Replacement part authentication apparatus, authentication method, and program
The printer authentication system addresses vulnerabilities by implementing dual authentication processes, ensuring secure and compatible operation even in emergencies, thus preventing unauthorized use and maintaining distribution continuity.
Patent Information
- Application Number
- JP2024112513
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-12
- Publication Date
- 2026-01-23
Smart Images

Figure 2026011693000001_ABST
Abstract
Description
[Technical Field]
[0001] The present specification relates to a replacement part authentication device, authentication method, and program for authenticating an installed replacement part. [Background technology]
[0002] Various technologies for authenticating replacement parts have been proposed in the past. Patent Document 1 below describes a printer that performs authentication using a printer ID stored in the cartridge's memory. The printer in Patent Document 1 allows use of the installed cartridge if the printer ID read from the memory of the installed cartridge matches the printer ID of the printer itself. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2018-505444 Summary of the Invention [Problem to be solved by the invention]
[0004] In a configuration where the printer ID stored in the cartridge memory is determined, as in the printer described in Patent Document 1, a third party could analyze the memory and copy the stored printer ID to the memory of another cartridge, potentially resulting in the use of an unauthorized cartridge. Therefore, by writing authentication information such as signature information to the cartridge memory and verifying whether the authentication information corresponds to the printer after installation, unauthorized use by simple copying as described above can be prevented. However, with a method that uses authentication information, for example, if an emergency occurs in which memory storing authentication information corresponding to a certain printer cannot be supplied, the development time required to supply a new corresponding memory could be required, potentially hindering normal distribution.
[0005] This specification has been proposed in consideration of the above-mentioned problems, and aims to provide a replacement part authentication device, authentication method, and program that can expand the compatibility of replacement parts that store authentication information in memory. [Means for solving the problem]
[0006] In order to achieve the above object, the replacement part authentication device of this specification comprises a mounting unit to which a replacement part can be detachably attached, an acquisition unit that acquires authentication information from the memory of the replacement part, and a controller, wherein the controller executes the following operations: a normal acquisition process that acquires normal authentication information from the memory of the replacement part via the acquisition unit based on the replacement part being mounted on the mounting unit; a normal authentication process that performs authentication using the normal authentication information if the normal authentication information can be acquired from the memory by the normal acquisition process; a normal permission process that permits use of the mounted replacement part if authentication by the normal authentication process is successful; an emergency acquisition process that acquires emergency authentication information different from the normal authentication information from the memory of the replacement part via the acquisition unit if the normal authentication information cannot be acquired in the normal acquisition process; an emergency authentication process that performs authentication using the emergency authentication information if the emergency authentication information can be acquired from the memory by the emergency acquisition process; and an emergency permission process that permits use of the mounted replacement part if authentication by the emergency authentication process is successful. Furthermore, the contents of this specification are not limited to implementation as a replacement part authentication device, but are also extremely useful when implemented as an authentication method in a replacement part authentication device, a program executed by a computer in the replacement part authentication device, or a program stored on a computer-readable medium. [Effects of the Invention]
[0007] According to the replacement part authentication device, authentication method, and program according to the present specification, it is possible to expand the compatibility of replacement parts that store authentication information in memory. [Brief explanation of the drawings]
[0008] [Figure 1] 1A and 1B are external perspective views of a printer 10, in which (A) shows a closed state with a cover 11 closed, and (B) shows an open state with the cover 11 open. [Figure 2] FIG. 2 is a schematic diagram showing the internal structure of the printer 10. [Figure 3] 1 is a block diagram of a printer 10. [Figure 4] FIG. 1 is a block diagram of an IC substrate 105. [Figure 5] 4 is a diagram showing compatibility in authentication between the printer 10 and the cartridge 100 under normal circumstances. [Figure 6] 10 is a flowchart of a cartridge authentication process. [Figure 7] 10 is a diagram showing compatibility in authentication between the printer 10 and the cartridge 100 in an emergency. DETAILED DESCRIPTION OF THE INVENTION
[0009] An embodiment that embodies the replacement part authentication device of this specification will be described below. Note that the embodiment described below is merely an example of the invention according to this specification, and it goes without saying that the embodiment can be modified as appropriate without departing from the spirit of this specification. FIG. 1 shows a perspective view of a printer 10 according to this embodiment, with FIG. 1(A) showing a closed state with the cover 11 closed and FIG. 1(B) showing an open state with the cover 11 open. In the following description, as shown in FIG. 1, the up-down direction 1, the left-right direction 2, and the front-rear direction 3 are defined based on the direction in which the printer 10 is viewed from the front.
[0010] (Printer 10 Overview) FIG. 2 is a schematic diagram of the internal structure of printer 10. As shown in FIGS. 1 and 2, printer 10 is a device that prints images on sheets using an inkjet method, and includes a roughly rectangular parallelepiped housing 13. Inside housing 13, there are provided a paper feed tray 15, a paper feed roller 16, a transport roller 17, a head 21 having a plurality of nozzles 19, a platen 22 facing head 21, a discharge roller 23, a discharge tray 25, an attachment case 27 to / from which cartridge 100 is attached / detached, a tube 29, a controller 30 (see FIG. 3), and a drive source 31 (see FIG. 3). Tube 29 connects a connection portion 28 of head 21 to a subtank 37 of attachment case 27, which will be described later.
[0011] The drive source 31 includes, for example, a motor and a reduction gear connected to the motor's output shaft, and rotates the feed roller 16, the transport roller 17, the discharge roller 23, etc. The printer 10 drives the drive source 31 to rotate the feed roller 16 and the transport roller 17, thereby transporting the sheet S stored in the paper feed tray 15 to the position of the platen 22. The printer 10 ejects ink 101 supplied from a cartridge 100 attached to an attachment case 27 through a tube 29, through the nozzles 19 of the head 21. For example, the printer 10 includes a carriage that moves back and forth in a main scanning direction that intersects with the direction in which the sheet S is transported by the transport roller 17. The head 21 is mounted on this carriage. The printer 10 ejects ink 101 through the nozzles 19 of the head 21 while moving the carriage from one side to the other in the main scanning direction. As a result, the ink 101 lands on the sheet S supported by the platen 22, printing an image on the sheet S. An image is printed on a partial area (one pass's worth) of the sheet S facing the head 21. Next, the printer 10 causes the transport rollers 17 to transport the sheet S so that the area where the next image is to be printed faces the head 21. The printer 10 alternately repeats these processes to print an image on one sheet S. The printer 10 rotates the discharge rollers 23 to discharge the sheet S on which the image has been printed onto the discharge tray 25. The sheet S discharged onto the discharge tray 25 can be removed from an opening 26 formed in the front surface 13A of the printer 10.
[0012] As shown in FIG. 1(B), an opening 13B is formed on the front surface 13A of the housing 13 at the right end in the left-right direction 2. The housing 13 is provided with a cover 11 that switches between an open state (FIG. 1(B)) in which the opening 13B is open and a closed state (FIG. 1(A)) in which the opening 13B is closed. An attachment case 27 (accommodation section 41) is provided in the space inside the housing 13 that extends beyond the opening 13B. The printer 10 also has a cover sensor 33 (see FIG. 3) for detecting whether the cover 11 is open or closed.
[0013] As shown in FIGS. 2 and 3, the mounting case 27 includes a contact 35, an attachment sensor 36 (see FIG. 3), a subtank 37 (see FIG. 2), an ink amount sensor 38, and a joint 39 (see FIG. 2). The mounting case 27 can accommodate four cartridges 100, one for each of the four colors: black (K), cyan (C), magenta (M), and yellow (Y). The mounting case 27 has slots into which each of the four cartridges 100 can be attached. That is, the mounting case 27 includes four contacts 35, attachment sensors 36, subtanks 37, ink amount sensors 38, and joints 39, one for each of the four cartridges 100. These four sets are provided in the four slots and have the same configuration except that the colors of the ink 101 are different. Therefore, the following description will focus on the configuration of one set. The number of cartridges 100 that can be accommodated in the mounting case 27 is not limited to four, and may be one, five, or more.
