Consumable identification method and device, medium and product
By combining asymmetric cryptography for two-way authentication and hardware random number generators, along with symmetric communication key encryption and hardware execution capability verification, the problem of low security in consumable identification in existing technologies is solved, achieving efficient and reliable identification of genuine and counterfeit consumables.
Patent Information
- Application Number
- CN202511629912.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-08
- Publication Date
- 2026-02-10
AI Technical Summary
In existing technologies, the identification of printing consumables relies on static parameters, resulting in low security, easy copying and cracking, and inability to effectively distinguish genuine from counterfeit consumables, leading to the proliferation of counterfeit consumables.
Two-way identity authentication is performed using trusted credentials based on asymmetric cryptography. A symmetric communication key encryption channel is established through dynamic interaction between private key signing and public key verification. The hardware execution capability of the consumable chip is assessed through verification code, and random numbers are generated by a hardware random number generator to enhance security.
It improves the reliability and anti-attack capability of consumable identification, prevents replay attacks, ensures the real-time and confidentiality of authentication, significantly improves the accuracy and robustness of identification, and reduces the circulation of counterfeit products.
Smart Images

Figure CN121504486A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electronic digital data processing technology, specifically to a consumable identification method, device, medium, and product. Background Technology
[0002] The printer technology field has made significant progress in recent years. Printing devices have become increasingly powerful, with continuously improving printing speed and quality. They are widely used in many scenarios such as offices, education, and homes, greatly improving the efficiency of information output and sharing. As an essential component for the normal operation of printers, the market size of printing consumables has also expanded with the popularization of printers. However, the development of the printing consumables market has also brought a series of problems, such as poor compatibility between compatible consumables and printers, and the proliferation of counterfeit consumables. These problems not only affect print quality but also harm the interests of original equipment manufacturers (OEMs).
[0003] To identify and manage printing consumables, existing printing consumable identification technologies typically employ a traditional one-way chip parameter reading method for verification. Specifically, the host computer reads pre-stored fixed parameters in the consumable chip, such as model number, capacity, and serial number, and compares these parameters with preset standard parameters in the host computer to determine the consumable's legitimacy and applicability. This method has long been a standard practice in the field of printing consumable identification, and to a certain extent, it can perform preliminary screening and verification of consumables.
[0004] However, this traditional identification method, which relies on one-way reading of fixed parameters, has significant drawbacks. The core problem lies in its extremely low security. The fixed parameters stored in the chip are static and can be easily read, copied, and cracked through technical means. Criminals can completely clone the parameters of genuine consumable chips onto inexpensive blank chips, thus creating counterfeit consumables that can be mistakenly identified as genuine by the host computer. Because this verification mechanism lacks dynamic interaction and anti-copying capabilities, it cannot truly verify the physical authenticity of the consumables, leading to a proliferation of counterfeit consumables in the market, seriously damaging the interests of original manufacturers and the printing experience for users. Therefore, the inability of existing technology to effectively distinguish genuine from counterfeit consumables is a technical problem that urgently needs to be solved. Summary of the Invention
[0005] To address the technical problem that existing technologies are unable to effectively distinguish genuine from counterfeit consumables, this application provides a consumable identification method, device, medium, and product.
[0006] In a first aspect, this application provides a method for identifying consumables, including: Obtain the consumable trusted certificate sent by the consumable, verify the consumable trusted certificate using the pre-stored root public key, and send the host trusted certificate to the consumable so that the consumable can verify the host trusted certificate using the pre-stored root public key of the consumable. The consumable trusted certificate is generated by the manufacturer using the root private key to sign the consumable public key during the production stage, and the host trusted certificate is generated by the manufacturer using the root private key to sign the host public key during the production stage. When the consumable's trusted credential is verified by the host, and the host's trusted credential is verified by the consumable, a first signature file is obtained, the first signature file is verified using the consumable's public key, and a second signature file is sent to the consumable so that the consumable can verify the second signature file using the host's public key. The first signature file is generated by the consumable using its private key, the second signature file is generated by the host using its private key, the consumable's public key is obtained from the verified trusted credential of the consumable, and the host's public key is obtained by the consumable from the verified trusted credential of the host. When the first signature file passes verification and the second signature file passes verification, a symmetric communication key is generated and sent to the consumable. Obtain the consumable parameters of the consumable, and generate a verification code that has a mapping relationship with the consumable parameters based on the consumable parameters according to preset rules; The verification code is encrypted using the symmetric communication key to obtain an encrypted verification code, which is then sent to the consumable. Simultaneously, a timer is started so that the consumable can decrypt the encrypted verification code using the symmetric communication key to obtain the verification code, run the verification code, and encrypt the running result using the symmetric communication key before sending it to the host. When the encrypted running result is received, the timer is stopped, the verification time is calculated, and the encrypted running result is decrypted to verify the running result. When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable.
[0007] This solution effectively addresses the low security issue caused by existing technologies relying on static parameters. First, it employs two-way authentication using trusted credentials based on asymmetric cryptography, ensuring the legitimacy of both communicating parties and laying a foundation of trust for subsequent interactions. Next, through dynamic interaction of private key signing and public key verification, it proves that both parties genuinely possess their private keys, effectively preventing replay attacks and ensuring real-time authentication. Building upon this, the method establishes a secure communication channel encrypted with a symmetric key, guaranteeing the confidentiality of subsequent core verification data. Its key innovation lies in extending authentication from simple cryptographic verification to assessing hardware execution capabilities by issuing verification code and measuring the time required for the consumable chip to execute it. Since genuine chips have a specific and stable performance range, any counterfeit product may exceed this verification time and be detected. This method effectively binds the authentication result to the inherent physical characteristics of the consumable's hardware, rendering counterfeiting methods that only copy keys and algorithms ineffective, thereby significantly improving the reliability and anti-attack capability of consumable identification.
