Image forming apparatus, image formation system, and consumables
The image forming apparatus and system utilize a consumable with an IC chip and authentication component to securely change settings and manage offline print limits using security capsules, addressing the lack of such functionality in existing devices.
Patent Information
- Application Number
- JP2024130237
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-29
- Filing Date
- 2024-08-06
- Publication Date
- 2025-10-14
AI Technical Summary
Existing image forming devices lack the application of authentication technology using security capsules, which is necessary to securely change settings and manage offline print limits.
An image forming apparatus and system that incorporates a consumable with an IC chip and authentication component, allowing verification of a security capsule to access and change settings or add offline print limits securely.
Enables secure setting changes and management of offline print limits using authentication technology, ensuring security and continuity of printing operations.
Smart Images

Figure 2025155518000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an image forming apparatus, an image forming system, and a consumable item. [Background technology]
[0002] Patent Document 1 discloses an authentication technology using a security capsule. In this authentication technology, a memory device is subject to certain functional restrictions. When a host system stores data in the memory device or retrieves data from the memory device, the certain functional restrictions on the memory device are released through authentication using the security capsule. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] U.S. Patent Publication 2022 / 0198072 Summary of the Invention [Problem to be solved by the invention]
[0004] Patent Document 1 does not particularly disclose a case where authentication technology using a security capsule is applied to an image forming apparatus.
[0005] An object of the present disclosure is to provide an image forming apparatus, an image forming system, and consumables that can apply authentication technology using security capsules to use in the image forming apparatus. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, the image forming apparatus disclosed in the first application is an image forming apparatus comprising a main body housing, a consumable that is detachable from the main body housing and has an IC chip including a consumable memory, an authentication component, and a consumable control unit, and a main body control unit, wherein the consumable memory stores setting information regarding the settings of the image forming apparatus in a restricted area, the authentication component performs a verification process to verify the signature of a security capsule signed with a private key using a public key corresponding to the private key when the security capsule is supplied from outside the image forming apparatus, the consumable control unit performs a process to enable execution of a command to obtain the setting information from the restricted area if verification by the verification process is successful, and the main body control unit performs a first setting change process to change the settings of the image forming apparatus based on the setting information obtained by executing the command.
[0007] In the image forming apparatus disclosed in the first aspect of the present application, the settings of the image forming apparatus can be changed by supplying a security capsule from the outside. The consumable memory provided in the consumables attached to the main body of the image forming device stores setting information related to the settings of the image forming device. The setting information is stored in a restricted area of the consumable memory, which restricts access and ensures security. Therefore, in order to read and change the contents of this setting information, a command to retrieve the setting information from the restricted area is required. In the first disclosure of the present application, when a security capsule signed with a private key is supplied from an external device, a verification process executed by an authentication component of an IC chip verifies the signature of the security capsule using a public key corresponding to the private key. If the verification is successful, a process is executed by a consumables control unit of the IC chip to enable execution of a command to obtain setting information from a restricted area. The setting information obtained by executing the command is used in a first setting change process executed by a main body control unit, thereby completing the change of the settings of the image forming device. As described above, according to the first disclosure of the present application, it is possible to execute the first setting change process of the image forming apparatus while ensuring security by utilizing authentication technology using a security capsule.
[0008] In addition, in order to achieve the above-mentioned object, the image forming system disclosed in the second application is an image forming system having an image forming device including a main body housing, a consumable that is detachable from the main body housing and has an IC chip including a consumable memory, an authentication component, and a consumable control unit, a main body control unit, and a server that can communicate with the image forming device, wherein the image forming device further includes a main body memory that stores a first number of offline prints that can be printed without incurring a user charge when communication with the server is not possible, the consumable memory stores a second number of offline prints in a restricted area, the authentication component performs a verification process to verify the signature of a security capsule signed with a private key using a public key corresponding to the private key when the security capsule is supplied from outside the image forming device, the consumable control unit performs a process to enable execution of a command to obtain the second number of offline prints from the restricted area if verification by the verification process is successful, and the main body control unit performs a print number addition process to add the second number of offline prints obtained by executing the command to the first number of offline prints.
[0009] In addition, in order to achieve the above-mentioned object, the consumable disclosed in the third application is a consumable that is attached to an image forming device and has an IC chip including a consumable memory, an authentication component, and a consumable control unit, wherein the consumable memory stores setting information regarding the settings of the image forming device in a restricted area, the authentication component is capable of executing a verification process to verify the signature of a security capsule signed with a private key using a public key corresponding to the private key when the security capsule is supplied from outside the image forming device, and the consumable control unit is capable of executing a process to enable a command to obtain the setting information from the restricted area when verification by the verification process is successful, and the setting information is used to change the settings of the image forming device after the process is executed. [Effects of the Invention]
[0010] According to the present disclosure, authentication technology using security capsules can be applied to use in image forming devices. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of a configuration of an image forming system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of a configuration of a server. [Figure 3] FIG. 2 is a block diagram illustrating an example of the configuration of a printer. [Figure 4] FIG. 2 is a block diagram illustrating an example of the configuration of a terminal device. [Figure 5] 10 is a diagram illustrating an example of the internal configuration of an IC chip of a cartridge. FIG. [Figure 6] FIG. 2 is a diagram illustrating an example of the internal configuration of a security capsule. [Figure 7] FIG. 1 is an explanatory diagram illustrating an example of an outline of a subscription printing service provided by an image forming system when the server and the printer are online and capable of communicating with each other. [Figure 8]FIG. 10 is an explanatory diagram illustrating an example of a state of the image forming system when offline, in which communication between the printer and the server is not possible. [Figure 9] 10 is a sequence chart illustrating an example of a control procedure executed by a server, a terminal device, and a printer. [Figure 10] 10 is a flowchart illustrating an example of a control procedure for a print count addition process in step S100. [Figure 11] 10 is a sequence chart illustrating an example of a control procedure executed by a server, a terminal device, and a printer in a modified example in which the expiration date of server maintenance is notified to the printer. [Figure 12] 10 is a sequence chart illustrating an example of a control procedure executed by a server, a terminal device, and a printer in a modified example in which the server is inquired about the execution status of maintenance. [Figure 13] 10 is a flowchart illustrating an example of a control procedure for initializing the offline print upper limit number in step S200. [Figure 14] 10 is a flowchart illustrating an example of a control procedure for a maintenance status notification process in step S300. [Figure 15] 10 is a flowchart illustrating an example of a control procedure for a print count addition process in a modified example in which multiple authentications are performed. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments will be described with reference to the drawings.
