Device attachable to and detachable from image forming apparatus, and method and apparatus for remanufacturing device

The solution of using a detachable device with a memory and authentication mechanism for image forming apparatuses addresses the risk of improper operation due to illegitimate data writing in remanufactured devices, ensuring proper functionality by verifying and authorizing data authenticity during remanufacturing.

JP2026028630APending Publication Date: 2026-02-20CANON KK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024131205
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2026-02-20

AI Technical Summary

Technical Problem

Existing remanufacturing technologies for image forming devices lack a mechanism to ensure the legitimacy of data writing, leading to a risk of improper operation when reused devices are installed in image forming apparatuses.

Method used

A detachable device for image forming apparatuses equipped with a memory having separate read-only and rewritable storage areas, along with a digital signature and authentication mechanism to verify and authorize data writing, ensuring the legitimacy of information stored during remanufacturing.

Benefits of technology

This approach significantly reduces the risk of improper operation of image forming apparatuses when using remanufactured devices by verifying the authenticity of data written to the device memory, thus ensuring proper functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026028630000001_ABST
    Figure 2026028630000001_ABST
Patent Text Reader

Abstract

To reduce the possibility that reuse of a device after remanufacture causes an inappropriate operation of an image forming apparatus.SOLUTION: A device attachable to and detachable from an image forming apparatus includes a memory having a read-only first storage area and a rewritable second storage area, a control means, and a connection part connected to an information processing apparatus when the device is remanufactured. The first storage area stores first information unique to the device, and the second storage area stores second information to be read and used by the image forming apparatus and a digital signature generated based on the first and second information. The control unit receives the second information, the digital signature, and authentication information generated based on at least the second information from the information processing apparatus when the device is remanufactured, and permits writing of the second information and the digital signature in the second storage area when verification of the second information based on the authentication information is successful.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a device that is detachable from an image forming apparatus, and to a method and apparatus for remanufacturing the device. [Background technology]

[0002] Image forming devices such as copiers, printers, facsimile receivers, and multifunction devices form images on sheets using developers such as toner or ink, and consumable components such as photosensitive drums. These consumable components are often housed in devices that are detachable from the image forming device. When the developer runs out or the remaining life of the components expires, a user installs a new device in the image forming device. Patent Document 1 discloses a cartridge-type device (e.g., a process cartridge) that is permanently installed in the image forming device, and a replenishment-type device (e.g., a replenishment pack) that is temporarily installed in the image forming device when replenishing the developer.

[0003] In recent years, with growing environmental awareness, efforts are being made to design used devices in advance so that they can be reused in image forming devices rather than being discarded. For example, a company that remanufactures devices for reuse collects used devices and performs tasks such as replenishing developers and replacing worn parts. Patent Document 2 discloses a technology in which a device authenticated by a cloud service writes data related to a remanufactured device into the device's memory in order to ensure proper operation of the image forming device when it is reused. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2023-106130 [Patent Document 2] International Publication No. 2022 / 173444 Summary of the Invention [Problem to be solved by the invention]

[0005] However, in the technology of Patent Document 2, the device itself does not have the function to guarantee the legitimacy of data writing, so there remains a risk that reusing the device after remanufacturing could cause the image forming apparatus to operate improperly.

[0006] In view of the above, the present invention aims to further reduce the risk that reuse of a remanufactured device will cause an image forming apparatus to operate improperly. [Means for solving the problem]

[0007] According to one aspect, there is provided a device detachable from an image forming apparatus, the device including: a memory having a first read-only storage area and a rewritable second storage area; control means; and a connection unit that is connected to an information processing apparatus when the device is remanufactured, the first storage area being an area for storing first information specific to the device; the second storage area being an area for storing second information to be read and used by the image forming apparatus, and a digital signature generated based on the first information and the second information; the control means, when the device is remanufactured, receiving the second information, the digital signature, and authentication information generated based on at least the second information from the information processing apparatus via the connection unit; and authorizing writing of the second information and the digital signature to the second storage area if verification of the second information based on the authentication information is successful. Corresponding methods and information processing apparatuses for remanufacturing the device are also provided. [Effects of the Invention]

[0008] According to the present invention, it is possible to further reduce the risk that reuse of a remanufactured device will cause an image forming apparatus to operate improperly. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a schematic diagram illustrating a general configuration of a cartridge authentication system according to an embodiment. [Figure 2] FIG. 2 is a schematic cross-sectional view showing an example of the internal physical configuration of the cartridge. [Figure 3] FIG. 2 is a schematic perspective view showing an example of the appearance of a cartridge memory. [Figure 4] FIG. 2 is a schematic cross-sectional view showing an example of the internal physical configuration of a printer in which a cartridge is installed. [Figure 5] FIG. 10 is a schematic perspective view showing an example of the appearance of a connection interface of a remanufacturing device. [Figure 6] FIG. 3 is an explanatory diagram illustrating an example of the configuration of a storage area of ​​a cartridge memory. [Figure 7] FIG. 2 is a block diagram showing the connection relationship between a cartridge, a remanufacturing device, and a management server when the cartridge is remanufactured, and an example of the configuration of each device. [Figure 8] FIG. 10 is a sequence diagram showing an example of the flow of a rewriting process executed when a cartridge is remanufactured. [Figure 9] FIG. 2 is a block diagram showing an example of the configuration of control functions of a printer in which a cartridge is installed. [Figure 10] FIG. 10 is a sequence diagram showing an example of the flow of cartridge authentication processing executed by the printer. [Figure 11] FIG. 4 is a sequence diagram showing an example of the flow of a job control process executed by a printer. [Figure 12] FIG. 10 is an explanatory diagram illustrating an example of the configuration of a storage area of ​​a cartridge memory according to a modified example. [Figure 13] FIG. 10 is a sequence diagram showing an example of the flow of a rewriting process according to a modified example. [Figure 14] FIG. 10 is a sequence diagram showing an example of the flow of a cartridge authentication process according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.

[0011] <1. System Overview> <1-1. Overall structure> 1 is a schematic diagram showing the overall configuration of a cartridge authentication system 1 according to one embodiment. Referring to FIG. 1, the cartridge authentication system 1 includes a cartridge 10, a printer 100, a remanufacturing device 200, and a management server 300.

[0012] The cartridge 10 is a device that can be attached to and detached from the printer 100. The printer 100 operates with the cartridge 10 attached. In this embodiment, an example in which the cartridge 10 is a process cartridge will be mainly described. In other embodiments, the cartridge 10 may be another type of cartridge, such as a toner cartridge or an ink cartridge. Note that the technology disclosed herein can also be applied to other types of devices, such as a refill pack that is temporarily attached to an image forming apparatus to replenish developer.

[0013] The printer 100 is an image forming device installed in the user environment E1. In this embodiment, an example will be mainly described in which the printer 100 is a laser printer that forms an image on a sheet using an electrophotographic method. In other embodiments, the printer 100 may be another type of printer, such as an inkjet printer. The printer 100 may be a monochrome printer or a color printer. Note that the technology disclosed herein can also be applied to other types of image forming devices, such as a copier or a multifunction peripheral.

[0014] The remanufacturing device 200 is a device that writes information to the cartridge 10 when the cartridge 10 is remanufactured. The remanufacturing device 200 is typically used by a remanufacturer that performs the work of remanufacturing the cartridge 10. The remanufacturer may be the same as or different from the manufacturer that produces the printer 100. The remanufacturing device 200 may be a general-purpose information processing device such as a PC (Personal Computer), or may be a device dedicated to writing information to the cartridge 10. The remanufacturing device 200 has a connection interface, described below, for connecting to the cartridge 10. In addition, the remanufacturing device 200 is connected to the network N1.

[0015] The network N1 may be the Internet, a cloud network, or a private network, or any combination thereof.

[0016] The management server 300 is a server device for managing the remanufacturing of the cartridge 10. Typically, the management server 300 is operated by the manufacturer of the printer 100 (or a third party commissioned by the manufacturer). For example, the management server 300 may be implemented as a web server, a cloud server, or an application server using a high-performance information processing device. The management server 300 is connected to a network N1. The remanufacturing device 200 can communicate with the management server 300 via the network N1.

