Intermediate circuit for modifying data between a host and a print component

WO2026182744A1PCT designated stage Publication Date: 2026-09-03HEWLETT PACKARD DEVELOPMENT COMPANY LP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/017983
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2026-09-03

Smart Images

  • Figure US2025017983_03092026_PF_FP_ABST
    Figure US2025017983_03092026_PF_FP_ABST
Patent Text Reader

Abstract

An intermediate circuit to connect to a print component and a host controller including a host-side contact array, a component-side contact array, and control logic to intercept, copy, transmit, and / or modify commands and responses between the print component and the host controller.
Need to check novelty before this filing date? Find Prior Art

Description

Atty. Dkt. No.: 86361743INTERMEDIATE CIRCUIT FOR MODIFYING DATA BETWEEN A HOST AND A PRINT COMPONENT REFERENCE TO RELATED PATENTS AND APPLICATIONS

[0001] The present disclosure is related to US Patent No. 8,205,976, US Patent No.: 11,256,654, US Patent No.: 9,619,663, US Patent No.: 10987936, EU Patent No.: 3688602, EP Patent No. 3183121, EU Patent 3181364, PCT Application No.: US2021 / 020262, PCT Application No.: US2019 / 058108, PCT Application No.: US2020 / 030860, US Patent No.: 11,407,229, US Patent No.: 11,453,212, PCT Application No.: US2019 / 016734, US Patent No.: 11,254,153, and PCT Application No.: US2023 / 036542, all of which are incorporated herein by reference.BACKGROUND

[0002] Printers deposit print material (e.g., fluid, ink, toner, resin, biological materials, or other substances, etc.) onto a substrate (e.g., paper, powder, support structures, etc.) to print in two or three dimensions. A print cartridge may store the print material for printing. A logic circuit on the cartridge may interface with a printer control interface, to receive signals from and transmit signals to the printer control interface.

[0003] A cartridge may be made compatible with certain host printers through certain encodings or configurations, requiring authenticated communications and / or confirmation of cryptographic keys. The cartridge may be provided with a memory that includes information about print material (e.g., print material type, color, maximum and / or updated fill level, etc.). The cartridge may respond, based on data in the memory, to queries from a host printer to indicate base keys, metadata, manufacturing data of the cartridge, color map parameters, configuration data of the cartridge, updated print material level, and other data. The cartridge may respond to signals from the host printer with responses that indicate a correct installation and functioning of circuitry of the cartridge. Over the years, cartridge chips have been14899-5990-1972.11Atty. Dkt. No.: 86361743provided with more advanced functionalities including additional parameters, authentication functions and security functions. At the same time, there may be a desire to refill a cartridge with new print material while being able to make use of (at least part of) the functionalities and data of the original cartridge and chip, such as updated print material level indication.BRIEF DESCRIPTION OF THE DRAWINGS

[0004] FIG. l is a block diagram of an example intermediate circuit.

[0005] FIG. 2 is a block diagram of an example intermediate circuit connected to a host and a component circuit.

[0006] FIG. 3 is a perspective view of an example print component with an intermediate circuit overlaying a component circuit.

[0007] FIG. 4 is a close view of the example print component of FIG. 3, with the intermediate circuit peeled up to expose a component circuit.

[0008] FIG. 5 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, a cryptographically authenticated intermediate response to a host.

[0009] FIG. 6 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, an intermediate response to a host.

[0010] FIG. 7 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, an unauthenticated intermediate response to a host.

[0011] FIG. 8 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, data to a host based on data from a print component.

[0012] FIG. 9 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, partition configuration data to a host.24899-5990-1972.11Atty. Dkt. No.: 86361743

[0013] FIG. 10 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, base key table data to a host.

[0014] FIG. 11 is a flow diagram illustrating operations of an example method for driving, by an intermediate circuit, a host-side data line of the intermediate circuit low in response to a voltage monitoring command from a host.

[0015] FIG. 12 is a flow diagram illustrating operations of an example method for establishing, by an intermediate circuit, a secure session with a host and a secure session with a print component.

[0016] FIG. 13 is a flow diagram illustrating operations of an example method for transmitting commands and responses between a host, an intermediate circuit, and a component using a secure session between the host and the intermediate circuit.

[0017] FIG. 14 is a flow diagram illustrating operations of an example method for transmitting commands and responses between a host, an intermediate circuit, and a component using a secure session between the host and the intermediate circuit and a secure session between the intermediate circuit and the component.

[0018] FIG. 15 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, a response to a timing challenge from a host.

[0019] FIG. 16 is a flow diagram illustrating operations of an example method for providing, by an intermediate circuit, transform map metadata to a host.

[0020] The foregoing and other features of the present disclosure will become apparent from the following description and appended claims, taken in conjunction with the accompanying drawings. Understanding that these drawings depict only several examples in accordance with the disclosure and are therefore, not to be considered limiting of its scope, the disclosure will be described with additional specificity and detail through use of the accompanying drawings.34899-5990-1972.11Atty. Dkt. No.: 86361743DETAILED DESCRIPTION

[0021] In the following detailed description, reference is made to the accompanying drawings, which form a part hereof. In the drawings, similar symbols typically identify similar components, unless context dictates otherwise. The illustrative examples described in the detailed description, drawings, and claims are not meant to be limiting. Other implementations may be utilized, and other changes may be made, without departing from the spirit or scope of the subject matter presented here. It will be readily understood that the aspects of the present disclosure, as generally described herein, and illustrated in the figures, can be arranged, substituted, combined, and designed in a wide variety of different configurations, all of which are explicitly contemplated and made part of this disclosure.

[0022] This disclosure relates to print components, such as print cartridges. Print components may include reservoirs to provide ink to a printhead. Print components may include integrated circuits to communicate with the host printer. The integrated circuits include memory and control logic to provide data in response to host printer commands, including signals indicating a configuration and / or correct functioning of the print component, and to execute encryption and / or authentication algorithms and calculations. Authentication includes generating a message authentication code using a key (e.g., session key) and including the message authentication code in a command / response, where the receiver of the command / response generates the same message authentication code using the same key to verify a match. Encryption, as discussed herein, includes using a key (e.g., a session key) to mathematically convert data into an encrypted form that can be decrypted using the same key.

[0023] A print component may be any component for print systems, such as an exchangeable print cartridge, or a component of a cartridge such as a fluid ejection device (e.g., printhead) or other integrated circuit associated with a cartridge. A print component may include a reservoir for storing print material. The print material may include any 2D or 3D print agent 44899-5990-1972.11Atty. Dkt. No.: 86361743including ink or toner for printing on a medium such as paper (2D) or (e.g., powdered) build material (3D). The print material may include dispensable fluid to be dispensed at relatively high precision (as to volume and / or location) for fields of implementation other than 2D or 3D imaging, including but not limited to forensic, laboratory or pharmaceutical applications. In some implementations, the print component includes an intermediate circuit to adjust characteristics of the print component and / or signals exchanged between the print component and a host.

[0024] In one example of this disclosure, intermediate circuits are integrated circuits configured to detect certain host printer signals, and / or respond to and / or transmit these host printer signals to print components. These intermediate circuits may be used to replace, change, add or renew certain functions with respect to an associated print component. It is noted that the functions disclosed in this disclosure can also be implemented in a print component, rather than separate from it. Intermediate circuits disclosed herein could be part of the print component or added to the print component. The intermediate circuit may be attached to, and / or a part of, a print cartridge, or may be adapted to be attached to print cartridges and print cartridge circuits. In this disclosure, an original logic circuit that is connected to a component such as a print cartridge may be referred to as component circuit. In an example, an intermediate circuit is added to a print component, for example connected to the component circuit, to alter characteristics of the print component as seen by a host printer. In again other examples, in use, the intermediate circuit may be attachable to the host (e.g., printer) contact array in the host, to connect to, and between, the component circuit and the host controller when the component is installed in the host. In other examples, the intermediate circuit may be configured to be connected anywhere between the component circuit (when installed) and host controller. For example, the intermediate circuit may be54899-5990-1972.11Atty. Dkt. No.: 86361743communicatively coupled to the I2C serial bus anywhere between the component circuit (when installed) and host controller.

[0025] In one example, one intermediate circuit is provided, which is configured to communicatively connect to one cartridge with component circuit. In other examples, there may be one intermediate circuit configured to be, in operation, connected to a plurality of component circuits, for example to a set of (e.g., four) cartridge component circuits.

[0026] The intermediate circuit can be attached or attachable to a cartridge, where the cartridge includes a plastic body (e.g., including a reservoir) and an integrated circuit to receive commands from the host printer and provide data to the host printer. The intermediate circuit can be communicatively connected to the integrated circuit of the cartridge. The integrated circuit and / or intermediate circuit may be, or at least function as, a microcontroller. The intermediate circuit may include a thin substrate such as a thin PCB or flexible circuit to allow it to be attached over a cartridge’s integrated circuit (or at least over the contact pads) between the cartridge’s integrated circuit and printer-side circuitry, for example, to intercept and / or selectively transmit printer signals intended for the cartridge’s integrated circuit. In some examples, the intermediate circuit could be connected to the host’s contact array.

[0027] In one example, the intermediate circuit may receive signals from a host controller (such as an ASIC print controller of a printer) and respond to the host controller with response signals, for example, in lieu of an associated print component integrated circuit. In another example, the intermediate circuit attached to a print cartridge may receive signals from the host controller and modify them for delivery to the print cartridge, that is, the integrated circuit of the print cartridge. The intermediate circuit may receive signals from the print cartridge (i.e., its integrated circuit) and modify them for delivery to the host controller. The intermediate circuit may also allow some signals to pass unchanged between the host controller and the print component. In fact, the intermediate circuit may be configured to 64899-5990-1972.11Atty. Dkt. No.: 86361743respond in lieu of the print component circuit, and / or transmit signals to and from the print component directly without changes, and / or selectively modify commands to and responses from the print component. In this description, when the intermediate circuit receives or transmits signals from or to the cartridge / component or printer, this implies that the intermediate circuit receives or transmits signals from or to the respective circuits of these devices. The intermediate circuit may be a logic circuit attached to the print cartridge with a component-side contact array connected to the print component and a host-side contact array connected to the host controller when the print cartridge is in an installed state.

[0028] The intermediate circuit may be attached to the print cartridge in order to modify signals of the host controller and / or the host, such as a printer, to the print component, to modify output from the print component to the host; or, to output signals to the host directly that are generated and / or stored by the intermediate circuit. The intermediate circuit may also transmit signals directly to and from the integrated circuit of the print component without altering the signal content, which content could include data.

[0029] Different types of print components may be compatible with certain series of hosts, and incompatible with other series of hosts. Furthermore, print components may include memory bits indicating use of the print components, for example indicating consumed and / or remaining fluid level. Furthermore, it may be a difficult, and / or it may be a cost, time and / or resource consuming effort, to reproduce data and / or functions of an original integrated circuit of a print component in a new integrated circuit to reproduce the original functionalities of the original integrated circuit.

