Information processing device, information terminal, and program

The information processing device addresses the issue of encryption key mismatch by obtaining and decrypting the key from an external source, simplifying the device configuration and ensuring data accessibility after board replacement.

JP2026112266APending Publication Date: 2026-07-06FUJIFILM BUSINESS INNOVATION CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
FUJIFILM BUSINESS INNOVATION CORP
Filing Date
2024-12-24
Publication Date
2026-07-06

AI Technical Summary

Technical Problem

In printers or similar devices, replacing a board requires transferring a storage device with encrypted data, but the encryption keys are unique to the old and new boards, preventing decryption and data access.

Method used

An information processing device obtains an encrypted encryption key from an external device via a communication interface, decrypts the data, and updates the encryption key to enable access on the new board.

Benefits of technology

Simplifies device configuration by eliminating the need for a separate circuit board to store encryption keys and allows seamless data access after board replacement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026112266000001_ABST
    Figure 2026112266000001_ABST
Patent Text Reader

Abstract

This system simplifies the device configuration compared to backing up encrypted encryption key data, which is unique to a circuit board removed from the device, to another circuit board within the same device. [Solution] The information processing device has a processor, and if, after replacing the first board with the second board, the processor fails to decrypt the first encrypted data stored in the memory device transferred from the first board to the second board, the processor obtains first encryption key data, which is encrypted using the first encryption key unique to the first board, from an external device connected via another terminal, and decrypts the first encrypted data using the first encryption key decrypted from the obtained first encryption key data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information terminal, and a program.

Background Art

[0002] High security for user data is required for printers and other devices. For this reason, for example, it is required to satisfy the following conditions. (1) Data on a removable storage device is encrypted with a specific algorithm (2) The plaintext encryption key used for encryption must not be stored on the same storage device as the encrypted data. (3) The plaintext encryption key must not be stored on a removable storage device.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, in a printer or other device, it may be necessary to replace a board during repair. In this case, the storage device is removed from the old board and attached to the new board. However, the encryption key used for data encryption is linked to the board on a one-to-one basis. Therefore, even if the storage device of the old board is transferred to the new board, the data stored in the storage device cannot be decrypted and used as it is. This is because the encryption key of the old board used for data encryption is different from the encryption key of the new board.

[0005] The present invention aims to simplify the device configuration compared to the case where encrypted encryption key data, which is obtained by encrypting an encryption key unique to a circuit board removed from the device, is backed up to another circuit board within the same device. [Means for solving the problem]

[0006] The invention described in claim 1 is an information processing device having a processor, wherein, after replacing the first board with a second board, if the decryption of the first encrypted data stored in the storage device transferred from the first board to the second board fails, the processor obtains first encryption key data, which is an encrypted first encryption key unique to the first board, from an external device connected via another terminal, and decrypts the first encrypted data using the first encryption key decrypted from the obtained first encryption key data. The invention described in claim 2 is an information processing apparatus according to claim 1, wherein the external device stores serial information unique to the circuit board and encryption key data obtained by encrypting the corresponding encryption key, and the processor provides the first serial information unique to the first circuit board, read from the storage device, to the other terminal, and obtains the first encryption key data corresponding to the first serial information from the other terminal. The invention described in claim 3 is an information processing device according to claim 2, wherein the processor provides the first serial information to the other terminal via a first communication interface and obtains the first encryption key data from the other terminal via a second communication interface different from the first communication interface. The invention described in claim 4 is the information processing device according to claim 3, wherein the first communication interface is NFC and the second communication interface is wireless LAN. The invention described in claim 5 is an information processing apparatus according to claim 4, wherein the processor reads the first serial information from the storage device and stores it in the NFC module when a maintenance mode is started. The invention described in claim 6 is an information processing apparatus according to claim 1, wherein the processor encrypts the data obtained by decrypting the first encrypted data using a second encryption key unique to the second substrate and stores it in the storage device. The invention described in claim 7 is an information terminal having a processor, the processor communicating with an information processing device that has failed to decrypt first encrypted data stored in a storage device transferred from the first board to the second board after replacing the first board with a second board, reading the serial information of the first board from the information processing device, obtaining first encrypted key data from an external device which is encrypted first encrypted key unique to the first board corresponding to the serial information, and transmitting the obtained first encrypted key data to the information processing device. The invention described in claim 8 is a program for a computer that, if decryption of the first encrypted data stored in a storage device transferred from the first board to the second board fails after replacing the first board with the second board, provides a function to obtain first encryption key data, which is encrypted using the first encryption key unique to the first board, from an external device connected via another terminal, and a function to decrypt the first encrypted data using the first encryption key decrypted from the obtained first encryption key data. [Effects of the Invention]

[0007] According to the invention described in claim 1, the device configuration can be simplified compared to the case in which the first encryption key data, which is encrypted using a first encryption key unique to the first circuit board removed from the device, is backed up to another circuit board within the same device. According to the invention described in claim 2, it is not necessary to provide a separate circuit board for backing up the encryption key within the device. According to the invention described in claim 3, the communication interface can be used differently depending on the information to be exchanged. According to the invention described in claim 4, the first encryption key data can be acquired within the device with a single tap operation. According to the invention described in claim 5, the first serial information can be provided to other terminals only in maintenance mode. According to the invention described in claim 6, the first encrypted data stored in the memory device inherited from the first substrate can be made available for use on the second substrate as well. According to the invention described in claim 7, first encryption key data obtained by encrypting the first encryption key unique to the first substrate removed from the device can be acquired and transferred to an information processing device. According to the invention described in claim 8, first encryption key data obtained by encrypting the first encryption key unique to the first substrate removed from the device can be acquired and transferred to an information processing device. [Brief explanation of the drawing]