[0017] <1-2. Cartridge Overview> FIG. 2 is a schematic cross-sectional view showing an example of the internal physical configuration of the cartridge 10. Referring to FIG. 2, the cartridge 10 includes a photoconductor 2, a charging roller 3, a toner container 5, a developing roller 6, a cleaner 7, and a cartridge memory 20. The photoconductor 2, the charging roller 3, the developing roller 6, and the cleaner 7 are components driven by the printer 100 during the image forming operation of the printer 100. The toner container 5 contains toner T as a developer. The toner T is supplied to the printer 100 when the printer 100 forms a toner image. The cartridge memory 20 stores identification information for the cartridge 10 and characteristic information that represents the characteristics of these components involved in the image forming operation of the printer 100. The configuration of the information stored in the cartridge memory 20 will be described in further detail below.

[0018] Fig. 3 is a schematic perspective view showing an example of the appearance of the cartridge memory 20. Referring to Fig. 3, the cartridge memory 20 has a pair of connection terminals 22. When the cartridge 10 is installed in the printer 100, the cartridge memory 20 is electrically connected to the printer 100 via the connection terminals 22.

[0019] <1-3. Printer Overview> 4 is a schematic cross-sectional view showing an example of the internal physical configuration of the printer 100 equipped with the cartridge 10. Referring to FIG. 4, the printer 100 includes an exposure unit 4, a transfer roller 8, a fixing unit 9, a cassette 11, a conveying path 12, an ejection tray 15, a controller 110, a connection terminal 119, and an engine control unit 120.

[0020] The photoreceptor 2 is an image carrier, and is driven to rotate in the direction of arrow A during image formation. A charging voltage is applied to the charging roller 3, which uniformly charges the surface of the photoreceptor 2. The exposure device 4 exposes the surface of the photoreceptor 2 to laser light in accordance with input image data from the engine control unit 120, thereby forming an electrostatic latent image on the surface of the photoreceptor 2. A developing voltage is applied to the developing roller 6, which develops the electrostatic latent image by supplying toner T contained in a toner container 5 to the photoreceptor 2, thereby forming a toner image on the surface of the photoreceptor 2.

[0021] Cassette 11 contains a stack of sheets. During image formation, sheets P are fed one by one from the stack of sheets in cassette 11 to conveyance path 12. Sheet P is conveyed along conveyance path 12 by multiple conveyance rollers and reaches a transfer position where transfer roller 8 is disposed. A transfer voltage is applied to transfer roller 8, which transfers the toner image formed on the surface of photoreceptor 2 to sheet P. Cleaner 7 removes toner remaining on the surface of photoreceptor 2. Fixer 9 heats and presses sheet P to fix the toner image to sheet P. After passing through fixer 9, sheet P is discharged to discharge tray 15.

[0022] The controller 110 cooperates with the engine control unit 120 to control the overall operation of the image forming apparatus 100. The engine control unit 120 is connected to the cartridge 10 attached to the printer 100 via a connection terminal 119. The engine control unit 120 controls the image forming operation of the printer 100 based on the characteristics represented by the characteristic information read from the cartridge 10. For example, image forming conditions such as charging voltage, developing voltage, transfer voltage, and process speed may be determined based on member characteristic information described below. Furthermore, the remaining amount of toner may be determined based on toner characteristic information described below. The configurations of the controller 110 and the engine control unit 120 will be described in more detail below.

[0023] In this embodiment, an example in which the cartridge 10 is connected to the engine control unit 120 via a connection terminal by wire will be mainly described, but in other embodiments, the cartridge 10 may be connected to the engine control unit 120 wirelessly, for example, via an antenna. The same applies to the connection between the cartridge 10 and the remanufacturing device 200.

[0024] <1-4. Remanufacturing of cartridges> As the printer 100 repeats image formation operations, the toner in the cartridge 10 eventually runs out, or the components of the cartridge 10 wear out and reach the end of their remaining life (for example, the rollers wear out). The user removes the cartridge 10 from the printer 100 and installs a new cartridge into the printer 100. Used cartridges 10 are collected by remanufacturers. In Figure 1, cartridges 10 collected by remanufacturers are shown by dashed lines.

[0025] The remanufacturer performs remanufacturing operations, such as refilling the cartridge 10 with toner and replacing worn components. The remanufacturer also connects the connection interface 201 of the remanufacturing device 200 to the cartridge 10. FIG. 5 is a schematic perspective view showing an example of the appearance of the connection interface 201. Referring to FIG. 5, the connection interface 201 has a pair of connection terminals 202 disposed in a recess 203 capable of receiving the cartridge memory 20. When the cartridge memory 20 is set in the recess 203, the connection terminals 202 come into electrical contact with the connection terminals 22 of the cartridge memory 20, enabling communication between the remanufacturing device 200 and the cartridge memory 20.

[0026] The remanufacturing device 200 acquires information to be written to the cartridge memory 20, such as identification information of the remanufactured cartridge 10 and characteristic information that indicates the characteristics of the components of the remanufactured cartridge 10, based on input from, for example, the remanufacturer. The remanufacturing device 200 requests the management server 300 to generate a digital signature for the information to be written to the cartridge memory 20, and writes the information to the cartridge memory 20 together with the digital signature provided by the management server 300.

[0027] When the remanufactured cartridge 10 is installed in the printer 100, the printer 100 reads the identification information and characteristic information that were rewritten during remanufacturing, along with the digital signature, from the cartridge memory 20. If the authenticity of the read information is successfully verified based on the digital signature, the printer 100 can perform image formation operations using the cartridge 10 under image formation conditions appropriate for the characteristics after remanufacturing. Naturally, the printer in which the remanufactured cartridge 10 is installed may actually be different from the printer in which the cartridge 10 was installed before remanufacturing.

[0028] <1-5. Cartridge memory configuration example> 6 is an explanatory diagram illustrating an example of the configuration of a storage area of ​​the cartridge memory 20 according to one embodiment. The cartridge memory 20 may be any type of non-volatile memory, such as an EEPROM (Electrically Erasable Programmable Read-Only Memory). Referring to FIG. 6, the cartridge memory 20 has a first storage area 31, a second storage area 33, and a common storage area 36.

[0029] The first storage area 31 is an area where first information 32 specific to a new cartridge 10 is stored. In the following description, the first information 32 is also referred to as initial information. In the example of FIG. 6, the initial information 32 includes cartridge identification information (ID), toner characteristic information, and component characteristic information. The cartridge ID is information (first identification information, ID1) that identifies an individual new cartridge 10 (i.e., before remanufacturing). The cartridge ID may be in any format, such as a combination of the manufacturing date and a serial number (which is reset each time the date changes). The toner characteristic information is information that represents the characteristics of the toner contained in the cartridge 10. For example, the toner characteristic information may include a parameter (e.g., "Black") that represents the color component of the toner contained in the cartridge 10. The toner characteristic information may also include a parameter that represents the amount of toner refilled into the cartridge 10 during manufacturing (e.g., in units of sheets, such as "1000 sheets"). The component characteristic information is information that represents the characteristics of the components that make up the cartridge 10. For example, the component characteristic information may include parameters that represent one or more of an optimal charging voltage, a developing voltage, and a transfer voltage. Note that part of the cartridge ID may represent a toner characteristic or a component characteristic (for example, an alphabet at a specific position may represent the color of the toner), and in that case, the initial information does not need to include independent characteristic information.

[0030] The second memory area 33 is an area for storing second information 34, which is the same type of information as the first information 32, but is rewritten during remanufacturing. In this embodiment, the second information 34 written to the second memory area 33 during the initial manufacturing of the cartridge 10 is a copy of the first information 32. When the cartridge 10 is remanufactured, the second information 34 is rewritten by the remanufacturing device 200 to information unique to the remanufactured cartridge 10. In the following description, the second information 34 will also be referred to as remanufacturing information. The remanufacturing information 34 may include a cartridge ID (second identification information, ID2) that identifies an individual cartridge 10 after remanufacturing, toner characteristic information that indicates the characteristics of the toner after remanufacturing, and component characteristic information that indicates the characteristics of the components after remanufacturing.

[0031] The second memory area 33 further stores a digital signature 35. The digital signature 35 is used by the printer 100 to verify the authenticity of the second information 34 when the printer 100 reads the second information 34 from the cartridge memory 20 and uses the second information 34. The digital signature 35 is generated by the management server 300 based on the first information 32 and the second information 34, as will be described later.

