responsible person can be traced through the watermark.

[0060] Step S2A: Identify the content of the printed document. When sensitive content is detected in the printed document, give a warning and record it.

[0061] This step is to check the content of the document before printing to identify potential risks of information leakage. The identification process can employ technical means such as keyword matching, regular expressions, and machine learning.

[0062] First, establish a sensitive content library that includes sensitive words, phrases, patterns, etc. Such as "Top Secret", "Internal Information", " / / d / / d / / d. / / d / / d / / d. / / d. / / d" (IP address pattern), etc. Then, perform a full-text scan of the printed document to match the items in the sensitive content library. If the match is successful, it is considered that the document may contain sensitive content. The match can be an exact match or a fuzzy match (such as the edit distance being less than or equal to 1). Considering the diversity of data, techniques such as text classification and named entity recognition can also be introduced to more intelligently discover sensitive content.

[0063] When sensitive content is detected, the system can take the following measures: (1) Issue a warning to prompt the user that the document may contain sensitive content and let the user confirm again whether to print.

[0064] (2) Force the user to modify the document and only allow printing after removing the sensitive content.

[0065] (3) For particularly sensitive content, higher-level approval is required. The system automatically sends a print approval request to the administrator, and printing is only allowed after approval.

[0066] (4) Record relevant logs, including the document name, submitter, submission time, identified sensitive content, etc., for subsequent auditing.

[0067] Through the identification of sensitive content, it is possible to reduce the leakage of documents caused by users' subjective negligence or objective ignorance and plug potential security loopholes in the printing process.

[0068] Step S2B: Statistically calculate the emissions of the printed document based on the printing device information.

[0069] While controlling printing security, the present invention also takes into account the environmental protection factors of printing. The system records various data related to the printing task, such as the number of printed pages, single-sided / double-sided, color / black and white, paper size, paper type, device energy consumption, etc., and estimates the carbon emissions based on this. The carbon emissions can be measured by the grams of carbon dioxide emissions caused by each sheet of paper. The calculation formula is: Carbon emissions = number of printed sheets × paper factor × color factor × energy consumption factor Among them, the paper factor is determined according to the paper size and type. For example, each A4 plain paper emits 7.8 grams, and each A3 plain paper emits 10.2 grams; the color factor distinguishes between monochrome and color. For example, 1.0 is taken for black and white printing, and 1.2 is taken for color printing; the energy consumption factor is related to the printer model and working status, and the equipment manual needs to be referred to.

[0070] The system can give a carbon emission quota for each user or department. When the quota is exceeded, a prompt or printing restriction is issued. Users can reduce emissions by reducing unnecessary printing and using environmentally friendly printing options (such as double-sided printing, multiple pages combined into one, draft mode, etc.). Administrators can monitor emissions in real time and warn and educate departments or individuals with excessive emissions.

[0071] While counting emissions, the system can also intelligently recommend the best printing parameters according to the content characteristics of the printed document, such as the number of words, image area, color richness, etc. For example, for a document mainly composed of text and with little content, it is recommended to use A5 paper for black and white printing; for a document with more image colors, it is recommended to use coated paper for color printing.

[0072] This embodiment comprehensively utilizes various technical means such as identity authentication, data encryption, pick-up verification, dynamic watermarking, content recognition, and environmental protection statistics. Starting from multiple links before, during, and after printing, a comprehensive printing security protection system and a green printing control plan are constructed to provide users with a more secure, environmentally friendly, and intelligent printing service. Embodiment 4

[0073] From the perspective of the system, this embodiment gives a secure printing management system corresponding to the foregoing method, as Figure 3 shown. The system includes: A user printing module, which is responsible for collecting printing task information, authenticating user information to obtain user identity authentication information, and generating forensics verification information according to the user identity authentication information and printing task information, etc. This module can also set the validity period of the pick-up instruction as needed.

[0074] An authentication sub-module, which is responsible for verifying the identity of the user. This sub-module supports multiple authentication methods, including username and password, face recognition, fingerprint recognition, voiceprint recognition, mobile phone verification code, etc. Face, fingerprint, and voiceprint recognition can collect the user's biometric features through external devices such as cameras, fingerprint scanners, and microphones, and compare them with the pre-registered templates. The mobile phone verification code requires the user to bind a mobile phone number in advance and receive a text message verification code during authentication. This sub-module is connected to the user database on the server side to obtain the user's registration information.