[0008] [Figure 1] This diagram illustrates an example of a system configuration assumed in the embodiment. [Figure 2] This diagram illustrates an example of database data. [Figure 3] This is a diagram illustrating an example of the configuration of an image forming apparatus. [Figure 4] This diagram illustrates an example of an NDEF record stored in an NFC tag. [Figure 5] This diagram illustrates an example of data stored in non-volatile memory. [Figure 6] This diagram illustrates an example of a mobile device configuration. [Figure 7] This flowchart illustrates an example of some of the work procedures and processing operations related to replacing a control board. [Figure 8] This flowchart illustrates another example of the work procedures and processing operations related to replacing the control board. [Figure 9] This diagram illustrates an example of an NDEF record containing a unique serial number and other information on the control board (old version). [Figure 10] This is a flowchart illustrating the processing operation of a circuit board replacement application installed on a mobile device. [Figure 11] This diagram illustrates the control board replacement procedure described in steps 102-104 (see Figure 7). [Figure 12] This diagram illustrates the processing operation in step 110 (see Figure 7). [Figure 13] This diagram illustrates the processing operation in step 115 (see Figure 8). [Figure 14]This is a diagram for explaining the processing operations of step 115 and step 116 (see FIG. 8). [Figure 15] This is a diagram for explaining the processing operations of step 117 to step 120 (see FIG. 8). [Figure 16] This is a diagram for explaining the processing operations of step 121 and step 122 (see FIG. 8).

Mode for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings. <Embodiment 1> <System Configuration> FIG. 1 is a diagram for explaining an example of the system configuration assumed in the embodiment. The system shown in FIG. 1 includes two subsystems. One is a subsystem operated by an operator who produces the image forming apparatus 10 (hereinafter referred to as "producing operator, etc."). The other is a subsystem at the site where the image forming apparatus 10 is installed (hereinafter referred to as "installation site"). Note that the image forming apparatus 10 is an example of an information processing apparatus.

[0010] The image forming apparatus 10 includes a control board 100. On the control board 100, for example, a board-specific encryption key used for encrypting user data and the like, a common key used for encrypting the encryption key, and a serial number unique to the control board 100 are recorded. The control board 100 and the serial number correspond one-to-one. Note that the serial number is an example of serial information unique to the control board.

[0011] The subsystem of the producing operator, etc. is provided with a database 110 connected to the network N. The database 110 is an example of an external device. In the database 110, encryption key data corresponding to the serial numbers of all the control boards 100 produced by the producing operator is recorded. The database 110 may be operated by the producing operator of the image forming apparatus 10 or by an operator commissioned by the producing operator.

[0012] Figure 2 illustrates an example of data from database 110. Database 110 stores encryption key data 110B associated with the serial number 110A unique to the control board. In Figure 2, for illustrative purposes, the information of the encryption key before encryption with the shared key is also shown as an example, but it is not necessary to store the encryption key.

[0013] In Figure 2, the encryption key data ENC1000A is recorded in association with the serial number "SN1000A". Encryption key data ENC1000A is an example of the first encryption key data. The encryption key data ENC1000A is data obtained by encrypting the encryption key KEY_A with a shared key. Therefore, when the encryption key data ENC1000A is decrypted with the shared key, the encryption key KEY_A is decrypted. The encryption key KEY_A is an example of a first encryption key.

[0014] Similarly, the encryption key data ENC1000B is recorded in association with the serial number "SN1000B". The encryption key data ENC1000B is data obtained by encrypting the encryption key KEY_B with a shared key. Therefore, when the encryption key data ENC1000B is decrypted with the shared key, the encryption key KEY_B is decrypted. The encryption key KEY_B is also an example of a first encryption key.

[0015] The installation site is, for example, the place where the image forming apparatus 10 is used. However, the installation site is not limited to the place where the image forming apparatus 10 is used, as it is also conceivable that the image forming apparatus 10 may be brought to a repair facility. In the case of Figure 1, the installation site also includes smartphones and other mobile devices 20. Mobile devices 20 are an example of information terminals. Mobile devices 20 are also an example of other terminals connected to the image forming apparatus 10.

[0016] In this embodiment, the mobile terminal 20 is carried by a customer engineer or the like who is responsible for maintaining the image forming apparatus 10. However, the mobile terminal 20 may also be a terminal used by a user of the image forming apparatus 10. However, the mobile terminal 20 is required to install a dedicated application program 21 (hereinafter referred to as the "board replacement app") used when replacing the control board 100.

[0017] In this embodiment, the image forming apparatus 10 and the mobile terminal 20 support communication via NFC (Near Field Communication). NFC is an example of a first communication interface. The image forming apparatus 10 and the mobile terminal 20 can communicate wirelessly via WiFi Direct or via WiFi through the access point 30. For example, the image forming apparatus 10 is equipped with a function that allows it to act as a master unit for the mobile terminal 20. Alternatively, the image forming apparatus 10 is equipped with a communication function for connecting to the access point 30 via a LAN (=Local Area Network).