[0013] <Image forming system> 1 shows an example of the configuration of an image forming system 1 according to an embodiment. The image forming system 1 is configured to be able to provide a predetermined printing service based on a user's billing. In this embodiment, a case will be described in which the image forming system 1 provides, for example, a subscription printing service.
[0014] 1, the image forming system 1 includes a server 100, a printer 200, and a terminal device 300. The server 100 provides a subscription printing service. The server 100, the printer 200, and the terminal device 300 are connected to a network NT and can communicate with each other. The printer 200 includes a main body housing 200a. The printer 200 is an example of an image forming device.
[0015] The network NT includes, for example, the Internet and mobile phone communication lines. Furthermore, the terminal device 300 and the printer 200 can send and receive information to and from each other via the USB protocol. In this embodiment, as shown in FIG. 1, a case will be described as an example in which a security capsule (described later) is supplied from the terminal device 300 to the printer 200 via a USB memory 2. In this case, the USB memory 2 is an example of a USB function. Note that the terminal device 300 and the printer 200 may be connected via a USB cable, with the printer 200 acting as a USB host to obtain the security capsule.
[0016] <server> An example of the configuration of the server 100 is shown in Fig. 2. As shown in Fig. 2, the server 100 has a processor 110, a memory 115, and a communication interface 190. The processor 110, the memory 115, and the communication interface 190 are connected via a bus 105 so as to be able to transmit and receive data to and from each other.
[0017] The memory 115 includes a volatile memory 120 and a non-volatile memory 130. The volatile memory 120 is, for example, a DRAM, and stores various programs and data to be processed. The non-volatile memory 130 is, for example, a hard disk drive or a solid state drive, and includes a program storage area 131 and a data storage area 132. The program storage area 131 stores various programs that perform processing to provide the print service. The various programs include processing programs based on the flowcharts in Figures 9, 11, 12, and 14, which will be described later. The data storage area 132 stores various data that is generated or used by the processing programs.
[0018] The processor 110 is a device that performs data processing, such as a CPU, and executes various programs stored in the program storage area 131. The processor 110 performs various processes including data communication with the printer 200 and the terminal device 300.
[0019] The communication interface 190 is a network interface for connecting to and communicating with the network NT.
[0020] It should be noted that the memory 115 is not limited to being configured with the above-mentioned device elements, but may also be configured with, for example, RAM, ROM, EEPROM, HDD, a portable recording medium such as a USB memory that can be attached to or detached from the server 100, a buffer provided in the processor 110, or a combination thereof.
[0021] Furthermore, the memory 115 may be a computer-readable storage medium. A computer-readable storage medium is a non-transitory medium. Other examples of non-transitory media include recording media such as CD-ROMs and DVD-ROMs. Non-transitory media are also tangible media. The same applies to the memory 215 of the printer 200, which will be described later.
[0022] <Printer> An example of the configuration of the printer 200 is shown in Fig. 3. As shown in Fig. 3, the printer 200 has a processor 210, a memory 215, a touch panel 240, operation keys 250, a transport mechanism 260, a cartridge holder 201, a main body contact 202, a USB interface 280, a communication interface 285, and a printing unit 290. The processor 210, memory 215, touch panel 240, operation keys 250, transport mechanism 260, main body contact 202, USB interface 280, communication interface 285, and printing unit 290 are connected to each other via a bus 205 so as to be able to send and receive data.
[0023] The memory 215 includes a volatile memory 220 and a non-volatile memory 230. The volatile memory 220 includes an image data storage area 222 that stores image data to be printed. The volatile memory 220 is, for example, a DRAM. The non-volatile memory 230 includes a program storage area 231 and a data storage area 232. The non-volatile memory 230 is, for example, an NVRAM, a flash memory, or the like. The program storage area 231 stores various programs. The various programs include firmware such as a print processing program, and processing programs based on the flowcharts of FIGS. 9 to 15, which will be described later. The data storage area 232 stores various data generated or used by the processing programs. The various data includes the offline printing limit number, which will be described later. The non-volatile memory 230 is an example of a main body memory.
[0024] The processor 210 is a device that performs data processing. The processor 210 is, for example, a CPU. The processor 210 executes various programs stored in the program storage area 231. The processor 210 that executes various programs is an example of a main body control unit.
[0025] The touch panel 240 can display various information and accepts user operations on the display screen. The touch panel 240 is, for example, a device that integrally combines a liquid crystal display and a transparent touch pad. The operation keys 250 are devices that mechanically accept user press operations.
[0026] Cartridge 270 is detachable from main body housing 200a of printer 200. Cartridge 270 is a consumable item that is attached to printer 200. For example, if printer 200 is a laser printer, cartridge 270 is a toner cartridge or a drum cartridge. Also, for example, if printer 200 is an inkjet printer, cartridge 270 is an ink cartridge. Cartridge 270 has an IC chip 271 (see FIG. 5, described below).