[0032] The common storage area 36 is an area where common information 37 that can be freely updated before and after remanufacturing is stored. In the example of Fig. 6, the common information 37 includes operation history information. The operation history information may include, for example, a parameter that indicates the cumulative number of sheets printed as a result of the execution of an image forming job. This parameter is initialized to zero at the time of initial manufacturing and remanufacturing, and can be counted up each time the printer 100 executes an image forming job.

[0033] In FIG. 6, alphabetical labels shown to the right of the first storage area 31, the second storage area 33, and the common storage area 36 indicate whether or not it is possible to read and write information from and to each storage area.

[0034] After the first information 32 is written in the first storage area 31 during initial manufacturing, only reading is permitted in the first storage area 31. Therefore, the first storage area 31 is labeled "RO," which means read-only.

[0035] In this embodiment, the second information 34 and digital signature 35 in the second storage area 33 can be rewritten under certain conditions during remanufacturing. The condition is that authentication information generated based on at least the second information 34 is received together with the second information 34 and the digital signature 35, and the cartridge 10 successfully verifies the second information 34 based on the authentication information. By providing the cartridge 10 with a function for ensuring the validity of the information to be written to the cartridge memory 20, the risk of the reusing of a remanufactured cartridge 10 causing improper operation of the printer 100 is reduced. Therefore, the second storage area 33 is labeled "RWM," indicating that the second information 34 can be rewritten under certain conditions. Conditional rewriting of the second information 34 will be described in more detail below.

[0036] The information in the shared memory area 36 can be rewritten at any time, including during image formation and remanufacturing. Therefore, the shared memory area 36 is labeled "RW," which means that the area is rewritable.

[0037] <2. Rewriting cartridge memory> FIG. 7 shows an example of the connection relationship between the cartridge 10, the remanufacturing device 200, and the management server 300 when the cartridge 10 is remanufactured by a remanufacturer, and the configuration of each device.

[0038] <2-1. Cartridge configuration> The cartridge 10 includes a cartridge memory 20, a connection terminal 22, an access control unit 24, and an encryption processing unit 26. The cartridge memory 20 has at least the read-only first memory area 31 and the rewritable second memory area 33 described with reference to Figure 6. The connection terminal 22 functions as a connection unit that is connected to a remanufacturing device 200 when the cartridge 10 is remanufactured.

[0039] The access control unit 24 is a control means that controls reading of information from and writing of information to the cartridge memory 20 based on commands received from the remanufacturing apparatus 200. For example, when the access control unit 24 receives a read command from the remanufacturing apparatus 200 that specifies a specific address in the cartridge memory 20, it reads the information stored at the specified address and transmits the read information to the remanufacturing apparatus 200 via the connection terminal 22. Furthermore, when the access control unit 24 receives a write command from the remanufacturing apparatus 200 that specifies a specific address (write destination address), it performs different processing depending on which storage area in the cartridge memory 20 the write destination address belongs to.

[0040] If the write destination address belongs to the first storage area 31, the access control unit 24 refuses to write information to that write destination address. If the write destination address belongs to the second storage area 33, the access control unit 24 receives, together with the write command, the information to be written to the write destination address, as well as authentication information for verifying the information. The access control unit 24 then causes the encryption processing unit 26 to verify the information based on the received authentication information, and if the verification is successful, writes the received information to the specified write destination address (rewrites the information stored in the write destination address). If the write destination address belongs to the common storage area 36, ​​the access control unit 24 writes the information included in the write command to that write destination address.

[0041] The cryptographic processing unit 26 is a tamper-resistant cryptographic processing means that includes a processing circuit that performs various cryptographic processes related to the use and remanufacturing of the cartridge 10, and a memory circuit that stores the cryptographic keys required for the cryptographic processes.

[0042] In this embodiment, the authentication that is a condition for permitting writing of information to the second storage area 33 may be authentication based on a message authentication code (MAC). Any known algorithm, such as CBC (Cipher Block Chaining)-MAC, CMAC (Cipher-based MAC), or PMAC (Parallelizable MAC), may be used as the algorithm for MAC generation and verification.

[0043] When manufacturing the cartridge 10, the manufacturer of the cartridge 10 generates first identification information (ID1) for identifying the cartridge 10 and a master key (K m ) based on the derived key (K d ) is derived: K d =F1(K m ,ID1) (1) In equation (1), the function F1() may be any one-way function. For example, the function F1() may be m and ID1 concatenation (K m The function F1() may be a cryptographic hash function that outputs a hash value of the key value K. For example, the cryptographic hash function may be SHA256, which is defined by the National Institute of Standards and Technology (NIST) as FIPS PUB 180-4. m The encryption algorithm may be a function representing an algorithm for encrypting ID1 using the secret key AES (Advanced Encryption Standard), which is a type of block cipher defined by NIST as FIPS PUB 197.

[0044] derived key K d The master key K used to derive m is managed secretly by the management server 300. On the other hand, the derived key K dis stored as an encryption key 38 in the encryption processing unit 26 of the cartridge 10. When the encryption processing unit 26 receives a request from the access control unit 24 to verify a message based on the MAC (for example, information to be written to the second storage area 33), the encryption processing unit 26 derives a derived key K from the input message. d The cryptographic processing unit 26 compares the verification MAC derived using the above with the input MAC. If the two MACs match, the cryptographic processing unit 26 outputs a verification result to the access control unit 24 indicating that the message is authentic (i.e., verification successful). On the other hand, if the two MACs do not match, the cryptographic processing unit 26 outputs a verification result to the access control unit 24 indicating that the message is not authentic (i.e., verification failed).

[0045] When the access control unit 24 requests the encryption processing unit 26 to generate a MAC, the encryption processing unit 26 derives a derived key K from the input message. d The MAC derived using the above is output to the access control unit 24. For example, the MAC generated by the encryption processing unit 26 can be used in the challenge-response authentication that is executed when the cartridge 10 is attached to the printer 100, which will be described later.

[0046] <2-2. Configuration of remanufacturing equipment> The remanufacturing device 200 includes a connection terminal 202, a central processing unit (CPU) 211, a memory 212, a communication unit 213, an input unit 214, and a display unit 215. The connection terminal 202 functions as a connection unit that accepts connection of the cartridge 10 when the cartridge 10 is remanufactured.

[0047] The CPU 211 is a control means that executes a computer program to control the overall operation of the remanufacturing apparatus 200. The memory 212 stores the computer program executed by the CPU 211. The communication unit 213 is a communication interface that enables the remanufacturing apparatus 200 to communicate with the management server 300 via the network N1. The input unit 214 is an input device that enables the remanufacturing apparatus 200 to accept user input. The display unit 215 is a display that displays information to the user of the remanufacturing apparatus.

[0048] In this embodiment, the CPU 211 functions as a rewrite processing unit 221 that rewrites the information stored in the cartridge memory 20 when the cartridge 10 is remanufactured. The flow of the rewrite processing executed by the rewrite processing unit 221 will be described in more detail later.

[0049] <2-3. Management Server Configuration> The management server 300 includes a CPU 311 , a memory 312 , a communication unit 313 , and a key management unit 315 .

[0050] The CPU 311 is a control means that executes computer programs to control the overall operation of the management server 300. The memory 312 stores the computer programs executed by the CPU 311. The communication unit 313 is a communication interface that enables the management server 300 to communicate with other devices via the network N1. The key management unit 315 manages encryption keys required to ensure proper use of the printer 100 and cartridge 10 in the cartridge authentication system 1. In the example of FIG. 7, the key management unit 315 manages a derived key K when the cartridge 10 is manufactured. d The master key K used to derive m , and the private key K used to generate the digital signature s Although not shown in Fig. 7, the management server 300 may further include an input device for receiving user input and a display for displaying information.

[0051] In this embodiment, when the cartridge 10 is remanufactured, the CPU 311 functions as a signature generation unit 321 that generates a digital signature in response to a request from the remanufacturing apparatus 200, and a MAC generation unit 322 that generates a MAC for a specified message. The roles of the signature generation unit 321 and the MAC generation unit 322 in the rewriting process will be further explained later.

[0052] <2-4. Rewrite process> Fig. 8 is a sequence diagram showing an example of the flow of the rewriting process executed when remanufacturing the cartridge 10. The rewriting process shown in Fig. 8 mainly involves the cartridge 10, remanufacturing device 200, and management server 300. In the following explanation, processing steps will be abbreviated as 'S'.