[0030] The intermediate circuit attached to the print cartridge may provide and / or modify signals to / from the host such that the host views the cartridge as being compatible and / or filled. Furthermore, hosts, such as printers, may be configured to analyze signals from print components to verify that the cartridges are in good condition and / or operating as expected 74899-5990-1972.11Atty. Dkt. No.: 86361743and / or compatible. The intermediate circuit attached to the print cartridge may provide and / or modify signals to / from the host such that the host treats the cartridge with intermediate circuit the same as a compatible and / or filled cartridge, or a cartridge that is in good condition and / or operating as expected. In an example, a printer may indicate a low ink level, based on the printer’s estimate of an ink level of a print cartridge. In this example, if the original print component is associated with a low-fill original print cartridge, but that cartridge has been refilled to a level associated with a high-fill print cartridge, the intermediate circuit may modify signals between the print component and the host such that the host views the print component as a high-fill print cartridge. The intermediate circuit may facilitate the refilling, remanufacturing, reconditioning and / or renewal of used cartridges and cartridge components by an OEM (Original Equipment Manufacturer) or third party. Also, certain data and / or functionalities of associated integrated circuits of print components do not need to be present, at least not completely, in the intermediate circuit, which could make it simpler to reproduce the intermediate circuit as compared to manufacturing integrated circuits with complete functionalities. The intermediate circuits could be alternative integrated circuits avoiding certain OEM proprietary functions present on the print component. The intermediate circuits could ensure that used components and component circuits have a desired compatibility and functionality when installed in the host system.

[0031] FIG. 1 is a block diagram of an example intermediate circuit 100 including a host-side contact array 110, a component-side contact array 120, and control logic 102. The host-side contact array 110 is to electrically connect the intermediate circuit 100 to a host controller. The host-side contact array 110 corresponds to a contact array on a host controller, in terms of contact pad layout and function. The host-side contact array 110 is to transmit signals between the intermediate circuit 100 and the host controller. The host-side contact array 110 includes multiple contacts, each contact to receive and / or transmit different electrical signals.84899-5990-1972.11Atty. Dkt. No.: 86361743In some implementations, the host-side contact array 110 receives and / or transmits combinations of signals on the multiple contacts. The component-side contact array 120 is to electrically connect the intermediate circuit 100 to a print component (or other component). The component-side contact array 120 corresponds to a contact array on an interconnect circuit of the print component. The interconnect circuit may be part of an integrated circuit package, such as a microcontroller package, and may include contacts, for example I2C serial bus contacts. The component-side contact array 120 is to transmit signals between the intermediate circuit 100 and the print component. The component-side contact array 120 includes multiple contacts, each contact to receive and / or transmit different electrical signals. In some implementations, the component-side contact array 120 receives and / or transmits combinations of signals on the multiple contacts.

[0032] The intermediate circuit 100 may receive signals at the host-side contact array 110 and allow the received signals to be transmitted to a print component at the component-side contact array 120. In this way, the intermediate circuit 100 allows signals from the host controller to pass through to the print component. The intermediate circuit 100 may receive signals at the host-side contact array 110 and modify the received signals and / or generate different signals for transmission at the component-side contact array 120. In this way, the intermediate circuit 100 intercepts signals from the host controller intended for the print component. The intermediate circuit 100 may similarly treat signals from the print component intended for the host controller by passing them through, intercepting them, and / or modifying them. The control logic 102 controls whether signals are copied, stored, modified, passed through, and generated by the intermediate circuit 100. In this disclosure when we refer to the intermediate circuit 100 being configured to execute a function, this also means that the control logic is configured for that function.94899-5990-1972.11Atty. Dkt. No.: 86361743

[0033] Note that it could be possible that one or more opposite contacts of the contact arrays 110, 120 form an integral contact used to transmit one or more signals to / from the host and to transmit one or more signals to / from the print component, as controlled by the control logic 102. A signal may include data, a current, a voltage, etc.

[0034] The intermediate circuit 100 may be a thin circuit. In some implementations, the intermediate circuit 100 includes a thin printed circuit board (PCB). The intermediate circuit 100, or at least its contacts, may be thin enough to fit between a host controller contact array and an interconnect circuit contact array of the cartridge, at least in connected condition of the host controller contact array, interconnect circuit contact array and intermediate circuit, without interfering with relative positions of the host and print component. Without the intermediate circuit 100 in between, in an installed state of the cartridge, the host controller contacts and the interconnect circuit contacts of the cartridge would still be in permanent contact. An interconnecting portion of the intermediate circuit 100 may be thin enough to be able to be placed between the host controller contacts and the interconnect circuit contacts in the installed state. In some implementations, interconnecting portions of the intermediate circuit 100, including routing and support / insulative substrate, have a maximum thickness of less than two millimeters or less than a millimeter. In some examples, the intermediate circuit may be adapted so that, when assembled in the print component, control logic and / or other circuitry of the intermediate circuit is located away from the interconnecting contact arrays of the host, print component and intermediate circuit, to avoid interference with the contacts and help keep the contact arrays flat.

[0035] As discussed herein, the intermediate circuit 100 may be used to modify signals between the host controller and the print component such that the host controller views the print component as a compatible, and / or unused (or less used) print component in good condition and / or operating as expected. Thus, portions of the intermediate circuit 100 may 104899-5990-1972.11Atty. Dkt. No.: 86361743need to be thin enough to fit between the host controller and the print component without requiring modification of the host structure or host signals. The intermediate circuit 100 may include a flexible circuit with the contacts on two sides, the respective host and componentside, whereby the flexible circuit may include an insulative layer that in interconnected condition extends between some of the host- and component-side contacts.

[0036] FIG. 2 is a block diagram of an example intermediate circuit 200 connected to a host 201 and a component circuit 230 of a print component 203 (e.g., print cartridge). For example, this illustrates a condition wherein the intermediate circuit 200 is attached to the print cartridges, whereby the print cartridge with intermediate circuit 200 is installed in a host printer. The intermediate circuit 200 may be similar to the intermediate circuit 100 of FIG. 1. The intermediate circuit 200 includes a host-side contact array 210, control logic 202, and a component-side contact array 220. The host-side contact array 210 interfaces (i.e., contacts, electrically interfaces) with a host contact array of the host 201. The component-side contact array 220 interfaces with a component contact array 240 of the component circuit 230. The component circuit 230 includes the component contact array 240 and control logic 232.

[0037] The component circuit 230 is coupled to the print component 203. The component contact array 240 of the component circuit 230 is configured to interface with the host contact array of the host 201 when the print cartridge is installed in the host 201. The control logic 232 of the component circuit 230 is configured to generate responses to electrical signals received via the component contact array 240 from the host 201 and to provide the generated responses (i.e., electrical signals) to the host 201 via the component contact array 240. The responses from the component circuit 230 to the host can include data stored in a memory of the print component 203.

[0038] In some implementations, the component-side contact array 220 of the intermediate circuit covers the component contact array 240 so that the host’s contact array contacts the 114899-5990-1972.11Atty. Dkt. No.: 86361743host-side contact array 210 of the intermediate circuit instead of the component contact array 240, in an installed condition of the print component 203 with intermediate circuit 200. In some implementations, the intermediate circuit 200 covers an entirety of the component circuit 230. In some implementations, the intermediate circuit 200 covers only a portion of the component circuit 230. In some implementations, the intermediate circuit 200 does not cover the component circuit 230, but includes electrical connections (e.g., wires) to the component contact array 240.

[0039] In some implementations, the component-side contact array 220 interfaces with all of the electrical contacts of the component contact array 240. In some implementations, the component-side contact array 220 interfaces with a portion of the electrical contacts of the component contact array 240, for example at least a data contact or data and clock. The component contact array 240 can include a voltage contact (VCC) to receive voltage to power the print component, a clock contact (SCL) to receive a clock signal, a ground contact (GND) to connect the print component to ground, and a data contact (SDA) to transmit and receive data. In an example, the component-side contact array 220 and the host contact array (not shown) includes a voltage contact to connect to the voltage contact of the component contact array 240, a clock contact to connect to the clock contact of the component contact array 240, a ground contact to connect to the ground contact of the component contact array 240, and a data contact to connect to the data contact of the component contact array 240. In an example, the component-side contact array 220 includes a data contact to connect to the data contact of the component contact array 240 and a clock contact to connect to the clock contact of the component contact array 240, but does not include contacts to connect to the voltage and ground contacts of the component contact array 240. In this example, when connected to the host, the voltage and ground contacts of the component contact array 240 may be coupled to voltage and ground contacts of the host contact array of the host 201 such that the component124899-5990-1972.11Atty. Dkt. No.: 86361743circuit 230 receives voltage and a connection to ground from the host 201. The host-side contact array 210 may similarly include at least clock (SCL) and data (SDA), and also ground (GND) and power (VCC) even though one or both of the latter two contacts can be avoided. The contact arrays 210, 220 of the intermediate circuit may constitute a I2C serial bus interface between control logics of the respective interconnected devices (print component, intermediate circuit, host).

[0040] In some implementations, the intermediate circuit 200 receives power from the host 201. In some implementations, the intermediate circuit 200 includes a battery to provide power for operations of the intermediate circuit 200. If the intermediate circuit 200 does not include a host-side voltage contact (e.g., a voltage contact on the host-side contact array 210 to receive voltage from the host 201) and a component side voltage contact (e.g., a voltage contact on the component-side contact array 220 to provide power to the component circuit 230), the intermediate circuit 200 does not receive power from the host 201 and can instead draw power from the battery of the intermediate circuit 200. The print component 203 can receive power from the battery or the host 201.

[0041] The intermediate circuit 200 can be coupled to the print component 203 and its component circuit 230 prior to installation of the print component 203 in order to interface with the component contact array 240 and the host contact array when the print component 203 is installed in the host 201. In this way, the intermediate circuit 200 is positioned to intercept electrical signals from the host 201 and from the component circuit 230. The intermediate circuit 200 can source, intercept, route, and / or modify the electrical signals from the host 201 and / or the component circuit 230 in order to respond to the host 201. The intermediate circuit 200 may be configured to source responses from the print component 203 so that the functionality or data it sources from the print component 203 does not need to be present on the intermediate circuit 200. The intermediate circuit 200 may be configured to (i)134899-5990-1972.11Atty. Dkt. No.: 86361743transmit directly or copy completely (or substantially) the response from the print component, and / or, (ii) modify or use the response of the print component to generate its own different response. In an example, the intermediate circuit 200 receives a set of electrical signals from the host 201 including a request for a type of cartridge of the print component 203. In this example, the intermediate circuit 200 provides (e.g., passes through, transmits, routes, etc.) the request to the component circuit 230 and the component circuit 230 provides a set of electrical signals including a response indicating a type of the print component 203. In this example, the intermediate circuit 200 modifies the set of electrical signals received from the component circuit 230 to provide a different set of electrical signals to the host 201 indicating a different type of print component. In this way, the intermediate circuit 200 can cause the host 201 to generate signals for the different type of print component instead of the actual type of the print component 203. The “type” may be associated with a particular region, cartridge number, SKU, or ID.

[0042] The control logic 202 of the intermediate circuit 200 determines which electrical signals from the host 201 and / or the component circuit 230 to pass through and / or modify. In this way, the intermediate circuit 200 is able to allow some electrical signals (e.g., requests, messages, commands) to pass through unchanged between the host 201 and the print component 203 and vice versa while modifying or generating its own response for others. In certain examples, in a normal use scenario that could concern installation of the print component with intermediate circuit 200 and executing several print jobs in the host printer, the intermediate circuit 200 provides its own responses for more than half of the standard communications between the print component (with intermediate circuit) and host (e.g., time-wise or bitlength-wise), without referring to the print component circuit 230, while using the print component responses in less than half of the standard communications, meaning that the intermediate circuit is able to execute most operations by itself, while only selectively144899-5990-1972.11Atty. Dkt. No.: 86361743referring to the print component circuit 230 for generating responses to the host for certain specific commands and / or data requests. The intermediate circuit 200, more particularly its control logic 202, is also configured to directly generate responses to host commands, and cryptographically authenticate these responses, without referring to the component circuit 230. The intermediate circuit 200, more particularly its control logic 202, is configured to decide if it will generate a response of its own, or at least partially defer to the component circuit 230, depending on the host command, for example depending on the type of host command.