[0018] WiFi Direct or WiFi is an example of a second communication interface. The second communication interface is a wireless LAN. In this embodiment, however, the LAN available to the image forming apparatus 10 is restricted from communicating with the area outside its installation location.

[0019] <Configuration of an image forming apparatus> Figure 3 is a diagram illustrating an example of the configuration of the image forming apparatus 10. In Figure 3, parts corresponding to those in Figure 1 are indicated by corresponding reference numerals. The image forming apparatus 10 includes, for example, a control board 100, a control panel 11, a printing engine 12, a scanner 13, an NFC tag 14, and a WiFi module 15.

[0020] The control panel 11 is a device that accepts user input. The control panel 11 may include, for example, a touch panel, buttons, and switches. The touch panel is a device having a structure in which a capacitive translucent thin-film sensor is laminated on the surface of a display, for example. The touch panel is an example of a device that has both input and output functions. Buttons and switches are examples of mechanical controls.

[0021] The printing engine 12 includes processing devices and associated mechanisms used to print information onto paper or other media. The processing device includes, for example, functional units for rendering, density correction, sharpness correction, contrast correction, and background color removal. The mechanism of the printing engine 12 differs depending on the printing method. For example, the mechanism of the printing engine 12 is different for photo printing and inkjet printing. Furthermore, the mechanism for transporting the medium (i.e., the transport mechanism) differs depending on whether the medium is cut paper or roll paper.

[0022] The scanner 13 is a device that optically reads information from the surface of a document. The scanner 13 supports at least one of two methods: one in which the reading unit is moved relative to a stationary document, and another in which the document is moved relative to a stationary reading unit. The NFC tag 14 has an embedded IC chip that enables contactless communication with NFC-enabled devices (e.g., mobile terminal 20). The NFC tag 14 also contains SRAM (Static Random Access Memory), a type of volatile memory. The NFC tag 14 is an example of an NFC module.

[0023] Figure 4 illustrates an example of an NDEF (=NFC Data Exchange Format) record stored in the NFC tag 14. The NDEF record shown in Figure 4 is a portion of the data stored in the NFC tag 14. The "header" information is recorded at offset a. Offset b records the "control board serial number". The serial number recorded is that of the control board installed at the time of shipment. When the control board is replaced (during the "board recovery mode" described later), the serial number unique to the old control board before replacement is recorded in offset b.

[0024] The offset c records the "type" of the current operating mode. In this embodiment, the offset c is recorded as either "0" or "1". "0" means "tap-based printing execution mode", and "1" means "tap-based board recovery mode". From offset d onward, information necessary for the handover connection is recorded. This information is known. The aforementioned NDEF record is read by the mobile device 20 through a tap operation.

[0025] Let's return to the explanation of Figure 3. The WiFi module 15 is a module that enables communication with WiFi-connected devices (e.g., mobile terminal 20). A module that has the function to directly connect with other devices equipped with WiFi functionality (e.g., mobile terminal 20) is called a WiFi direct module. If the WiFi module 15 is a WiFi direct module, the image forming apparatus 10 operates as a base station for a mobile terminal 20 or the like. In this case, the image forming apparatus 10 can communicate with other devices (e.g., the mobile terminal 20) without an access point 30.

[0026] The control board 100 includes, for example, a processor 101, a system ROM (=Read Only Memory) 102, a ROM 103, a RAM (=Random Access Memory) 104, a master non-volatile memory 105, and a backup non-volatile memory 106. The master non-volatile memory 105 is an example of a storage device that is transferred to the new control board 100 when the circuit board is replaced. The master non-volatile memory 105 may include, for example, an SD (Secure Digital) memory card, a hard disk drive (i.e., a magnetic recording device), or a semiconductor memory soldered to a sub-board connected to the control board 100 by a connector.

[0027] The processor 101 is a semiconductor device that implements various functions through the execution of a program. This program includes, for example, firmware 102A (see Figure 5) and UEFI (Unified Extensible Firmware Interface) 102B (see Figure 5). In this embodiment, UEFI 102B includes a customer engineer mode (hereinafter also referred to as "diagnostic mode").

[0028] Firmware 102A is a program that controls the operation and functions of the control panel 11 and other devices that make up the image forming apparatus 10. UEFI102B is a boot program that controls the startup process. System ROM 102 and ROM 103 are directly soldered to the control board 100. In other words, system ROM 102 and ROM 103 cannot be physically removed from the control board 100 by customer engineers, etc. System ROM 102 and ROM 103 are, for example, soldered to the control board 100.

[0029] The system ROM 102 stores, in addition to the firmware 102A mentioned above, encryption key data 102C (see Figure 5). Encryption key data 102C is data obtained by encrypting an encryption key unique to the control board 100 (e.g., KEY_A) with a common key 103A (see Figure 5). ROM 103 stores, for example, a common key 103A. The common key 103A is the plaintext encryption key used to encrypt the encryption key unique to the control board 100. The common key 103A is written to ROM 103 when the control board 100 is shipped.