[0008] Optionally, the step of sending a second signature file to the consumable to enable the consumable to verify the second signature file using the host public key specifically includes: Use the host hardware random number generator to generate the first random number; The first random number is signed using the host private key to obtain the second signature file; Send a second signature file to the consumable to instruct the consumable to verify the second signature file using the host public key; The first signature file is obtained by the consumable through the following method: generating a second random number using the consumable hardware random number generator, and signing the second random number using the consumable private key to obtain the first signature file.
[0009] This solution requires both the host and consumables to use a hardware random number generator to generate random numbers as signature objects, thereby enhancing the security of the authentication process. The hardware random number generator uses a physical process to produce truly random data, and its output is completely unpredictable. This mechanism completely disables attackers' methods of intercepting and replaying past legitimate communication data. Therefore, by introducing true hardware random numbers, this invention significantly improves the replay attack resistance of the two-way authentication process, making it more robust in complex attack environments.
[0010] Optionally, the step of generating a symmetric communication key and sending the symmetric communication key to the consumable specifically includes: The symmetric communication key is generated using a preset key derivation function based on the first random number and the second random number. The symmetric communication key is encrypted using the public key of the consumables to obtain the encrypted symmetric communication key; The encrypted symmetric communication key is sent to the consumable, so that the consumable can use its private key to decrypt the encrypted symmetric communication key to obtain the symmetric communication key.
[0011] This scheme uses randomly generated numbers exchanged by both parties, combined with a key derivation function, to generate a session key. This ensures that no single party can predict or control the final key, effectively preventing the risk of a malicious party generating a weak key. More importantly, this method provides forward confidentiality. Since the session key is dynamically generated based on a one-time temporary random number and is not directly related to the device's long-term private key, even if the device's long-term private key is leaked in the future, it cannot be used to decrypt previously intercepted communication data, thereby reducing potential security risks. Finally, the generated symmetric key is encrypted using the consumable's public key before transmission, ensuring that only legitimate consumables holding the corresponding private key can decrypt and obtain the session key.
[0012] Optionally, after the step of stopping the timer, calculating the verification time, and decrypting the encrypted running result upon receiving the encrypted running result, the method further includes: When the verification duration is greater than or equal to the preset duration, or when the running result fails the verification, the unique identifier of the consumable is extracted from the consumable trusted certificate; Add the unique identifier to the blacklist database.
[0013] This solution allows the system to automatically extract a unique identifier and add a consumable to a blacklist database when it is identified as counterfeit due to abnormal verification time or incorrect results. When a host encounters a blacklisted consumable later, it can directly reject it during the initial authentication process, eliminating the need to repeat the resource-intensive full authentication procedure. Furthermore, this blacklist database has network synergy effects and can be shared among numerous host devices via firmware updates or cloud services. This enables the rapid transformation of single-point detection of a new type of counterfeit consumable into a global immunity capability, significantly reducing the circulation space and attack window for counterfeit products.
[0014] Optionally, after the step of obtaining the trusted credential for the consumables being sent, the method further includes: Obtain the unique identifier of the consumable; Search the blacklist database, which includes unique identifiers that confirm non-genuine consumables; If a unique identifier exists for the consumable, it is confirmed that the consumable is a counterfeit product, and the user is notified.
[0015] This solution significantly improves authentication efficiency and saves system resources. By first extracting the unique identifier of the consumable and comparing it with a blacklist database, this method can instantly intercept confirmed counterfeit consumables. This avoids repeatedly performing the time-consuming and computationally resource-intensive full authentication process for known counterfeit products, greatly shortening the response time for such consumables and quickly providing clear prompts to users.
[0016] Optionally, the step of confirming that the consumable is a genuine consumable when the verification time is less than the preset time and the running result passes the verification specifically includes: The baseline verification time distribution characteristics of genuine consumables running on the verification code are obtained through a cloud server; The preset duration is calculated based on the baseline verification duration distribution characteristics; When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable.
[0017] This solution dynamically sets preset durations by obtaining baseline verification duration distribution characteristics from a cloud server, significantly improving the accuracy and adaptability of the hardware verification process. Compared to a fixed, locally stored duration threshold, it effectively accommodates minor performance fluctuations in genuine chips caused by factors such as production batches, ambient temperature, and aging, significantly reducing the probability of misidentifying genuine products as counterfeit. More importantly, the cloud update mechanism empowers the system to dynamically respond to new attacks. If a counterfeit product accurately mimics the current duration, the manufacturer can push new verification code and a corresponding new baseline duration distribution to the cloud, enabling all networked hosts to synchronously update their defense strategies without requiring firmware upgrades. This design makes the verification standard dynamic and evolving, greatly enhancing the accuracy, robustness, and long-term effectiveness of the identification system.
[0018] Optionally, after the step of confirming that the consumable is a genuine consumable, the method further includes: Detect the remaining consumables and printing demand; The user is prompted when the remaining consumables are less than the required printing quantity. Printing begins when the remaining amount of consumables is greater than or equal to the printing demand, and the remaining amount of consumables is monitored in real time. When the remaining amount of the consumable is less than a preset remaining amount threshold, photoelectric detection is used to detect the remaining amount of the consumable.
[0019] This invention, after confirming the consumables are genuine, further provides an intelligent consumable balance management solution, significantly improving user experience and enhancing the reliability of the printing system. By comparing the remaining consumables with the printing demand before the start of a print job, it effectively avoids print job failures due to insufficient balance, saving users time and paper. Its core innovation lies in employing a hybrid detection strategy: for most of the consumable's lifespan, it relies on a reliable chip that has been verified as genuine to estimate the remaining balance; while in the critical stage when the consumable is about to run out, it switches to more precise photoelectric physical detection. This combined approach integrates the convenience of chip counting with the high precision of physical detection at critical points, ensuring the accuracy of balance information throughout its entire lifecycle.