[0043] The intermediate circuit 200 can establish different secure cryptographic sessions between the intermediate circuit 200 and the host 201 and between the intermediate circuit 200 and the component circuit 230, using different cryptographic keys for the different cryptographic sessions. In some implementations, the intermediate circuit 200 can establish a secure cryptographic session with one of the host 201 and the component circuit 230 while exchanging unencrypted signals with the other of the host 201 and the component circuit 230. In this way, the intermediate circuit 200 is able to authenticate its signals with the host 201 and / or the component circuit 230 in order to alter responses of the host 201 and / or the component circuit 230.

[0044] In other examples, the intermediate circuit can be connected and / or fixed to the printer, so that it is preinstalled in the printer before the print component is installed. The intermediate circuit may be connected anywhere along the printer-side I2C bus, on the host contact array or between the host contact array and the host controller. The host-side contact array of the intermediate circuit may be connected to the host contact array. The componentside contact array of the intermediate circuit may contact the component contact array only when the print component is installed. The intermediate circuit could be configured to remain installed while several components are replaced and connected to the intermediate circuit. For 154899-5990-1972.11Atty. Dkt. No.: 86361743example, the intermediate circuit could be mounted in a cartridge receiving slot with its hostside contact array over the printer contact array, so that the component circuit connects to the component-side contact array of the intermediate circuit. Some or all of the digital and electrical characteristics of the intermediate circuit that is pre-attached to the host could be the same as some or all of the digital and electrical characteristics of the intermediate circuit that is pre-attached to the component. Therefore, the example features explained in the several examples of this disclosure of intermediate circuits, whether or not it is specified that these are for pre-attachment to a print component, may equally apply to intermediate circuits for pre-installation to or in a host. Both example intermediate circuits are to connect to the print component and host controller during usage.

[0045] FIG. 3 is a perspective view of an example print component 303, in an assembled condition of the intermediate circuit 300. The print component 303 may be similar to the print component 203 of FIG. 2 and the intermediate circuit 300 may be similar to the intermediate circuit of FIG. 1 and / or 2. The print component 303 is a print cartridge including a reservoir for storing print fluid. In an example, the print component 303 is to provide the print fluid to a separate printhead in the printer. The print component 303 includes a component circuit which is not visible in FIG. 3, as the component circuit is covered by an intermediate circuit 300 including a host-side contact array 310. The component circuit may be a microcontroller provided with logic and an I2C serial bus contact array. Also the intermediate circuit 300 may be, or function as, a microcontroller provided with logic and multiple (e.g., 2) I2C serial bus contact arrays. The intermediate circuit 300 covers the component circuit such that a host contact array interfaces with the host-side contact array 310 instead of a component contact array of the component circuit. In certain examples, in assembled condition, it is sufficient that the host-side contact array 310 of the intermediate circuit 300 extends over the component contact array 340 (Fig. 4), at least partially, to intercept and respond to signals from the host164899-5990-1972.11Atty. Dkt. No.: 86361743contact array, while the rest of the intermediate circuit 300 does not necessarily cover the component circuit. The intermediate circuit 300 further includes a component-side contact array 320 that interfaces with the component contact array 340.

[0046] FIG. 4 is a close view of the print component 303 of FIG. 3, with the intermediate circuit 300 peeled up to expose the component circuit 330. The component circuit includes the component contact array 340. The intermediate circuit 300 is positioned on top of the component circuit 330 such that the host-side contact array 310 overlays the component contact array 340 such that the host-side contact array 310 interfaces with the host contact array when the print component 303 is installed in the host instead of the component contact array 340 interfacing with the host contact array and the component-side contact array 320 of the intermediate circuit 300 interfaces with the component contact array 340.

[0047] FIG. 5 is a flow diagram illustrating operations of an example method 500 for providing, by an intermediate circuit, a cryptographically authenticated intermediate response to a host. The method 500 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 500 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0048] At operation 510, the intermediate circuit receives, at a host-side contact array of the intermediate circuit, from a host controller, a cryptographically authenticated host command. The host controller may be electrically coupled to the intermediate circuit to provide electrical signals at the host-side contact array. In an example, the host controller is a component of a printer for transmitting electrical signals to removable print components, such as print cartridges, and includes a set of electrical contacts that contact the host-side contact array of the intermediate circuit when a print cartridge including the intermediate circuit is installed in the printer.174899-5990-1972.11Atty. Dkt. No.: 86361743

[0049] In some implementations, the cryptographically authenticated host command is cryptographically authenticated using a message authentication code generated by the host controller using a cryptographic key. The cryptographic key can be referred to as a “session key,” and can be used by the host controller and / or the intermediate circuit to authenticate messages between the host controller and the intermediate circuit. The session key can be generated for each communication session based on a base key and / or secret key. The intermediate controller can generate a session key identifier and a corresponding session key and transmit the session key identifier to the host controller. The session key identifier can include a portion from the originator of a start session command (the host controller) that is included in the start session command and another portion from the respondent (the intermediate circuit). The host controller can identify the session key using the session key identifier in order to authenticate signals (e.g., messages, commands, requests, etc.) from the intermediate circuit including message authentication codes generated using the session key. Likewise, the intermediate circuit can authenticate signals from the host controller including authentication codes generated using the session key.

[0050] In order to authenticate the cryptographically authenticated host command, the host controller and the intermediate circuit establish a cryptographic session prior to the intermediate circuit receiving the host command. In some implementations, the intermediate circuit receives a command from the host controller to establish a cryptographic session, establishes the cryptographic session with the host controller (including transmitting the session key identifier to the host controller), and, in response to the command from the host controller to establish the cryptographic session, sends a command to the print component to start a cryptographic session to establish a cryptographic session between the intermediate circuit and the print component. In an example, the intermediate circuit, in response to a command from the host controller to start a cryptographic session, transmits a command to184899-5990-1972.11Atty. Dkt. No.: 86361743the print component to start a cryptographic session in order to establish parallel sessions with the host controller and the print component. In an example, the intermediate circuit, in response to a command from the host controller to initiate a secure cryptographic session, provides, at the host-side contact array, to the host controller a secure host cryptographic session key ID, transmits a command to the print component to establish a secure cryptographic session, and receives, at the component-side contact array, from the print component, a secure component cryptographic session key ID. In this example, the intermediate circuit can perform these operations in various different orders, such as receiving the secure component cryptographic session key ID before providing the secure host cryptographic session key ID to the host controller.

[0051] The session keys (and corresponding session key IDs) can be generated using information stored on the host, the intermediate circuit, and / or the print component. The session keys are generated using the session key IDs and base keys and / or secret keys stored on the host, the intermediate circuit, and / or the print component. The session key IDs can include a first portion from an originator of the session (i.e., the host controller or the intermediate circuit) and a second portion from a respondent to the session (i.e., the intermediate circuit or the print component). In an example, the session key IDs include a cryptographic session counter corresponding to a number of cryptographic sessions established using the corresponding base key, where each base key is associated with a corresponding session counter. The print component generates the secure component cryptographic session key using the corresponding session key ID that includes a print component session counter corresponding to a number of cryptographic sessions established by the print component using the corresponding base key over a lifetime of the print component. The intermediate circuit generates the secure host cryptographic session key using an intermediate cryptographic session counter for the corresponding base key that is194899-5990-1972.11Atty. Dkt. No.: 86361743incremented based on cryptographic sessions established between the intermediate circuit and the host controller using the corresponding base key, where the base key used for the session between the intermediate circuit and the print component can be different from the base key used for the session between the intermediate circuit and the host controller. The intermediate cryptographic session counter can be initialized based on the print component session counter or a different number (e.g., smaller number). By using a smaller number, the intermediate circuit can indicate to the host controller that the print component has been used less than it has, by indicating a lower number of cryptographic sessions than indicated by the print component session counter.

[0052] In some implementations, the intermediate circuit does not establish a cryptographic session with the print component in response to establishing a cryptographic session with the host controller, but instead establishes a cryptographic session with the print component in response to a command or request from the host controller requiring information from the print component. In an example, the intermediate circuit establishes a cryptographic session with the print component in response to the cryptographically authenticated host command from the host controller.

[0053] At operation 520, the intermediate circuit provides, in response to the host command, at a component-side contact array of the intermediate circuit, to a print component, a cryptographically authenticated intermediate command based on the host command. The cryptographically authenticated intermediate command may be cryptographically authenticated using a message authentication code generated by the intermediate circuit using another session key (i.e., a different session key than the one used for the session between the intermediate circuit and the host controller). In some implementations, the intermediate circuit uses the same session key for authenticating signals between the intermediate circuit and the host controller and for authenticating signals between the intermediate circuit and the 204899-5990-1972.11Atty. Dkt. No.: 86361743print component. In some implementations, the intermediate circuit uses separate session keys for authenticating signals between the intermediate circuit and the host controller and for authenticating signals between the intermediate circuit and the print component.

[0054] The intermediate command can be based on the host command by including or copying portions of the host command, by modifying portions of the host command, and / or by corresponding to a same command type as the host command. In this way, the intermediate circuit can pass through and / or modify signals from the host controller to the print component. In an example, the host command is a command to provide data stored on the print component (a read command) and the intermediate command is a command to provide different data stored on the print component.

[0055] At operation 530, the intermediate circuit receives, at the component-side contact array, from the print component, a cryptographically authenticated component response. The component response is in response to the intermediate command. Thus, as the intermediate command is based on the host command, the component response may or may not correspond to a response the print component would provide in response to the host command. If the intermediate circuit modified the host command to generate the intermediate command, the component response is different than a response the print component would provide in response to the host command.

[0056] At operation 540, the intermediate circuit provides, at the host-side contact array, to the host controller, a cryptographically authenticated intermediate response based on the component response as a response to the cryptographically authenticated host command. The intermediate response based on the component response can include a portion of the component response and / or a modified portion of the component response, and can correspond to a same type of response (e.g., responding to a similar query, including similar214899-5990-1972.11Atty. Dkt. No.: 86361743data) as the component response. In this way, the intermediate circuit can pass through and / or modify signals from the print component to the host controller.

[0057] In some implementations, the cryptographically authenticated host command, the cryptographically authenticated intermediate command, the cryptographically authenticated component response, and / or the cryptographically authenticated intermediate response are encrypted. In some implementations, the method 500 includes decrypting, by the intermediate circuit, using a host encryption key, the host command, encrypting, using a component encryption key, the decrypted host command, or a modified version thereof, to generate the cryptographically authenticated intermediate command. The host encryption key can be used to encrypt and decrypt signals between the intermediate circuit and the host controller, and the component encryption key can be used to encrypt and decrypt signals between the intermediate circuit and the print component. In some implementations, the host encryption key is the same as the secure host cryptographic session key. In some implementations, the component encryption key is the same as the secure component cryptographic session key. In some implementations, encryption and authentication are performed in separate cryptographic operations. In an example, an encryption key is used to encrypt plaintext to generate cyphertext, and then an authentication key is used to generate a message authentication code. In some implementations, encryption and authentication are performed in a single cryptographic operation using a single key. In an example, a session key is used to perform authenticated encryption in which plaintext is encrypted to generate cyphertext and a message authentication code is generated. Reference is made to US9619663B2.