[0075] The encryption transmission module is responsible for providing end-to-end encryption services during the transmission of printing task information. This module integrates mainstream encryption protocols such as SSL / TLS, IPsec, and VPN, and can be flexibly selected according to needs. SSL / TLS is mainly used for secure communication between browsers and servers, IPsec is used for the security of any network connection between machines, and VPN is used to establish a dedicated enterprise internal network on a public network. Through encryption, it is ensured that data is not stolen or tampered with during network transmission.

[0076] The encrypted pick-up module is responsible for locking the printing file storage device after the printing task is output. Only after verifying the correct pick-up verification information can the file be unlocked. This module controls actuators such as relays, solenoid valves, and servo motors to achieve physical locking of the storage device. When the storage device is a physical compartment (such as a filing cabinet), it is locked through an electromagnetic lock; when the storage device is a logical compartment (such as a folder), it is locked through file encryption. Pick-up verification can be performed by entering a dynamic password, scanning a QR code, providing biometric features, etc.

[0077] The dynamic watermark embedding module is responsible for embedding a digital watermark generated based on a timestamp and forensic verification information into the printed document. This module first generates a digital watermark according to algorithms (such as hashing, symmetric encryption, and asymmetric encryption), and then uses digital watermark technology to integrate the watermark pattern into the printed document. The integration method can be to directly print the watermark at the corresponding position of the document through GDI or PDL instructions, or to superimpose the watermark pattern on the document image using digital image processing algorithms. Here, both visible watermarks and invisible watermarks can be generated. Invisible watermark technologies include text line spacing encoding, character spacing encoding, etc.

[0078] The sensitive content recognition module is responsible for scanning the printed document and detecting sensitive content. Based on natural language processing technology, this module performs word segmentation, part-of-speech tagging, named entity recognition, keyword extraction, etc. on the document content to discover sensitive words, sensitive phrases, or sensitive patterns. This requires a predefined sensitive content library containing the text features of various sensitive information. When sensitive content is recognized, this module will issue a warning, record an audit log, and decide whether to report for approval according to the rules. The approval is responsible for the authorization management module.

[0079] The environmental protection statistics module is responsible for recording the paper and ink cartridge usage of printing tasks, estimating carbon emissions, and giving environmental protection printing suggestions. This module needs to collect real-time status data of the printer, including the number of printed pages, paper tray capacity, ink cartridge model, etc., and obtain statistical results after comprehensive analysis. At the same time, this module gives the optimal environmental protection settings, such as recommending double-sided printing, multi-page combination, ink-saving mode, etc. by analyzing the content of the printed document (such as the number of words, image area, etc.). Environmental protection data can be displayed on the management console, and an alarm threshold can be set.

[0080] The above-mentioned functional modules cooperate with each other, ensuring the information security of the entire printing process and achieving green energy conservation. With the full combination of software and hardware design, the security technology is seamlessly integrated with the business process, forming an adaptive and elastic printing security architecture. Example 5

[0081] This embodiment provides a blockchain-based secure printing management system that introduces blockchain technology to enhance the immutability and traceability of printing vouchers. On the basis of Example 4, the system adds the following new features: The printing task information, user identity authentication information, and forensic verification information are combined into a data block, together with additional information such as a time stamp and a random number, and a block with a valid signature is generated through a consensus algorithm and appended to the end of the blockchain. The block header contains the hash value of the previous block, forming a chained structure. Once a block is confirmed and added to the blockchain, its internal data cannot be tampered with.

[0082] The blockchain network consists of authorized nodes, which can be printers or servers. Each node stores a complete copy of the blockchain. When a new printing task is submitted, the generated block is broadcast across the network and verified by the authorized nodes. Only when the verification passes and most nodes add the block to their local chains is the block considered to take effect.

[0083] Due to the characteristics of the blockchain, any act of privately copying or leaking a printed document will leave an indelible record. This mandatory behavior recording function makes the printing process a self-evident complete evidence chain, which is conducive to post-event auditing and evidence collection.