[0020] In a second aspect, embodiments of this application provide a consumable identification device, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, which includes computer instructions, and the one or more processors call the computer instructions to cause the consumable identification device to perform the method described in the first aspect and any possible implementation thereof.
[0021] Thirdly, embodiments of this application provide a computer program product containing instructions that, when the computer program product is run on a consumable identification device, cause the consumable identification device to perform the method described in the first aspect and any possible implementation thereof.
[0022] Fourthly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a consumable identification device, cause the consumable identification device to perform the method described in the first aspect and any possible implementation thereof. Attached Figure Description
[0023] Figure 1 This is a flowchart illustrating a consumable identification method in an embodiment of this application; Figure 2 This is a timing diagram of a consumable identification method in an embodiment of this application; Figure 3 This is another flowchart illustrating the consumable identification method in the embodiments of this application; Figure 4 This is a schematic diagram of the physical device structure of a consumable identification device in the embodiments of this application. Detailed Implementation
[0024] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0025] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.
[0026] In the description of the embodiments of this application, the term "multiple" means two or more. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0027] This application provides a consumable identification method, referencing... Figure 1 and Figure 2 , Figure 1 This is a flowchart of a consumable identification method provided in an embodiment of this application. Figure 2 This is a timing diagram of a consumable identification method in an embodiment of this application. The method includes: Step S101: Obtain the consumable trusted credential sent by the consumable, verify the consumable trusted credential using the pre-stored root public key, and send the host trusted credential to the consumable so that the consumable can use the pre-stored root public key to verify the host trusted credential. Among them, the consumable trusted certificate refers to a digital certificate used to prove the legitimacy of the consumable's identity. In a specific embodiment of the present invention, the certificate encapsulates the consumable's unique public key and a digital signature generated by the root private key from the public key. The host trusted certificate refers to a digital certificate with a similar structure to the consumable trusted certificate, used to prove the legitimacy of the host's identity. The root public key represents the top-level public key pre-generated by the host and consumable manufacturers and used to verify all legitimate device certificates. The cryptographic algorithm for this public key can be ECC (elliptic curve cryptography). Pre-storage refers to the process of solidifying the root public key into a secure storage area within the host and consumable during the manufacturing stage, which cannot be tampered with externally. Verification refers to using the root public key to decrypt and compare the signature in the digital certificate according to an asymmetric cryptographic algorithm to confirm the authenticity and integrity of the certificate.
[0028] Specifically, this step is performed after the host (e.g., printer) and consumables (e.g., ink cartridges) establish a physical electrical connection. It is the starting point of the entire identification process and aims to establish a two-way root of trust between the host and the consumables. When the consumables are installed on the host, the two parties exchange identity credentials. The consumables send its internally stored "consumable trusted credential" to the host. Upon receiving it, the host uses its pre-stored "root public key" to verify the signature portion of the credential.
[0029] Optionally, during the production phase of the host and consumables, the following methods can be used to generate trusted host credentials and trusted consumable credentials: First, a unique root key pair (root public key Root_Pub, root private key Root_Priv) is generated. This root key pair is stored in the offline hardware security module, and the root private key cannot be exported.
[0030] When producing consumables and main units, the root public key Root_Pub is pre-installed in the firmware of the main unit and consumables and cannot be tampered with.
[0031] When a host is generated, a host public-private key pair (Host_Pub, Host_Priv) is created. Host_Priv is stored in the host's secure area. At the same time, the host public key is signed with Root_Priv to form a trusted host credential Host_Cert=(Host_Pub, Sig_Host), where Sig_Host=Sign(Root_Priv, Host_Pub) (signing the host public key with the root private key). The trusted host credential is then stored in the host.
[0032] When consumables are generated, a public-private key pair (Consumable_Pub, Consumable_Priv) is generated during production. The Consumable_Priv is stored in the secure area of the consumable. At the same time, the consumable public key is signed with the Root_Priv to form a consumable trusted credential Consumable_Cert=(Consumable_Pub, Sig_Consumable), where Sig_Consumable=Sign(Root_Priv, Consumable_Pub) (signing the consumable public key with the root private key), and the Consumable_Cert (consumable trusted credential) is stored in the consumable.
[0033] Next, the host and consumable device verify trusted credentials, for example, by executing a verification function `Verify(Root_Pub, Consumable_Pub, Sig_Consumable)`. If the verification passes, the host confirms that the consumable device's public key `Consumable_Pub` is trusted. Then, the host sends its own "host trusted credentials" to the consumable device, which performs a fully symmetric verification process, using its pre-stored "root public key" to verify the legitimacy of the host's public key. Only when this two-way verification is successful—that is, when the host and consumable device mutually confirm each other's root identity—can the subsequent authentication steps begin.
[0034] Step S102: When the trusted credential of the consumable is verified by the host and the trusted credential of the host is verified by the consumable, a first signature file is obtained, the first signature file is verified using the public key of the consumable, and a second signature file is sent to the consumable so that the consumable uses the public key of the host to verify the second signature file. The first signature file refers to the result generated by the consumable using its own private key to sign a specific piece of data, which is used to prove to the host that it truly holds the private key; the second signature file refers to the result generated by the host using its own host private key to sign another specific piece of data, which is used to prove to the consumable that it holds the private key.