[0014] The mounting case 27 is box-shaped and has a storage section 41 that stores the mounted cartridge 100. An opening 41A that communicates with the opening 13B of the housing 13 is formed on the front side of the mounting case 27. The cartridge 100 is attached to and detached from the storage section 41 of the mounting case 27 through the openings 13B and 41A. The cartridge 100 includes a housing 103 and a lid 104. A liquid chamber 103A that stores ink 101 is formed inside the housing 103. The top of the liquid chamber 103A is closed by the lid 104. An IC board 105 on which a memory 110 is mounted is provided on the lid 104. The memory 110 is, for example, a rewritable nonvolatile memory such as an EEPROM. Note that the memory 110 is not limited to an EEPROM, and may be another nonvolatile memory such as a flash memory.
[0015] The contact 35 is attached to, for example, the upper wall 41B of the accommodating section 41. The contact 35 is provided at a position where it comes into contact with an electrode 111 (see FIG. 3) provided on the IC board 105 of the cartridge 100 when the cartridge 100 is attached to the attachment case 27. The contact 35 is electrically connected to the controller 30 (see FIG. 3) of the printer 10. The controller 30 acquires information from the memory 110 of the IC board 105 through the contact 35 and the electrode 111. The controller 30 also writes information to the memory 110 of the IC board 105 through the contact 35 and the electrode 111.
[0016] In this specification, the term "acquire" is used as a concept that does not necessarily require a request. In other words, the concept of "controller 30 acquires information" also includes information being output from memory 110 to controller 30 without a request from controller 30. Therefore, "acquire" is a concept that includes both the case where controller 30 actively reads information from memory 110 and the case where cartridge 100 actively outputs information from memory 110 without a request.
[0017] The mounting case 27 also includes four sub-tanks 37 corresponding to the four cartridges 100. The sub-tanks 37 are located further rearward than the back wall of the storage section 41 and are capable of storing ink 101. An inlet 37C is formed at the lower end of the front wall of the sub-tank 37. The inlet 37C is connected to the liquid chamber 103A of the cartridge 100 via a joint 39. The joint 39, for example, has a mechanism for opening and closing a flow path depending on whether the cartridge 100 is mounted. The mounting sensor 36 is provided, for example, on the upper wall 41B of the storage section 41 and is a sensor for detecting whether the cartridge 100 is mounted in the mounting case 27. The ink amount sensor 38 is provided on the bottom wall of the sub-tank 37 and outputs a different signal to the controller 30 depending on whether the amount of ink in the sub-tank 37 has decreased below a predetermined amount. This predetermined amount is, for example, an amount sufficient to print several hundred sheets S. The cartridge 100 is empty when the amount of ink falls below a predetermined amount. Therefore, the printer 10 can print several hundred sheets even after the ink 101 level reaches the height of the detection position of the ink amount sensor 38 and the cartridge 100 becomes empty.
[0018] An outlet 37A formed in the lower part of the rear wall of the subtank 37 is connected to the connection part 28 of the head 21 via a tube 29. This allows the subtank 37 to supply ink 101 to the head 21 from the outlet 37A via the tube 29. The subtank 37 is also connected to the outside of the printer 10 through an atmosphere communication passage 37B formed in the top wall, and is open to the atmosphere. The liquid chamber 103A of the cartridge 100 is also connected to the outside of the cartridge 100 through an atmosphere communication passage 104A formed in the lid part 104, and is open to the atmosphere. Therefore, the ink 101 in the liquid chamber 103A and the ink 101 in the subtank 37 move through the joint 39 due to the difference in head. When the liquid levels of the ink 101 in the liquid chamber 103A and the subtank 37 are the same, an equilibrium state is reached, and in this equilibrium state, the movement of the ink 101 stops.
[0019] (Controller 30) As shown in FIG. 3, the controller 30 includes a CPU 43, a ROM 44, a RAM 45, an EEPROM 46, and an ASIC 47. The ROM 44 stores a control program CP and other programs used by the CPU 43 to control the operation of each device. The ROM 44 also stores a first normal-time authentication program PG1A, a second normal-time authentication program PG1B, a first emergency-time authentication program PG2A, and a second emergency-time authentication program PG2B. These authentication programs are programs for authenticating the cartridge 100, and perform authentication using authentication information (such as first normal-time authentication information AI1A) stored in the cartridge 100 (described later). Details of the first normal-time authentication program PG1A and other programs will be described later. The RAM 45 is used as a storage area for temporarily recording data, signals, and the like used by the CPU 43 when executing each program (such as the control program CP), or as a working area for data processing. The EEPROM 46 stores setting information that should be retained even after the power is turned off. For example, the EEPROM 46 stores the remaining amount of ink 101 in the subtank 37 .
[0020] The memory configuration described above is merely an example. For example, the controller 30 may be provided with a flash memory instead of an EEPROM as a non-volatile memory. The first normal authentication program PG1A and the like may be stored in the EEPROM 46 instead of the ROM 44. In the following description, the controller 30 that executes the control program CP and the authentication programs (PG1A, PG1B, PG2A, PG2B) may be referred to simply by their device names. For example, the phrase "the controller 30 drives the motor of the drive source 31 via the ASIC 47" means "the controller 30 executes the control program CP in the CPU 43 and controls the drive source 31 via the ASIC 47, thereby driving the motor." The medium for storing the control program CP, the authentication programs (PG1A, PG1B, PG2A, PG2B), and the like is not limited to the ROM 44 built into the printer 10, but may also be a computer-readable storage medium (such as a USB memory). Computer-readable storage media are non-transitory media. In addition to the above examples, non-transitory media also include storage media such as CD-ROMs and DVD-ROMs. Non-transitory media are also tangible media. On the other hand, electrical signals carrying programs downloaded from servers on the Internet are computer-readable signal media, which is a type of computer-readable medium, but are not included in non-transitory computer-readable storage media.
[0021] The ASIC 47 is an Application Specific Integrated Circuit, and operates the drive source 31, head 21, etc. The controller 30 drives the motor of the drive source 31 via the ASIC 47, thereby rotating the feed roller 16, the transport roller 17, and the discharge roller 23. The controller 30 also outputs a drive signal to the drive element of the head 21 via the ASIC 47, thereby ejecting ink 101 through the nozzles 19 of the head 21. The ASIC 47 can output multiple types of drive signals depending on the amount of ink to be ejected through the nozzles 19.
[0022] 1 and 3, the printer 10 is equipped with, as a user interface, for example, a touch panel 48 and operation buttons 49. The ASIC 47 is electrically connected to the cover sensor 33, the contacts 35, the installation sensor 36, and the ink amount sensor 38. The controller 30 accesses the memory 110 of the IC board 105 of the cartridge 100 installed in the installation case 27 via the contacts 35.
[0023] The printer 10 also includes a network IF (abbreviation of interface) 51. The network IF 51 is, for example, a LAN interface. The controller 30 is connectable to a PC, the Internet, a server, etc. via the network IF 51. The network IF 51 is not limited to a wired network IF, and may be a wireless network IF. The configuration of the printer 10 described above is an example. For example, the printer 10 may not be configured to include the network IF 51. The printer 10 may also download the first normal authentication program PG1A, etc. from a server via the network IF 51.
[0024] Fig. 4 shows a block diagram of IC substrate 105. As shown in Fig. 4, IC substrate 105 includes, in addition to memory 110, control unit 112 and signal processing circuit 113. Control unit 112 is connected to memory 110 and is a memory controller that controls writing of information to memory 110 and acquisition of information from memory 110. Signal processing circuit 113 is connected between control unit 112 and electrodes 111 and executes transmission and reception of signals (information) between control unit 112 and electrodes 111.