[0027] The main body contacts 202 are provided on the cartridge holder 201. The processor 210 reads and writes cartridge information from and to an IC chip 271 of a cartridge 270 housed in the cartridge holder 201 via the main body contacts 202.
[0028] The USB interface 280 is a USB connector to which a USB memory 2 or a USB cable can be attached / detached. The communication interface 285 is a network interface that enables communication with the server 100 or the terminal device 300 via the network NT. The communication interface 285 can receive, for example, information about the number of pages in a contract plan based on the user's charge in a subscription printing service from the server 100. The communication interface 285 is an example of a communication unit.
[0029] The conveying mechanism 260 conveys sheets supplied from a tray capable of holding multiple sheets. The printing unit 290 is located on a path along which sheets are conveyed by the conveying mechanism 260. The printing unit 290 forms an image corresponding to a print job on the sheet conveyed by the conveying mechanism 260 using a predetermined method. The predetermined method is not particularly limited, but may be, for example, an inkjet method or a laser method. The printing unit 290 prints on the sheet based on a print job sent from the terminal device 300 or operations on the touch panel 240 and operation keys 250.
[0030] <Terminal Device> The terminal device 300 is, for example, a general-purpose personal computer, and may be a notebook computer as shown in Fig. 1 or a desktop computer. The terminal device 300 may also be a mobile terminal such as a smartphone. An example of the configuration of the terminal device 300 is shown in Fig. 4.
[0031] As shown in FIG. 4, the terminal device 300 includes a CPU 310, a memory 320, a display unit 330, an input unit 340, a USB interface 350, a communication interface 360, and a large-capacity memory 370.
[0032] The large-capacity memory 370 includes a program storage area 371 and a data storage area 372. The large-capacity memory 370 is, for example, a hard disk drive or a flash memory. Various programs are stored in the program storage area 371 as, for example, firmware. The CPU 310 executes the various programs stored in the program storage area 371. The CPU 310 executes various processes, including data communication with the server 100 and the printer 200 via the communication interface 360 and the network NT. The CPU 310 also transmits and receives information to and from the printer 200 via the USB interface 350.
[0033] The display unit 330 is, for example, a liquid crystal display, a touch panel, etc., and displays various information. The input unit 340 is, for example, a keyboard, a mouse, a touch panel, etc., and accepts various operations by the user. The user can input various instructions to the terminal device 300 by operating the input unit 340.
[0034] <Cartridge IC chip> As described above, cartridge 270 has IC chip 271. An example of the internal configuration of IC chip 271 is shown in FIG. 5. As shown in FIG. 5, IC chip 271 has memory subsystem controller 277 and memory 273. Memory subsystem controller 277 has authentication component 272, processor 278, and local memory 279. Memory 273 has accessible area 274 and restricted-access area 275. Processor 278 is an example of a consumables control unit, memory 273 is an example of a consumables memory, and restricted-access area 275 is an example of a restricted area.
[0035] Authentication component 272 has a public key 276. Public key 276 corresponds to the private key used to sign the security capsule.
[0036] The accessible area 274 is an area where there are no restrictions on reading information by the processor 210. In the accessible area 274, for example, cartridge information indicating the type of cartridge 270 and the like is stored.
[0037] The access restriction area 275 is an area where reading of information by the processor 210 is restricted. The access restriction area 275 stores setting information related to the settings of the printer 200. The processor 278 can acquire the setting information from the access restriction area 275 by executing an access command that can access the access restriction area 275. The access command becomes executable if a security capsule signed with a private key is supplied from the outside and signature verification using the public key 276 corresponding to the private key is successful. The setting information acquired by executing the access command is used to change the settings of the printer 200. In this embodiment, an offline print upper limit addition value is stored as an example of setting information. The offline print upper limit addition value is an addition value for increasing the number of prints that can be made without charge to the user in the subscription printing service. The offline print upper limit addition value is an example of a second offline print limit. The access command is an example of a command.
[0038] <Security Capsule> As described above, the security capsule 3 is supplied from the terminal device 300 to the printer 200, for example, via the USB memory 2. An example of the internal configuration of the security capsule 3 is shown in FIG. 6. As shown in FIG. 6, the security capsule 3 has a production ID 31, a counter 32, and a command list 33. The production ID 31 is identification information related to the production of the security capsule 3. The counter 32 is information related to the number of times the security capsule 3 has been authenticated. The command list 33 is information related to the access commands that can be used to access the access-restricted area 275. The information in the production ID 31, the counter 32, and the command list 33 is signed with a private key.
[0039] Specifically, the information of the manufacturing ID 31, the counter 32, and the command list 33 is compressed using, for example, a hash function, and a hash value is calculated. The calculated hash value is encrypted using a private key. The security capsule 3 contains the compressed information of the manufacturing ID 31, the counter 32, and the command list 33, and the encrypted hash value. The encrypted hash value functions as a digital signature.
[0040] Signature verification using the public key 276 is performed, for example, as follows: The encrypted hash value is obtained from the security capsule 3 and decrypted using the public key 276. The compressed information of the manufacturing ID 31, counter 32, and command list 33 is also obtained from the security capsule 3 and decompressed using the same hash function as that used for compression, and a hash value is calculated. It is verified whether the decrypted hash value at the time of compression matches the calculated hash value at the time of decompression; if they match, the signature verification is successful, and if they do not match, the signature verification is unsuccessful.