[0053] Prior to the rewriting process, in S101, the remanufacturer performs remanufacturing operations such as refilling toner into the cartridge 10 and replacing worn components. Once the operations are completed, in S102, the remanufacturer connects the cartridge 10 to the connection interface 201 of the remanufacturing device 200. Thereafter, the CPU 211 of the remanufacturing device 200 starts a computer program for rewriting, and the rewriting processing unit 221 starts the rewriting process.

[0054] In S111, the rewrite processing unit 221 transmits a read command to the cartridge 10 to read the initial information stored in the first memory area 31 of the cartridge memory 20. In S112, the access control unit 24 of the cartridge 10 transmits the initial information read from the first memory area 31 to the remanufacturing apparatus 200. The initial information includes, for example, first identification information (ID1).

[0055] Next, in S113, the rewrite processing unit 221 transmits an information registration request including the first identification information received from the cartridge 10 to the management server 300. In S114, the MAC generation unit 322 of the management server 300 registers the first identification information received from the remanufacturing apparatus 200 in the memory 312 for use in later MAC generation. In S115, the MAC generation unit 322 notifies the remanufacturing apparatus 200 that registration of the first identification information has been completed.

[0056] Next, in S116, the rewriting processing unit 221 acquires remanufacturing information about the remanufactured cartridge 10. For example, the remanufacturing information includes second identification information (ID2) determined by the remanufacturer, and characteristic information that indicates the characteristics of the toner and components of the remanufactured cartridge 10. The remanufacturing information may be received, for example, via a user interface provided by the input unit 214 and display unit 215 of the remanufacturing device 200, or may be received (for example, in the form of a data file) from some external device via the communication unit 213.

[0057] Next, in S121, the rewrite processing unit 221 transmits a signature generation request for generating a digital signature based on the initial information and remanufacturing information to the management server 300. In S122, the signature generation unit 321 of the management server 300 generates a digital signature based on the secret key K stored in the key management unit 315 in response to the signature generation request. s The digital signature SIG1 based on the initial information and remanufacturing information is generated using the above. The digital signature may be generated according to any known signature generation method, such as the DSA (Digital Signature Algorithm) method or the Elliptic Curve DSA (ECDSA) method. In S123, the signature generation unit 321 transmits the generated digital signature SIG1 to the remanufacturing device 200.

[0058] Next, in S124, the rewrite processing unit 221 generates a write data set W1 for writing the remanufacturing information to the cartridge memory 20. For example, the write data set W1 may include one or more of the following: ·Remanufacturing information - Secondary identification information - Toner characteristic information -Material characteristics information Digital Signature Destination address

[0059] Next, in S125, the rewrite processing unit 221 transmits a MAC generation request to the management server 300 to request generation of a message authentication code using the write data set W1 as a message. In S126, the MAC generation unit 322 generates a MAC using the master key K mand a derived key K from the first identification information ID1 registered in S114 according to equation (1). d (first derived key) and derive the derived key K d In step S127, the MAC generator 322 transmits the generated message authentication code C1 to the remanufacturing apparatus 200.

[0060] Next, in S128, the rewrite processing unit 221 transmits a write command including the write data set W1 and the message authentication code C1 to the cartridge 10. In S129, the access control unit 24 of the cartridge 10 causes the encryption processing unit 26 to verify the write data set W1 based on the message authentication code C1 received from the remanufacturing device 200. The encryption processing unit 26 verifies the write data set W1 based on the message authentication code C1 received from the remanufacturing device 200. d Using the (second derived key) 38, a message authentication code C for verification is obtained from the write data set W1. v The derived code C v Here, we check whether the message authentication code C1 matches the message authentication code C1. v Since the values ​​match, the verification is deemed successful. In response to the successful verification, in S130 the access control unit 24 writes the remanufacturing information and digital signature SIG1 to the specified write destination address in the cartridge memory 20. Then, in S131, the access control unit 24 notifies the remanufacturing device 200 of the completion of writing.

[0061] 8 may be executed in a different order from that shown in the figure. The same applies to the processing steps shown in other sequence diagrams. For example, the acquisition of remanufacturing information in S116 may be performed at any time before the request for signature generation to the management server 300 in S121.

[0062] In the above-described rewriting process, when remanufacturing cartridge 10, a digital signature generated based not only on the remanufacturing information rewritten in second memory area 33 but also on the initial information in read-only first memory area 31 is written to second memory area 33. The initial information is information unique to cartridge 10 that is determined by the manufacturer of cartridge 10 at the time of initial manufacture and written to first memory area 31. Therefore, the digital signature used to verify the remanufacturing information when cartridge 10 is installed in printer 100 and used will be different for each cartridge 10. This makes it possible to prevent unauthorized remanufacturing of cartridges 10 through copying or analysis of the remanufacturing information and digital signature between different cartridges.

[0063] Furthermore, in the above-described rewriting process, the cartridge 10 receives from the remanufacturing device 200 authentication information generated based on at least the remanufacturing information, along with the remanufacturing information and the digital signature. Then, if the remanufacturing information based on the received authentication information is successfully verified, the access control unit 24 of the cartridge 10 permits writing of the remanufacturing information and the digital signature to the second memory area 33. Thus, by providing the cartridge itself with a function to ensure the legitimacy of data writing, it becomes difficult for a malicious third party to write inappropriate data to the cartridge memory 20. This reduces the risk that reuse of a remanufactured cartridge 10 will cause the printer 100 to operate improperly.

[0064] The authentication information is a master key K that is different from the cryptographic keys (private key and public key) used to generate and verify the digital signature. m Derived key K derived from d These master keys K m and the derived key K d Since the encryption key required to generate the authentication information is not stored in the printer 100, the encryption key required to generate the authentication information will not be leaked even if a third party analyzes the printer 100. In other words, only the remanufacturing device 200 that has the proper authority to communicate with the management server 300 can write the remanufacturing information to the cartridge 10.

[0065] Furthermore, if the authentication information is generated based on the digital signature of the remanufacturing information in addition to the remanufacturing information, it becomes even more difficult for a third party who does not have the private key for generating the digital signature to write inappropriate data to the cartridge memory 20. If the authentication information is generated based on the write destination address of the remanufacturing information as well, the cartridge memory 20 can be protected from attacks that attempt to write data to inappropriate storage areas by tampering with the write destination address of a write command.

[0066] <2-5. Example of memory contents before and after rewriting> Table 1 below shows examples of information stored in cartridge memory 20 before and after rewriting during remanufacturing. The leftmost column in Table 1 shows examples of address numbers for the predetermined addresses where each piece of information is written. The second column from the left shows the parameter name for each piece of information. The third and fourth columns from the left show examples of the values ​​of each parameter before and after rewriting.

[0067] [Table 1]

[0068] In the example of Table 1, the combination of "manufacturing date" and "serial number" identifies an individual cartridge 10. That is, individual cartridges manufactured on the same manufacturing date are distinguished by their serial numbers, and the serial number can be reset when the date changes. Such identification information can be used for troubleshooting when a problem occurs when using the cartridge 10.

[0069] "Toner color" and "yield of prints" are examples of toner characteristic information. If the cartridge 10 contains only one color of toner, "toner color" refers to that one color. If a cartridge containing four colors of toner (e.g., yellow, magenta, cyan, and black) is used to form a color image, "toner color" may refer to a combination of those four colors. "Yield of prints" may be determined according to the amount of toner refilled into the cartridge 10. "Yield of prints" may also be used to estimate the amount of remaining toner after the cartridge 10 has started to be used. "Developing voltage" is an example of component characteristic information.

[0070] Before remanufacturing, copies of the first identification information, toner characteristic information, and component characteristic information stored in the first storage area 31 are stored in the second storage area 33. During remanufacturing, the information in the first storage area 31 is not updated, and the information in the second storage area 33 is rewritten with information for the remanufactured cartridge 10. For example, the "number of printable pages" is rewritten from 1,000 to 800 because the amount of replenished toner is different from the initial amount. The "developing voltage" is also rewritten, for example, from 280 V to 300 V in conjunction with the replacement of the developing roller 6.

[0071] The "number of printed sheets" stored in the common memory area 36 indicates 980 sheets, which is close to the value of the "number of printable sheets" before remanufacturing, but is reset to zero at the time of remanufacturing. When reuse of the remanufactured cartridge 10 begins, the "number of printed sheets" can be counted up again.