[0025] The memory 110 of the IC substrate 105 stores remaining amount 123, cartridge type information 125, ID information 128, equilibrium calculation parameters 129, first normal authentication information AI1A, and second normal authentication information AI1B. The remaining amount 123 is information indicating the remaining amount of ink 101 in the cartridge 100. The cartridge type information 125 is information indicating the type of cartridge 100. For example, the cartridge type information 125 is information indicating the color of ink 101 contained in the cartridge 100 or information indicating the destination of the cartridge 100. The destination information is information that can identify the country, region, state, etc. where the cartridge 100 is to be sold or used. The destination information may be information on a country-by-country basis, or may be information indicating a country, region, etc. Furthermore, the ID information 128 is information that can individually identify the IC substrate 105 (cartridge 100), such as UID (Unique ID) information in which a unique value (such as numbers or letters) is assigned to each IC substrate 105. Furthermore, the balance calculation parameters 129 are parameters (such as an arithmetic formula or coefficients) of a balance calculation formula for calculating the amount of ink in the cartridge 100 from the total amount of ink 101, which is the sum of the amount of ink in the cartridge 100 and the amount of ink in the subtank 37. As a method for calculating the ink amounts in the liquid chamber 103A and the subtank 37 from the total amount of ink 101 using the balance calculation formula, for example, the known technology described in JP 2019-69568 A can be used.
[0026] Furthermore, the first and second normal authentication information AI1A, AI1B are information for authenticating the cartridge 100 and for later verifying whether the cartridge 100 is genuine. Specifically, the first normal authentication information AI1A is, for example, information in which a digital signature is applied to the UID indicated by the ID information 128, and information in which a hash value calculated by substituting the UID into a predetermined arithmetic expression is encrypted (encrypted with a private key or the like). Therefore, the first normal authentication information AI1A is information unique to each IC substrate 105 (cartridge 100). The encryption program for encrypting the UID, the decryption program for decrypting the first normal authentication information AI1A, the ID information 128 (UID), etc. are managed by the manufacturer of the IC substrate 105.
[0027] Furthermore, the first normal-time authentication program PG1A stored in the ROM 44 of the controller 30 is a program that acquires and authenticates (verifies) the first normal-time authentication information AI1A. The controller 30, for example, executes the first normal-time authentication program PG1A acquired from the ROM 44 on a sub-microcomputer of the ASIC 47, acquires the first normal-time authentication information AI1A from the memory 110 using the first normal-time authentication program PG1A, and authenticates the acquired first normal-time authentication information AI1A. The controller 30 uses the first normal-time authentication program PG1A to decrypt the first normal-time authentication information AI1A acquired from the memory 110. The controller 30 also uses the first normal-time authentication program PG1A to calculate a hash value using the ID information 128 (UID) acquired from the memory 110 and a predetermined arithmetic expression. If the decrypted first normal-time authentication information AI1A matches the hash value resulting from the calculation, the controller 30 determines that the authentication has been successful. If they do not match, the controller 30 determines that the authentication has failed. The IC board 105 may perform the decryption and hash value calculation.
[0028] The second normal authentication information AI1B is, for example, electronically signed information, similar to the first normal authentication information AI1A. For example, the second normal authentication information AI1B is information in which an electronic signature is added to information about the color of the ink 101 and the destination of the printer 10. The color and destination information is, for example, numbers or character strings indicating the type of color or destination, and is information set as cartridge type information 125. Therefore, the second normal authentication information AI1B is different information for each color and destination. Even for cartridges 100 with the same destination, if the colors of the ink 101 are different, the second normal authentication information AI1B will be different information. The second normal authentication information AI1B is information obtained by encrypting a hash value calculated by substituting numerical values indicating the color and destination into a predetermined arithmetic expression. The encryption program, decryption program, and color and destination information related to the second normal authentication information AI1B are managed by the manufacturer of the printer 10. Therefore, information relating to the electronic signature of the first normal authentication information AI1A and information relating to the electronic signature of the second normal authentication information AI1B are managed by the respective manufacturers of the IC substrate 105 and the printer 10. Then, as will be described later, by performing two-stage authentication using the two pieces of normal authentication information, it is possible to improve the reliability and security of the authentication of the cartridge 100.
[0029] The second normal-mode authentication program PG1B stored in the ROM 44 of the controller 30 is a program for acquiring and authenticating the second normal-mode authentication information AI1B. The controller 30 executes the second normal-mode authentication program PG1B acquired from the ROM 44 on the sub-microcomputer of the ASIC 47, acquires the second normal-mode authentication information AI1B from the memory 110, and authenticates the acquired second normal-mode authentication information AI1B. The controller 30 uses the second normal-mode authentication program PG1B to decrypt the second normal-mode authentication information AI1B acquired from the memory 110. The controller 30 also uses the second normal-mode authentication program PG1B to acquire color and destination information from the cartridge type information 125 in the memory 110 and calculates a hash value using the acquired color and destination information and a predetermined arithmetic expression. If the decrypted second normal-mode authentication information AI1B matches the hash value resulting from the calculation, the controller 30 determines that the authentication is successful. If they do not match, the controller 30 determines that the authentication is unsuccessful.
[0030] The above-described contents of the first and second normal authentication information AI1A and AI1B and the contents of the authentication process of the first and second normal authentication programs PG1A and PG1B are merely examples. For example, an unencrypted hash value may be used as the first normal authentication information AI1A. In this case, the controller 30 may calculate a hash value from the ID information 128 stored in the memory 110 and determine whether the calculated hash value matches the first normal authentication information AI1A. The first and second normal authentication information AI1A and AI1B may not be calculated information such as a hash value. For example, the first normal authentication information AI1A may be information obtained by encrypting a unique value generated for each cartridge 100. In this case, the unique value may be stored in the memory 110, and a match may be determined between the unique value and the decrypted value of the first normal authentication information AI1A. The manufacturer of the printer 10 may also manage all of the encryption programs for the first and second normal authentication information AI1A and AI1B. Furthermore, the entity that executes the first normal-state authentication program PG1A is not limited to the sub-microcomputer of the ASIC 47, but may be another processing device such as the CPU 43. Furthermore, the first normal-state authentication information AI1A does not need to be information unique to each IC substrate 105, but may instead be the same information for each manufacturer of the cartridge 100 or each type of IC substrate 105. Furthermore, information other than the UID (such as the serial number of the cartridge 100) may be used as information for generating the first normal-state authentication information AI1A.
[0031] Public key cryptography may also be used for authentication. For example, an electronic document encrypted using a private key known only to the manufacturer of the IC board 105 is stored in the memory 110 as first normal authentication information AI1A. A public key is also stored in the ROM 44 of each printer 10. The controller 30 may determine that authentication is successful if it can decrypt the first normal authentication information AI1A using the public key. Therefore, a known authentication method used for electronic signatures or the like may be adopted for authenticating the first and second normal authentication information AI1A and AI1B. The same applies to the first and second normal authentication information AI1A' and AI1B', the first and second emergency authentication information AI2A and AI2B, the first and second emergency authentication programs PG2A and PG2B, and the like, which will be described later.
[0032] 4 are merely examples. For example, if the cartridge 100 is recyclable, information related to recycling may be stored in the memory 110. Recycling here refers to, for example, a remanufacturing manufacturer collecting, disassembling, cleaning, reassembling, inspecting, and setting information in the memory 110 after use of the cartridge 100, and then selling the cartridge as a recycled product. In this case, the initial value of the remaining amount at the time of recycling, the number of times recycling has been performed, post-recycling equilibrium calculation parameters, and the like may be stored in the memory 110. The cartridge 100 may then be authenticated using this information. For example, the cartridge 100 may be authenticated using the initial value of the remaining amount after recycling and a hash value obtained using a predetermined arithmetic expression.
[0033] (Cartridge authentication process) Here, the components that make up cartridge 100 may be procured from multiple companies or regions to ensure a stable supply of cartridge 100. However, if IC substrate 105 and memory 110 are procured from multiple companies, there is a risk that the strength of security in authentication may be weakened. Specifically, if authentication can be performed in the same way for all IC substrates 105, the security of the IC substrate 105 with the lowest security level among the multiple types of IC substrates 105 may be breached, and counterfeit cartridges 100 may be produced.