[0041] <Subscription printing service> FIG. 7 shows an overview of the subscription printing service provided by the server 100 when the server 100 and printer 200 are online and able to communicate. In the subscription printing service, a contract plan limit is set as the maximum number of pages that can be printed on a sheet. The contract plan limit is the number of pages that can be printed within a specified period based on the contract plan signed by the user. The contract plan limit is an example of the allowable number of pages that can be printed. If printing is performed in excess of the contract plan limit, the subscription printing service may charge the user an additional fee corresponding to the number of pages exceeding the contract plan limit in addition to the fixed fee.
[0042] In a subscription printing service, a contract is automatically renewed periodically at a specified subscription contract period in order for the user to print. Furthermore, with a subscription printing service, the user is billed for the printing service fee for the subscription contract period in a deferred payment after the subscription contract period ends. There are multiple contract plans available, each specifying the number of pages that can be printed within a specified period and the contract period. The user selects one of the contract plans and signs up for it. As long as the number of pages printed by the user within the specified period, which is the number of pages printed during the period, is within the number of pages in the contract plan, printing is possible without additional charges. If the number of pages printed during the specified period exceeds the number of pages in the contract plan, the user is charged an additional fee for the excess number of pages. Furthermore, if the number of pages printed during the subscription contract period does not reach the number of pages in the contract plan, the remaining number, calculated by subtracting the number of pages printed during the period from the number of pages in the contract plan, is carried over to the following month as a carryover print count with an expiration date.
[0043] As shown in FIG. 7, the server 100 and the printer 200 each synchronize and store two parameters: the number of pages printed during the subscription contract period and the number of pages carried over; they also store the same fixed value for the number of pages in the contract plan. The number of pages printed during the subscription contract period is the number of pages printed by the user within a specified period. The number of pages carried over is the remaining number of pages carried over to the next subscription contract period if the number of pages printed during the subscription contract period does not reach the number of pages in the contract plan. For example, if the subscription contract period is one month, from the beginning to the end of the month, the number of pages printed during the subscription contract period is reset to 0 at the beginning of each month on the server 100 and the printer 200. The number of pages actually printed during the subscription contract period is then counted up by the printer 200 as the number of pages printed during the subscription contract period, and this value is sent to the server 100 each time printing is performed by the printer 200, or periodically, and stored for synchronization.
[0044] At the beginning of each month, the server 100 calculates the number of pages to be carried over and stores it in synchronization with the printer 200. In other words, if the number of pages printed during the previous month's subscription contract cycle does not reach the number of pages in the contract plan, the remaining number obtained by subtracting the number of pages printed during the period from the contract plan number is calculated as the number of pages to be carried over for the current month.
[0045] The processor 210 of the printer 200 can continue printing during the current month's subscription contract period as long as the number of prints during the period does not exceed the total number of prints in the contract plan and the number of prints carried over. Even if the number of prints exceeds the total, the excess number of prints may be counted up and synchronously stored as an additional print number, and the corresponding additional fee may be charged the following month.
[0046] In addition, with subscription printing services, the cost of consumables such as ink and toner is included in the fee for the printing service, so even if a consumable runs out, the user can request the manufacturer or operating company to ship the consumables and have them replenished without incurring any additional costs.
[0047] <Features of this embodiment> The printer 200 of this embodiment can print up to the contract plan number based on the user's charge based on the subscription contract described above. At this time, as shown in FIG. 8 , if the printer 200 enters an offline state where communication between the printer 200 and the server 100 is disabled for some reason, such as server maintenance, the printer 200 and the server 100 cannot synchronize the number of pages printed during the period described above. Therefore, to prevent missed charges, offline printing is limited to a predetermined number. This predetermined number is stored in the data storage area 232 of the nonvolatile memory 230 of the printer 200 as the maximum offline printing number that the user can print without being charged when the communication interface 285 cannot communicate with the server 100. The maximum offline printing number is an example of a first offline printing number. This allows the user to continue printing within the maximum offline printing number, even when the printer enters an offline state.
[0048] However, there may be cases where a user unexpectedly prints a large amount of data while offline. In this case, if the number of pages to be printed exceeds the offline printing limit, the print limit is triggered, causing inconvenience to the user. In particular, if the server goes offline due to server maintenance, this is due to a situation on the part of the server 100 that provides the subscription printing service, and there is no cause for concern for the user, so a solution is required.
[0049] Therefore, in this embodiment, when server maintenance is to be performed, a security capsule 3 is provided in advance from the server 100 to the user's terminal device 300 by, for example, email, as shown in Fig. 8. The security capsule 3 is security information that includes an access command capable of acquiring the offline print upper limit count addition value stored in the access restriction area 275 of the cartridge 270. The user supplies the security capsule 3 from the terminal device 300 to the printer 200 via, for example, a USB memory 2. That is, the security capsule 3 is supplied via the USB interface 280 of the printer 200.
[0050] The authentication component 272 of the IC chip 271 verifies the signature of the security capsule 3 using the public key 276 corresponding to the private key used to sign the security capsule 3. If the verification is successful, the processor 278 of the IC chip 271 obtains an access command that allows access to the restricted access area 275 from the command list 33 of the security capsule 3 and executes the access command. The processor 210 of the printer 200 obtains the offline print upper limit number addition value stored in the restricted access area 275 of the cartridge 270. The processor 210 adds the obtained offline print upper limit number addition value to the offline print upper limit number stored in the data storage area 232 of the non-volatile memory 230 to increase and update the offline print upper limit number. This increases the number of prints that can be continued when the printer 200 and the server 100 are offline. As a result, it is possible to avoid the activation of the print limit even when a user prints a large amount of data offline. This is described in detail below.
[0051] <Control procedure> An example of a control procedure executed by the server 100, the terminal device 300, and the printer 200 to realize the above-mentioned features will be described with reference to the flowcharts of FIGS.