[0058] In some implementations, the method 500 includes, in response to a data read request from the host controller, the request including a location and / or a length of the data, requesting, by the intermediate circuit, the data from the print component based on the host request, receiving, by the intermediate circuit, the component data, and responding, by the 224899-5990-1972.11Atty. Dkt. No.: 86361743intermediate circuit, with data including the component data to the host controller. In an example, the cryptographically authenticated host command includes the data read request, the cryptographically authenticated intermediate command includes the request for the data to the print component, the cryptographically authenticated component response includes the component data, and the cryptographically authenticated intermediate response includes the data including the component data. Further details are provided in FIG. 8.

[0059] In some implementations, the print component is configured to store, or provide, transform map primitive data and / or transform map metadata, and wherein the control logic of the intermediate circuit is configured to transmit a response that is at least partly based on, and / or copies, at least a part of the transform map primitive data and / or transform map metadata in response to a map data read request from the host controller. The map data read request and response may be an embodiment of the previous example of the data read request and response. The transform map (primitive) data and metadata may concern primitive data and metadata associated with a plurality of transform maps. The transform map may be referred to as a channel map, color map, color table or color conversion table. The transform map may be stored in a compressed and / or deconstructed form, whereby the compressed and / or deconstructed data components may be referred to as primitive data. The metadata and primitive data for the plurality of transform maps may be compressed as a single blob. In an example, the cryptographically authenticated host command includes the map data read request, the cryptographically authenticated intermediate command includes an intermediate map data read request, the cryptographically authenticated component response includes the transform map primitive data and / or the transform map metadata, and the cryptographically authenticated intermediate response includes the at least part of the transform map primitive data and / or transform map metadata. In some implementations, the cryptographically authenticated intermediate response includes an intermediate transform map based on the234899-5990-1972.11Atty. Dkt. No.: 86361743print component transform map primitive data and / or transform map metadata. In an example, the intermediate circuit can substitute transform map primitive data and / or transform map metadata from an earlier version of the print component (e.g., earlier model, earlier state) for the transform map primitive data and / or transform map metadata actually stored on the print component. In this way, the intermediate circuit can cause the host controller to generate a transform map for the earlier version of the print component instead of the actual print component. Further details are provided in FIG. 9. Reference is made to WO2016 / 028272A1, US10027853B2, WO2018 / 009235 and WO2022 / 093228A1.

[0060] FIG. 6 is a flow diagram illustrating operations of an example method 600 for providing, by an intermediate circuit, an intermediate response to a host. The method 600 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 600 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0061] At operation 610, the intermediate circuit (intermediate integrated circuit) receives, at a host-side contact array of the intermediate circuit, from a host controller, a host command.

[0062] At operation 620, the intermediate circuit, in response to the host command, provides, at the component-side contact array, to the print component, an intermediate command that is either the host command or an altered command that is based on the host command.

[0063] At operation 630, the intermediate circuit receives, at the component-side contact array, from the print component, a print component response.

[0064] At operation 640, the intermediate circuit provides, at the host-side contact array, to the host controller, an intermediate response that includes the print component response or an altered (e.g., different) response that is based on the print component response, the244899-5990-1972.11Atty. Dkt. No.: 86361743intermediate response comprising at least one of a list of base key attributes, data attributes, cryptographically authenticated transform map data, and a low voltage data signal that is held low for at least one duration and / or at a timing that is based on the component response low voltage signal. Reference is made to US8205976B2 and US11256654B2.

[0065] The intermediate command can be based on the host command and / or the intermediate response can be based on the print component response by including a same command type code as the command on which the intermediate command is based, by copying a portion of the command and / or by modifying a portion of the command. The intermediate command may include a different command code, but of a same command code type (e.g., having the same function) as the original command. In an example, the host command is a cryptographically authenticated read command including a command code for authenticated read commands and the intermediate command is an unauthenticated read command including a command code for unauthenticated read commands. In this example, although the command codes for the host command and the intermediate command are different, they both correspond to a same type of command, or a same command code type (i.e., read command).

[0066] In instances where the intermediate response includes the list of base key attributes, the list of based key attributes can be modified or altered from a print component list of base key attributes in the print component response to modify a session counter value. As discussed herein, the session counter value for a base key indicates a number of cryptographic sessions established by the print component using the base key, where the total number of sessions across all base keys roughly corresponds to an age or use of the print component. By modifying the session counter values in the print component list of base key attributes, the intermediate circuit can indicate to the host controller that the print component is newer, or less used, than the print component actually is in order to modify what commands or signals the host controller sends to the print component and / or how the host controller reacts to the 254899-5990-1972.11Atty. Dkt. No.: 86361743age or usage of the print component. In an example, the host controller may generate an alert of an end of lifetime or low ink warning based on the session counter value being above a predetermined threshold, but the intermediate circuit can prevent such alerts / warnings by modifying the session counter value. In some implementations, the list of base key attributes includes a plurality of session counter values corresponding to a plurality of base keys, and the intermediate circuit modifies one or more of the plurality of session counter values in generating the list of base key attributes such that the list of base key attributes provided to the host controller includes the one or more modified session counter values. In some implementations, the base keys are used as session keys and / or are used to generate session keys, where the session counter values correspond to a number of times the base keys have each been used as a session key, or used to derive (generate) a session key. Additional detail is provided in FIG. 12.

[0067] The component circuit may store a partition configuration that assigns attributes assigned to each partition, including data addresses, encryption attributes and access modes for each partition. In some implementations, the data attributes provided by the intermediate circuit to the host controller include modified or altered data attributes of the print component based on data attributes of the print component in the print component response. In other implementations, the intermediate circuit is configured to copy and / or transmit the complete partition configuration data or parts of the configuration data from the component circuit in its response to the host. In some implementations, the data attributes of the print component include a data partition configuration (e.g., datastore partition configuration) of the print component, and the modified data attributes of the print component include a copied and / or modified data partition configuration of the print component. In an example, the intermediate circuit receives the data attributes of the print component in the print component response including a data attribute of a memory partition of the print component as read-only, and the264899-5990-1972.11Atty. Dkt. No.: 86361743intermediate circuit modifies the data attribute of the memory partition to be write-once in the data attributes provided by the intermediate circuit to the host controller. Additional detail is provided in FIG. 16.

[0068] In some implementations, the host command includes a command to drive a data line of the print component low and a time value to indicate a duration, the intermediate command comprises the command to drive the data line of the print component low, copying or modifying the host command, the print component response comprises driving the data line of the print component low for a predetermined amount of time, and the intermediate response comprises driving a data line of the intermediate circuit low for at least one period that has a timing and / or duration based on the component response. In this way, the intermediate circuit can provide a response to the host controller that corresponds to an expected response and will allow the host to confirm proper cartridge installation. By controlling a low voltage condition based on the condition of the data line of the print component, the intermediate circuit is able to provide the response (i.e., data line low for the predetermined amount of time) to the host controller based on the component response. Additional detail is provided in FIG. 11.

[0069] In some implementations, the intermediate circuit, in response to a host command including a time period value, transmits a command to the print component that is the same command type as the host command for the print component to drive the data line of the print component low for at least one duration. In response to the print component driving the data line of the print component low, and / or directly in response to the host command, the intermediate circuit drives the data line of the intermediate circuit low. Then, in response to the print component releasing the data line of the print component to a high or default voltage, the intermediate circuit releases the data line of the intermediate circuit to a high voltage. The intermediate circuit may be configured to pull the voltage low continuously, to release it based 274899-5990-1972.11Atty. Dkt. No.: 86361743on the component's release of the low voltage signal on the data line (SDA), or, it could be configured to release the data line to a default / high voltage in between the beginning and end of the low voltage duration so that it is not a continuous low voltage, as long as the printer can confirm correct installation. The total time period duration of a low voltage condition, either interrupted or continuous, could for example be between approximately 30 and 200 ms. In some implementations, the intermediate circuit drives the data line of the intermediate circuit low in response to the print component driving the data line of the print component low, while in some implementations, the intermediate circuit drives the data line of the intermediate circuit low in response to the host command and transmits the command to the print component after, or in parallel with, driving the data line of the intermediate circuit low.

[0070] In some implementations, the host command, the intermediate command, the print component response, and / or the intermediate response are authenticated and / or encrypted. In an example, the host command is generated using a secure host cryptographic session key and the intermediate command is generated using a secure component cryptographic session key. In an example, the intermediate circuit holds the data line of the intermediate circuit low according to the data line of the print component being low, and provides an authenticated and / or encrypted success response to the host controller upon completion of the response (i.e., upon returning the data line of the intermediate circuit high), where the success response is authenticated and / or encrypted using the secure host cryptographic session key.

[0071] FIG. 7 is a flow diagram illustrating operations of an example method 700 for providing, by an intermediate circuit, an unauthenticated intermediate response to a host. The method 700 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 700 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.284899-5990-1972.11Atty. Dkt. No.: 86361743

[0072] At operation 710, the intermediate circuit receives, at the host-side contact array of the intermediate circuit, from a host controller, an unauthenticated host command. The unauthenticated host command may be unauthenticated because it does not include a message authentication code, and / or it is not calculated based on a session key, and / or it is not encrypted.

[0073] At operation 720, in response to the host command, the intermediate circuit provides, at the component-side contact array, to the print component, an unauthenticated intermediate command based on the host command. In some implementations, the intermediate circuit determines whether to transmit the command to the print component as the intermediate command or to generate a new command for the intermediate command based on the host command. In this way, the intermediate circuit can pass through or modify the host command to the print component.

[0074] At operation 730, the intermediate circuit receives, at the component-side contact array, from the print component, an unauthenticated component response from the component.

[0075] At operation 740, the intermediate circuit provides, at the host-side contact array, to the host controller, an unauthenticated intermediate response based on the component response, which is the response to the unauthenticated host command. In some implementations, the intermediate circuit determines whether to transmit the response to the host controller as the intermediate response or to generate a new response for the intermediate response based on the print component response. In this way, the intermediate circuit can pass through or modify the response to the host controller.

[0076] The intermediate circuit can exchange authenticated signals (e.g., commands, responses) with the host controller and / or the print component. In an example, the294899-5990-1972.11Atty. Dkt. No.: 86361743intermediate circuit establishes a secure session with the host controller, but not with the print component, such that signals exchanged between the intermediate circuit and the host controller are authenticated, but signals exchanged between the intermediate circuit and the print component are not authenticated, as in the method 700. An example of a secure session between the intermediate circuit and the host controller is provided in FIG. 13. An example of a secure session between the intermediate circuit and the host controller and a secure session between the intermediate circuit and the print component is provided in FIG. 14. The intermediate circuit may be configured to authenticate commands to the component circuit for certain command types and to not authenticate commands to the component circuit for other command types, whereby the commands to the component are based on the respective host commands, and also to authenticate or not responses to the host controller based on the host command type, whereby the responses are based on the respective component responses. In some implementations, the intermediate circuit responds to authenticated commands from the host controller with authenticated responses, and responds to unauthenticated commands from the host controller with unauthenticated responses.

[0077] FIG. 8 is a flow diagram illustrating operations of an example method 800 for providing, by an intermediate circuit, data to a host based on data from a print component. The method 800 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 800 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0078] At operation 810, the intermediate circuit receives an authenticated or unauthenticated read data command including a beginning location and a length from a host controller of a host (e.g., printer). In some implementations, the read data command includes multiple commands each including a beginning location and a length. In some implementations, the 304899-5990-1972.11Atty. Dkt. No.: 86361743read data command is a single read command that specifies multiple beginning locations and multiple associated lengths.