[0034] On the other hand, if parts are procured only from one company, and that company is unable to supply IC substrate 105 or memory 110 for some reason, sales of cartridge 100 will be impossible. Furthermore, even if IC substrate 105, etc. cannot be procured from Company A and IC substrate 105, etc. can be procured from Company B, there is a risk that Company B's IC substrate 105, etc. cannot be immediately used in place of Company A's due to differences in physical structure and electrical signals, such as differences in the positions of the terminals included in electrodes 111 of IC substrate 105, differences in the signals flowing through each terminal, and differences in the addresses of memory 110. This requires development time to reuse IC substrate 105, etc. from a different company, which could hinder distribution of cartridge 100.
[0035] Therefore, the printer 10 of this embodiment is designed to allow the use of cartridges 100 that are incompatible under normal circumstances in an emergency. In this specification, an emergency refers to a situation in which normal distribution becomes difficult for some reason, such as an emergency in which the IC substrate 105 or memory 110 described above cannot be supplied, making it impossible to supply cartridges 100 that were normally supplied. An emergency can be a situation in which cartridges 100 cannot be supplied due to various reasons, such as a shortage of raw materials, a shortage of manufacturing equipment, or changes in social conditions. Furthermore, an emergency is not limited to the above-described situation. For example, an emergency can also be a situation in which normal authentication (authentication using at least one of the first normal authentication information AI1A and the second normal authentication information AI1B) cannot be performed due to some malfunction. Specifically, an emergency can also be a situation in which normal authentication cannot be performed due to some malfunction in the first normal authentication program PG1A or the second normal authentication program PG1B. Therefore, various situations in which normal cartridges 100 cannot be supplied can be adopted as an emergency.
[0036] FIG. 5 shows the authentication compatibility between the printer 10 and cartridge 100 under normal circumstances. In the following explanation, as an example, assume that the IC substrate 105 for cartridge 100 destined for destination A is made by a different manufacturer than for destination B. Destinations A and B are, for example, Japan and the United Kingdom. The printer 10 and cartridge 100 destined for destination A will be referred to as the first printer 10A and first cartridge 100A, respectively, and the printer 10 and cartridge 100 destined for destination B will be referred to as the second printer 10B and second cartridge 100B. When referring to the printer 10 and cartridge 100 collectively, they will be referred to as the printer 10 and cartridge 100 without adding an alphabetical character after the reference numeral.
[0037] For example, the first and second normal-time authentication programs PG1A and PG1B stored in the first printer 10A correspond to destination A, and correspond to the first and second normal-time authentication information AI1A and AI1B stored in the first cartridge 100A for destination A. Specifically, the first normal-time authentication information AI1A is information set by the manufacturer of the IC board 105 supplied to destination A. Furthermore, the second normal-time authentication information AI1B is information obtained by encrypting a hash value calculated using a predetermined arithmetic expression from information indicating destination A, etc.
[0038] Similarly, the first and second normal authentication programs PG1A' and PG1B' stored in the second printer 10B correspond to destination B, and correspond to the first and second normal authentication information AI1A' and AI1B' stored in the second cartridge 100B for destination B. The first normal authentication information AI1A' is information set by the manufacturer of the IC board 105 supplied to destination B. The second normal authentication information AI1B' is information obtained by encrypting a hash value calculated using a predetermined arithmetic expression from information indicating destination B, etc.
[0039] Furthermore, the first emergency authentication program PG2A stored in the first printer 10A is the same program as, for example, the first normal-time authentication program PG1A' stored in the second printer 10B at destination B. Therefore, the first emergency authentication program PG2A is a program that corresponds to the acquisition and authentication of the first normal-time authentication program PG1A' stored in the second cartridge 100B at destination B. Furthermore, the second emergency authentication program PG2B stored in the first printer 10A is a program that corresponds to the acquisition and authentication of second emergency authentication information AI2B (see FIG. 7) stored in the second cartridge 100B in an emergency. Details of the second emergency authentication program PG2B and the second emergency authentication information AI2B will be described later.
[0040] FIG. 6 shows a flowchart of the cartridge authentication process executed by the controller 30. The controller 30 authenticates the cartridge 100 by executing this cartridge authentication process. When the cartridge 100 is attached to the attachment case 27 (accommodating section 41), the controller 30 executes the control program CP stored in the ROM 44 to execute the process of FIG. 6. More specifically, the controller 30 starts the process of FIG. 6 when, for example, the cartridge 100 is attached to the attachment case 27 for the first time. The controller 30 also starts the process of FIG. 6 when the attached cartridge 100 is replaced and the ID information 128 of the replaced cartridge 100 does not match. Note that the condition for starting the process of FIG. 6 is not limited to the condition that the cartridge 100 is attached. For example, the controller 30 may execute the process of FIG. 6 every time a predetermined number of sheets (e.g., one sheet) are printed. The controller 30 may also execute the process of FIG. 6 for the attached cartridge 100 every time the printer 10 is powered on.
[0041] To avoid complicating the explanation, the following description will be directed to a case where one of the four cartridges 100 that can be attached to the attachment case 27 is processed. For example, the case where one cartridge 100 is replaced will be described. However, when processing multiple cartridges 100, the processing can be performed by executing the processing described below for each cartridge 100, just as in the case of one cartridge. Therefore, the controller 30 may start the processing of FIG. 6 when at least one of the four cartridges 100 is replaced, etc.
[0042] Furthermore, each destination printer 10 executes similar processing using an authentication program (such as the first normal authentication program PG1A) stored in its own ROM 44. For this reason, the following description will mainly focus on the cartridge processing of the first printer 10A for destination A, and will omit the description of the cartridge processing of the second printer 10B for destination B as appropriate.
[0043] (When the first cartridge 100A is installed) First, as a normal processing, a case where the first cartridge 100A is installed in the first printer 10A will be described. When the controller 30 of the first printer 10A starts the processing of Figure 6, in step (hereinafter simply referred to as S) 1, it obtains the first normal-time authentication program PG1A from the ROM 44 and causes the sub-microcomputer of the ASIC 47 to execute the obtained first normal-time authentication program PG1A. When the controller 30 executes the first normal-time authentication program PG1A, it obtains first normal-time authentication information AI1A from the memory 110 of the replaced first cartridge 100A.
[0044] Next, the controller 30 determines whether or not the first normal-state authentication information AI1A was acquired from the replaced first cartridge 100A (S2). As shown in FIG. 5, the first normal-state authentication information AI1A is stored in the memory 110 of the first cartridge 100A of destination A. The first normal-state authentication program PG1A is a program corresponding to the acquisition of the first normal-state authentication information AI1A. Therefore, by executing the first normal-state authentication program PG1A in S1, the controller 30 successfully acquires the first normal-state authentication information AI1A (S2: YES), and executes S3. The controller 30 authenticates the acquired first normal-state authentication information AI1A (S3). As described above, the controller 30 decrypts the first normal-state authentication information AI1A using the first normal-state authentication program PG1A, calculates a hash value based on the ID information 128 acquired from the memory 110 of the first cartridge 100A, and executes authentication (S3). If the controller 30 is unable to acquire the ID information 128 from the memory 110, the controller 30 may notify an error.
[0045] Next, the controller 30 determines whether the authentication in S3 was successful (S5). If the hash value obtained by decrypting the first normal authentication information AI1A matches the hash value calculated from the ID information 128 and authentication is successful (S5: YES), the controller 30 executes S6. If the hash values do not match, the controller 30 determines that authentication has failed (S5: NO) and executes S7. In S7, the controller 30 may, for example, restrict the use of the replaced first cartridge 100A and not perform printing using the replaced first cartridge 100A. Furthermore, the controller 30 displays a message on the touch panel 48 indicating that the replaced first cartridge 100A cannot be used because authentication has failed. The controller 30 then ends the processing shown in FIG. 6.
[0046] Furthermore, the controller 30 may retain the error and restrict printing until the first cartridge 100A is replaced with another one and authentication is successful. As a result, if a non-genuine first cartridge 100A is installed, the controller 30 makes a negative determination in S5 (S5: NO) and restricts use of the printer 10. Note that the controller 30 may notify the user in S7 that authentication has failed by lighting a lamp or issuing a sound. Furthermore, the controller 30 may not completely prohibit use of the first cartridge 100A in S7. For example, the controller 30 may permit some processing, such as checking information stored in the memory 110 of the first cartridge 100A.