[0030] For security reasons, the common key 103A, which is the plaintext encryption key, is prohibited from being stored on the same storage device as the encryption key data 102C. Furthermore, the common key 103A is prohibited from being stored on a storage device that is removable from the control board 100. For this reason, in this embodiment, the common key 103A is stored in the ROM 103. RAM104 is a semiconductor memory used, for example, as an execution area for programs. For example, a computer is composed of a processor 101, a system ROM 102, and RAM 104.

[0031] The master non-volatile memory 105 is a removable storage device relative to the control board 100. The master non-volatile memory 105 contains a serial number 105A (see Figure 5) unique to the control board 100 installed at the time of shipment, and user data (encrypted data 105B, unencrypted data 105C (see Figure 5)). Encrypted data 105B refers to user data encrypted with an encryption key unique to the control board 100. The encrypted user data includes information set by the user. User-set information is an example of highly confidential information. For this reason, it is stored in an encrypted state using the encryption key.

[0032] The backup non-volatile memory 106 is a semiconductor memory directly attached to the control board 100. The backup non-volatile memory 106 stores data (backup data) that is a copy of the data stored in the master non-volatile memory 105. Therefore, the backup non-volatile memory 106 contains the serial number 106A (see Figure 5) unique to the control board 100 installed at the time of shipment, and backup data (encrypted data 106B, unencrypted data 106C (see Figure 5)).

[0033] Figure 5 illustrates an example of data stored in non-volatile memory. The encryption key data 102C is stored in the system ROM 102. On the other hand, the plaintext symmetric key 103A used to generate the encryption key data 102C is stored in ROM 103. In other words, the encryption key data 102C and the symmetric key 103A are stored in physically different non-volatile memories. Furthermore, the plaintext common key 103A is stored in a semiconductor memory (i.e., ROM 103) directly attached to the control board 100.

[0034] <Mobile device configuration> Figure 6 is a diagram illustrating an example configuration of the mobile terminal 20. In Figure 6, parts corresponding to those in Figure 1 are indicated by corresponding reference numerals. The mobile terminal 20 includes, for example, a processor 201, a ROM 202, a RAM 203, a non-volatile memory 204, a touch panel 205, an NFC module 206, and a WiFi module 207.

[0035] The mobile device 20 also includes a speaker, microphone, and other components. ROM202 stores, for example, firmware and UEFI. The non-volatile memory 204 has the board replacement application 21 installed. The board replacement application 21 executes the processing operations for board replacement, which will be described later. The touch panel 205 is a device having a structure in which a capacitive, light-transmitting thin-film sensor is laminated on the surface of a display, for example. The NFC module 206 is a device that reads NDEF records from the NFC tag 14 (see Figure 3). The WiFi module 207 is an interface for WiFi communication.

[0036] <Control board replacement procedure and processing operation> Figure 7 is a flowchart illustrating an example of some of the work procedures and processing operations related to the replacement of the control board 100 (see Figure 1). Figure 8 is a flowchart illustrating an example of the remaining parts of the work procedures and processing operations related to the replacement of the control board 100 (see Figure 1). The work procedure and processing actions shown in Figure 8 are a continuation of the work procedure and processing actions shown in Figure 7. In the symbols S shown in Figures 7 and 8, S represents a step.

[0037] A customer engineer visiting the installation site for a malfunction or inspection of the image forming apparatus 10 (see Figure 1) determines whether or not the control board 100 (see Figure 1) needs to be replaced (step 101). If it is determined that the control board 100 does not need to be replaced (for example, if the problem can be resolved by replacing consumable parts), a negative result is obtained in step 101. In this case, work other than replacing the control board 100 is performed. Therefore, the process does not proceed to replacing the control board 100.

[0038] On the other hand, if it is determined that the control board 100 needs to be replaced, a positive result is obtained in step 101. In this case, the customer engineer removes the control board 100 from the image forming apparatus 10 (step 102). In Figure 7, the control board 100 that is removed is labeled as "Old Control Board". "Control board (old)" refers to the currently installed, faulty control board 100, and is a designation used to distinguish it from the newly installed control board 100. In the following, when it is necessary to distinguish it from "control board (old)", the newly installed control board 100 will be referred to as "control board (new)". Note that the old control board is an example of the first board, and the new control board is an example of the second board.

[0039] Next, the customer engineer removes the master non-volatile memory 105 (see Figure 3) from the control board (old) (step 103). The master non-volatile memory 105 stores the control board's unique serial number 105A (see Figure 5), encrypted data 105B (see Figure 5), and unencrypted data 105C (see Figure 5). Next, the customer engineer installs the removed master non-volatile memory 105 onto the control board (new) (step 104). Next, the customer engineer installs the control board (new) into the image forming apparatus 10 (step 105).

[0040] The customer engineer then turns on the main power supply of the image forming apparatus 10 (step 106). This initiates the boot process using UEFI102B (see Figure 5). The UEFI102B boot process is executed by processor 101 (see Figure 3). The processor 101 determines whether or not a startup error has been detected (step 107).

[0041] If no startup errors are detected, a negative result is obtained in step 107. If a negative result is obtained in step 107, for example, only unencrypted data 105C may be stored in the master non-volatile memory 105. In this case, the processor 101 executes firmware 102A (see Figure 5). In other words, the image forming apparatus 10 becomes ready for use.