[0052] 9, in step S10, the processor 110 of the server 100 sends a notification that server maintenance will be performed and a security capsule 3 to the terminal device 300. The security capsule 3 has an access command that can acquire the additional value of the offline print upper limit number stored in the access restriction area 275 of the cartridge 270.
[0053] In step S20, maintenance is performed on the server 100. During the execution of this server maintenance, the processor 110 of the server 100 is unable to communicate with the printer 200 and the terminal device 300. After the above, the processor 110 of the server 100 ends this flowchart.
[0054] In step S30, the CPU 310 of the terminal device 300 receives the server maintenance notification and the security capsule 3 sent from the server 100 in step S10.
[0055] In step S40, the CPU 310 of the terminal device 300 determines whether or not the USB memory 2 is connected to the USB interface 350. If the USB memory 2 is not connected, the CPU 310 repeats step S40 (step S40: No), and if the USB memory 2 is connected (step S40: Yes), the CPU 310 proceeds to the next step S50.
[0056] In step S50, the CPU 310 of the terminal device 300 writes the security capsule 3 to the USB memory 2. With this, the CPU 310 of the terminal device 300 ends this flowchart.
[0057] In step S60, the processor 210 of the printer 200 determines whether or not the USB memory 2 to which the security capsule 3 was written in step S50 has been connected to the USB interface 280. If the USB memory 2 has not been connected, step S60 is repeated (step S60: No), and if the USB memory 2 has been connected (step S60: Yes), the process proceeds to the next step S100.
[0058] In step S100, the processor 210 of the printer 200 executes a print count addition process to increase the offline print limit by adding the offline print limit addition value. Details of this print count addition process will be described later. With this, the processor 210 of the printer 200 ends this flowchart.
[0059] An example of the control procedure for the print count addition process in step S100 is shown in Fig. 10. As shown in Fig. 10, in step S110, the processor 210 of the printer 200 reads and acquires the security capsule 3 from the USB memory 2.
[0060] In step S 120 , the authentication component 272 of the IC chip 271 starts authenticating the security capsule 3 .
[0061] In step S130, the authentication component 272 of the IC chip 271 verifies the signature of the security capsule 3 using the public key 276 corresponding to the private key used to sign the security capsule 3, and determines whether the signature verification was successful. If the signature verification fails (step S130: No), the authentication component 272 ends this flowchart without executing steps S140 to S170, which will be described later. On the other hand, if the signature verification is successful (step S130: Yes), the authentication component 272 proceeds to the next step S140. Step S130 is an example of the verification process.
[0062] In step S140, the processor 278 of the IC chip 271 obtains an access command that can access the restricted access area 275 of the cartridge 270 from the command list 33 of the security capsule 3. Step S140 is an example of processing that makes it possible to execute a command to obtain setting information from the restricted area.
[0063] In step S150, the processor 278 of the IC chip 271 executes the access command.
[0064] In step S160, the processor 210 of the printer 200 reads the additional value of the upper limit of offline printing sheets from the access restriction area 275 of the memory 273 of the IC chip 271 of the cartridge 270.
[0065] In step S170, the processor 210 of the printer 200 adds the offline printing limit number addition value read in step S160 to the offline printing limit number stored in the data storage area 232 of the non-volatile memory 230. The increased offline printing limit number is stored and updated in the data storage area 232. That is, in step S170, based on the offline printing limit number addition value, the setting of the printer 200 is changed from a setting that allows printing within the offline printing limit number to a setting that allows printing within the increased offline printing limit number. Step S170 is an example of a first setting change process and a print count addition process. Also, a setting that allows printing within the offline printing limit number is an example of a first setting, and a setting that allows printing within the increased offline printing limit number is an example of a second setting. This concludes the flow chart.
[0066] <Effects of the embodiment> The printer 200 of this embodiment can change its settings by supplying a security capsule 3 from the outside. Memory 273 of IC chip 271 provided in cartridge 270 attached to main body housing 200a of printer 200 stores setting information related to the settings of printer 200. The setting information is stored in restricted access area 275 of memory 273, which restricts access and ensures security. Therefore, in order to read and change the contents of this setting information, a command to obtain the setting information from restricted access area 275 is required.
[0067] In this embodiment, when a security capsule 3 signed with a private key is supplied from the outside, the authentication component 272 of the IC chip 271 verifies the signature of the security capsule 3 using the public key corresponding to the private key in step S130. If the verification is successful, the processor 278 of the IC chip 271 acquires an access command that allows access to the restricted access area 275 in step S140, and executes the access command in step S150. As a result, the processor 210 of the printer 200 acquires setting information in step S160, and by using the setting information in step S170, the change in the setting of the printer 200 is completed. As described above, according to this embodiment, it is possible to change the settings of the printer 200 while ensuring security by utilizing authentication technology using the security capsule 3. This makes it possible to apply authentication technology using the security capsule 3 to use in the printer 200.
[0068] Furthermore, particularly in this embodiment, by using the USB interface 280, the security capsule 3 can be supplied from the terminal device 300 to the printer 200 via the USB memory 2 or a USB cable, etc. Since the security capsule 3 is not supplied from the terminal device 300 to the printer 200 via the network NT, security can be ensured.
[0069] Furthermore, particularly in this embodiment, the maximum number of pages that can be printed offline without incurring a charge to the user is stored in nonvolatile memory 230 provided in printer 200. This allows printer 200 to continue printing within the maximum number of pages that can be printed offline, even if printer 200 goes offline and communication between printer 200 and server 100 is disabled due to some reason such as server maintenance.