[0035] Specifically, this step is executed after the successful two-way authentication in step S101. Its core purpose is to ensure that the device currently participating in the communication is a genuine entity holding the private key, and not a forgery that has only copied the trusted credentials. In this embodiment, to generate the first signature file, the consumable first generates dynamic, specific data for this interaction internally. The generation of this data does not depend on the host, ensuring the consumable's initiative. Subsequently, the consumable uses its private key to sign the specific data and sends the signature result as the first signature file, along with the original signed data, to the host. Simultaneously, the host generates a second signature file, and the host and consumable perform a symmetrical reverse operation. The host uses its private key to sign another specific data, generating a second signature file, which is then sent to the consumable for verification using the verified host public key. After receiving the file, the host uses the consumable's public key verified in step S101 to verify the first signature file, confirming that the signature was indeed generated by the consumable's private key for the specific data.
[0036] Step S103: When the first signature file passes verification and the second signature file passes verification, a symmetric communication key is generated and sent to the consumable. The symmetric communication key refers to a single key shared by both communicating parties, used for rapid encryption and decryption of transmitted data in subsequent communications. In this step, "sending" specifically refers to the secure transmission of the generated symmetric communication key from the host to the consumables using asymmetric encryption.
[0037] Among them, the symmetric communication key refers to a single key shared by both communicating parties, which is used to symmetrically encrypt and decrypt transmitted data in subsequent communications. Its characteristic is high encryption and decryption efficiency.
[0038] Specifically, this step is executed after the successful verification of the two-way private key holding in step S102. Its purpose is to securely establish a confidential channel for subsequent sensitive data transmission, provided that the identities of both parties have been fully verified. In this embodiment, the host and consumables establish the symmetric communication key through a secure key negotiation or distribution process. For example, one possible implementation is that one party generates a key and then uses the other party's public key for encrypted transmission; another possible approach is that both parties independently calculate the same key based on previously exchanged dynamic data (such as the random number in step S102) using a preset key derivation function, without even needing to directly send the key itself. Regardless of the specific method used, the final result of this step is that both the host and the consumables possess a common, secret symmetric communication key, ensuring the confidentiality and integrity of all subsequent communications.
[0039] Step S104: Obtain the consumable parameters of the consumable, and generate a verification code that has a mapping relationship with the consumable parameters based on the consumable parameters according to preset rules; Among them, consumable parameters refer to various types of data stored inside the consumable that can characterize its own attributes. These data can be static, such as "chip model" and "hardware unique identifier (UID)", or dynamic, such as "sensor correction value" and "crystal oscillator correction value". Preset rules refer to a deterministic algorithm or function embedded in the host firmware. This algorithm takes all or part of the consumable parameters as input and generates verification code as output. Mapping relationship refers to a fixed and reproducible correspondence between consumable parameters and verification code. That is, as long as the same combination of consumable parameters is input, the same verification code output can always be obtained through the preset rules. Verification code represents a sequence of instructions that can be run on the consumable chip processor or a dataset that needs to perform specific calculations. Its design purpose is to evaluate the actual hardware computing power and characteristics of the consumable chip through actual operation.
[0040] Specifically, this step, executed after the successful establishment of the symmetric encrypted channel in step S103, is the preparation stage for the core hardware verification process. The host sends a command to the consumable via the established secure channel to "obtain" one or more of its "consumable parameters." After obtaining the parameters, the host uses them as input to its internal "preset rule" algorithm. Based on these parameters, the algorithm generates a specific "verification code" through a series of preset mathematical and logical operations. For example, the rule might combine the consumable's unique hardware identifier (UID) with the firmware version number, perform a hash operation, and use part of the hash result as the operation instruction and the other part as the number of operations to form the verification code. Because consumable parameters (especially the hardware UID) are unique to each consumable, counterfeit products cannot overcome the challenge by pre-programming a generic verification program or result. They must possess a parameter system and code generation logic completely identical to the genuine product, thus raising the threshold and reliability of anti-counterfeiting measures.
[0041] Step S105: Encrypt the verification code using the symmetric communication key to obtain an encrypted verification code, and send the encrypted verification code to the consumable. At the same time, start a timer so that the consumable can use the symmetric communication key to decrypt the encrypted verification code to obtain the verification code, run the verification code, and encrypt the running result using the symmetric communication key before sending it to the host. Encryption refers to using the symmetric communication key established in step S103 to process the verification code through a symmetric encryption algorithm (such as the AES algorithm) to ensure its confidentiality during transmission; timing refers to the host recording the time point when the event of sending the encrypted verification code occurs, as the starting point for measuring the response performance of the consumables.
[0042] Specifically, this step is executed after the host successfully generates the customized verification code in step S104, and is the stage for issuing the dynamic hardware verification challenge. In this embodiment, the host first uses a symmetric communication key to encrypt the verification code generated in step S104, forming an encrypted verification code. This prevents the verification code from being intercepted and analyzed by a third party during transmission. Subsequently, the host sends the encrypted verification code to the consumable through the physical interface and starts an internal timer at the moment of transmission.
[0043] After receiving the encrypted verification code, the consumable device decrypts it using the same symmetric communication key stored locally, thus restoring the plaintext of the verification code. Next, the consumable device runs the verification code within its internal secure execution environment. After execution, the consumable device re-encrypts the result using the same symmetric communication key and sends the encrypted result back to the host.
[0044] Step S106: When the encrypted running result is received, stop the timer, calculate the verification time, and decrypt the encrypted running result to verify the running result; The verification duration refers to the time elapsed from when the host starts timing in step S105 until the host receives the encrypted running result returned by the consumable in this step; the verification running result refers to the process of comparing the decrypted result returned by the consumable with the correct result expected by the host locally.