[0042] On the other hand, if a boot error is detected, a positive result is obtained in step 107. In this case, the processor 101 starts the UEFI 102B diagnostic mode (step 108). The diagnostic mode is an example of a maintenance mode. The processor 101 (see Figure 3) receives an instruction to copy backup data from the diagnostic menu (step 109). The instruction to copy is given by the customer engineer. In this embodiment, the instruction to copy means to execute the board recovery mode.

[0043] Next, the processor 101 copies the unencrypted data 105C (see Figure 5) from the master non-volatile memory 105 (see Figure 5) to the backup non-volatile memory 106 (see Figure 5) (step 110). Next, the processor 101 decrypts the encrypted data 105B stored in the master non-volatile memory 105 (see Figure 5) using the encryption key (new) of the control board (new) (step 111). The encrypted data 105B is an example of the first encrypted data.

[0044] The encryption key (new) is unique to the control board (new) and can be obtained by decrypting the encryption key data 102C (see Figure 5) with the common key 103A (see Figure 5). Next, the processor 101 determines whether or not it failed to decrypt the encrypted data 105B (step 112). If decryption is successful, a negative result is obtained in step 112. In this case, the processor 101 returns to the diagnostic mode menu screen. When instructed to exit diagnostic mode, the firmware is executed.

[0045] On the other hand, if decoding fails, a positive result is obtained in step 112. In this case, the processor 101 reads the serial number 105A, which is unique to the control board (old), from the master non-volatile memory 105 (see Figure 5) (step 113). Next, the processor 101 writes the handover connection information and the serial number unique to the control board (old) into the SRAM of the NFC tag 14 (see Figure 3) (step 114).

[0046] Figure 9 illustrates an example of an NDEF record containing a unique serial number and other information for the control board (old version). The data structure shown in Figure 9 corresponds to the data structure shown in Figure 4. In Figure 9, the serial number "SN1000A" is written at offset b as the unique serial number of the control board (old). Also, "Type (1)" is written at offset c. "Type (1)" means that the current operating mode is the board recovery mode via tapping. This completes the preparation for NFC tapping.

[0047] Return to the explanation of Figure 8. Subsequently, communication with the database 110 (see Figure 1) is performed via the customer engineer's mobile terminal 20 (see Figure 1) (step 115). Figure 10 is a flowchart illustrating the processing operation of the circuit board replacement application 21 (see Figure 6) installed on the mobile terminal 20. The processing operation of the circuit board replacement application 21 is executed by the processor 201 (see Figure 6). The circuit board replacement application 21 runs in the background.

[0048] The processor 201 determines whether or not an NFC tap has been detected (step 201). If no NFC tap is detected, a negative result is obtained in step 201. In this case, the processor 201 repeats the determination process in step 201. On the other hand, if an NFC tap is detected, a positive result is obtained in step 201. In this case, the processor 201 determines whether or not the reading of the NDEF record from the NFC tag 14 (see Figure 3) has been completed (step 202).

[0049] If the reading of the NDEF record is not complete, a negative result is obtained in step 202. In this case, the processor 201 repeats the determination process in step 202. On the other hand, if the reading of the NDEF record is complete, a positive result is obtained in step 202. In this case, the processor 201 obtains the serial number of the old control board from offset b of the NDEF record (see Figure 9) (step 203). In Figure 9, the serial number of the old control board is "SN1000A".

[0050] Next, the processor 201 transmits the serial number of the control board (old) to the database 110 (see Figure 1) (step 204). This transmission is performed over network N (e.g., the Internet). Subsequently, the processor 201 obtains the encryption key data (old) corresponding to the control board (old) from the database 110 (step 205).

[0051] Next, the processor 201 establishes a handover connection with the image forming apparatus 10 (see Figure 1) via WiFi or WiFi Direct (step 206). The information necessary for the handover connection with the image forming apparatus 10 is read from the NFC tag 14 (see Figure 3) when the NFC is tapped. After this, the processor 201 transmits the encryption key data (old) to the image forming apparatus 10 (step 207). Returning to the explanation of Figure 8.

[0052] After step 114, the processor 101 of the image forming apparatus 10 determines whether or not it has received the encryption key data from the control board (old) (step 116). If the encryption key data for the control board (old) has not been received, a negative result is obtained in step 116. In this case, the processor 101 repeats the determination process in step 116. Furthermore, if the board replacement application 21 is not installed on the mobile terminal 20 (see Figure 1) used for NFC tapping, even if the NDEF record can be read, the encryption key data (old) cannot be obtained from the database 110 (see Figure 1).

[0053] In this case, the negative result from step 116 persists. In this case, the processor 101 may display a screen on the control panel 11 (see Figure 3) prompting the installation of, for example, the board replacement application 21. The conditions for display include, for example, requiring that the judgment time in step 116 exceeds a threshold (time). On the other hand, if the reception of the encryption key data on the control board (old) is confirmed, a positive result is obtained in step 116. In this case, the processor 101 decrypts the received encryption key data with the shared key (step 117). Hereafter, the decrypted encryption key will be referred to as the "encryption key (old)".

[0054] Next, the processor 101 decrypts the encrypted data (old) backed up in the backup non-volatile memory 106 using the decrypted encryption key (old) to generate plaintext user data (step 118). The encrypted data to be decrypted (old) is the user data copied from the master non-volatile memory 105 to the backup non-volatile memory 106 in step 110 (see Figure 7).