[0072] In this way, if a copy of the initial information is stored in the second storage area 33 when the cartridge 10 is manufactured, the printer 100 in which this cartridge 10 is installed does not need to change the address to be referenced depending on the remanufactured status (whether it is new or not) of the cartridge 10. In other words, the printer 100 can always read the identification information and characteristic information appropriate to the status of the cartridge 10 from the same address in the second storage area 33, regardless of whether the cartridge 10 is new or remanufactured. This reduces the complexity of implementing the control functions of the printer 100.

[0073] Note that the information configuration, parameter names, and values ​​shown in Table 1 are merely examples for illustrative purposes. Some of the above parameters may be omitted, and additional parameters may be employed. For example, the identification information for identifying the cartridge may include an identifier for identifying the cartridge manufacturer or remanufacturer. The toner identification information may also include a remaining toner warning threshold for warning the user that the toner is low.

[0074] <3. Use of cartridges in printers> FIG. 9 shows an example of a configuration related to the control functions of the printer 100 in which the cartridge 10 is installed.

[0075] <3-1. Printer configuration> In the example of FIG. 9, the printer 100 includes, in addition to the cartridge 10, a controller 110, a communication unit 113, an operation unit 114, and an engine control unit 120.

[0076] The controller 110 includes, for example, a CPU and a memory, and controls the overall operation of the printer 100 by executing a computer program stored in the memory. The communication unit 113 is a communication interface that enables the printer 100 to communicate with other devices via the network N1. The operation unit 114 provides a user interface to a user of the printer 100. The operation unit 114 may include, for example, input devices such as a touch panel, buttons, and switches, and output devices such as a display and speaker. The controller 110 causes the engine control unit 120 to execute an image formation job (e.g., a print job or a copy job) that is received from an external device such as a host computer H1 or accepted via the operation unit 114.

[0077] The engine control unit 120 includes a CPU 121, a memory 122, and an encryption processing unit 123. The CPU 121 functions as an authentication unit 131 and a print control unit 132 by executing a computer program stored in the memory 122. The authentication unit 131 performs cartridge authentication processing to confirm the authenticity of the cartridge 10 when the cartridge 10 is installed in the printer 100. When the controller 110 instructs the print control unit 132 to execute a job, the print control unit 132 controls each unit of the printer 100 to form an image on a sheet under image formation conditions determined based on information read from the cartridge memory 20, as described with reference to FIG. 4. The cartridge authentication processing executed by the authentication unit 131 and the job control processing executed by the print control unit 132 will be described in further detail below.

[0078] The encryption processing unit 123 is a tamper-resistant encryption processing means that includes a processing circuit that performs various encryption processes related to the authentication of the cartridge 10 and a storage circuit that stores an encryption key required for the encryption processes. In this embodiment, the encryption processing unit 123 stores a private key K managed by the key management unit 315 of the management server 300. s The public key K corresponding to p is stored in advance (private key K s and public key K p(These form a key pair in public key cryptography.) Public key K p is used to verify the digital signature read from the cartridge memory 20.

[0079] When the cartridge 10 is installed in the printer 100, in addition to verifying the digital signature, a challenge-response authentication may be performed to confirm the authenticity of both parties. The cryptographic processing unit 26 of the cartridge 10 and the cryptographic processing unit 123 of the printer 100 may have functions such as storing an encryption key or password for challenge-response authentication, generating a response based on a challenge, and verifying a response returned from the other party. As an encryption key for challenge-response authentication, the cryptographic processing unit 26 of the cartridge 10 may use the above-mentioned derived key K d In this case, the encryption processing unit 123 of the printer 100 may use the master key K m are stored in advance, and the first identification information ID1 and the master key K received from the cartridge 10 are stored in advance. m Based on the derived key K d can be derived.

[0080] <3-2. Cartridge authentication process> 10 is a sequence diagram showing an example of the flow of cartridge authentication processing executed by the printer 100 when the cartridge 10 is installed in the printer 100. The cartridge authentication processing shown in FIG. 10 mainly involves the cartridge 10, and the encryption processing unit 123 and authentication unit 131 of the printer 100.

[0081] First, in S151, the authentication unit 131 transmits a read command to the cartridge 10 to read the initial information stored in the first memory area 31 of the cartridge memory 20. In S152, the access control unit 24 of the cartridge 10 transmits the initial information read from the first memory area 31 to the printer 100. The initial information includes, for example, first identification information (ID1).

[0082] Next, in S153, the authentication unit 131 sends a read command to the cartridge 10 to read the remanufacturing information stored in the second memory area 33 of the cartridge memory 20. In S154, the access control unit 24 of the cartridge 10 sends the remanufacturing information read from the second memory area 33 to the printer 100. The remanufacturing information includes, for example, second identification information (ID2).

[0083] Next, in S155, the authentication unit 131 sends a read command to the cartridge 10 to read the digital signature stored in the second memory area 33 of the cartridge memory 20. In S156, the access control unit 24 of the cartridge 10 sends the digital signature read from the second memory area 33 to the printer 100.

[0084] Next, in S157, the authentication unit 131 outputs the initial information, remanufacturing information, and digital signature received from the cartridge 10 to the cryptographic processing unit 123, and requests the cryptographic processing unit 123 to verify the signature. In S158, the cryptographic processing unit 123 uses the public key K p Specifically, the cryptographic processing unit 123 verifies the signature by using a hash value derived from the initial information and the remanufacturing information and a digital signature with the public key K. p If the hash values ​​obtained by decrypting the data match, the encryption processing unit 123 determines that the signature verification is successful (i.e., the initial information and remanufacturing information are authentic). If the two hash values ​​do not match, the encryption processing unit 123 determines that the signature verification is unsuccessful. In S159, the encryption processing unit 123 outputs the verification result to the authentication unit 131. If the signature verification is unsuccessful, the authentication unit 131 may skip the subsequent processing steps S160 and S162. Here, it is assumed that the signature verification is successful.

[0085] Next, in S160, the authentication unit 131 determines whether the cartridge 10 is new or remanufactured (remanufactured) based on a comparison of the first identification information and the second identification information. For example, if the second identification information is equal to the first identification information, the authentication unit 131 determines that the cartridge 10 is new. On the other hand, if the second identification information is not equal to the first identification information, the authentication unit 131 determines that the cartridge 10 is remanufactured.

[0086] Next, in S162, the authentication unit 131 performs additional challenge-response authentication with the access control unit 24 of the cartridge 10. The challenge-response authentication here may be performed according to any known method, and a detailed description of the flow thereof will be omitted here.

[0087] Next, in S164, the authentication unit 131 displays the results of verifying the digital signature, determining whether the cartridge is new or remanufactured, and the challenge-response authentication on the screen of the operation unit 114. If the signature verification or the challenge-response authentication fails, a warning may be displayed on the screen to the user. If the signature verification or the challenge-response authentication fails, the authentication unit 131 may prohibit use of the cartridge 10, or may allow use of the cartridge 10 if the user who received the warning chooses to continue using it.

[0088] The authentication unit 131 stores the results of the above-described cartridge authentication process in an internal memory. If the cartridge 10 is removed from the printer 100 and then re-installed, the authentication unit 131 can execute the cartridge authentication process again.

[0089] The determination in S160 as to whether the product is new or remanufactured may be made at any time after the remanufacturing information is read in S154.

[0090] <3-3. Job control processing> 11 is a sequence diagram showing an example of the flow of job control processing executed by the printer 100. The job control processing shown in FIG. 11 mainly involves the cartridge 10, the operation unit 114 of the printer 100, and the print control unit 132.

[0091] First, in S170, the operation unit 114 outputs an image formation job received from a user to the print control unit 132 together with job setting information such as the number of copies to be printed and the sheet size, and input image data.

[0092] At S171, the print control unit 132 sends a read command to the cartridge 10 to read the remanufacturing information stored in the second memory area 33 of the cartridge memory 20, regardless of whether the cartridge 10 is new or remanufactured. At S172, the access control unit 24 of the cartridge 10 sends the remanufacturing information read from the second memory area 33 to the printer 100. If the cartridge 10 is new, the remanufacturing information is a copy of the initial information.

[0093] Next, in S173, the print control unit 132 sends a read command to the cartridge 10 to read the operation history information stored in the common memory area 36 of the cartridge memory 20. In S174, the access control unit 24 of the cartridge 10 sends the operation history information read from the common memory area 36 to the printer 100.