[0047] Furthermore, from S6 onwards, the controller 30 performs authentication using the second normal-time authentication program PG1B and the second normal-time authentication information AI1B, similarly to the first normal-time authentication program PG1A and the first normal-time authentication information AI1A. Therefore, in the following description of authentication using the second normal-time authentication program PG1B, the same content as that of the first normal-time authentication program PG1A will be omitted as appropriate.
[0048] In S6, the controller 30 obtains the second normal-mode authentication program PG1B from the ROM 44, executes the second normal-mode authentication program PG1B using the sub-microcomputer of the ASIC 47, and obtains the second normal-mode authentication information AI1B from the memory 110. If the controller 30 successfully obtains the second normal-mode authentication information AI1B (S8: YES), it performs authentication using the obtained second normal-mode authentication information AI1B (S9). The controller 30 decrypts the second normal-mode authentication information AI1B using the second normal-mode authentication program PG1B, calculates a hash value from the color and destination information in the cartridge type information 125 obtained from the memory 110, and determines whether the hash values match. If the hash values match and authentication is successful (S10: YES), the controller 30 permits use of the replaced first cartridge 100A (S11), and ends the processing shown in FIG. 6. The controller 30 executes (permits) printing using the replaced first cartridge 100A based on a copy instruction from the touch panel 48 or a print instruction from a PC via the network IF 51. This allows two-stage authentication to be performed using two pieces of authentication information: first normal authentication information AI1A set by the manufacturer of the IC board 105 and second normal authentication information AI1B set by the manufacturer of the printer 10, thereby improving the security level for the cartridge 100 in normal operation. This can also prevent the use of an unauthorized cartridge 100.
[0049] On the other hand, if the controller 30 fails to acquire the second normal-mode authentication information AI1B (S8: NO) or fails to authenticate the second normal-mode authentication information AI1B (S10: NO), the controller 30 executes S7 and restricts the use of the first cartridge 100A. The controller 30 may also display on the touch panel 48 a message indicating that the controller 30 failed to acquire the authentication information (S8: NO) or failed to authenticate (S10: NO) (S7). The controller 30 may execute the processes for acquiring the first and second normal-mode authentication programs PG1A and PG1B and the processes for acquiring the first and second normal-mode authentication information AI1A and AI1B together in S1, rather than dividing the processes into two steps at S1 and S6. For example, the controller 30 may execute the first and second normal-mode authentication programs PG1A and PG1B in S1 and acquire the first and second normal-mode authentication information AI1A and AI1B together.
[0050] (When the second cartridge 100B is installed) Next, a case where the second cartridge 100B is installed in the first printer 10A will be described as a normal processing. As shown in FIG. 5, the second cartridge 100B stores first normal-time authentication information AI1A' and second normal-time authentication information AI1B' for destination B, but does not store first normal-time authentication information AI1A and second normal-time authentication information AI1B for destination A. Furthermore, the first normal-time authentication program PG1A supports processing for acquiring the first normal-time authentication information AI1A for destination A, but does not support processing for acquiring the first normal-time authentication information AI1A' for destination B. Therefore, in S2, the controller 30 cannot acquire the first normal-time authentication information AI1A from the memory 110 of the installed second cartridge 100B, so it makes a negative determination (S2: NO) and executes S13.
[0051] From S13 onwards, the controller 30 executes authentication using the first and second emergency authentication programs PG2A and PG2B in the same way as the authentication using the first and second normal authentication programs PG1A and PG1B in S1 to S11. Therefore, in the following explanation, the same content as the authentication using the first and second normal authentication programs PG1A and PG1B will be omitted as appropriate.
[0052] In S13, the controller 30 retrieves the first emergency authentication program PG2A from the ROM 44 and executes the first emergency authentication program PG2A on the sub-microcomputer of the ASIC 47. As described above, the first emergency authentication program PG2A is the same program as the first normal-time authentication program PG1A' for destination B and corresponds to the acquisition and authentication of the first normal-time authentication information AI1A' for destination B. As shown in FIG. 7, in an emergency, the first emergency authentication program PG2A executes authentication of the first normal-time authentication information AI1A' for destination B. For this reason, for convenience of explanation, the first normal-time authentication information AI1A' may be referred to as first emergency authentication information AI2A. Furthermore, in the flowchart of FIG. 6, the first normal-time authentication information AI1A' is referred to as first emergency authentication information AI2A to avoid cluttering the drawing.
[0053] In S13, the controller 30 executes the first emergency authentication program PG2A and acquires the first normal-state authentication information AI1A' (first emergency authentication information AI2A) from the memory 110 of the second cartridge 100B. Because the first emergency authentication program PG2A corresponds to the first emergency authentication information AI2A, the controller 30 succeeds in acquiring the first emergency authentication information AI2A from the memory 110 of the second cartridge 100B (S14: YES) and executes authentication using the first emergency authentication information AI2A (S15). Because the first normal-state authentication information AI1A' stored in the second cartridge 100B is the first emergency authentication information AI2A, the controller 30 succeeds in authentication using the first emergency authentication information AI2A in S16 (S16: YES) and executes S17.
[0054] In S17, the controller 30 acquires the second emergency authentication program PG2B from the ROM 44 and executes the second emergency authentication program PG2B using the sub-microcomputer of the ASIC 47. The controller 30 then executes a process to acquire the second emergency authentication information AI2B (see FIG. 7) from the memory 110 of the second cartridge 100B (S17). As shown in FIG. 6, the second emergency authentication information AI2B is not stored in the second cartridge 100B. Furthermore, the second emergency authentication program PG2B does not correspond to the second normal-state authentication information AI1B' stored in the second cartridge 100B. Therefore, the controller 30 cannot acquire the second emergency authentication information AI2B (S18: NO), and as in S7, issues a notification that authentication of the second cartridge 100B has failed and restricts printing by the second cartridge 100B (S19). The controller 30 then terminates the process shown in FIG. 6. Therefore, the second cartridge 100B for destination B cannot be used in the first printer 10A for destination A.
[0055] If the first normal-state authentication information AI1A' is not stored in the second cartridge 100B (S14: NO) or if authentication of the first normal-state authentication information AI1A' (first emergency-state authentication information AI2A) fails (S16: NO), the controller 30 executes S19 to notify the user of an error, etc. The second printer 10B is equipped with first and second normal-state authentication programs PG1A', PG1B' corresponding to the first and second normal-state authentication information AI1A', AI1B'. Therefore, when the second cartridge 100B is installed, the second printer 10B executes the same process as in FIG. 6 to perform authentication using the first and second normal-state authentication information AI1A', AI1B'. Authentication of the second cartridge 100B is successful (S5: YES, S10: YES), and the second printer 10B is permitted to use (S11). On the other hand, when the first cartridge 100A is installed in the second printer 10B, authentication fails (S2: NO, S14: YES, S16: YES, S18: NO), and the second printer 10B does not permit use of the first cartridge 100A (S19).
[0056] (When the third cartridge 100C is installed) Next, an emergency procedure will be described for when the third cartridge 100C is installed in the first printer 10A. As described above, under normal circumstances, the second cartridge 100B for destination B cannot be used in the first printer 10A for destination A, and is not compatible with the first cartridge 100A for destination A. By separating the suppliers and destinations of the IC substrate 105 and other components, the security level of the cartridge 100 can be improved and the sale of counterfeit products can be curbed.
[0057] On the other hand, as shown in FIG. 7, if it becomes difficult to supply the first cartridge 100A to destination A, for example, it becomes difficult to continue using the first printer 10A. In such an emergency, for example, the manufacturer of the printer 10 manufactures a third cartridge 100C for destination B, storing the second emergency authentication information AI2B in place of the second normal authentication information AI1B' in the memory 110 of the second cartridge 100B. The manufacturer then sells the third cartridge 100C to destination A, allowing users to continue using the first printer 10A. Note that when manufacturing the third cartridge 100C, it is not necessary to delete the second normal authentication information AI1B' from the second cartridge 100B. For example, the third cartridge 100C may store the second emergency authentication information AI2B in addition to the second normal authentication information AI1B'.