[0055] Next, the processor 101 encrypts the plaintext user data with the encryption key of the control board (new) to generate encrypted data (new) (step 119). Next, the processor 101 saves the encrypted data (new) to the backup non-volatile memory 106 (step 120).

[0056] Next, the processor 101 saves the generated encrypted data (new) to the master non-volatile memory 105 (see Figure 3) (step 121). The saving process here may involve overwriting the encrypted data (old) inherited from the old control board before replacement. Alternatively, the encrypted data (old) may be deleted from the backup non-volatile memory 106 after saving the encrypted data (new).

[0057] Next, the processor 101 reads the serial number of the new control board from the backup non-volatile memory 106 and overwrites it in the master non-volatile memory 105 (step 122). This resolves the mismatch between the serial number stored in the master non-volatile memory 105, which was replaced by the new control board from the old control board, and that of the new control board. After this, processor 101 exits UEFI diagnostic mode and runs the firmware.

[0058] <Control board replacement procedure and processing flow> Figure 11 illustrates the replacement procedure for the control board 100 described in steps 102 to 104 (see Figure 7). Figure 11 is denoted by reference numerals corresponding to the parts shown in Figures 1 and 5. In Figure 11, the serial number of the old control board removed from the image forming apparatus 10 is assumed to be "SN1000A". In this case, the master non-volatile memory 105 has the serial number unique to the old control board (i.e., "SN1000A") 105A recorded in it.

[0059] Furthermore, the system ROM 102 stores encrypted data (i.e., encryption key data (old)) 102C, which contains the encryption key unique to the control board (old). In the case of Figure 11, "ENC1000A" corresponding to "SN1000A" is stored. The customer engineer removes the master non-volatile memory 105 from the old control board and installs it on the new control board 100 (i.e., the new control board). In the case of Figure 11, the serial number of the control board (new) is "SN1000B". Therefore, the system ROM 102 of the control board (new) contains the encryption key data (new) (i.e., "ENC1000B") 102C corresponding to "SN1000B".

[0060] Figure 12 is a diagram illustrating the processing operation of step 110 (see Figure 7). Figure 12 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 1 and 5. The control board (new) shown in Figure 12 has already been installed in the image forming apparatus 10 (see Figure 1), and the diagnostic mode of UEFI 102B (see Figure 5) has been started.

[0061] As shown in Figure 12, the serial number 105A of the control board (new) is "SN1000B". However, the serial number 105A of the master non-volatile memory 105 inherited from the control board (old) is "SN1000A". Incidentally, the serial number 106A of the backup non-volatile memory 106 is the same as the serial number of the control board (new).

[0062] In this state, first, the unencrypted data 105C is copied from the master non-volatile memory 105 to the backup non-volatile memory 106. Note that the encrypted data 106B (see Figure 5) is not recorded in the backup non-volatile memory 106 immediately after replacement.

[0063] Figure 13 is a diagram illustrating the processing operation of step 115 (see Figure 8). Figure 13 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 1 and 3. Figure 13 shows the data flow when an NFC tap is performed. First, the serial number of the control board (old model) (i.e., "SN1000A") and handover information are read to the mobile terminal 20 via NFC tap. The serial number here is an example of the first serial information. Next, the mobile terminal 20 queries the database 110 for encryption key data specific to the acquired serial number (i.e., SN1000A) via the circuit board replacement application 21.

[0064] Figure 14 illustrates the processing operations of steps 115 and 116 (see Figure 8). Figure 14 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 1 and 3. Database 110 stores encryption key data 110B (see Figure 2) unique to the old control board, associated with the serial number 110A (see Figure 2) of the old control board. In Figure 14, the encryption key data (i.e., ENC1000A) corresponding to the serial number of the control board (old) is read out to the mobile terminal 20.

[0065] Next, the mobile terminal 20 transfers the encryption key data (i.e., ENC1000A) corresponding to the serial number of the control board (old) to the image forming apparatus 10, which is connected via handover. After this, the image forming apparatus 10 writes the encryption key data to the RAM 104. Note that RAM104 is volatile memory. Therefore, when the main power is turned off, all data stored in RAM104 (including encryption key data) will be erased.

[0066] Figure 15 is a diagram illustrating the processing operations of steps 117 to 120 (see Figure 8). Figure 15 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 1, 3, and 5. In the image forming apparatus 10, the encrypted data (old) is decrypted using an encryption key (i.e., KEY_A) decrypted from the encryption key data (i.e., ENC1000A) unique to the control board before replacement (old). The plaintext user data generated by decryption is stored in RAM 104.

[0067] Next, the image forming apparatus 10 encrypts the plaintext user data with an encryption key unique to the control board (new) (i.e., KEY_B), and writes the generated encrypted data 106B to the backup non-volatile memory 106. KEY_B is an example of a second encryption key. Furthermore, the master non-volatile memory 105 still stores encrypted data 105B, which was encrypted using an encryption key (i.e., KEY_A) unique to the control board (old).

[0068] Figure 16 is a diagram illustrating the processing operations of steps 121 and 122 (see Figure 8). Figure 16 is denoted with reference numerals corresponding to the parts that correspond to those in Figures 1, 3, and 5. When encrypted data (new) is generated using an encryption key (i.e., KEY_B) unique to the new control board (new), the image forming apparatus 10 stores the encrypted data (new) in the master non-volatile memory 105. As a result, the same encrypted data (new) is stored in both the master non-volatile memory 105 and the backup non-volatile memory 106.