[0045] Specifically, this step is the stage where the host receives and analyzes the consumable's response. In this embodiment, once the host's communication interface receives the data packet of the encrypted operation result from the consumable, it immediately stops the timer started in step S105. By calculating the start and end time difference of the timer, the host obtains the total time spent on this verification interaction, i.e., the "verification duration." This duration reflects the overall performance of the consumable throughout the entire process from receiving, decrypting, running, encrypting, and transmitting back.
[0046] Simultaneously, the host computer uses a symmetric communication key to decrypt the received encrypted execution result, obtaining the plaintext result. Since the verification code is generated by the host based on the consumable parameters, the host can pre-calculate or know the unique correct result that the verification code should produce when run on genuine consumables. Therefore, the host compares the decrypted result with this expected result to verify the correctness of the execution result.
[0047] Step S107: When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable. The preset duration refers to a time threshold pre-set inside the host to measure whether the response speed of the consumable is qualified; confirming that the consumable is a genuine consumable means that the host finally makes the judgment that the consumable is an authorized and legal product.
[0048] Specifically, this step is the final determination stage of the identification method of this invention. In this embodiment, the host will perform a logical judgment with two conditions. The first condition is a performance judgment: the host compares the "verification time" calculated in step S106 with the "preset time". Only when the verification time is less than the preset time does it indicate that the hardware performance of the consumable has reached the standard of a genuine product, effectively eliminating response delays caused by the use of low-speed chips or software simulation. The second condition is a functional judgment: the host checks whether the conclusion of the "verification operation result" in step S106 is "passed". This ensures that the internal operation logic and core algorithm of the consumable are correct.
[0049] Only when both of the above conditions are met simultaneously—that is, the consumable's response speed is fast enough (verification time < preset time) and the response content is completely correct (the running result passes verification)—will the host finally "confirm that the consumable is a genuine consumable." Afterward, the host will allow the consumable to work normally, such as performing core functions like printing. If either condition is not met, the consumable will be judged as non-genuine, and the host can trigger corresponding alarms or subsequent measures such as function restrictions. This dual verification mechanism, combining functional correctness and hardware performance characteristics, constitutes the core of the anti-counterfeiting mechanism of this invention.
[0050] The following is a more detailed description of the process of the method provided in this implementation.
[0051] Optionally, steps S201-S203 are more specific steps than step S102.
[0052] Step S201: Generate a first random number using the host hardware random number generator; The host hardware random number generator refers to a physical circuit module integrated inside the host motherboard or security chip. It can generate high-quality, unpredictable true random numbers by utilizing the inherent randomness of physical processes (such as thermal noise, clock jitter, etc.), which is fundamentally different from pseudo-random number generators that rely on deterministic algorithms. In the context of this step, the first random number refers to the random number generated by the hardware random number generator and used as challenge data.
[0053] Specifically, to ensure the uniqueness and non-replayability of each authentication interaction, the host does not use a fixed challenge value. Instead, it calls its internal hardware random number generator to generate a unique first random number in real time, used only for this session. Using a hardware random number generator provides cryptographically secure randomness, ensuring that the challenge data cannot be predicted or calculated by an attacker, thereby greatly enhancing the security of the authentication process.
[0054] Step S202: Sign the first random number using the host private key to obtain the second signature file; Specifically, the host takes the first random number generated in step S201 as input data and calls the "host private key" in its secure storage area (the public key corresponding to this private key has been verified by consumables in step S101). The host then performs a signature operation on the random number using a preset digital signature algorithm (such as ECDSA). The output of the operation is the "second signature file".
[0055] Step S203: Send a second signature file to the consumable to instruct the consumable to verify the second signature file using the host public key; Specifically, this step is the execution phase where the host transmits the challenge to the consumable. The host packages the "second signature file" generated in step S202 and sends it to the consumable via the communication interface. After receiving the data packet, the consumable can use the "host public key" that it has verified and trusted in step S101 to verify the received "second signature file" to confirm whether it is indeed a valid signature generated by the host private key for the "first random number". If the verification is successful, the consumable can confirm that the current communication object is a real, legitimate, and online host.
[0056] In summary, steps S201 to S203 describe in detail the latter part of the two-way authentication in step S102, namely, the process by which the host proves its identity to the consumable. Similarly, the process by which the consumable proves its identity to the host (i.e., the process of generating the "first signature file") can also be implemented in a completely symmetrical manner, based on its own hardware random number generator and the consumable's private key.
[0057] Optionally, steps S301-S303 are more specific steps than step S103.
[0058] Step S301: Generate the symmetric communication key using the first random number and the second random number through a preset key derivation function; The first random number refers to the random number generated on the host side for challenge-response authentication (as generated in step S201 above); the second random number refers to the random number generated on the consumable side for symmetrically performing challenge-response authentication; the preset key derivation function (KDF) is a cryptographic algorithm whose function is to generate one or more keys with good randomness from one or more shared secret values (two random numbers in this example) through a cryptographically secure extraction and expansion process.
[0059] Specifically, this step is the core of key generation. In this embodiment, after completing two-way authentication (step S102), the host possesses both its own generated "first random number" and the "second random number" obtained from the consumable supplier. To generate a shared session key, the host inputs both random numbers into a "preset key derivation function" embedded within the host. This function calculates a new key with higher cryptographic strength, namely the "symmetric communication key." This method of jointly generating a key using the randomness contributed by both parties follows good cryptographic practices, ensuring that even if one party's random number generator has flaws, the security of the final key can still be guaranteed.
[0060] Step S302: Encrypt the symmetric communication key using the consumable public key to obtain the encrypted symmetric communication key; Specifically, the purpose of this step is to provide a secure transmission container for the symmetric communication key generated in step S301. In this embodiment, the host invokes the trusted "consumable public key" confirmed in step S101 to encrypt the "symmetric communication key" just generated by KDF using an asymmetric encryption algorithm (e.g., RSA-OAEP). The output of this operation is the "encrypted symmetric communication key".