[0070] Furthermore, particularly in this embodiment, an additional value for the maximum offline printing number is stored as setting information in the access restriction area 275 of the IC chip 271 of the cartridge 270. This normally restricts access to ensure the security of the additional value for the maximum offline printing number, and when the security capsule 3 is supplied, an access command that allows access to the access restriction area 275 is acquired, making the additional value for the maximum offline printing number available and allowing the maximum offline printing number to be changed.
[0071] In this embodiment, in step S170, the offline printing upper limit number is increased by adding the offline printing upper limit number addition value. This increases the number of prints that can be continued when the printer 200 and the server 100 are offline. As a result, it becomes possible to avoid the activation of the print limit even when a user prints a large amount of data offline.
[0072] <Modification> The present disclosure is not limited to the above-described embodiment, and various modifications are possible within the scope of the spirit and technical concept thereof. Such modifications will be described below in order.
[0073] (1) To notify the printer of the expiration date of server maintenance Since server maintenance has an expiration date, there may be cases where the setting changes do not need to continue after the server maintenance is completed. Therefore, as in this modified example, the server 100 may notify the printer 200 in advance of the expiration date of the server maintenance, and the printer 200 may return the changed settings to the original settings when the expiration date has passed.
[0074] 11 shows an example of a control procedure executed by the server 100, the terminal device 300, and the printer 200 in this modified example. Note that in FIG. 11, the same steps as those in FIG. 9 are denoted by the same reference numerals, and descriptions thereof will be omitted where appropriate.
[0075] As shown in FIG. 11, in step S3, the processor 110 of the server 100 transmits the expiration date of the server maintenance to the printer 200.
[0076] In step S6, the processor 210 of the printer 200 receives the expiration date of the server maintenance transmitted from the server 100 in step S3. The processor 210 stores the received expiration date of the server maintenance in an appropriate storage area, such as the data storage area 232 of the non-volatile memory 230. The expiration date of the server maintenance can also be said to be the expiration date of the setting change made in step S150. Therefore, in step S6, the processor 210 can also be said to obtain the expiration date of the setting change of the printer 200 from the server 100. Step S6 is an example of expiration date obtaining processing.
[0077] Subsequent steps S10 to S60 and step S100 are the same as those in Fig. 9, and therefore will not be described further. After executing step S100, processor 210 of printer 200 proceeds to the next step S70.
[0078] In step S70, processor 210 of printer 200 determines whether the expiration date of the server maintenance received in step S6 has expired. If the expiration date of the server maintenance has not expired, processor 210 repeats step S70 (step S70: No), and if the expiration date of the server maintenance has expired (step S70: Yes), the process proceeds to the next step S80.
[0079] In step S80, processor 210 of printer 200 initializes the increased offline printing limit to the original number. That is, in step S80, the printer 200 setting is changed from a setting that allows printing within the increased offline printing limit to a setting that allows printing within the offline printing limit before the increase. Step S80 is an example of a second setting change process. The setting that allows printing within the increased offline printing limit is an example of a second setting, and the setting that allows printing within the offline printing limit before the increase is an example of a first setting. With this, processor 210 of printer 200 ends this flowchart.
[0080] In the modified example described above, processor 110 of server 100 notifies printer 200 in advance of the expiration date of server maintenance. After changing the settings of printer 200 in step S150, processor 210 of printer 200 restores the settings of printer 200 to the state before the change in step S80 when the expiration date has passed. This makes it possible to limit the period during which the setting changes are valid to the expiration date of the server maintenance.
[0081] (2) When querying the server about the maintenance status In the modified example (1), the server 100 notifies the printer 200 in advance of the expiration date of the server maintenance, but the method by which the printer 200 knows the server maintenance period is not limited to this. For example, the printer 200 may inquire of the server 100 about the execution status of the maintenance.
[0082] 12 shows an example of a control procedure executed by the server 100, the terminal device 300, and the printer 200 in this modified example. Note that in FIG. 12, the same steps as those in FIG. 9 are denoted by the same reference numerals, and descriptions thereof will be omitted where appropriate.
[0083] Steps S10 to S60 and step S100 are the same as those in Fig. 9, and therefore will not be described here. After executing step S100, the processor 210 of the printer 200 proceeds to the next step S200.
[0084] In step S200, the processor 210 of the printer 200 queries the server 100 about the maintenance status, and executes an offline printing upper limit number initialization process to initialize or not initialize the offline printing upper limit number depending on the response result. Details of this offline printing upper limit number initialization process will be described later. With this, the processor 210 of the printer 200 ends this flowchart.
[0085] In step S300, the processor 110 of the server 100 executes a maintenance status notification process to notify the printer 200 of the status of server maintenance in response to the offline print upper limit count initialization process of step S200. Note that this step S300 is not limited to being executed after step S20, but may also be executed before step S20, depending on the timing of when the server maintenance of step S20 is executed. In FIG. 12, step S300 executed before step S20 is indicated by a dashed line. Details of this maintenance status notification process will be described later. With this, the processor 110 of the server 100 ends this flowchart.
[0086] An example of the control procedure for initializing the offline print upper limit number in step S200 is shown in Fig. 13. As shown in Fig. 13, in step S210, processor 210 of printer 200 sends a query to server 100 about the execution status of server maintenance, i.e., whether server maintenance has been completed. Step S210 is an example of query processing.
[0087] In step S220, the processor 210 of the printer 200 determines whether or not there has been a response from the server 100 to the inquiry sent in step S210. During server maintenance, the printer 200 is in an offline state where communication between the printer 200 and the server 100 is not possible, and therefore there is no response to the inquiry. On the other hand, before or after server maintenance is performed, the printer 200 is in an online state where communication between the printer 200 and the server 100 is possible, and therefore there is a response to the inquiry. If there is no response, the processor 210 repeats this step S220 (step S220: No), and if there is a response (step S220: Yes), the processor 210 proceeds to the next step S230.