[0079] At operation 820, the intermediate circuit determines whether the intermediate circuit contains the data corresponding to the read data command. Note that this step of determination does not need to include a data comparison, but rather, the intermediate circuit could respond to the host directly, or refer to the print component, based on the host command type, whereby for certain command types a direct response to the host is provided and for other command types the component circuit is involved. The integrated circuit includes a memory for storing configurations, print component data, base keys, base key identifiers, base key attributes such as session counters, and other data for identifying commands from the host controller, passing through and / or modifying commands to the print component, and passing through and / or modifying responses to the host controller. At operation 830, in response to the intermediate circuit containing (e.g., storing in memory) the requested data, the intermediate circuit provides the requested data to the host.

[0080] At operation 840, in response to the intermediate circuit not containing the requested data, the intermediate circuit sends an authenticated or unauthenticated intermediate read data command to the print component. In some implementations, the intermediate read data command is the same as the read data command from the host. In some implementations, the intermediate read data command is based on the read data command or is a modified version of the read data command. The intermediate read data command can be authenticated or unauthenticated independent of whether the read data command from the host was authenticated or unauthenticated. In some implementations, the intermediate read data command is authenticated based on the intermediate read data command requesting data from a memory partition that requires authentication to be read.314899-5990-1972.11Atty. Dkt. No.: 86361743

[0081] At operation 850, the intermediate circuit receives data from the print component in response to the intermediate read data command. The data may be the data requested by the host and corresponding to the read data command, or other data corresponding to the intermediate read data command. The intermediate circuit can determine whether to modify or pass through the data from the print component. At operation 860, the intermediate circuit provides the data to the host. At operation 870, the intermediate circuit modifies the data and provides the modified data to the host at operation 880. In some implementations, the integrated circuit modifies a portion of the data and provides a portion of the data unchanged to the host.

[0082] The data provided to the host by the intermediate circuit, modified or not, can include data indicating a trademark of a manufacturer of the print component, a region in which the print component was to be sold, a capacity of print fluid contained in the print component, an amount of print fluid remaining in the print component, a date of manufacture of the print component, properties of the print fluid, servicing requirements of the print fluid, transform map data and / or metadata, timing challenge maximum allowable response time and a maximum number of retries for a timing challenge, a secure upgrade enabled indication, and / or an identifier of the print component. Specific examples of communications between the host controller, the intermediate circuit, and the print component are provided in FIGS. 9-16.

[0083] FIG. 9 is a flow diagram illustrating operations of an example method 900 for providing, by an intermediate circuit, data configuration data to a host. The method 900 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 900 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.324899-5990-1972.11Atty. Dkt. No.: 86361743

[0084] At operation 910, the intermediate circuit receives an authenticated or unauthenticated data partition configuration query from a host controller of a host (e.g., printer).

[0085] At operation 920, the intermediate circuit sends an authenticated or unauthenticated intermediate data partition configuration query to the print component. In some implementations, the intermediate data partition configuration query is the same as the data partition configuration query from the host. In some implementations, the intermediate data partition configuration query is based on the data partition configuration query or is a modified version of the data partition configuration query (e.g., authenticated or not authenticated). The intermediate data partition configuration query can be authenticated or unauthenticated independent of whether the data partition configuration query from the host was authenticated or unauthenticated.

[0086] At operation 930, the intermediate circuit receives a data partition configuration from the print component in response to the intermediate data partition configuration query. The data partition configuration can indicate how data is stored in a memory of the print component, including identifiers and / or characteristics of data partitions. In an example, the data partition configuration indicates data partition (data block) attributes such as lengths, access modes (e.g., read / write access), and / or encryption attributes of the print component, which allows the host to readily access individual usage data partitions in the right way and without needing to scan the entire usage data first. Different partition configurations can be used for a single printer, for example, to allow for additional partitions or additional data fields within a data partition. The intermediate circuit may at least partially pass through or copy the partition configuration of the component circuit, and / or partially or significantly modify it. The partition configuration can be a continuous data string that encodes the attributes (e.g., location / length, access mode and encryption attribute) of subsequent data partitions of usage data, relatively small in data size as compared to the actual usage data.334899-5990-1972.11Atty. Dkt. No.: 86361743The intermediate circuit can determine whether to modify or pass through the data partition configuration from the print component. At operation 940, the intermediate circuit provides the data to the host. At operation 950, the intermediate circuit modifies the data and provides the modified data to the host at operation 960. In some implementations, the integrated circuit modifies a portion of the data and provides a portion of the data unchanged to the host. The intermediate circuit can modify any portion of the data partition configuration. In an example, the intermediate circuit may copy certain attributes from the component circuit while it directly provides certain attributes from the intermediate circuit itself, and / or it may add attributes of certain partitions and / or may add entire partitions. In an example, the intermediate circuit modifies a write access portion of the data partition configuration to modify a write access of a partition from “read-only” to “write-once.” The data partition configuration can be the partition map as described in US Patent No. 8,205,976, the entirety of which is incorporated herein by reference.

[0087] FIG. 10 is a flow diagram illustrating operations of an example method 1000 for providing, by an intermediate circuit, base key table data to a host. The method 1000 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1000 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0088] At operation 1010, the intermediate circuit receives an authenticated or unauthenticated base key table query from a host controller of a host (e.g., printer).

[0089] At operation 1020, the intermediate circuit sends an authenticated or unauthenticated intermediate base key table query to the print component. In some implementations, the intermediate base key table query is the same as the base key table query from the host. In some implementations, the intermediate base key table query is based on the base key table 344899-5990-1972.11Atty. Dkt. No.: 86361743query or is a modified version of the base key table query (e.g., authenticated or not authenticated). The intermediate base key table query can be authenticated or unauthenticated independent of whether the base key table query from the host was authenticated or unauthenticated.

[0090] At operation 1030, the intermediate circuit receives base key table data from the print component in response to the intermediate base key table query. The base key table data can indicate attributes of base keys stored on the print component such as key length and base key session counter values. In an example, the base key table data includes a plurality of base key identifiers and corresponding base key session counter values indicating a number of times each base key corresponding to a base key identifier was used to establish a secure cryptographic session. The intermediate circuit can determine whether to modify or pass through the base key table data from the print component. At operation 1040, the intermediate circuit provides the base key table data to the host. At operation 1050, the intermediate circuit modifies the base key table data and provides the modified data to the host at operation 1060. In some implementations, the integrated circuit modifies a portion of the base key table data and provides a portion of the base key table data unchanged to the host. In an example, the intermediate circuit modifies the base key table data to lower a base key session counter value for one or more base keys indicated in the base key table data.

[0091] FIG. 11 is a flow diagram illustrating operations of an example method 1100 for driving, by an intermediate circuit, a host-side data line of the intermediate circuit low in response to a voltage monitoring command from a host. The method 1100 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1100 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.354899-5990-1972.11Atty. Dkt. No.: 86361743

[0092] At operation 1110, the intermediate circuit receives an authenticated or unauthenticated voltage monitoring command including a time period from a host controller of a host (e.g., printer). In response, the intermediate circuit may pull the host-side data signal to a low voltage, for example instead of at step 1140.

[0093] At operation 1120, the intermediate circuit sends an authenticated or unauthenticated intermediate voltage monitoring command to the print component. In some implementations, the intermediate voltage monitoring command is the same as the voltage monitoring command from the host. In some implementations, the intermediate voltage monitoring command is based on the voltage monitoring command or is a modified version of the voltage monitoring command (e.g., modified time period). The intermediate voltage monitoring command includes the time period included in the voltage monitoring command or another time period. For example the intermediate circuit may be configured to set the time period to a shorter duration as the time period from the host to account for delay in sending or passing through the host command to the component circuit, and the delay between the component circuit releasing the data line to a default voltage condition and the intermediate circuit releasing the data line in response to the component circuit (block 1150). The intermediate voltage monitoring command can be authenticated or unauthenticated independent of whether the voltage monitoring command from the host was authenticated or unauthenticated.

[0094] At operation 1130, the intermediate circuit monitors a component data line of the print component. The print component, in response to the intermediate voltage monitoring command, drives the component data line low for a duration based on the time period and then releases the component data line high at the end of the duration. A default voltage of the component data line may be high, such that releasing the component data line causes the component data line to return to the default (high) level. In some implementations, the print component drives the component data line low by connecting the component data line to 364899-5990-1972.11Atty. Dkt. No.: 86361743ground. The intermediate circuit monitors the component data line by monitoring a component-side data line of the intermediate circuit that is electrically coupled to the component data line. When the component data line is voltage high, the component-side data line of the intermediate circuit is voltage high, and when the component data line is voltage low, the component-side data line of the intermediate circuit is voltage low. Thus, by monitoring the voltage of the component-side data line, the intermediate circuit can monitor the voltage of the component data line.

[0095] At operation 1140, the intermediate circuit drives a voltage of a host-side data line low according to the voltage of the component. The host-side data line is electrically coupled to a corresponding electrical data contact of the host controller. The electrical contact of the host controller is configured to be electrically coupled to the component data line. However, the intermediate circuit interposes between the host controller and the print component such that the host controller is electrically coupled to the intermediate circuit. In some implementations, the intermediate circuit drives the voltage of the host-side data line low before transmitting the intermediate voltage monitoring command to the print component in operation 1120, in response to the host command with the time period. In some implementations, the intermediate circuit drives the voltage of the host-side data line low in response to the component data line being low.

[0096] The intermediate circuit is configured to release the host-side data line to return to the default voltage in response to the voltage on the component-side data contact returning to high at the end of the duration. At operation 1150, when the voltage of the component data line pulls up (i.e., goes data high, returns to default high voltage), the intermediate circuit releases the voltage of the host-side data line high (i.e., returns the host-side data line to high voltage). In some implementations, the intermediate circuit is configured to cause the hostside data line to have high voltage by removing a connection between ground and the host- 374899-5990-1972.11Atty. Dkt. No.: 86361743side data line. In some implementations, the intermediate circuit is configured to cause the host-side data line to have high voltage by connecting the host-side data line to a voltage source.

[0097] By monitoring the voltage of the component data line and driving the voltage of the host-side data line according to the monitored voltage of the component data line, the intermediate circuit can provide an expected response to the host controller by driving the host-side data line low for a duration corresponding to the time period specified by the host controller. The host controller can calculate an expected duration based on the specified time period and verify whether the duration of voltage low on the host-side data line corresponds to the calculated or expected duration. In an example, the host controller calculates the expected duration based on a time for transmission and an expected amount of time for the component to authenticate the voltage monitoring command. The host controller can, based on the duration of voltage low on the host-side data line, determine whether the print component originates from an authorized source. The host controller can verify that the hostside data line goes low within a predetermined time interval after the host command with the time period, and verify that the host-side data line stays low for the expected duration. An initial delay between the host command including the time period and the host-side data line going low is caused by transmission delay and authentication delay, which delays may be similar to or longer than delays incurred between a host controller and a print component without an intermediate circuit.

[0098] Within the method 1100, the “high” and “low” voltages are relative voltages for transmitting information. In some implementations, the high voltage is between 3 and 6 volts, while the low voltage is less than 1 volt. The voltage monitoring command can be the command specifying a time period described in US Patent No. 11,256,654, the entirety of which is incorporated herein by reference.384899-5990-1972.11Atty. Dkt. No.: 86361743

[0099] FIG. 12 is a flow diagram illustrating operations of an example method 1200 for establishing, by an intermediate circuit, a secure session with a host and a secure session with a print component. The method 1200 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1200 can be performed by an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0100] At operation 1210, the intermediate circuit receives a start session command from host controller of a host. The start session command is a command to start a secure cryptographic session with the host controller, within which session signals (e.g., messages, commands, responses, etc.) are authenticated using message authentication codes. In some implementations, the intermediate circuit receives the start session command as an i2c bus follower.