[0061] Step S303: Send the encrypted symmetric communication key to the consumable, so that the consumable can use its private key to decrypt the encrypted symmetric communication key to obtain the symmetric communication key; Specifically, this step is the final step in key distribution. The host sends the "encrypted symmetric communication key" to the consumable. After receiving this encrypted data packet, the consumable calls its internally stored "consumable private key" to perform the decryption operation. If decryption is successful, the consumable can recover the "symmetric communication key" that is completely consistent with the one generated by the host in step S301.
[0062] Thus, through the series of operations from S301 to S303, both the host and the consumable have securely obtained the same session key, successfully establishing a symmetric encrypted secure communication channel, providing confidentiality assurance for subsequent data interaction in step S104 and beyond. This "derivative-encryption-distribution" combined method simplifies the logic on the consumable side compared to the method where the consumable also independently performs KDF calculations, centralizing control over key generation and distribution on the host side, while ensuring absolute security of the distribution process through asymmetric encryption.
[0063] Optionally, after step S106, this scheme may also execute steps S401 and 402; Step S401: When the verification duration is greater than or equal to the preset duration, or when the running result fails verification, extract the unique identifier of the consumable from the consumable trusted certificate; Among them, verification time greater than or equal to the preset time means that the response speed of the consumable is not up to standard, that is, the performance verification fails; running result fails verification means that the calculation result returned by the consumable is incorrect, that is, the function verification fails; the consumable trusted certificate refers to the digital certificate containing its public key and identity information provided by the consumable to the host in the initial interaction step S101; the unique identifier (UID) refers to the serial number or identifier embedded in the certificate that can uniquely identify the consumable chip, such as the chip's hardware serial number.
[0064] Specifically, this step is the tracing and marking process after authentication failure. When the confirmation conditions of step S106 are not met, the host triggers this process. The host then retrieves the "consumable trusted certificate" that was cached in memory during the interaction in step S101. By parsing the data structure of this certificate, the host can locate the specific field containing the "unique identifier" and extract its value. The purpose of this is that even if the consumable is counterfeit, as long as it provides a parsable certificate, its identity can be identified, providing a basis for subsequent processing.
[0065] Step 402: Add the unique identifier to the blacklist database; The blacklist database refers to a list stored in the host's non-volatile memory (such as flash memory) that is specifically used to record the unique identifiers of consumables that have been identified as non-genuine or problematic.
[0066] Specifically, this step is the solidification of the failure marker. After successfully extracting the "unique identifier" of the problematic consumable in step S401, the host writes it into the internally maintained "blacklist database." This database is persistently stored and will not be lost due to power outages.
[0067] Optionally, after obtaining the trusted credential for the consumables sent by the consumables, this solution may also execute steps S501-503; S501, Obtain the unique identifier of the consumable; Specifically, this step follows immediately after step S101. Once the host receives its "consumable trusted credential" from the consumable, before performing any complex public key verification or challenge-response, the host first performs a preliminary parsing of the credential to directly extract the "unique identifier." This operation is the same as the extraction action in step S401, but its timing and purpose are completely different: the purpose here is for pre-checking, not for post-marking.
[0068] S502, Search the blacklist database, which includes unique identifiers confirmed as non-genuine consumables; Specifically, the host uses the newly acquired unique identifier as the query key to search its internal blacklist database. The contents of this database are accumulated through the aforementioned steps S402.
[0069] S503, if a unique identifier exists for the consumable, then the consumable is confirmed to be a non-genuine consumable, and the user is notified; Specifically, if an entry matching the unique identifier of the current consumable is found in the blacklist database, this indicates that the consumable (or a clone with the same unique identifier) has been identified as counterfeit in the past. At this point, the host computer no longer needs to perform the subsequent complex verification steps S102 to S107, and directly determines that the consumable is counterfeit. Subsequently, the host computer immediately terminates interaction with the consumable and displays a prompt to the user such as "Incompatible consumable detected" or "Please use genuine consumable," while simultaneously locking the device's functions. The authentication process will only proceed to step S102 if the search result is "Not found." This optional pre-inspection mechanism greatly optimizes the handling of known counterfeit products, achieving immediate identification and immediate rejection.
[0070] Optionally, steps S601-S603 are more specific steps than step S107.
[0071] Step S601: Obtain the baseline verification time distribution characteristics of genuine consumables running on the verification code through the cloud server; Among them, the cloud server refers to a remote server maintained by the manufacturer and accessible via the network, which stores a large amount of performance data of genuine consumables; the verification code refers to the specific code generated for the consumable currently connected to the host in step S104; the baseline verification time distribution characteristic is not a single time value, but describes the statistical characteristics of the time consumed when a large number of genuine consumables run the same verification code, such as the mean, standard deviation, median or specific percentile.
[0072] Specifically, this step is the data source stage for setting dynamic thresholds. In this embodiment, after the host generates a "verification code" for the current consumable (or after calculating the actual verification time in S106), it connects to the manufacturer's "cloud server" via the network. The host sends the identifier of the "verification code" or its key parameters to the server, which then queries its vast database for performance data recorded by thousands of genuine consumables running this code during factory testing or actual use. The server performs statistical analysis on this data to obtain a set of "benchmark verification time distribution characteristics" that comprehensively reflects the performance distribution of genuine consumables, and returns it to the host. For example, the server might return that the average time for the code to run on genuine consumables is 50 milliseconds, with a standard deviation of 3 milliseconds.