[0088] In step S230, processor 210 of printer 200 determines whether server maintenance has ended, based on the response from server 100. If server maintenance has not ended, i.e., if server maintenance has not yet been performed (step S230: No), processor 210 ends this flowchart without executing step S240, which will be described later. On the other hand, if server maintenance has ended (step S230: Yes), processor 210 proceeds to the next step S240. Step S230 is an example of a determination process.
[0089] In step S240, processor 210 of printer 200 initializes the increased offline printing limit to the original number. That is, in step S240, the printer 200 setting is changed from a setting that allows printing within the increased offline printing limit to a setting that allows printing within the offline printing limit before the increase. Step S240 is an example of a third setting change process. The setting that allows printing within the increased offline printing limit is an example of a second setting, and the setting that allows printing within the offline printing limit before the increase is an example of a first setting. With the above, processor 210 of printer 200 ends this flowchart.
[0090] Fig. 14 shows an example of the control procedure for the maintenance status notification process in step S300. As shown in Fig. 14, in step S310, processor 110 of server 100 determines whether or not there has been an inquiry about the execution status of server maintenance from printer 200. If there has been no inquiry, processor 110 repeats this step S310 (step S310: No), and if there has been an inquiry (step S310: Yes), the process proceeds to the next step S320.
[0091] In step S320, processor 110 of server 100 transmits the execution status of server maintenance to printer 200. The execution status of server maintenance includes the state before and after the server maintenance is performed. With this, processor 110 of server 100 ends this flowchart.
[0092] In the modified example described above, after changing the settings, processor 210 of printer 200 makes an inquiry to server 100 in step S210, and determines whether server maintenance has ended in step S230 based on the response. If processor 210 determines that server maintenance has ended, processor 210 restores the settings of printer 200 to the state before the settings were changed in step S240. This makes it possible to limit the period during which the setting changes are effective to the period during which server maintenance is being performed.
[0093] (3) When multiple authentications are performed In the embodiment, the signature of the security capsule 3 is verified to authenticate the security capsule 3, but the accuracy of authentication may be improved by performing multiple authentications.
[0094] An example of the control procedure for the print count addition process in this modified example is shown in Fig. 15. Note that in Fig. 15, the same steps as those in Fig. 10 are given the same reference numerals, and the description thereof will be omitted where appropriate.
[0095] Steps S110 and S120 are not described here because they are the same as those in Fig. 10. After executing step S120, the processor 210 of the printer 200 proceeds to the next step S125.
[0096] In step S125, the authentication component 272 of the IC chip 271 authenticates the credentials of the security capsule 3 and determines whether the authentication of the credentials has been successful. The authentication of the credentials is performed, for example, based on a password or PIN code entered by the user. If the authentication of the credentials has failed (step S125: No), the authentication component 272 ends this flowchart without executing steps S130 to S170, which will be described later. On the other hand, if the authentication of the credentials has been successful (step S125: Yes), the authentication component 272 proceeds to the next step S130.
[0097] Step S130 is the same as that shown in Fig. 10. That is, the authentication component 272 of the IC chip 271 verifies the signature of the security capsule 3 using the public key 276 corresponding to the private key used to sign the security capsule 3, and determines whether the signature verification is successful. If the signature verification fails (step S130: No), the authentication component 272 ends this flowchart without executing steps S135 to S170, which will be described later. On the other hand, if the signature verification is successful (step S130: Yes), the authentication component 272 proceeds to the next step S135.
[0098] In step S135, the authentication component 272 of the IC chip 271 authenticates the manufacturing ID of the security capsule 3 and determines whether the authentication of the manufacturing ID has been successful. The authentication of the manufacturing ID is performed based on the manufacturing ID 31 included in the security capsule 3. If the authentication of the manufacturing ID has failed (step S135: No), the authentication component 272 ends this flowchart without executing steps S137 to S170, which will be described later. On the other hand, if the authentication of the manufacturing ID has been successful (step S135: Yes), the authentication component 272 proceeds to the next step S137.
[0099] In step S137, the authentication component 272 of the IC chip 271 authenticates the counter in the security capsule 3 and determines whether the authentication of the counter has been successful. The authentication of the counter is performed based on the counter 32 included in the security capsule 3. If the authentication of the counter has failed (step S137: No), the authentication component 272 ends this flowchart without executing steps S140 to S170, which will be described later. On the other hand, if the authentication of the counter has been successful (step S137: Yes), the authentication component 272 proceeds to the next step S140.
[0100] Steps S140 to S170 are the same as those in FIG. 10, and therefore the description thereof will be omitted.
[0101] In the above, qualification authentication, signature verification, manufacturing ID authentication, and counter authentication have been performed as multiple authentications, but it is not necessary to perform all of the authentications other than signature verification. That is, at least one of qualification authentication, manufacturing ID authentication, and counter authentication may be performed. In that case, in the above flowchart, it is sufficient to perform step S130 and at least one of step S125, step S135, and step S137.
[0102] (4) Other Although the above description has been given of the case where the setting information is the additional value of the upper limit of offline printing count, the setting information is not limited to this. In other words, the setting information may be various information other than the additional value of the upper limit of offline printing count, as long as it is information that can be read from the restricted access area 275 of the cartridge 270 by executing an access command obtained from the security capsule 3 supplied from outside the printer 200 and that can be used to change the settings of the printer 200.