[0058] Specifically, when the third cartridge 100C is installed, the controller 30 of the first printer 10A executes the process of Figure 6. The first emergency authentication information AI2A stored in the third cartridge 100C is the same as the first normal authentication information AI1A' of the second cartridge 100B. Therefore, the controller 30 makes a negative determination in S2 (S2: NO) and a positive determination in S14 and S16 (S14: YES, S16: YES), just as in the case where the second cartridge 100B is installed as described above.
[0059] In S17, the controller 30 obtains and executes the second emergency authentication program PG2B from the ROM 44, and executes processing to obtain the second emergency authentication information AI2B from the memory 110 of the third cartridge 100C. As shown in Fig. 7, the third cartridge 100C stores the second emergency authentication information AI2B, which is not normally stored. Therefore, the controller 30 makes a positive determination in S18 (S18: YES), and executes authentication using the second emergency authentication information AI2B (S21).
[0060] The second emergency authentication program PG2B is an authentication program that corresponds to the acquisition and authentication of the second emergency authentication information AI2B. Therefore, if the correct information is stored as the second emergency authentication information AI2B in the third cartridge 100C, the controller 30 succeeds in authentication using the second emergency authentication information AI2B in S22 (S22: YES) and executes S23. As in S11, the controller 30 permits use of the third cartridge 100C and ends the process shown in FIG. 6. This allows the first printer 10A at destination A to use the third cartridge 100C, in which the second emergency authentication information AI2B is stored, in the second cartridge 100B at destination B. In other words, a cartridge 100 that cannot be used under normal circumstances can be supplied as a compatible cartridge 100 in an emergency. In this way, compatibility of cartridges 100 can be expanded in an emergency, maintaining smooth distribution. If the authentication in S22 fails, the controller 30 restricts the use of the third cartridge 100C (S19).
[0061] Therefore, the second emergency authentication information AI2B can be any information that can be stored in the memory 110 in an emergency. Furthermore, the second emergency authentication program PG2B can be any program that can execute authentication based on the second emergency authentication information AI2B. For example, the second emergency authentication program PG2B and the second emergency authentication information AI2B are set and managed by the manufacturer of the printer 10. The second emergency authentication information AI2B may be an encrypted hash value calculated based on information indicating the color of the third cartridge 100C and information indicating a destination C that is not normally used. The information regarding the destination C that is not normally used may be, for example, information indicating a non-existent country (information for emergencies). Furthermore, the cartridge type information 125 stored in the memory 110 of the third cartridge 100C is changed to change the destination from destination B to destination C. In S21, the second emergency authentication program PG2B calculates a hash value based on the color information indicated in the cartridge type information 125 of the third cartridge 100C and information on the destination (destination C). Then, in S22, the second emergency authentication program PG2B may determine whether the calculated hash value matches the hash value obtained by decrypting the second emergency authentication information AI2B.
[0062] Alternatively, information about destination C may be set in the second emergency authentication program PG2B. Then, in S21, the second emergency authentication program PG2B may calculate a hash value using the information about destination C set in its own program, rather than obtaining the information about destination from the third cartridge 100C. In this case, there is no need to change the cartridge type information 125 of the third cartridge 100C from destination B.
[0063] Furthermore, authentication using the second emergency authentication information AI2B and the second emergency authentication program PG2B may be authentication that does not use at least one of the information on the color and destination of the ink 101. For example, the second emergency authentication information AI2B may be a hash value calculated based on color information of the third cartridge 100C and authentication information (information used only in emergencies) set by the manufacturer of the printer 10. Furthermore, authentication using the second emergency authentication information AI2B and the second emergency authentication program PG2B may be authentication that uses the public key cryptography (private key, public key) described above. Furthermore, unencrypted information, such as a hash value calculated from the ID information 128 of the second cartridge 100B, may be used as the second emergency authentication information AI2B.
[0064] Therefore, various authentication methods can be adopted as the authentication method for the second emergency authentication information AI2B and the second emergency authentication program PG2B. However, from the perspective of eliminating compatibility between the first cartridge 100A and the second cartridge 100B under normal circumstances and preventing unauthorized use, it is preferable that the second emergency authentication information AI2B and the second emergency authentication program PG2B are information that is not used under normal circumstances. Specifically, it is preferable that the combination of the second emergency authentication information AI2B and the second emergency authentication program PG2B be other than the combination of the second normal-time authentication information AI1B and the second normal-time authentication program PG1B used with the first cartridge 100A under normal circumstances, or the combination of the second normal-time authentication information AI1B' and the second normal-time authentication program PG1B' used with the second cartridge 100B under normal circumstances.
[0065] Furthermore, once supply of the first cartridge 100A can be resumed, the compatibility of the cartridges 100 for destinations A and B can be eliminated by halting production of the third cartridge 100C that stores the second emergency authentication information AI2B. As shown in FIG. 7, the second printer 10B for destination B stores a first emergency authentication program PG2A' that is identical to the first normal-state authentication program PG1A of the first printer 10A for destination A, and a second emergency authentication program PG2B'. Therefore, if it becomes difficult to supply the second cartridge 100B for destination B, the first cartridge 100A can be used in place of the second cartridge 100B, just as in the case of the first cartridge 100A. Specifically, a fourth cartridge (not shown) is manufactured in which the second emergency authentication information AI2B' (authentication information corresponding to the second emergency authentication program PG2B') is stored in the memory 110 of the first cartridge 100A instead of the second normal-state authentication information AI1B. As a result, the fourth cartridge can be supplied to the second printer 10B at destination B in place of the second cartridge 100B.
[0066] Furthermore, the printer 10 may be configured not to execute authentication using the first and second emergency authentication programs PG2A and PG2B during normal operation. For example, the printer 10 may be configured to have a normal mode and an emergency mode. When the emergency mode is set, the printer 10 executes the processing of FIG. 6. Furthermore, when the normal mode is set, the printer 10 may execute S7 if a negative determination is made in S2 of FIG. 6 (S2: NO). This prevents the printer 10 from acquiring the first and second emergency authentication information AI2A and AI2B during normal operation.
[0067] Furthermore, the printer 10 may not normally include the first and second emergency authentication programs PG2A and PG2B. For example, the printer 10 may download the first and second emergency authentication programs PG2A and PG2B from a server when the emergency mode is set. This allows the printer 10 to acquire the first and second emergency authentication programs PG2A and PG2B that correspond to the authentication information of the third cartridge 100C that is supplied in the event of an emergency.
[0068] The relationship between the contents of this specification and the terminology used in the above embodiment is as follows: In the above embodiment, the printer 10 is an example of a replacement part authentication device. The mounting case 27 is an example of an mounting unit. The contacts 35 are an example of an acquisition unit. The CPU 43 is an example of a computer. The ROM 44 is an example of a storage unit. The cartridge 100, the first cartridge 100A, the second cartridge 100B, and the third cartridge 100C are examples of replacement parts. The first and second normal authentication information AI1A and AI1B are examples of authentication information and normal authentication information. The ink 101 is an example of a consumable item. The second emergency authentication information AI2B is an example of authentication information and emergency authentication information. The first normal authentication information AI1A' and the first emergency authentication information AI2A are examples of authentication information and other normal authentication information. The second normal authentication information AI1B' is an example of authentication information. The control program CP is an example of a program. The first and second normal-time authentication programs PG1A and PG1B are an example of a normal-time authentication program. The second emergency-time authentication program PG2B is an example of an emergency authentication program. S1 and S6 are an example of a normal-time acquisition process and a normal-time acquisition step. S3 and S9 are an example of a normal-time authentication process and a normal-time authentication step. S11 is an example of a normal-time permission process and a normal-time permission step. S17 is an example of an emergency-time acquisition process and an emergency acquisition step. S15 is an example of an emergency authentication process and an emergency authentication step. S23 is an example of an emergency-time permission process and an emergency permission step.