[0073] Step S602: Calculate the preset duration based on the baseline verification duration distribution characteristics; Specifically, this step involves the local calculation of the dynamic threshold. After receiving the baseline verification duration distribution characteristics returned from the cloud, the host computer applies a built-in algorithm to calculate the preset duration for this authentication. This algorithm is designed to accommodate the normal performance fluctuations of genuine consumables to the greatest extent possible, while strictly excluding counterfeit products. A common calculation method is to use the upper limit of the confidence interval in statistics. For example, the "preset duration" can be set as "mean + k × standard deviation" (μ + kσ). The value of k can be adjusted according to the required security level (e.g., k=3 or k=4). In the example above, if k=3, then the preset duration = 50ms + 3 × 3ms = 59ms. This method makes the "preset duration" no longer a fixed value set based on experience, but a scientifically generated threshold dynamically based on massive amounts of real data.
[0074] Step S603: When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable. The same as step S107, so it will not be repeated here.
[0075] Optional, see reference Figure 3 After step S107, after confirming that the consumables are genuine through the above step S107, since the host has established a complete trust relationship with the consumables, reliable consumable usage management can be further implemented. Therefore, this solution can also execute steps S701 and 704. Step S701: Detect the remaining amount of consumables and the printing demand; Among them, the remaining consumable quantity refers to the estimated value of currently available consumables (such as ink volume or toner grams) calculated based on the initial quantity and the amount used recorded inside the consumable chip; the print demand refers to the amount of consumables that the host computer estimates to complete the print job after analyzing the content of the document to be printed (such as the number of pages, color coverage, resolution, etc.).
[0076] Specifically, this step is a pre-judgment process before the print job begins. After the consumables pass the authenticity verification (step S107), the user initiates a print command. At this time, the host does not start printing immediately, but first performs this pre-check. The host queries the consumable chip for its electronic counter's "remaining consumables". At the same time, the host's print driver or firmware parses the print job submitted by the user and estimates, through a complex algorithm, how much consumables will be needed to complete the task. This result is the "printing demand".
[0077] Step S702: When the remaining amount of consumables is less than the printing demand, the user is notified; Specifically, this step involves the pre-emptive handling logic after a printing failure. The host computer compares the "remaining consumables" obtained in step S701 with the "printing demand." If the remaining consumables are insufficient to complete the entire print job, the system will abort the printing process and issue a clear prompt to the user through the user interface (such as a pop-up window on a computer screen or the printer's own display), such as "Insufficient consumables to complete the current print job. Please replace the consumables and try again." This effectively avoids print job failures, wasted paper and time due to consumables running out midway, significantly improving the user experience.
[0078] Step S703: When the remaining amount of consumables is greater than or equal to the printing demand, printing begins, and the remaining amount of consumables is monitored in real time. Specifically, if the prediction result of step S701 indicates sufficient consumables, the host computer starts the printing engine and begins the physical printing process. Simultaneously, a monitoring program runs in the background. Unlike subsequent photoelectric detection methods that monitor remaining consumables, here the host computer records the print volume in real time. After printing, the remaining volume is subtracted from the printed volume to obtain the remaining consumables after this printing. The total consumable quantity is pre-written into the consumables during generation, and a query command is continuously sent to the consumables chip, either continuously or after each page / several pages printed, to obtain a constantly updated estimate of the "remaining consumables quantity." The consumables chip then dynamically reduces its internal counter value based on its actual inkjet or toner dispensing actions. In this way, the host computer can monitor the consumption of consumables during the printing process in real time.
[0079] Step S704: When the remaining amount of the consumable is less than a preset remaining amount threshold, photoelectric detection is used to detect the remaining amount of the consumable. Among them, the preset reserve threshold is a pre-set warning line that indicates that the consumables are about to run out, such as 10%; photoelectric detection is a physical detection method that does not rely on the electronic counting of the chip, but directly senses the stock status of the consumables through physical sensors.
[0080] Specifically, this step is a "double-check" mechanism for precise confirmation, initiated when consumables are about to run out. During the real-time monitoring in step S703, once the host detects that the remaining consumable amount read from the chip is lower than a preset remaining threshold, it triggers a physical detection process. For example, a photoelectric sensor (such as an infrared emitter and receiver) is installed in a specific location inside the printer's consumable compartment. This sensor can emit a beam of light through a specific area of the consumable (such as the transparent window of the ink cartridge). When the physical liquid level of the consumable (such as ink) is above this detection point, the light path is blocked; when the liquid level drops below the detection point, the light path is open, and the signal of the receiver changes.
[0081] By reading the status of this photoelectric sensor, the host computer obtains a highly reliable confirmation signal regarding whether the consumables are "physically" running out, independent of electronic counting. The purpose is to calibrate and verify the accuracy of the chip's counting. It effectively prevents problems such as falsely reporting empty consumables when they are actually empty due to chip counting errors, or the printer continuing to operate without consumables (potentially damaging critical components like the print head) due to the chip's failure to promptly report empty consumables, greatly improving the overall reliability of consumable level detection.
[0082] The consumable identification device in the embodiments of this invention is described below from the perspective of hardware processing. Please refer to [link / reference]. Figure 4 This is a schematic diagram of the physical device structure of a consumable identification device in the embodiments of this application.
[0083] It should be noted that, Figure 4 The structure of the consumable identification device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0084] like Figure 4 As shown, the consumable identification device includes a CPU 401, which can perform various appropriate actions and processes according to a program stored in the read-only memory ROM 402 or a program loaded from the storage section 408 into the random access memory RAM 403, such as performing the methods described in the above embodiments. The RAM 403 also stores various programs and data required for system operation. The CPU 401, ROM 402, and RAM 403 are interconnected via a bus 404. An I / O interface 405 is also connected to the bus 404.