[0084] In this blockchain network, users can query the printing tasks they submitted, but can only see the information related to themselves and cannot see the information of others. Administrators have higher viewing permissions and can see the printing records of all users for unified management and auditing.

[0085] In specific applications, the blockchain network can also be combined with the Internet of Things to upload information such as printing vouchers and environmental data to the chain to achieve full-time monitoring of the entire printing environment. When an abnormality occurs during the printing process, such as illegal copying or leakage, the system can immediately detect and give an early warning. Each associated terminal can also build a trusted collaborative network based on the blockchain to share threat intelligence and jointly combat printing security incidents.

[0086] The above blockchain-based design further enhances the security of printing task information and audit logs, while making control and auditing more transparent and efficient. Copying this mechanism to all aspects of printing management can comprehensively improve the credibility of printing services.

[0087] Finally, it should be noted that the embodiments provided by the present invention are illustrative rather than exhaustive. Without departing from the spirit and scope of the present invention, those of ordinary skill in the art can make various modifications and improvements, and these modifications and improvements should also be regarded as the protection scope of the present invention. For example, on the premise of ensuring printing safety and environmental protection concepts, specific implementation details such as the module division, architecture design, interface form, data structure, and algorithm selection of the system can be flexibly adjusted according to actual needs. Again, the present invention can be combined with emerging technologies such as artificial intelligence, big data analysis, and 5G communication to further expand the application scenarios and functional space. In short, the systems and methods provided by the present invention are open and extensible, and should not be limited to the specific details given in the embodiments.

Claims

1. A secure printing management method, characterized in that, Including: Collect print task information, authenticate the user identity based on the collected user information to obtain user identity authentication information, and generate forensic verification information based on the user identity authentication information and the print task information; Encrypt the print task information during the transmission process; Execute a pick-up instruction based on the pick-up verification information to unlock the print file storage device that conforms to the pick-up verification information.

2. The method according to claim 1, wherein The pick-up instruction is preset with a time limit. When the preset time limit is exceeded, the pick-up instruction becomes invalid, so that the print file storage device is locked again.

3. The method according to claim 1, characterized in that Add a unique dynamic watermark to the printed document based on the submission time of the print task information and the forensic verification information.

4. The method according to claim 3, characterized in that, The dynamic watermark is printed on the back of the printed document; and / or, divide the printed document page into a text area and a watermark area, and the dynamic watermark is printed in the watermark area.

5. The method according to claim 1, characterized in that, Identify the content of the printed document. When sensitive content is detected in the content of the printed document, give a warning and record it; and / or, generate a print authorization request information and send the print authorization request information to the account corresponding to the high-privilege user information.

6. The method according to claim 1, wherein Statistically calculate the emissions of the printed document based on the print device information, where the print device information includes at least one of paper data, print device type, and print settings; and / or, the print task information includes at least one or a combination of several of document format, print content, submission time, paper type, and print layout; and / or, match a suitable paper type according to the content of the printed document, where the paper type includes at least one of paper size and paper material.

7. The method according to claim 1, characterized in that, The user identity authentication information includes at least one of user permissions, username password, face recognition, fingerprint recognition, voiceprint recognition, and mobile phone verification code.

8. The method according to claim 1, characterized in that, The encryption uses any one of the SSL / TLS, IPsec, VPN, SSH, HTTPS protocols to encrypt the transmission of print data.

9. A system for secure printing management, characterized in that, Including: A user print module that collects print task information, authenticates the user identity based on the collected user information to obtain user identity authentication information, and generates forensic verification information based on the user identity authentication information and the print task information; An encrypted transmission module that encrypts the print task information during the transmission process; An encrypted pick-up module that executes a pick-up instruction based on the pick-up verification information to unlock the print file storage device that conforms to the pick-up verification information.

10. A computer-readable storage medium, characterized in that, A command auditing program is stored on the computer-readable storage medium. When the command auditing program is executed by a processor, the steps of the method described in any one of claims 1-8 are implemented.

Citation Information

Cited By

  • Interaction method of multi-service sharing self-service terminal based on mobile application and storage medium

    CN121281170A