[0103] In the above description, the consumables for printer 200 are cartridges, but the consumables are not limited to this. In other words, the consumables may be any parts that are consumed in printer 200, such as a belt unit that transfers a toner image onto paper.
[0104] In addition, in the modified examples (1) and (2), the increased offline printing upper limit number is reset to the original number after the completion of server maintenance, but the timing of the reset is not limited to this. For example, the increased offline printing upper limit number may be reset to the original number each time the printer 200 is turned off and then on.
[0105] Furthermore, in the above, the flowcharts shown in Figures 9 to 15 do not limit the present disclosure to the procedures shown in the flowcharts, and procedures may be added or deleted or the order may be changed within the scope that does not deviate from the intent and technical idea of the present disclosure.
[0106] Furthermore, in addition to the above, the methods according to the embodiments and modifications may be used in appropriate combination.
[0107] Although not specifically illustrated, the present disclosure can be implemented with various modifications within the scope of the spirit thereof. [Explanation of symbols]
[0108] 1. Image forming system 2 USB memory 100 servers 200 Printer (an example of an image forming device) 200a main body housing 201 Cartridge holder 202 Main body contact 210 processor (an example of the main body control unit) 215 memory 220 Volatile Memory 230 Non-volatile memory (an example of main memory) 270 Cartridges (an example of consumables) 271 IC chips 272 Authentication Components 273 Memory (an example of consumable memory) 274 accessible areas 275 Restricted Access Area (Example of a restricted area) 278 Processor (Example of consumables control unit) 280 USB interface 285 Communication Interface (Example of communication unit) 300 Terminal Equipment
Claims
1. A main body housing; a consumable item detachable from the main body housing, the consumable item having an IC chip including a consumable item memory, an authentication component, and a consumable item control unit; a main body control unit; An image forming apparatus comprising: The consumable memory includes: storing setting information relating to settings of the image forming apparatus in a restricted area; The authentication component: When a security capsule signed with a private key is supplied from outside the image forming apparatus, a verification process is performed to verify the signature of the security capsule using a public key corresponding to the private key; The consumables control unit If the verification process is successful, a process is performed to enable execution of a command to acquire the setting information from the restricted area; The main body control unit A first setting change process for changing the setting of the image forming apparatus based on the setting information acquired by executing the command. An image forming apparatus characterized by executing the above.
2. It further has a USB interface, The authentication component: When the security capsule is supplied via the USB interface, the verification process is executed.
2. The image forming apparatus according to claim 1, wherein:
3. the image forming apparatus, a communication unit capable of communicating with a server, the communication unit being capable of receiving information regarding the number of printable sheets allowed based on a user's charge from the server; a main body memory that stores a first offline print count that can be printed without charging a user when the communication unit is unable to communicate with the server; 2. The image forming apparatus according to claim 1, further comprising:
4. The setting information is The second offline print number is the number of pages that can be printed without charging the user.
4. The image forming apparatus according to claim 3.
5. In the first setting change process, the main body control unit Execute a print number addition process to add the second offline print number to the first offline print number.
5. The image forming apparatus according to claim 4.
6. The main body control unit In the first setting change process, the setting of the image forming apparatus is changed from a first setting to a second setting; The main body control unit further an expiration date acquisition process for acquiring, from a server, an expiration date of the setting change of the image forming apparatus performed by the first setting change process; a second setting change process for changing the setting of the image forming apparatus from the second setting to the first setting when the expiration date acquired in the expiration date acquisition process has passed after the setting of the image forming apparatus has been changed from the first setting to the second setting by the first setting change process; 2. The image forming apparatus according to claim 1, wherein the image forming apparatus executes the following.
7. Further, a communication unit capable of communicating with the server is included, The main body control unit In the first setting change process, the setting of the image forming apparatus is changed from a first setting to a second setting; The main body control unit further an inquiry process of inquiring of the server via the communication unit whether or not server maintenance has been completed after the setting of the image forming apparatus has been changed from the first setting to the second setting by the first setting change process; a determination process for determining whether the server maintenance has been completed in response to a response from the server; a third setting change process for changing the setting of the image forming apparatus from the second setting to the first setting when it is determined that the server maintenance has been completed by the determination process; 2. The image forming apparatus according to claim 1, wherein the image forming apparatus executes the following.
8. an image forming apparatus including: a main body housing; a consumable item detachable from the main body housing, the consumable item having an IC chip including a consumable item memory, an authentication component, and a consumable item control unit; and a main body control unit; a server capable of communicating with the image forming apparatus; An image forming system having: The image forming apparatus further comprises: a main body memory that stores a first offline print number that can be printed without charging a user when communication with the server is disabled; The consumable memory includes: The second offline print count is stored in the limit area. The authentication component: When a security capsule signed with a private key is supplied from outside the image forming apparatus, a verification process is performed to verify the signature of the security capsule using a public key corresponding to the private key; The consumables control unit If the verification is successful, a command to obtain the second offline print count from the restricted area is executed. The main body control unit a print number addition process for adding the second offline print number acquired by executing the command to the first offline print number; An image forming system comprising:
9. A consumable item to be attached to an image forming apparatus, an IC chip including a consumable memory, an authentication component, and a consumable control unit; The consumable memory includes: storing setting information relating to settings of the image forming apparatus in a restricted area; The authentication component: When a security capsule signed with a private key is supplied from outside the image forming device, a verification process can be executed to verify the signature of the security capsule using a public key corresponding to the private key, The consumables control unit If the verification process is successful, a process of enabling a command to acquire the setting information from the restricted area to be executed is executed; The setting information is After the process is executed, the image forming device is configured to change settings. A consumable item characterized by:
Citation Information
Patent Citations
Security capsule for enabling restricted features of a memory device
US20220198072A1