[0085] The following components are connected to I / O interface 405: input section 406 including audio input devices, push-button switches, etc.; output section 407 including a liquid crystal display (LCD) and audio output devices, indicator lights, etc.; storage section 408 including a hard disk, etc.; and communication section 409 including a network interface card such as a LAN (Local Area Network) card, modem, etc. Communication section 409 performs communication processing via a network such as the Internet. Drive 410 is also connected to I / O interface 405 as needed. Removable media 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 410 as needed so that computer programs read from them can be installed into storage section 408 as needed.
[0086] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by CPU 401, it performs the various functions defined in the present invention.
[0087] It should be noted that specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0088] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those shown in the drawings.
[0089] Specifically, the consumable identification device in this embodiment includes a processor and a memory. The memory stores a computer program, and when the computer program is executed by the processor, it implements the consumable identification method provided in the above embodiment.
[0090] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the consumable identification device described in the above embodiments; or it may exist independently and not assembled into the consumable identification device. The storage medium carries one or more computer programs, which, when executed by a processor of the consumable identification device, cause the consumable identification device to implement the consumable identification method provided in the above embodiments.
[0091] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A method for identifying consumables, characterized in that, Includes the following steps: Obtain the consumable trusted certificate sent by the consumable, verify the consumable trusted certificate using the pre-stored root public key, and send the host trusted certificate to the consumable so that the consumable can verify the host trusted certificate using the pre-stored root public key of the consumable. The consumable trusted certificate is generated by the manufacturer using the root private key to sign the consumable public key during the production stage, and the host trusted certificate is generated by the manufacturer using the root private key to sign the host public key during the production stage. When the consumable's trusted credential is verified by the host, and the host's trusted credential is verified by the consumable, a first signature file is obtained, the first signature file is verified using the consumable's public key, and a second signature file is sent to the consumable so that the consumable can verify the second signature file using the host's public key. The first signature file is generated by the consumable using its private key, the second signature file is generated by the host using its private key, the consumable's public key is obtained from the verified trusted credential of the consumable, and the host's public key is obtained by the consumable from the verified trusted credential of the host. When the first signature file passes verification and the second signature file passes verification, a symmetric communication key is generated and sent to the consumable. Obtain the consumable parameters of the consumable, and generate a verification code that has a mapping relationship with the consumable parameters based on the consumable parameters according to preset rules; The verification code is encrypted using the symmetric communication key to obtain an encrypted verification code, which is then sent to the consumable. Simultaneously, a timer is started so that the consumable can decrypt the encrypted verification code using the symmetric communication key to obtain the verification code, run the verification code, and encrypt the running result using the symmetric communication key before sending it to the host. When the encrypted running result is received, the timer is stopped, the verification time is calculated, and the encrypted running result is decrypted to verify the running result. When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable.
2. The method according to claim 1, characterized in that, The step of sending a second signature file to the consumable to enable the consumable to verify the second signature file using the host public key specifically includes: Use the host hardware random number generator to generate the first random number; The first random number is signed using the host private key to obtain the second signature file; Send a second signature file to the consumable to instruct the consumable to verify the second signature file using the host public key; The first signature file is obtained by the consumable through the following method: generating a second random number using the consumable hardware random number generator, and signing the second random number using the consumable private key to obtain the first signature file.
3. The method according to claim 1, characterized in that, The step of generating a symmetric communication key and sending the symmetric communication key to the consumable specifically includes: The symmetric communication key is generated using a preset key derivation function by generating a first random number and a second random number. The symmetric communication key is encrypted using the public key of the consumables to obtain the encrypted symmetric communication key; The encrypted symmetric communication key is sent to the consumable, so that the consumable can use its private key to decrypt the encrypted symmetric communication key to obtain the symmetric communication key.
4. The method according to claim 1, characterized in that, Upon receiving the encrypted execution result, the timer is stopped, the verification time is calculated, and the encrypted execution result is decrypted. Following the step of verifying the execution result, the method further includes: When the verification duration is greater than or equal to the preset duration, or when the running result fails verification, the unique identifier of the consumable is extracted from the consumable trusted certificate; Add the unique identifier to the blacklist database.
5. The method according to claim 1, characterized in that, After the step of obtaining the trusted credential for the consumables sent by the consumables, the method further includes: Obtain the unique identifier of the consumable; Search the blacklist database, which includes unique identifiers that confirm non-genuine consumables; If a unique identifier exists for the consumable, it is confirmed that the consumable is a counterfeit product, and the user is notified.
6. The method according to claim 1, characterized in that, The step of confirming that the consumable is a genuine consumable when the verification time is less than the preset time and the running result passes the verification specifically includes: The baseline verification time distribution characteristics of genuine consumables running on the verification code are obtained through a cloud server; The preset duration is calculated based on the baseline verification duration distribution characteristics; When the verification time is less than the preset time and the running result passes the verification, the consumable is confirmed to be a genuine consumable.
7. The method according to claim 1, characterized in that, After confirming that the consumable is a genuine product, the method further includes: Detect the remaining consumables and printing demand; The user is prompted when the remaining consumables are less than the required printing quantity. Printing begins when the remaining amount of consumables is greater than or equal to the printing demand, and the remaining amount of consumables is monitored in real time. When the remaining amount of the consumable is less than a preset remaining amount threshold, photoelectric detection is used to detect the remaining amount of the consumable.
8. A consumable identification device, characterized in that, The consumable identification device includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the consumable identification device to perform the method as described in any one of claims 1-7.
9. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is executed on the consumable identification device, the consumable identification device performs the method as described in any one of claims 1-7.
10. A computer program product, characterized in that, When the computer program product is run on the consumable identification device, the consumable identification device performs the method as described in any one of claims 1-7.