[0101] At operation 1220, the intermediate circuit starts a secure cryptographic session and provides an intermediate session key id to the host controller. The intermediate session key id identifies an intermediate session key stored on the intermediate circuit or the print component and the host. The host stores base keys in non-volatile memory and stores session keys derived from the base keys in volatile memory. Similarly, the intermediate circuit can store the base keys in non-volatile memory and store session keys derived from the base keys in volatile memory. The intermediate circuit can store base keys, session keys, secret keys, and other data in non-volatile memory. By sending the intermediate session key id to the host controller for the host controller to derive the same intermediate session key, the intermediate circuit establishes a secure session with the host controller such that the host controller and the intermediate circuit will authenticate signals (e.g., messages, commands, responses) exchanged between themselves using the intermediate session key.394899-5990-1972.11Atty. Dkt. No.: 86361743

[0102] In some implementations, the intermediate circuit generates the intermediate session key id and the corresponding intermediate session key in response to the start session command. The intermediate circuit generates the intermediate session key id and the corresponding intermediate session key based on a secret key (i.e., base key) stored in a memory of the intermediate circuit. In an example, the intermediate circuit generates the intermediate session key id (i.e., identifier) based on base key attributes (e.g., base key id and session counter) and generates the intermediate session key based on the intermediate session key id and the base key value. In some implementations, the host generates the intermediate session key using the intermediate session key identifier and a secret key stored in a memory of the host.

[0103] At operation 1230, the intermediate circuit issues a start session command to the print component. In some implementations, the intermediate circuit issues the start session command as an i2c bus leader. The print component receives the start session command from the intermediate circuit. In some implementations, the print component receives the start session command as an i2c bus follower. The print component responds by starting a secure session and providing a component session key id to the intermediate circuit. In some implementations, the print component generates the component session key id and the corresponding component session key using a secret key (i.e., base key) stored in a memory of the print component. In an example, the print component generates the component session key id based on base key attributes (e.g., base key id and session counter) and generates the component session key based on the component session key id and the base key value.

[0104] In some implementations, the intermediate circuit issues the start session command to the print component in response to the start session command from the host. In some implementations, the intermediate circuit exchanges messages (i.e., receives commands and provides responses) with the host controller until a response from the print component is 404899-5990-1972.11Atty. Dkt. No.: 86361743needed, at which point the intermediate circuit issues the start session command to the print component. In an example, if the intermediate circuit receives a command from the host controller to provide data that is stored on the intermediate circuit, the intermediate circuit can send a response to the host controller including the data without establishing a secure cryptographic session with the print component. In an example, the intermediate circuit can have a secure cryptographic session with the host controller but not with the print component, as in FIG. 13. In an example, the intermediate circuit can have secure cryptographic sessions with both the host controller and the print component, as in FIG. 14.

[0105] At operation 1240, the intermediate circuit receives, from the print component, the component session key id. In some implementations, the intermediate circuit generates the component session key using the component session key id and a secret key (i.e., base key) stored in a memory of the intermediate circuit.

[0106] At operation 1250, the intermediate circuit uses the intermediate session key in communications with the host controller and uses the component session key in communications with the print component. The intermediate circuit uses the intermediate session key to generate message authentication codes to include in messages to the host controller and / or to authenticate message authentication codes received from the host controller. The intermediate circuit uses the component session key to generate message authentication codes to include in messages to the print component and / or to authenticate message authentication codes received from the print component. In some implementations, the host controller uses the message authentication code in a message from the intermediate circuit to verify an authenticity of the print component. In an example, the host controller receives a message including a first message authentication code from the intermediate circuit and generates a second message authentication code using the intermediate session key. In this example, the host controller compares the first message authentication code to the second 414899-5990-1972.11Atty. Dkt. No.: 86361743message authentication code to determine whether they match, where a match indicates authenticity of the print component. In this way, the intermediate circuit can authenticate the print component to the host controller by providing signals to the host controller that appear to originate from the print component. Similarly, the intermediate circuit can authenticate itself to the print component by providing signals to the print component that appear to originate from a host controller.

[0107] Messages sent from the intermediate circuit to the host controller have characteristics of messages from a print component, and messages sent from the intermediate circuit to the print component have characteristics of messages from a host controller, allowing the intermediate circuit to pass through and / or modify messages between the host controller and the print component. Details of authentication of messages between a host controller and a print component are found in US Patent No. 9,619,663. The intermediate circuit can pass through and / or modify messages such as those described in US Patent No. 9,619,663, which is incorporated herein by reference.

[0108] FIG. 13 is a flow diagram illustrating operations of an example method 1300 for transmitting commands and responses between a host, an intermediate circuit, and a component using a secure session between the host and the intermediate circuit. The method 1300 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1300 is performed by a host controller 1301, an intermediate circuit 1302, and a print component 1303.

[0109] At operation 1310, the host controller 1301 sends a start session command to the intermediate circuit 1302. At operation 1320, the intermediate circuit 1032 sends a start session response to the host controller 1301, the start session response including an intermediate session key identifier corresponding to an intermediate session key. At operation 424899-5990-1972.11Atty. Dkt. No.: 863617431330, the host controller 1301 sends an authenticated command to the intermediate circuit 1302, the authenticated command including a message authentication code generated using the intermediate session key generated by the host controller 1301 using the intermediate session key identifier. The intermediate circuit 1302 can authenticate the host controller 1301 by generating a message authentication code using the intermediate session key and comparing the generated message authentication code to the received message authentication code. At operation 1340, the intermediate circuit 1302 sends an authenticated response to the host controller 1301 including a message authentication code generated using the intermediate session key. The host controller 1301 can authenticate the intermediate circuit 1302 by generating a message authentication code using the intermediate session key and comparing the generated message authentication code to the received message authentication code.

[0110] At operation 1350, the host controller 1301 sends an authenticated command (authenticated using a message authentication code) to the intermediate circuit 1302. At operation 1360, the intermediate circuit sends an unauthenticated command (not including a message authentication code) to the print component 1303 based on the authenticated command received from the host controller 1301. At operation 1370, the print component 1303 sends an unauthenticated response (not including a message authentication code) to the intermediate circuit 1302. At operation 1380, the intermediate circuit 1302 sends an authenticated response including a message authentication code generated using the intermediate session key to the host controller 1301 based on the unauthenticated response received from the print component 1303.[OHl] The authenticated commands and authenticated responses exchanged between the host controller 1301 and the intermediate circuit 1302 in operations 1330-1350 and 1380 are part of a secure session between the host controller 1301 and the intermediate circuit 1302.434899-5990-1972.11Atty. Dkt. No.: 86361743

[0112] The intermediate circuit 1302 can modify the authenticated command received at 1350 to generate the unauthenticated command sent at 1360. The intermediate circuit 1302 can modify the unauthenticated response received at 1370 to generate the authenticated response sent at 1380. In this way, the intermediate circuit 1302 can modify communications between the host controller 1301 and the print component 1303 to modify attributes of the print component 1303 as seen by the host controller 1301 in order to change how the host controller 1301 responds to the print component 1303, to pass commands to the print component that the intermediate circuit cannot respond to accurately, and / or to pass commands to the print component to avoid performing processing steps at the intermediate circuit. In an example, the intermediate circuit 1302 modifies attributes of the print component 1303 to cause the print component 1303 to appear to the host controller 1301 as a new or less-used print component such that the host controller 1301 does not generate usage or low ink alerts. In an example, the intermediate circuit 1302 modifies attributes of the print component 1303 to cause the print component 1303 to appear to the host controller 1301 as a print component with a higher ink fill level such that the host controller 1301 generates low ink alerts based on the higher ink fill level and not an original lower ink fill level of the print component 1303. In an example, the intermediate circuit does not include data to provide a correct response to a command from the host controller, so the intermediate circuit passes the command to the print component. In an example, the intermediate circuit does not include hardware (e.g., timer, dedicated calculation circuitry) to provide a correct response to a command from the host controller, so the intermediate circuit passes the command to the print component. Thus, the intermediate circuit can modify signals between the host controller and the print component to change attributes of the print component as seen by the host controller, and pass through commands in order to authenticate the print component to the host controller.444899-5990-1972.11Atty. Dkt. No.: 86361743

[0113] FIG. 14 is a flow diagram illustrating operations of an example method 1400 for transmitting commands and responses between a host, an intermediate circuit, and a component using a secure session between the host and the intermediate circuit and a secure session between the intermediate circuit and the component. The method 1400 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1400 is performed by a host controller 1401, an intermediate circuit 1402, and a print component 1403.

[0114] At operation 1410, the host controller 1401 sends a start session command to the intermediate circuit 1402. At operation 1420, the intermediate circuit 1402 sends a start session command to the print component 1403. At operation 1430, the print component 1403 sends a start session response including a component session key identifier to the intermediate circuit 1402. At operation 1440, the intermediate circuit 1402 sends a start session response to the host controller 1401 including an intermediate session key identifier. The intermediate session key identifier may be the same as the component session key identifier, or different.

[0115] At operation 1450, the host controller 1401 sends an authenticated command including a message authentication code generated using the intermediate session key to the intermediate circuit 1402. At operation 1460, the intermediate circuit 1402 sends an authenticated command based on the authenticated command received from the host controller 1401, but including a message authentication code generated using the component session key, to the print component 1403. At operation 1470, the print component 1403 sends an authenticated response including a message authentication code generated using the component session key to the intermediate circuit 1402. At operation 1480, the intermediate circuit 1402 sends an authenticated response based on the authenticated response received from the print component 1403, but including a message authentication code generated using the intermediate session key, to the host controller 1401.454899-5990-1972.11Atty. Dkt. No.: 86361743

[0116] The authenticated command sent at 1450 and the authenticated response sent at 1480 are part of a secure cryptographic session between the host controller 1401 and the intermediate circuit 1402. The authenticated command sent at 1460 and the authenticated response sent at 1470 are part of a secure cryptographic session between the intermediate circuit 1402 and the print component 1403. In this way, the intermediate circuit 1402 can send and receive messages in separate cryptographic sessions using separate session keys to exchange authenticated messages with the host controller 1401 and the print component 1403.

[0117] As discussed herein, the intermediate circuit 1402 can modify and / or pass through commands from the host controller 1401 and responses from the print component 1403 in order to modify interactions between the host controller 1401 and the print component 1403. By using secure sessions with the host controller 1401 and / or the print component 1403, the intermediate circuit 1402 can effectively be invisible to the host controller 1401 and the print component 1403 while modifying interactions between the two.