[0069] Finally, the serial number stored in the master non-volatile memory 105 (i.e., SN1000A) is rewritten to a serial number unique to the new control board (i.e., SN1000B). As a result, the same serial number (i.e., SN1000B) is stored in both the master non-volatile memory 105 and the backup non-volatile memory 106.

[0070] <Summary> Even when the master non-volatile memory 105 (see Figure 3) removed from the old control board is installed on the new control board, the encrypted data from the old control board becomes available for use on the new control board. In this embodiment, the transfer of encrypted data is achieved through communication between the newly installed control board (new) and the mobile terminal 20. Therefore, the image forming apparatus 10 does not need to be equipped with a separate board for transferring encrypted data. As a result, the configuration of the image forming apparatus 10 is simplified.

[0071] <Other Embodiments> (1) Although embodiments of the present invention have been described above, the technical scope of the present invention is not limited to the embodiments described above. It is clear from the claims that embodiments with various modifications or improvements made to those described above are also included in the technical scope of the present invention.

[0072] (2) In the above embodiment, a customer engineer was shown replacing the control board 100 (see Figure 1), but the replacement of the control board 100 may be performed by the user of the image forming apparatus 10.

[0073] (3) In the above embodiment, we have illustrated the case in which the board replacement application 21 is installed on a mobile terminal 20 (see Figure 1) carried by a customer engineer, but there are no restrictions on the terminal on which the board replacement application 21 is installed.

[0074] (4) In the above-described embodiment, the case of replacing the control board 100 of the image forming apparatus 10 (see Figure 1) was illustrated, but the target equipment is not limited to the image forming apparatus 10. The target equipment can be any equipment in which encrypted user data is stored in the master non-volatile memory 105 (see Figure 3).

[0075] (5) In the above-described embodiment, the board-specific serial number and handover information are sent to the mobile terminal 20 (see Figure 1) via an NDF tap, but other communication interfaces may be used. For example, the information may be transmitted using a USB cable or a LAN cable. Alternatively, data may be transferred using a USB memory stick, SD card, or other removable recording medium.

[0076] (6) In the above-described embodiment, encryption key data (old) unique to the control board (old) is notified from the mobile terminal 20 to the image forming apparatus 10 via WiFi or WiFi Direct, but other communication interfaces may be used. For example, the information may be communicated using a USB cable or a LAN cable. Alternatively, data may be transferred using a USB memory, SD card, or other removable recording medium.

[0077] (7) In the embodiments described above, each process is performed on any computer. Furthermore, any computer may perform these processes using a processor as hardware, a program as software, or a combination thereof. In that case, the processor is configured to work with the program to perform various processes in the embodiment, and can also function as a unit or means in the embodiment.

[0078] Furthermore, the order in which the processor executes the processes is not limited to the order described and may be changed as appropriate. Any computer may be a general-purpose computer, a computer designed for a specific purpose, a workstation, or any other system capable of performing each process. A processor may consist of one or more pieces of hardware, and the type of hardware is not limited. For example, a processor may consist of a CPU (=Central Processing Unit), an MPU (=Micro Processing Unit), a programmable logic device such as an FPGA (=Field Programmable Gate Array), a dedicated circuit for performing specific processing such as an ASIC (=Application Specific Integrated Circuit), a GPU (=Graphic Processing Unit), or an NPU (=Neural Processing Unit).

[0079] Furthermore, the hardware may be a combination of different types of hardware. When multiple hardware components are configured to execute one or more processes of a processor, these components may reside in physically separate devices or in the same device. Also, in any embodiment, the order of each process performed by the processor is not limited to the order described above and may be changed as appropriate. The hardware is composed of electrical circuits, etc., which are combinations of circuit elements such as semiconductor elements.

[0080] Furthermore, the program may be firmware or software such as microcode. Alternatively, the program may be, for example, a group of program modules, each of which may be implemented by a processor configured to perform its respective function. The program may also be program code or multiple code segments stored in one or more non-temporary computer-readable media (e.g., storage media or other storage devices).

[0081] A program may be divided and stored on multiple non-temporary computer-readable media located on devices that are physically separated from each other. Program code or code segments may represent any combination of procedures, functions, subprograms, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. Program code or code segments may be connected to other code segments or hardware circuits by sending and receiving information, data, arguments, parameters, or memory contents.

[0082] (8) The present invention can also be applied to programs and program products.