[0069] According to the above-described embodiment, the following effects are achieved. (1) The printer 10 of this embodiment includes an attachment case 27 into which the cartridge 100 can be detachably attached, a contact 35 that acquires the first and second normal-state authentication information AI1A, AI1B from the memory 110 of the cartridge 100, and a controller 30. The controller 30 acquires the first and second normal-state authentication information AI1A, AI1B from the memory 110 of the attached cartridge 100 (S1, S6). If the controller 30 acquires the first and second normal-state authentication information AI1A, AI1B (S2: YES, S8: YES), it performs authentication using the first and second normal-state authentication information AI1A, AI1B (S3, S9). If the authentications of S3 and S9 are successful (S5: YES, S10: YES), the controller 30 permits use of the attached first cartridge 100A (S11). Furthermore, if the controller 30 is unable to acquire the first normal authentication information AI1A (S2: NO), it acquires second emergency authentication information AI2B, which is different from the first normal authentication information AI1A, from the memory 110 of the installed cartridge 100 (S17). If the controller 30 is able to acquire the second emergency authentication information AI2B (S18: YES), it executes authentication using the second emergency authentication information AI2B (S21). If authentication using the second emergency authentication information AI2B is successful (S22: YES), the controller 30 permits use of the installed cartridge 100 (S23).
[0070] According to this, under normal circumstances, authentication is performed using the first and second normal authentication information AI1A, AI1B, so that the cartridge 100 in which the first and second normal authentication information AI1A, AI1B are stored can be used in the printer 10. Furthermore, even in the case of a third cartridge 100C that cannot be used under normal circumstances, such as in an emergency when the memory 110 storing the first and second normal-state authentication information AI1A and AI1B is unavailable, the third cartridge 100C (second cartridge 100B) can be made usable with the first printer 10A by storing the second emergency authentication information AI2B in the memory 110. That is, compatibility of cartridges 100 can be expanded in an emergency. Compatible cartridges 100 can be supplied quickly while ensuring security, thereby preventing interruptions to the distribution of cartridges 100. Furthermore, when the memory 110 storing the first and second normal-state authentication information AI1A and AI1B becomes available, supply of compatible cartridges 100 can be stopped by stopping supply of the memory 110 (third cartridge 100C) storing the second emergency authentication information AI2B.
[0071] (2) Furthermore, the first normal-state authentication information AI1A', which is different from the first normal-state authentication information AI1A, is authentication information used for authentication in the second printer 10B, which cannot perform authentication using the second normal-state authentication information AI1B. If the controller 30 of the first printer 10A cannot acquire the first normal-state authentication information AI1A (S2: NO), the controller 30 acquires the first normal-state authentication information AI1A' (first emergency authentication information AI2A) in addition to the second emergency authentication information AI2B from the memory 110 (S13). The controller 30 performs authentication using the first normal-state authentication information AI1A' (first emergency authentication information AI2A) in addition to the second emergency authentication information AI2B (S15). If authentication of both the first and second emergency authentication information AI2A and AI2B is successful (S16: YES, S22: YES), the controller 30 permits use of the installed cartridge 100 (the third cartridge 100C in the above embodiment) (S23).
[0072] According to this, in the first printer 10A that can normally use the first cartridge 100A having the first normal authentication information AI1A, it is possible to make it impossible to use the second cartridge 100B that has other normal authentication information (first normal authentication information AI1A') used in another printer (such as the second printer 10B). The printers 10 that can use the cartridge 100 can be divided by the different normal authentication information. Then, in an emergency such as when the memory 110 storing the first normal authentication information AI1A is unavailable, a cartridge 100 for another printer 10 that cannot be used under normal circumstances can be used by storing the first normal authentication information AI1A' and the second emergency authentication information AI2B in the memory 110. That is, compatibility between a cartridge 100 having normal authentication information and a cartridge 100 having other normal authentication information can be ensured under abnormal circumstances. Furthermore, by performing authentication using two pieces of authentication information, the other normal authentication information and the emergency authentication information, the security of the compatible cartridge 100 can be improved.
[0073] (3) Furthermore, the controller 30 performs authentication using the first and second normal authentication information AI1A and AI1B, respectively, in the cartridge authentication process of Fig. 6 (S3, S9). If the authentication of the first and second normal authentication information AI1A and AI1B, respectively, is successful (S5: YES, S10: YES), the controller 30 permits use of the attached cartridge 100 (S11). According to this, by performing authentication using the two pieces of authentication information, the first and second normal-state authentication information AI1A and AI1B, it is possible to improve the security of the cartridge 100 under normal circumstances. For example, the first and second normal-state authentication information AI1A and AI1B can be set and managed by different manufacturers of the printer 10, thereby further improving the security of the cartridge 100.
[0074] (4) The ROM 44 also stores first and second normal-time authentication programs PG1A and PG1B used by the controller 30 when authenticating the first and second normal-time authentication information AI1A and AI1B, and a second emergency authentication program PG2B used when authenticating the second emergency authentication information AI2B. This allows the printer 10 to perform authentication using the second emergency authentication information AI2B in an emergency without downloading or updating the authentication program.
[0075] (5) The first normal authentication information AI1A is signature information that is a signature on the ID information 128 (the UID of the IC substrate 105). This allows authentication of the cartridge 100 by applying an electronic signature to the unique information and common information of the cartridge 100. This makes it possible to prevent the circulation of cartridges 100 with counterfeit substrate IDs.
[0076] (6) Furthermore, the second emergency authentication information AI2B (first normal authentication information AI1A') is signature information that is a signature on information about the color of the ink 101 and information about the destination of the cartridge 100. This makes it possible to authenticate the cartridge 100 by applying an electronic signature to the information about the color of the ink 101 and the destination. This makes it possible to prevent the distribution of cartridges 100 with forged ink 101 color information or forged destination information.
[0077] The present invention is not limited to the above-described embodiment, and various modifications are possible without departing from the spirit of the present invention. For example, the controller 30 performed two-stage authentication for the cartridge 100 using the first and second normal-state authentication information AI1A and AI1B, but this is not limited to this. The controller 30 may perform authentication using only one of the first normal-state authentication information AI1A or the second normal-state authentication information AI1B. Therefore, it is also possible to use only one of the authentication information of the manufacturer of the IC board 105 or the authentication information of the manufacturer of the printer 10. Alternatively, the controller 30 may perform three or more stages of authentication using three or more pieces of authentication information. In this case, as in the above embodiment, compatibility can be controlled by using different authentication programs and authentication information for normal and emergency situations. Furthermore, the first and second normal authentication information AI1A, AI1B may be information in which a signature is attached to information other than the UID (board ID), color, and destination. For example, the first and second normal authentication information AI1A, AI1B may be information in which a signature is attached to the model number of the cartridge 100. Furthermore, in the above embodiment, information on the color of the ink 101 is used as the information on the type of ink in this specification, but this is not limited to this. For example, the information on the type of ink may be information indicating the composition of the ink, such as pigment ink or dye ink. Therefore, for example, information on the composition of the ink 101 with an electronic signature may be used as the second normal authentication information AI1B. Furthermore, the first and second normal authentication information AI1A, AI1B, the first and second emergency authentication information AI2A, AI2B, etc. may be unencrypted information (such as hash values). 5 and 7 are merely examples. For example, the second emergency authentication program PG2B provided in the first printer 10A at destination A and the second emergency authentication program PG2B' provided in the second printer 10B at destination B may be the same authentication program. Therefore, the second emergency authentication information AI2B' stored in the first cartridge 100A in an emergency may be the same as the second emergency authentication information AI2B stored in the second cartridge 100B in an emergency.
[0078] 6 is merely an example. For example, the controller 30 may first perform authentication using the second normal-state authentication information AI1B (S6 to S10) and then perform authentication using the first normal-state authentication information AI1A (S1 to S5). In this case, for example, the controller 30 may execute the second normal-state authentication program PG1B in S1, and if the second normal-state authentication information AI1B cannot be acquired in S2 (S2: NO), first perform authentication using the second emergency authentication program PG2B (S17 to S22). Then, if the authentication using the second emergency authentication information AI2B is successful (S22: YES), the controller 30 may execute authentication using the first emergency authentication information AI2A (S13 to S16).