[0118] FIG. 15 is a flow diagram illustrating operations of an example method 1500 for providing, by an intermediate circuit, a response to a timing challenge from a host. The method 1500 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1500 can be performed by any other example intermediate circuits of this disclosure, including an intermediate circuit, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0119] At operation 1510, the intermediate circuit receives an authenticated timing challenge command from a host controller. The timing challenge command can be authenticated using a message authentication code generated using an intermediate session key used by both the intermediate circuit and the host controller, as discussed herein. The timing challenge command is a request to perform a specific mathematical operation involving certain 464899-5990-1972.11Atty. Dkt. No.: 86361743challenge parameters, for example including a random seed number generated by the host controller and a calculation count or cycle that indicates a number of times the operation is to be performed, for example within a certain time window (i.e., an amount of time). In one example, the print component and / or the intermediate circuit may be configured to provide at least one time window and corresponding calculation count. The timing challenge involves a cyclical calculation that is to be executed by the component circuit in a relatively short time frame. In some implementations, the output of a first iteration of the operation is used as input for a subsequent iteration of the operation, whereby the number of iterations may be based on the calculation count, to arrive at the output after the final iteration. The component circuit may be provided with dedicated logic hardware adapted (but not necessarily limited) to execute the time challenge calculation sequence at a relatively high speed, within the time window. Upon issuing the timing challenge, the host controller begins a timing sequence to monitor the amount of time it takes to receive a challenge response, which should be received within the predetermined time window that corresponds to the calculation count. The host controller can send the timing challenge to reference logic on the host to receive a reference response.

[0120] At operation 1520, the intermediate circuit establishes a secure session with a print component. Establishing the secure session with the print component includes sending a start session command and receiving a component session key id, as discussed herein.

[0121] At operation 1530, the intermediate circuit authenticates and / or decrypts the timing challenge command from the host using the intermediate session key and authenticates and / or encrypts the timing challenge command using the component session key. In this way, the intermediate circuit translates the timing challenge command from use in the secure session between the intermediate circuit and the host controller for use in the secure session between the intermediate circuit and the print component. In an example, the intermediate circuit 474899-5990-1972.11Atty. Dkt. No.: 86361743removes a message authentication code generated using the intermediate session key and replaces it with a message authentication code generated using the component session key such that the timing challenge command can be authenticated by the print component. In some implementations, the timing challenge command is both authenticated and encrypted using the corresponding session key.

[0122] At operation 1540, the intermediate circuit transmits an authenticated timing challenge command to the print component. The authenticated timing challenge command to the print component includes a message authentication code generated using the component session key. The timing challenge to the print component includes the same challenge parameters (random seed, calculation count) as the timing challenge from the host controller. The print component performs the mathematical operations using the challenge parameters to generate a challenge response. At operation 1550, the intermediate circuit receives the challenge response from the print component.

[0123] At operation 1560, the intermediate circuit authenticates and / or decrypts the response from the print component using the component session key and authenticates and / or encrypts the challenge response using the intermediate session key, thereby translating the challenge response from use in the cryptographic session between the intermediate circuit and the print component for use in the cryptographic session between the intermediate circuit and the host controller. In an example, the intermediate circuit removes a message authentication code generated using the component session key from the challenge response and adds a message authentication code generated using the intermediate session key. In some implementations, the timing challenge command is both authenticated and encrypted using the corresponding session key. At operation 1570, the intermediate circuit transmits the authenticated and / or encrypted challenge response to the host controller, for example, within the time window that corresponds to the calculation count. In some implementations, certain data related to the 484899-5990-1972.11Atty. Dkt. No.: 86361743challenge response (e.g., time window, calculation count) is digitally signed. For example, the parameters for the time challenge may be stored and / or transmitted by the component circuit, and transmitted (and / or re-authenticated) by the intermediate circuit, whereby the parameters may be digitally signed. The parameters as stored and / or transmitted by the component circuit, and subsequently transmitted by the intermediate circuit, may include a time (window) for completing the time challenge and a calculation count that sets a number of iterations. By digitally signing the time challenge parameters (e.g., during manufacture / customization / personalization of the component circuit), these parameters can be considered reliable. Digitally signing data content may prevent tampering of that data content by third parties.

[0124] The intermediate circuit can be configured to provide the calculation count and / or time window to the host controller, either directly or based on a data response from the print component circuit, for the host controller to be able to verify the time challenge response and response time. The host controller can compare the received challenge response to an expected response, such as the reference response received from the reference logic on the host. The host controller can authenticate the print component based on the challenge response matching the expected response and the challenge response being received within an expected time window. Details of the timing challenge response are found in US Patent No. 10987936, which is incorporated herein by reference.

[0125] By passing the timing challenge to the print component, the intermediate circuit can provide an authentic challenge response to the host controller without performing the challenge calculations and ensuring that the challenge response is delivered within the expected time window. As the print component is authentic, or includes components that are authentic, the intermediate circuit can use the authentic challenge response from the print component for responding to the timing challenge from the host controller. By being able to 494899-5990-1972.11Atty. Dkt. No.: 86361743refer the time challenge to the print component circuit, the intermediate circuit does not need to be provided with dedicated hardware logic and / or does not need to be configured to execute the time challenge calculation and / or does not need to provide the calculation count and time window to the host.

[0126] FIG. 16 is a flow diagram illustrating operations of an example method 1600 for providing, by an intermediate circuit, transform map metadata to a host. The method 1600 can include more, fewer, or different operations than shown. The operations can be performed in the order shown, in a different order, or concurrently. The method 1600 can be performed by any example intermediate circuit of this disclosure, such as the intermediate circuit 100 of FIG. 1, the intermediate circuit 200 of FIG. 2, or the intermediate circuit 300 of FIG. 3.

[0127] At operation 1610, the intermediate circuit receives an authenticated read command for transform map metadata from a host controller. The read command from the host controller is authenticated (includes a message authentication code) using an intermediate session key for a cryptographic session between the intermediate circuit and the host controller. A transform wrapper is for dynamically building a transform map by a host based on the transform map metadata and transform map primitive data. The print component circuit may be configured to provide the transform wrapper to the host. The transform map metadata can indicate, for each transform map (e.g., channel map), a type of depositing material, print media, print mode and printer. The transform wrapper, which can be stored and / or provided by the print component circuit, may include the transform map metadata for building transform maps from primitive data elements also included in the transform wrapper. The printer firmware may build color maps for printing CMYK images based on RGB digital images based on the primitive data and the metadata. The transform wrapper may provide flexibility to handle the different ink versions and system permutations that may arise, such as changes in inks, media support, color tables, and printers. For example, including one or 504899-5990-1972.11Atty. Dkt. No.: 86361743more new color tables or color maps on a print component could improve the color output of the printer, for example for improved ink / toner types that did not exist when an original printer platform (of a particular printer, print components and print material) was first developed, whereby these new color maps may be stored on later print components of the same platform to provide for the improved color printing output for the same printer. We refer to WO2016028272A1 and WO2022093228A1.

[0128] At operation 1620, the intermediate circuit establishes a secure cryptographic session with the print component that uses a component session key, as discussed herein. At operation 1630, the intermediate circuit authenticates and / or decrypts the read command from the host controller using the intermediate session key and authenticates and / or encrypts the read command using the component session key, thereby translating the read command from use in the secure cryptographic session between the intermediate circuit and the host controller for use in the secure cryptographic session between the intermediate circuit and the print component. At operation 1640, the intermediate circuit transmits the authenticated read command to the component. The intermediate circuit receives, in response to the authenticated read command to the component, an authenticated response from the component including transform map metadata.

[0129] At operation 1650, the intermediate circuit authenticates and / or decrypts the response from the print component using the component session key. In some implementations, the intermediate circuit modifies the response at operation 1660, for example, the intermediate circuit modifies the transform wrapper. The intermediate circuit can modify the transform map metadata to change how the host generates the transform map using the transform wrapper and / or provide altered or partial primitive data so that a different transform map is built. In an example, the intermediate circuit can modify the transform map metadata in order514899-5990-1972.11Atty. Dkt. No.: 86361743to cause the host controller to view the print component as a different type of print component, or a print component having different characteristics or properties.

[0130] At operation 1670, the intermediate circuit authenticates and / or encrypts the response including the transform map metadata using the intermediate session key. At operation 1680, the intermediate circuit transmits the authenticated response including the transform map metadata to the host controller.

[0131] The method 1600 can be repeated as often as the host controller requests transform map metadata. In an example, the host controller requests transform map metadata for multiple different transform maps corresponding to different types and / or versions of media, depositing materials, and / or users.

[0132] Where it says in this disclosure that the intermediate circuit is configured for certain functions then this also refers to the control logic of the intermediate circuit being configured for these functions. When the intermediate circuit is configured to receive a response from the print component, this also means that the intermediate circuit is configured to receive the response from the component circuit and / or on the component-side contact array. Similar principles apply to transmitting responses and commands, which are transmitted over the host-side and component-side contact arrays, respectively, of the intermediate circuit,. The intermediate circuit may be configured to receive and respond to the plurality of the example host commands mentioned in this disclosure, in which it may refer to the component circuit for one, several, or all of the host commands, while responding directly to the host commands for the other host commands.

[0133] Aspects of this disclosure describe an intermediate circuit to connect to a print component, or at least a component circuit of a print component, and a host controller. The intermediate circuit may comprise a host-side contact array; a component-side contact array;524899-5990-1972.11Atty. Dkt. No.: 86361743and control logic. The control logic may be configured to receive, at the host-side contact array, from the host controller, a cryptographically authenticated host command. The control logic may be configured to, in response to the host command, provide, at the component-side contact array, to the component circuit of the print component, a cryptographically authenticated intermediate command based on the host command. The intermediate circuit may be configured to receive, at the component-side contact array, from the print component, a cryptographically authenticated component response. The intermediate circuit may furthermore be configured to provide, at the host-side contact array, to the host controller, a cryptographically authenticated intermediate response based on the component response as a response to the cryptographically authenticated host command. In further examples, the control logic may be configured to, in response to the cryptographically authenticated host command from the host controller, transmit a command to the print component to start a cryptographic session. The control logic may be configured to, in response to a command from the host controller to start a cryptographic session, transmit a command to the print component to start a cryptographic session. The control logic may be configured to, in response to a command from the host controller to initiate a secure cryptographic session, provide, at the host-side contact array, to the host controller, a secure host cryptographic session key ID; and receive, at the component-side contact array, from the print component, a secure component cryptographic session key ID, whereby, for example a secure host cryptographic session key is generated using an intermediate session counter, and wherein for example a secure component cryptographic session key is generated using a print component session counter. The control logic may be configured to decrypt, using the host session key, the host command, encrypt, using the component session key, the decrypted host command, or a modified version thereof, to generate the cryptographically authenticated intermediate command; decrypt, using the component session key, the cryptographically534899-5990-1972.11Atty. Dkt. No.: 86361743authenticated component response; and / or encrypt, using the host session key, the decrypted cryptographically authenticated component response to generate the cryptographically authenticated intermediate response. The control logic may be configured to, in response to a data read request from the host controller, the request including a location and / or length of the data: request the data from the print component based on the data read request; receive component data from the print component; and / or, respond with data including the component data to the host controller. The control logic of the intermediate circuit may be configured to transmit a response that is at least partly based on, and / or copy at least a part of, the transform map primitive data and / or transform map metadata in response to a corresponding read request from the host controller. The cryptographically authenticated component response may include the print component transform map primitive data and / or transform map metadata. The control logic may be configured so that the cryptographically authenticated intermediate response may include an intermediate transform map based on the print component transform map primitive data and / or transform map metadata. Furthermore, the control logic may be configured to, in response to the host command, provide, at the component-side contact array, an intermediate command that is either the host command or a modified command that is based on the host command; receive, at the component-side contact array, from the print component, a print component response; and / or, provide, at the host-side contact array, to the host controller, an intermediate response that includes the print component response or a modified response that is based on the print component response. The intermediate response may comprise a list of base key attributes, and / or data attributes, and / or cryptographically authenticated transform map data, and / or a low voltage data signal that is held low for a duration and / or at a timing based on the component response. A command that is based on another command may include a same command type code. The intermediate response may include the list of base key attributes, and the list of base key544899-5990-1972.11Atty. Dkt. No.: 86361743attributes may be modified from a print component list of base key attributes in the print component response to modify a session counter value. The data attributes may include modified data attributes of the print component based on, or including some, data attributes of the print component in the print component response. The data attributes of the print component may include a partition configuration of the print component. The modified data attributes of the print component may include a modified data partition configuration of the print component. A host command may comprise a command to drive a data line of the print component low and a time value to indicate a duration, the intermediate command comprises the command to drive the data line of the print component low, copying or modifying the host command, the print component response comprises driving the data line of the print component low for a predetermined amount of time, and the intermediate response comprises driving a data line of the intermediate circuit low for at least one period that has a timing and / or duration based on the component response. For example, the control logic may be configured to, in response to a host command including a time period value, transmit a command to the print component that is the same command type for the print component to drive the data line of the print component low for at least one duration; drive a data line of the intermediate circuit low in response to the host command including a time period value or in response to the print component driving the data line low; and / or, in response to the print component releasing the data line of the print component to the high or default voltage, release the data line of the intermediate circuit to a high voltage. The host command may be generated using a secure host cryptographic session key and the intermediate circuit is configured to generate the intermediate command using a secure component cryptographic session key. In a further example, an intermediate circuit is provided that is configured to connect to a print component circuit and a host controller, the intermediate circuit comprising a host-side contact array, a component-side contact array, and / or control logic. The control logic may be554899-5990-1972.11Atty. Dkt. No.: 86361743configured to receive, at the host-side contact array, from the host controller, an unauthenticated host command; and / or, in response to the host command, provide, at the component-side contact array, to the print component, an unauthenticated intermediate command based on the host command; and / or, receive, at the component-side contact array, from the print component, an unauthenticated component response from the component; and / or, provide, at the host-side contact array, to the host controller, an unauthenticated intermediate response based on the component response, which is the response to the unauthenticated host command. The control logic may furthermore be configured to determine whether to transmit the command and / or response, received from the host and / or print component, respectively, or to generate a new command and / or response based on the received command and / or response. The intermediate circuit may comprise a row of I2C serial bus contacts on the host and component side, to contact the host and component, respectively. The intermediate circuit may be adapted to, on the component-side, be attached to a microcontroller of a print cartridge. In some examples, the intermediate circuit could be for pre-attachment to a print component so that it does not contact the host until the print component is installed. In other examples, the intermediate circuit could be pre-attached to a printer so that it does not contact the print component until the component is installed.