[0083] <Note> (((1))) An information processing device having a processor, wherein, after replacing a first board with a second board, if the processor fails to decrypt the first encrypted data stored in a storage device transferred from the first board to the second board, it obtains first encryption key data, which is encrypted using a first encryption key unique to the first board, from an external device connected via another terminal, and decrypts the first encrypted data using the first encryption key decrypted from the obtained first encryption key data. (((2))) The information processing apparatus according to (((1))), wherein the external device stores serial information unique to the board and encryption key data obtained by encrypting the corresponding encryption key, and the processor provides the first serial information unique to the first board read from the storage device to the other terminal, and obtains the first encryption key data corresponding to the first serial information from the other terminal. (((3))) The information processing apparatus according to (((2))), wherein the processor provides the first serial information to the other terminal via a first communication interface and obtains the first encryption key data from the other terminal via a second communication interface different from the first communication interface. (((4))) The information processing device described in (((3))), wherein the first communication interface is NFC and the second communication interface is wireless LAN. (((5))) The information processing apparatus according to (((4))), wherein when the maintenance mode is started, the processor reads the first serial information from the storage device and stores it in the NFC module. (((6))) The information processing apparatus according to any one of (((1))) to (((5))), wherein the processor encrypts the data obtained by decrypting the first encrypted data using a second encryption key unique to the second board and stores it in the storage device. (((7))) An information terminal having a processor, the processor communicates with an information processing device that failed to decrypt the first encrypted data stored in a storage device transferred from the first board to the second board after replacing the first board with a second board, reads the serial information of the first board from the information processing device, obtains first encrypted key data from an external device, which is encrypted using the first encrypted key unique to the first board corresponding to the serial information, and transmits the obtained first encrypted key data to the information processing device. (((8))) A program to enable a computer to perform the following functions if, after replacing the first board with the second board, decryption of the first encrypted data stored in the memory device transferred from the first board to the second board fails, the computer to acquire first encryption key data, which is encrypted using the first encryption key unique to the first board, from an external device connected via another terminal, and to decrypt the first encrypted data using the first encryption key decrypted from the acquired first encryption key data.

[0084] According to the information processing device described in (((1))), the device configuration can be simplified compared to the case where the first encryption key data, which is encrypted using the first encryption key unique to the first circuit board removed from the device, is backed up to another circuit board within the same device. According to the information processing device described in (((2))), it is not necessary to install a separate circuit board for backing up the encryption key within the device. According to the information processing device described in (((3))), the communication interface can be selected according to the information to be exchanged. According to the information processing device described in (((4))), the first encryption key data can be acquired within the device with a single tap operation. According to the information processing device related to (((5))), the first serial information can be provided to other terminals only in maintenance mode. According to the information processing device described in (((6))), the first encrypted data stored in the memory device inherited from the first board can be made available for use on the second board as well. According to the information terminal in (((7))), the first encryption key data, which is encrypted using the first encryption key unique to the first circuit board removed from the device, can be acquired and transferred to the information processing device. According to the program described in (((8))), the first encryption key data, which is encrypted using the first encryption key unique to the first circuit board removed from the device, can be obtained and transferred to the information processing device. [Explanation of symbols]

[0085] 10…Image forming apparatus, 11…Control panel, 101, 201…Processor, 12…Printing engine, 13…Scanner, 14…NFC tag, 15, 207…WiFi module, 20…Mobile terminal, 21…Board replacement app, 30…Access point, 100…Control board, 102A…Firmware, 102B…UEFI, 102C, 110B…Encryption key data, 103, 202…ROM, 103A…Common key, 104, 203…RAM, 105…Master non-volatile memory, 105A, 106A, 110A…Serial number, 105B, 106B…Encrypted data, 105C…Unencrypted data, 106…Backup non-volatile memory, 106B, 106C…Backup data, 110…Database, 204…Non-volatile memory, 205…Touch panel, 206…NFC module

Claims

1. It has a processor, The aforementioned processor, If, after replacing the first board with the second board, the decryption of the first encrypted data stored in the memory device transferred from the first board to the second board fails, The first encryption key data, which is obtained by encrypting the first encryption key unique to the first board, is acquired from an external device connected via another terminal. The first encrypted data is decrypted using the first encryption key decrypted from the acquired first encryption key data. Information processing device.

2. The aforementioned external device stores serial information unique to the circuit board and encryption key data obtained by encrypting the corresponding encryption key. The aforementioned processor, The first serial information specific to the first board, read from the storage device, is provided to the other terminal. The first encryption key data corresponding to the first serial information is obtained from the other terminal. The information processing apparatus according to claim 1.

3. The aforementioned processor, The first serial information is provided to the other terminal via the first communication interface. The first encryption key data is obtained from the other terminal via a second communication interface different from the first communication interface. The information processing apparatus according to claim 2.

4. The first communication interface is NFC, The second communication interface is a wireless LAN. The information processing apparatus according to claim 3.

5. The aforementioned processor, When maintenance mode is started, the first serial information is read from the storage device and stored in the NFC module. The information processing apparatus according to claim 4.

6. The aforementioned processor, The data obtained by decrypting the first encrypted data is encrypted using a second encryption key unique to the second substrate and stored in the storage device. The information processing apparatus according to claim 1.

7. It has a processor, The aforementioned processor, After replacing the first board with the second board, the information processing device that failed to decrypt the first encrypted data stored in the memory device transferred from the first board to the second board communicates with the information processing device, The serial information of the first substrate is read from the information processing device. The first encryption key data, which is obtained by encrypting the first encryption key unique to the first board corresponding to the serial information, is acquired from an external device. The acquired first encryption key data is transmitted to the information processing device. Information terminal.

8. If, after replacing the first board with the second board, the decryption of the first encrypted data stored in the memory device transferred from the first board to the second board fails, On the computer, The first encryption key data, which is encrypted using a first encryption key unique to the first board, is obtained from an external device connected via another terminal. A function to decrypt the first encrypted data using the first encryption key decrypted from the acquired first encryption key data, A program to achieve this.

Citation Information

Patent Citations

  • Image processing system, image processing method, and program

    JP2016116227A