CRUM IC Secure Module Test Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing image forming apparatuses require frequent replacement of ink or toner units, necessitating a secure and efficient method to authenticate and monitor consumables, while preventing unauthorized access to critical information stored in customer replaceable unit (CRUM) chips.
Innovation Solution
A CRUM integrated circuit (IC) with a secure module that receives encryption keys and encrypted test codes, performs authorization, decrypts test codes, and generates test commands to operate in test mode, ensuring security features are disabled during testing and enabling secure user mode operations, thereby enhancing the security and authenticity of consumable monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security functions are enabled in CRUM IC, then unauthorized access to critical information is prevented, but testing and debugging of the CRUM IC becomes difficult
Solution Approach 1:
The patent implements a dual-mode operation system where the CRUM IC can dynamically switch between user mode (with security functions enabled) and test mode (with security functions disabled). This dynamic switching capability allows the system to adapt its security level based on operational context, enabling both secure user operation and facilitated testing when needed.
Solution Approach 2:
The patent employs preliminary action by implementing a test mode that can be activated before final security configuration. During manufacturing and testing phases, the test mode allows security functions to be disabled in advance, enabling comprehensive testing of the CRUM IC without security restrictions. After testing is complete, the system transitions to user mode where security functions are enabled for normal operation.
2Reliability
If encryption keys are stored in CRUM IC, then authorization and authentication are enhanced, but the risk of key extraction and unauthorized decryption increases
Solution Approach 1:
The patent extracts the decryption functionality from the secure storage environment and implements it in a controlled test mode. The encryption keys remain securely stored in the CRUM IC, but the decryption operation is performed only when explicitly requested through a standardized interface in test mode, rather than being continuously available. This separation reduces the attack surface for key extraction while maintaining necessary decryption capabilities for authorized testing and operation.
Data Source
AI summary
A customer replaceable unit monitor (CRUM) integrated circuit (IC) includes: a secure module configured to receive an encryption key and an encrypted test code from outside; and a CRUM module controlled by the secure module. The secure module may perform authorization on the basis of the received encryption key. The secure module may perform decryption of the encrypted test code to generate a decrypted test code. The secure module may store the decrypted test code in a volatile memory. The secure module may generate a test command based on the decrypted test code in the volatile memory, and provide the test command to the CRUM module.