[0134] The herein described subject matter sometimes illustrates different components contained within, or connected with, different other components. It is to be understood that such depicted architectures are merely exemplary, and that in fact many other architectures can be implemented which achieve the same functionality. In a conceptual sense, any arrangement of components to achieve the same functionality is effectively "associated" such that the desired functionality is achieved. Hence, any two components herein combined to achieve a particular functionality can be seen as "associated with" each other such that the desired functionality is achieved, irrespective of architectures or intermedial components.564899-5990-1972.11Atty. Dkt. No.: 86361743Likewise, any two components so associated can also be viewed as being "operably connected," or "operably coupled," to each other to achieve the desired functionality, and any two components capable of being so associated can also be viewed as being "operably couplable," to each other to achieve the desired functionality. Specific examples of operably couplable include but are not limited to physically mateable and / or physically interacting components and / or wirelessly interactable and / or wirelessly interacting components and / or logically interacting and / or logically interactable components.

[0135] With respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity. For example, recitations of plural elements can be understood to include of the element discussed.

[0136] It will be understood by those within the art that, in general, terms used herein, and especially in the appended claims (e.g., bodies of the appended claims) are generally intended as "open" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "includes but is not limited to," etc.). It will be further understood by those within the art that if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, as an aid to understanding, the following appended claims may contain usage of the introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles "a" or "an" limits any particular claim containing such introduced claim recitation to inventions containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at 574899-5990-1972.11Atty. Dkt. No.: 86361743least one" and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should typically be interpreted to mean "at least one" or "one or more"); the same holds true for the use of definite articles used to introduce claim recitations. In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should typically be interpreted to mean at least the recited number (e.g., the bare recitation of "two recitations," without other modifiers, typically means at least two recitations, or two or more recitations). Furthermore, in those instances where a convention analogous to "at least one of A, B, and C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). In those instances where a convention analogous to "at least one of A, B, or C, etc." is used, in general such a construction is intended in the sense one having skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" would include but not be limited to systems that have A alone, B alone, C alone, A and B together, A and C together, B and C together, and / or A, B, and C together, etc.). It will be further understood by those within the art that virtually any disjunctive word and / or phrase presenting two or more alternative terms, whether in the description, claims, or drawings, should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase "A or B" will be understood to include the possibilities of "A" or "B" or "A and B." Further, unless otherwise noted, the use of the words “approximate,” “about,” “around,” “substantially,” etc., mean plus or minus ten percent.

[0137] The foregoing description of illustrative examples has been presented for purposes of illustration and of description. It is not intended to be exhaustive or limiting with respect to the precise form disclosed, and modifications and variations are possible in light of the above584899-5990-1972.11Atty. Dkt. No.: 86361743teachings or may be acquired from practice of the disclosed examples. It is intended that the scope of the invention be defined by the claims appended hereto and their equivalents.594899-5990-1972.11

Claims

Atty. Dkt. No.: 86361743WHAT IS CLAIMED IS:

1. An intermediate circuit to connect to a print component and a host controller, comprising:a host-side contact array;a component-side contact array; andcontrol logic to:receive, at the host-side contact array, from the host controller, a cryptographically authenticated host command;in response to the host command, provide, at the component-side contact array, to the print component, a cryptographically authenticated intermediate command based on the host command;receive, at the component-side contact array, from the print component, a cryptographically authenticated component response; andprovide, at the host-side contact array, to the host controller, a cryptographically authenticated intermediate response based on the component response as a response to the cryptographically authenticated host command.

2. The intermediate circuit of claim 1, the control logic configured to:in response to the cryptographically authenticated host command from the host controller, transmit a command to the print component to start a cryptographic session.

3. The intermediate circuit of claim 1, the control logic configured to:in response to a command from the host controller to start a cryptographic session, transmit a command to the print component to start a cryptographic session.

4. The intermediate circuit of any previous claim, the control logic to, in response to a command from the host controller to initiate a secure cryptographic session:provide, at the host-side contact array, to the host controller, a secure host cryptographic session key ID; andreceive, at the component-side contact array, from the print component, a secure component cryptographic session key ID.604899-5990-1972.11Atty. Dkt. No.: 863617435. The intermediate circuit of claim 4, wherein a secure host cryptographic session key is generated using an intermediate session counter, and wherein a secure component cryptographic session key is generated using a print component session counter.

6. The intermediate circuit of any previous claim, the control logic to:decrypt the host command;encrypt the decrypted host command, or a modified version thereof, to generate the cryptographically authenticated intermediate command;decrypt the cryptographically authenticated component response; andencrypt the decrypted cryptographically authenticated component response to generate the cryptographically authenticated intermediate response.

7. The intermediate circuit of any previous claim, the control logic to:decrypt, using the host session key, the host command;encrypt, using the component session key, the decrypted host command, or a modified version thereof, to generate the cryptographically authenticated intermediate command;decrypt, using the component session key, the cryptographically authenticated component response; andencrypt, using the host session key, the decrypted cryptographically authenticated component response to generate the cryptographically authenticated intermediate response.

8. The intermediate circuit of any previous claim, the control logic configured to, in response to a data read request from the host controller, the request including a location and / or length of the data:request the data from the print component based on the data read request; receive component data from the print component; andrespond with data including the component data to the host controller.

9. The intermediate circuit of any previous claim, wherein the print component is configured to store, or provide, transform map primitive data and / or transform map metadata, and wherein the control logic of the intermediate circuit is configured to transmit a response that is at least partly based on, and / or copies, at least a part of, the transform map614899-5990-1972.11Atty. Dkt. No.: 86361743primitive data and / or transform map metadata in response to a map data read request from the host controller.

10. The intermediate circuit of claim 9, wherein, when the cryptographically authenticated component response includes the print component transform map primitive data and / or transform map metadata, the cryptographically authenticated intermediate response includes an intermediate transform map based on the print component transform map primitive data and / or transform map metadata.

11. An intermediate circuit to connect to a print component and a host controller, comprising:a host-side contact array;a component-side contact array; andcontrol logic to:receive, at the host-side contact array, from the host controller, a host command;in response to the host command, provide, at the component-side contact array, to the print component, an intermediate command that is either the host command or a modified command that is based on the host command;receive, at the component-side contact array, from the print component, a print component response; andprovide, at the host-side contact array, to the host controller, an intermediate response that includes the print component response or a modified response that is based on the print component response, the intermediate response comprising at least one of:a list of base key attributes,data attributes,cryptographically authenticated transform map data, anda low voltage data signal that is held low for a duration and / or at a timing based on the component response.624899-5990-1972.11Atty. Dkt. No.: 8636174312. The intermediate circuit of claim 11, wherein a command that is based on another command includes a same command type code.

13. The intermediate circuit of claim 11, wherein the intermediate response includes the list of base key attributes, and wherein the list of base key attributes is modified from a print component list of base key attributes in the print component response to modify a session counter value.

14. The intermediate circuit of claim 11, wherein the data attributes include modified data attributes of the print component based on data attributes of the print component in the print component response.

15. The intermediate circuit of claim 14, wherein the data attributes of the print component include a data partition configuration of the print component, and wherein the modified data attributes of the print component include a modified data partition configuration of the print component.

16. The intermediate circuit of any of claims 11-15, wherein the host command comprises a command to drive a data line of the print component low and a time value to indicate a duration, the intermediate command comprises the command to drive the data line of the print component low, copying or modifying the host command, the print component response comprises driving the data line of the print component low for a predetermined amount of time, and the intermediate response comprises driving a data line of the intermediate circuit low for at least one period that has a timing and / or duration based on the component response.

17. The intermediate circuit of any of claims 11-16, wherein in response to a host command including a time period value, the control logic is to:transmit a command to the print component that is the same command type for the print component to drive the data line of the print component low for at least one duration;in response to the print component driving the data line of the print component low or in response to the host command, drive a data line of the intermediate circuit low; and in response to the print component releasing the data line of the print component to the high or default voltage, release the data line of the intermediate circuit to a high voltage.634899-5990-1972.11Atty. Dkt. No.: 8636174318. The intermediate circuit of any of claims 11-17, wherein the host command is generated using a secure host cryptographic session key and the intermediate command is generated using a secure component cryptographic session key.

19. An intermediate circuit to connect to a print component and a host controller, comprising:a host-side contact array;a component-side contact array; andcontrol logic to:receive, at the host-side contact array, from the host controller, an unauthenticated host command;in response to the host command, provide, at the component-side contact array, to the print component, an unauthenticated intermediate command based on the host command;receive, at the component-side contact array, from the print component, an unauthenticated component response from the component; andprovide, at the host-side contact array, to the host controller, an unauthenticated intermediate response based on the component response, which is the response to the unauthenticated host command.

20. The intermediate circuit of claim 19, the control logic configured to determine whether to transmit the command and / or response, received from the host and / or print component, respectively, or to generate a new command and / or response based on the received command and / or response.

21. The intermediate circuit of claim 19 or claim 20 comprising a row of I2C serial bus contacts on the host and component side, to contact the host and component, respectively, and being adapted to, on the component-side, be attached to a microcontroller of a print cartridge.644899-5990-1972.11