[0079] Furthermore, the configuration of the printer 10 in the above embodiment is merely an example. The replacement part authentication device in this specification is not limited to inkjet printing devices, but may also be an electrophotographic printing device. Therefore, the replacement part in this specification is not limited to cartridges containing ink, but may also be cartridges containing toner. Furthermore, the consumable material in this specification is not limited to ink, but may also be toner. In this case, the first and second normal authentication information AI1A, AI1B, etc. may be stored in a memory provided in the toner cartridge. Furthermore, the replacement part authentication device of this specification may be a device that performs printing using other printing methods such as thermal transfer printing or thermal printing, etc. Therefore, the replacement parts and consumables of this specification may also include ink ribbons, thermal paper, and components for storing them. Furthermore, the ink 101 may be stored in a container (such as a bottle) other than the cartridge 100. In this case, the container is an example of a replaceable part in this specification.
[0080] In the above embodiment, the printer 10 is used as the replacement part authentication device of this specification, but this is not limiting. The replacement part authentication device of this specification may also be a so-called "multifunction device" that has functions such as a facsimile function, a scan function, and a copy function. The printer 10 may not have the subtank 37. Furthermore, the printer 10 may not have the network IF 51. The controller 30 may also include a SoC (System on a Chip) instead of or in addition to the ASIC 47. The controller 30 may also include a plurality of ASICs 47 and CPUs 43. The controller 30 may also be configured not to include a CPU 43, but to execute programs for controlling various operations in the ASIC 47. Furthermore, the replacement part authentication device of the present application is not limited to a printing device, and other devices in which replacement parts are replaced can be used. Specifically, a sewing machine, a laser marker, a machine tool, or the like can be used as the replacement part authentication device. Thread or needles from a sewing machine can also be used as replacement parts. A laser oscillation unit of a laser marker or a head that performs laser processing can also be used as replacement parts. Tools for machine tools can also be used as replacement parts.
[0081] Furthermore, the contents of this specification are not limited to the dependent relationships set forth in the claims. [Explanation of symbols]
[0082] 10 Printer (replacement part authentication device), 10A First printer (replacement part authentication device), 10B Second printer (replacement part authentication device, other replacement part authentication device), 27 Mounting case (mounting part), 30 Controller, 35 Contact (acquisition part), 43 CPU (computer), 44 ROM (storage part), 100 Cartridge (replacement part), 100A First cartridge (replacement part), 100B Second cartridge (replacement part), 100C Third cartridge (replacement part), 101 Ink (consumable), 110 Memory, AI1A First normal-time authentication information (authentication information, normal-time authentication information), AI1A' First normal-time authentication information (authentication information, other normal-time authentication information), AI1B Second normal-time authentication information (authentication information, normal-time authentication information), AI1B' Second normal-time authentication information (authentication information), AI2B Second emergency authentication information (authentication information, emergency authentication information), AI2A First emergency authentication information (authentication information, other normal authentication information), CP control program (program), PG1A first normal authentication program (normal authentication program), PG1B second normal authentication program (normal authentication program), PG2B second emergency authentication program (emergency authentication program).
Claims
1. A mounting part that allows replacement parts to be attached and detached; an acquisition unit that acquires authentication information from a memory of the replacement part; A controller; Equipped with The controller a normal time acquisition process for acquiring normal time authentication information from the memory of the replacement part via the acquisition unit based on the fact that the replacement part is attached to the attachment unit; a normal authentication process for executing authentication using the normal authentication information when the normal authentication information is acquired from the memory by the normal acquisition process; a normal authorization process for authorizing use of the installed replacement part when authentication by the normal authentication process is successful; an emergency acquisition process for acquiring, via the acquisition unit, emergency authentication information different from the normal authentication information from the memory of the replacement part when the normal authentication information cannot be acquired in the normal acquisition process; an emergency authentication process for performing authentication using the emergency authentication information when the emergency authentication information is acquired from the memory by the emergency acquisition process; an emergency permission process for permitting use of the installed replacement part when authentication by the emergency authentication process is successful; Replacement part authentication device that performs
2. The memory includes: Other normal authentication information can be stored, The other normal authentication information is authentication information to be used for authentication in another replacement part authentication device different from the replacement part authentication device, which is not capable of performing authentication using the normal authentication information; the controller When the normal authentication information cannot be acquired in the normal acquisition process, in the emergency acquisition process, the other normal authentication information is acquired from the memory of the replacement part in addition to the emergency authentication information; In the emergency authentication process, authentication is performed using the other normal authentication information in addition to the emergency authentication information; 2. The replacement part authentication device according to claim 1, wherein, if authentication using the emergency authentication information is successful and authentication using the other normal authentication information is successful, the emergency permission process is executed and use of the installed replacement part is permitted.
3. The normal authentication information is First normal authentication information; second normal authentication information different from the first normal authentication information; Including, The controller In the normal state acquisition process, the first normal state authentication information and the second normal state authentication information are acquired from the memory of the replacement part, when the first normal time authentication information and the second normal time authentication information are acquired from the memory by the normal time acquisition process, performing authentication using each of the first normal time authentication information and the second normal time authentication information in the normal time authentication process; 3. The replacement part authentication device according to claim 1, wherein if authentication of the first normal authentication information and the second normal authentication information is successful, the normal authorization process is executed and use of the installed replacement part is permitted.
4. Further comprising a storage unit, The storage unit includes: a normal authentication program used by the controller when authenticating the normal authentication information; an emergency authentication program used by the controller when authenticating the emergency authentication information; 3. The replacement part authentication device according to claim 1, wherein both of the above are stored.
5. The normal authentication information is 3. The replacement part authentication device according to claim 1, wherein the signature information is a signature of the information relating to the replacement part.
6. The replacement part is storing consumable materials consumed by the replacement part authentication device; The emergency authentication information is 3. The replacement part authentication device according to claim 1, wherein the signature information is a signature of the information on the type of the consumable product and the information on the destination of the replacement part.
7. A mounting part that allows replacement parts to be attached and detached; an acquisition unit that acquires authentication information from a memory of the replacement part; An authentication method in a replacement part authentication device comprising: a normal time acquisition step of acquiring normal time authentication information from the memory of the replacement part via the acquisition unit based on the fact that the replacement part is attached to the attachment unit; a normal authentication step of performing authentication using the normal authentication information when the normal authentication information is acquired from the memory by the normal acquisition step; a normal authorization step of authorizing use of the installed replacement part when authentication by the normal authentication step is successful; an emergency acquisition step of acquiring, when the normal authentication information cannot be acquired in the normal acquisition step, emergency authentication information different from the normal authentication information from the memory of the replacement part via the acquisition unit; an emergency authentication step of performing authentication using the emergency authentication information when the emergency authentication information is acquired from the memory by the emergency acquisition step; an emergency permission step of permitting use of the installed replacement part when authentication by the emergency authentication step is successful; Authentication methods, including:
8. A mounting part that allows replacement parts to be attached and detached; an acquisition unit that acquires authentication information from a memory of the replacement part; A program executed by a computer of a replacement part authentication device comprising: The computer, a normal time acquisition process for acquiring normal time authentication information from the memory of the replacement part via the acquisition unit based on the fact that the replacement part is attached to the attachment unit; a normal authentication process for executing authentication using the normal authentication information when the normal authentication information is acquired from the memory by the normal acquisition process; a normal authorization process for authorizing use of the installed replacement part when authentication by the normal authentication process is successful; an emergency acquisition process for acquiring, via the acquisition unit, emergency authentication information different from the normal authentication information from the memory of the replacement part when the normal authentication information cannot be acquired in the normal acquisition process; an emergency authentication process for performing authentication using the emergency authentication information when the emergency authentication information is acquired from the memory by the emergency acquisition process; an emergency permission process for permitting use of the installed replacement part when authentication by the emergency authentication process is successful; A program that executes the following.
Citation Information
Patent Citations
printing material cartridge
JP2018505444A