[0094] Next, in S175, the print control unit 132 determines image formation conditions (e.g., development voltage) based on the characteristic information included in the remanufacturing information received from the cartridge 10. Here, the print control unit 132 may estimate the remaining toner amount from the ratio of the amount of used toner (the number of printed pages indicated by the operation history information) to the toner capacity (the number of printable pages indicated by the toner characteristic information), and notify the user of the remaining toner amount on the screen of the operation unit 114. Next, in S176, the print control unit 132 controls each unit of the printer 100 to form an image on a sheet according to the image formation conditions determined in S175.

[0095] Next, in S177, a write command is sent to the cartridge 10 to update the operation history information in the common memory area 36 of the cartridge memory 20. This write command may indicate, for example, the number of printed sheets indicated by the operation history information read in S174 plus the increase due to the execution of the image formation job in S176. In S178, the access control unit 24 of the cartridge 10 updates the operation history information in the common memory area 36 in accordance with the write command (for example, by writing the new value of the number of printed sheets to the specified write destination address). Then, in S179, the access control unit 24 notifies the printer 100 that the write is complete.

[0096] Next, in S180, the print control unit 132 displays the results of the image formation job execution on the screen of the operation unit 114.

[0097] If the cartridge 10 is a remanufactured product, the remanufacturing information read from the cartridge memory 20 in S172 is information that was successfully verified based on the authentication information during remanufacturing and written to the cartridge memory 20. In addition, it has been confirmed by signature verification in the cartridge authentication process described above that the cartridge 10 has not been tampered with between the time of remanufacturing and the time of installation in the printer 100. Therefore, the printer 100 can safely execute an image formation job in accordance with image formation conditions based on the appropriate toner characteristic information and component characteristic information written to the cartridge memory 20 by the legitimate remanufacturer.

[0098] <4. Modifications> In the embodiment described above, when the cartridge 10 is remanufactured two or more times, remanufacturing information appropriate to the characteristics of the components of the remanufactured cartridge 10 is written each time to the same second storage area 33 of the cartridge memory 20. In contrast, in one modified example, the cartridge memory 20 may have multiple second storage areas 33 into which remanufacturing information should be written. This section describes such a modified example.

[0099] <4-1. Cartridge memory configuration example> In this modified example, the cartridge memory 20 of the cartridge 10 has a read-only first memory area 31 and N (N is an integer greater than 1) rewritable second memory areas 33_1 to 33_N. The manufacturer of the cartridge 10 writes first information (initial information) unique to the cartridge 10 in advance to the first memory area 31. Copies of the first information may be written to the N second memory areas 33_1 to 33_N. During the nth (n=1, ..., N) remanufacturing, the rewriting processing unit 221 of the remanufacturing device 200 writes second information (remanufacturing information) and a corresponding digital signature to be read and used by the printer 100 after the nth remanufacturing into the nth second memory area 33_n. The access control unit 24 of the cartridge 10 conditionally permits writing to each second memory area 33_n, as in the above-described embodiment. The condition is that authentication information generated based on at least the second information is received together with the second information and the digital signature, and that verification of the second information based on the authentication information is successful in the cartridge 10. The authentication unit 131 of the printer 100 in which the cartridge 10 is mounted can determine how many times the cartridge 10 has been remanufactured based on a comparison of the identification information stored in each memory area. If the authentication unit 131 determines that remanufacturing has been performed n times, it uses the second information and its digital signature read from the nth second memory area 33_n for the above-mentioned cartridge authentication.

[0100] 12 is an explanatory diagram showing an example of the configuration of the storage areas of the cartridge memory 20 according to this modified example. Here, it is assumed that N=2. Referring to FIG. 12, the cartridge memory 20 has a first storage area 31, two second storage areas 33_1 and 33_2, and a common storage area 36.

[0101] The second storage area 33_1 is an area in which second information 34_1, which is rewritten at the time of the first remanufacturing, is stored. At the time of the first manufacturing of the cartridge 10, the second information 34_1 written in the second storage area 33_1 may be a copy of the first information 32. At the time of the first remanufacturing of the cartridge 10, the second information 34_1 is rewritten by the remanufacturing device 200 to information unique to the remanufactured cartridge 10. The second information 34_1 may include the cartridge ID (second identification information ID2_1), toner characteristic information, and component characteristic information of the cartridge 10 after the first remanufacturing.

[0102] The second storage area 33_1 further stores a digital signature 35_1. The digital signature 35_1 is used to verify the second information 34_1 when the printer 100 reads the second information 34_1 from the cartridge memory 20 and uses the second information 34_1. The digital signature 35_1 is generated by the management server 300 based on the first information 32 and the second information 34_1.

[0103] The second memory area 33_2 is an area in which second information 34_2, which is rewritten at the time of the second remanufacturing, is stored. At the time of the first manufacturing of the cartridge 10, the second information 34_2 written in the second memory area 33_2 may be a copy of the first information 32. At the time of the second remanufacturing of the cartridge 10, the second information 34_2 is rewritten by the remanufacturing device 200 to information unique to the remanufactured cartridge 10. The second information 34_2 may include the cartridge ID (second identification information ID2_2), toner characteristic information, and component characteristic information of the cartridge 10 after the second remanufacturing.

[0104] The second memory area 33_2 further stores a digital signature 35_2. The digital signature 35_2 is used to verify the second information 34_2 when the printer 100 reads the second information 34_2 from the cartridge memory 20 and uses the second information 34_2. The digital signature 35_2 is generated by the management server 300 based on the first information 32 and the second information 34_2.

[0105] In FIG. 12, the second storage areas 33_1 and 33_2 are labeled "RWM," which means that they are conditionally rewritable.

[0106] <4-2. Rewrite process> 13 is a sequence diagram showing an example of the flow of a rewriting process executed when remanufacturing the cartridge 10. The rewriting process shown in FIG. 13 mainly involves the cartridge 10, the remanufacturing device 200, and the management server 300.

[0107] Since S201 to S215 in FIG. 13 are the same processing steps as S101 to S115 in FIG. 8, a repeated description thereof will be omitted here.

[0108] In S216, the rewrite processing unit 221 transmits to the cartridge 10 a read command for reading the remanufacturing information stored in the second memory areas 33_1 and 33_2 of the cartridge memory 20. In S217, the access control unit 24 of the cartridge 10 transmits the remanufacturing information read from the second memory areas 33_1 and 33_2 to the remanufacturing device 200. The remanufacturing information read here includes, for example, two pieces of second identification information (ID2_1, ID2_2).

[0109] Next, in S218, the rewriting processing unit 221 of the remanufacturing device 200 compares the first identification information (ID1) with the two second identification information (ID2_1, ID2_2) to determine which remanufacturing iteration this time corresponds to. For example, if ID1 = ID2_1 = ID2_2, this remanufacturing corresponds to the first remanufacturing. If ID1 ≠ ID2_1 and ID1 = ID2_2, this remanufacturing corresponds to the second remanufacturing. If ID1 ≠ ID2_1 and ID1 ≠ ID2_2, this remanufacturing may correspond to the third remanufacturing, but remanufacturing more than the upper limit N may be prohibited. Here, it is assumed that this remanufacturing is determined to be the kth remanufacturing (k = 1 or 2). Next, in S219, the rewriting processing unit 221 acquires remanufacturing information for the cartridge 10 after the kth remanufacturing.

[0110] Next, in S221, the rewrite processing unit 221 transmits a signature generation request to the management server 300 to request generation of a digital signature based on the initial information (for example, the first identification information ID1) and the remanufacturing information (for example, the second identification information ID2_k). In S222, the signature generation unit 321 of the management server 300 generates a digital signature based on the private key K stored in the key management unit 315 in response to the signature generation request. s A digital signature SIG based on the initial information and remanufacturing information is generated using k In S223, the signature generation unit 321 generates the generated digital signature SIG k is transmitted to the remanufacturing equipment 200.

[0111] Next, in S224, the rewrite processing unit 221 generates a write data set W for writing the remanufacturing information to the cartridge memory 20. k For example, write data set W k may include one or more of the following: ·Remanufacturing information -Second identification information (ID2_k) - Toner characteristic information -Material characteristics information Digital Signature (SIG k ) Destination address The write destination address here differs depending on the number of remanufacturing times k.

[0112] Next, in S225, the rewrite processing unit 221 writes the write data set W k In S226, the MAC generation unit 322 transmits a MAC generation request to the management server 300, requesting the generation of a message authentication code having the master key K m and a derived key K from the first identification information ID1 registered in S214 according to equation (1). d (first derived key) and derive the derived key K d Write data set W using k Message authentication code C based on k In S227, the MAC generation unit 322 generates the generated message authentication code C k is transmitted to the remanufacturing equipment 200.

[0113] Next, in S228, the rewrite processing unit 221 writes the write data set W k and message authentication code C k In step S229, the access control unit 24 of the cartridge 10 transmits a write command including the message authentication code C received from the remanufacturing device 200. k Write dataset W based on k In this case, it is assumed that the verification is successful. In response to the successful verification, the access control unit 24 writes the remanufacturing information and the digital signature SIG to the specified write destination address in the cartridge memory 20 in S230. k Then, in S231, the access control unit 24 notifies the remanufacturing equipment 200 of the completion of writing.

[0114] <4-3. Example of memory contents before and after rewriting> Table 2 below shows an example of information stored in the cartridge memory 20 before and after rewriting during the first remanufacturing in this modified example.

[0115] [Table 2]

[0116] In Table 2, the combination of "manufacturing date" and "serial number" is also used as identification information for identifying an individual cartridge 10. "Toner color" and "number of pages that can be printed" are examples of toner characteristic information. "Developing voltage" is an example of component characteristic information. "Remaining toner warning threshold" is a threshold that is compared with "number of pages printed" to trigger a warning that the toner level is low.

[0117] When the cartridge 10 is manufactured for the first time, copies of the first identification information, toner characteristic information, and component characteristic information stored in the first memory area 31 are stored in the two second memory areas 33_1 and 33_2. When the cartridge 10 is remanufactured for the first time, the information in the first second memory area 33_1 is rewritten with information for the remanufactured cartridge 10. For example, the "number of printable sheets" is rewritten from 1,000 to 4,000. Also, the "developing voltage" is rewritten from 300 V to 280 V. Furthermore, the digital signature SIG0 is rewritten to the digital signature SIG1. The "number of prints" stored in the common memory area 36 is reset to zero at the time of remanufacturing.

[0118] Table 3 below shows an example of information stored in the cartridge memory 20 before and after rewriting during the second remanufacturing in this modified example.

[0119] [Table 3]

[0120] At the time of the second remanufacturing, the information in the second second memory area 33_2 is rewritten to information for the remanufactured cartridge 10. For example, the "number of printable sheets" is rewritten from 1000 to 3000. Also, the "developing voltage" is rewritten from 300V to 280V. Furthermore, the digital signature SIG0 is rewritten to the digital signature SIG2. The "number of prints" stored in the common memory area 36 is reset to zero at the time of remanufacturing.

[0121] According to this modification, the history of remanufacturing information written by the remanufacturing device 200 is left in the cartridge memory 20 without being overwritten. Therefore, it is possible to realize precise device management, such as estimating the degree of wear of the cartridge 10 based on the history of remanufacturing information, or tracing and investigating the cause of any trouble that may occur.

[0122] <4-4. Cartridge authentication process> 14 is a sequence diagram showing an example of the flow of cartridge authentication processing executed by the printer 100 when the cartridge 10 is attached to the printer 100 in this modified example. The cartridge authentication processing shown in FIG. 14 mainly involves the cartridge 10, and the encryption processing unit 123 and authentication unit 131 of the printer 100.

[0123] First, in S251, the authentication unit 131 sends a read command to the cartridge 10 to read the initial information stored in the first memory area 31 of the cartridge memory 20. In S252, the access control unit 24 of the cartridge 10 sends the initial information read from the first memory area 31 to the printer 100. The initial information includes, for example, first identification information (ID1).

[0124] Next, in S253, the authentication unit 131 transmits to the cartridge 10 a read command for reading the remanufacturing information stored in the second memory areas 33_1 and 33_2 of the cartridge memory 20. In S254, the access control unit 24 of the cartridge 10 transmits the remanufacturing information read from the second memory areas 33_1 and 33_2 to the printer 100. The remanufacturing information transmitted here includes, for example, two pieces of second identification information (ID2_1 and ID2_2).

[0125] Next, in S255, the authentication unit 131 compares the first identification information (ID1) with the two pieces of second identification information (ID2_1, ID2_2) to determine what number of remanufacturings this time corresponds to. Here, it is assumed that this remanufacturing is determined to be the kth time (k=1 or 2).

[0126] Next, in S256, the authentication unit 131 receives the digital signature SIG k In S257, the access control unit 24 of the cartridge 10 transmits a read command to the cartridge 10 to read the digital signature SIG k is sent to the printer 100.

[0127] Next, in S258, the authentication unit 131 receives the initial information, remanufacturing information, and digital signature SIG k to the cryptographic processing unit 123 and requests the cryptographic processing unit 123 to verify the signature. In S259, the cryptographic processing unit 123 outputs the public key K p In S260, the encryption processing unit 123 outputs the verification result to the authentication unit 131. If the signature verification fails, the authentication unit 131 may skip the subsequent processing step S262. Here, it is assumed that the signature verification is successful.

[0128] Next, in S262, the authentication unit 131 performs additional challenge-response authentication with the access control unit 24 of the cartridge 10. The challenge-response authentication here may be performed according to any known method, and a detailed description of the flow will be omitted here.

[0129] Next, in S264, the authentication unit 131 displays the results of verifying the digital signature, determining the number of remanufacturing times k, and the challenge-response authentication on the screen of the operation unit 114. If the signature verification or the challenge-response authentication fails, a warning may be displayed on the screen to the user. If the signature verification or the challenge-response authentication fails, the authentication unit 131 may prohibit use of the cartridge 10, or may allow use of the cartridge 10 if the user who received the warning chooses to continue use.

[0130] The authentication unit 131 stores the results of the above-described cartridge authentication process in an internal memory along with the value of the number of remanufacturing attempts k. The value of the number of remanufacturing attempts k can be used in job control processing to determine the address from which remanufacturing information is read to be used to determine image formation conditions. If the cartridge 10 is removed from the printer 100 and then reinserted, the authentication unit 131 can execute the cartridge authentication process again.

[0131] <4-5. Further derivative examples> In this modification, the digital signature SIG written to the n-th second memory area 33_n is nThe above description mainly focuses on an example in which the digital signature SIG is generated based on the first information (initial information) and the second information (remanufacturing information) written to the n-th second storage area 33_n. n The method for generating the digital signature SIG is not limited to this example. n may be generated based on the first information (initial information) and the second information (remanufacturing information) written in the first to n-th second storage areas 33_1 to 33_n, respectively.

[0132] Although the present specification mainly describes an example in which a digital signature is used to verify the authenticity of the remanufacturing information, a message authentication code may be used instead of a digital signature. In that case, the printer 100 and the management server 300 may hold an additional key pair (e.g., a master key and a derivative key) for verifying the authenticity of the remanufacturing information.

[0133] <5. Other embodiments> The above-described embodiment can also be realized in the form of a process in which a program for realizing one or more functions is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program, or by a circuit (e.g., ASIC) that realizes one or more functions.

[0134] The disclosure of this specification includes at least the following devices, methods, and information processing apparatuses. (Item 1) A device detachable from an image forming apparatus, a memory having a first read-only storage area and a second rewritable storage area; a control means; a connection part to be connected to an information processing device when the device is remanufactured; Including, the first storage area is an area for storing first information specific to the device, the second storage area is an area for storing second information that is read and used by the image forming device, and a digital signature that is generated based on the first information and the second information, The control means, when the device is remanufactured, receiving the second information, the digital signature, and authentication information generated based on at least the second information from the information processing device via the connection unit; permitting the second information and the digital signature to be written to the second storage area if the verification of the second information based on the authentication information is successful; device. (Item 2) Item 1. The device according to item 1, wherein the authentication information is generated by a server device that communicates with the information processing device using a key different from the cryptographic key used to generate and verify the digital signature. (Item 3) 3. The device of claim 1, wherein the authentication information is generated further based on the digital signature. (Item 4) the second information is stored at a predetermined address in the memory; the control means receives a write command including a write destination address of the second information from the information processing device; the authentication information is generated further based on the write destination address; Item 3. The device according to item 3. (Item 5) The device comprises: cryptographic processing means that holds a master key and a first derivative key that is generated in advance based on the first information; further comprising the control means transmits the first information to the information processing device via the connection unit when the device is remanufactured; the authentication information is generated by a server device that manages the master key using a second derived key that is generated based on the master key and the first information; the cryptographic processing means performs the verification of the second information based on the authentication information acquired from the server device and received from the information processing device, using the first derived key; The device according to any one of items 1 to 4. (Item 6) Item 6. The device of item 5, wherein the authentication information is a message authentication code. (Item 7) 7. The device according to any one of items 1 to 6, wherein the first information includes first identification information for identifying the device before remanufacturing. (Item 8) 8. The device of item 7, wherein the second information includes a copy of the first identification information before the device is remanufactured, and when the device is remanufactured, the copy of the first identification information is rewritten to second identification information for identifying the device after remanufacture. (Item 9) the device further includes components involved in an image forming operation by the image forming apparatus; the second information includes characteristic information representing characteristics of the component; The device according to any one of items 1 to 8. (Item 10) 10. The device according to item 9, wherein the characteristic information is rewritten by the information processing device when the device is remanufactured. (Item 11) 11. The device according to item 9 or 10, wherein the components involved in the image forming operation include at least one of a developer supplied from the device to the image forming apparatus and a member driven in the image forming operation. (Item 12) 12. The device according to any one of items 1 to 11, wherein the device is a cartridge that is mounted in the image forming apparatus when used. (Item 13) 13. The device according to any one of items 1 to 12, wherein the digital signature is used by the image forming device to verify the second information when the image forming device reads and uses the second information from the device. (Item 14) the memory has N (N is an integer greater than 1) rewritable second storage areas, an n-th (n=1,...,N) second storage area is used, at the time of the n-th remanufacturing, to write the second information and the corresponding digital signature, which are read and used by the image forming device after the n-th remanufacturing; 14. The device according to any one of items 1 to 13. (Item 15) Item 15. The device of item 14, wherein the digital signature written to the nth second storage area is generated based on the first information and the second information written to the nth second storage area. (Item 16) Item 15. The device of item 14, wherein the digital signature written to the nth second memory area is generated based on the first information and the second information written to each of the first to nth second memory areas. (Item 17) 1. A method for remanufacturing a device detachable from an image forming apparatus, the method being performed using an information processing device connected to the device, the method comprising: the device includes a memory having a first read-only storage area and a second rewritable storage area; The method comprises: reading first information specific to the device from the first storage area of ​​the device to the information processing device; acquiring, by the information processing device, second information to be read and used by the image forming apparatus from the device; acquiring, by the information processing device, a digital signature generated based on the first information and the second information; acquiring, by the information processing device, authentication information generated based on at least the second information; transmitting, from the information processing device to the device, a write command for writing the second information and the digital signature to the second storage area together with the authentication information; writing the second information and the digital signature to the second storage area when the device has successfully verified the second information based on the authentication information; A method comprising: (Item 18) An information processing apparatus for remanufacturing a device detachable from an image forming apparatus, the device includes a memory having a first read-only storage area and a second rewritable storage area; The information processing device includes: a connection portion that is connected to the device when the device is remanufactured; a control means for controlling writing of information from the information processing device to the device; Equipped with The control means reading first information specific to the device from the first storage area of ​​the device; The image forming apparatus obtains second information to be read from the device and used; obtaining a digital signature generated based on the first information and the second information; obtaining authentication information generated based on at least the second information; sending a write command to the device together with the authentication information to write the second information and the digital signature to the second storage area; writing of the second information and the digital signature to the second storage area is permitted if the second information is successfully verified based on the authentication information in the device; Information processing device.

[0135] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]

[0136] 1: cartridge authentication system, 10: device (cartridge), 20: memory, 22: connection terminal (connection section), 24: access control section (control means), 26: encryption processing section (encryption processing means), 31: first storage area, 32: first information (initial information), 33: second storage area, 34: second information (remanufacturing information), 100: image forming apparatus, 200: information processing apparatus (remanufacturing apparatus), 202: connection terminal (connection section), 211: CPU (control means), 300: server apparatus (management server)

Claims

1. A device detachable from an image forming apparatus, a memory having a first read-only storage area and a second rewritable storage area; a control means; a connection part to be connected to an information processing device when the device is remanufactured; Including, the first storage area is an area for storing first information specific to the device, the second storage area is an area for storing second information that is read and used by the image forming device, and a digital signature that is generated based on the first information and the second information, The control means, when the device is remanufactured, receiving the second information, the digital signature, and authentication information generated based on at least the second information from the information processing device via the connection unit; permitting the second information and the digital signature to be written to the second storage area when the second information is successfully verified based on the authentication information; device.

2. The device of claim 1 , wherein the authentication information is generated by a server device communicating with the information processing device using a cryptographic key different from a cryptographic key used to generate and verify the digital signature.

3. The device of claim 1 , wherein the authentication information is generated further based on the digital signature.

4. the second information is stored at a predetermined address in the memory; the control means receives a write command including a write destination address of the second information from the information processing device; the authentication information is generated further based on the write destination address; The device of claim 3.

5. The device comprises: cryptographic processing means for holding a master key and a first derivative key generated in advance based on the first information; further comprising the control means transmits the first information to the information processing device via the connection unit when the device is remanufactured; the authentication information is generated by a server device that manages the master key using a second derived key that is generated based on the master key and the first information; the cryptographic processing means performs the verification of the second information based on the authentication information acquired from the server device and received from the information processing device, using the first derived key; The device of claim 1 .

6. The device of claim 5 , wherein the authentication information is a message authentication code.

7. The device of claim 1 , wherein the first information includes first identification information for identifying the device before remanufacturing.

8. 8. The device of claim 7, wherein the second information includes a copy of the first identification information before the device is remanufactured, and when the device is remanufactured, the copy of the first identification information is rewritten to second identification information for identifying the device after remanufacture.

9. the device further includes components involved in an image forming operation by the image forming apparatus; the second information includes characteristic information representing a characteristic of the component; The device of claim 1 .

10. The device according to claim 9 , wherein the characteristic information is rewritten by the information processing device when the device is remanufactured.

11. The device according to claim 9 , wherein the components involved in the image forming operation include at least one of a developer supplied from the device to the image forming apparatus and a member driven in the image forming operation.

12. The device according to claim 1 , wherein the device is a cartridge that is mounted in the image forming apparatus.

13. The device of claim 1 , wherein the digital signature is used by the image forming device to verify the second information when the image forming device reads the second information from the device and uses it.

14. the memory has N (N is an integer greater than 1) rewritable second storage areas, an n-th (n=1, ..., N) second storage area is used, at the time of the n-th remanufacturing, to write the second information and the corresponding digital signature that are read and used by the image forming device after the n-th remanufacturing; The device of claim 1 .

15. The device of claim 14 , wherein the digital signature written to the nth second storage area is generated based on the first information and the second information written to the nth second storage area.

16. The device of claim 14 , wherein the digital signature written to the nth second memory area is generated based on the first information and the second information written to each of the first to nth second memory areas.

17. 1. A method for remanufacturing a device detachable from an image forming apparatus, the method being performed using an information processing device connected to the device, the method comprising: the device includes a memory having a first read-only storage area and a second rewritable storage area; The method comprises: reading first information specific to the device from the first storage area of ​​the device to the information processing device; acquiring, by the information processing device, second information to be read and used by the image forming apparatus from the device; acquiring, by the information processing device, a digital signature generated based on the first information and the second information; acquiring, by the information processing device, authentication information generated based on at least the second information; transmitting, from the information processing device to the device, a write command for writing the second information and the digital signature to the second storage area together with the authentication information; writing the second information and the digital signature to the second storage area when the second information is successfully verified based on the authentication information by the device; A method comprising:

18. An information processing apparatus for remanufacturing a device detachable from an image forming apparatus, the device includes a memory having a first read-only storage area and a second rewritable storage area; The information processing device includes: a connection portion that is connected to the device when the device is remanufactured; a control means for controlling writing of information from the information processing device to the device; Equipped with The control means reading first information specific to the device from the first storage area of ​​the device; the image forming apparatus obtains second information to be read from the device and used; obtaining a digital signature generated based on the first information and the second information; obtaining authentication information generated based on at least the second information; sending a write command to the device together with the authentication information to write the second information and the digital signature to the second storage area; writing of the second information and the digital signature to the second storage area is permitted if the second information is successfully verified based on the authentication information in the device; Information processing device.

Citation Information

Patent Citations

  • Image formation system, method, image formation device and server device

    JP2023106130A

  • Reprocessing a replaceable supply component to reconfigure an end-user device

    WO2022173444A1