Dynamic Encryption for Image Printer Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for replacement units in image forming apparatuses are vulnerable to side channel attacks, as attackers can infer secret information by controlling challenge data and observing response data, lacking measures to counter such attacks.
Innovation Solution
The authentication method involves encrypted communication between the authentication apparatus and the authentication target apparatus, where encryption processing information is changed with each communication, making it difficult for attackers to infer secret information by using selected verification and authentication information, and updating sub-data values to ensure different encryption processing information for each communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a challenge-response scheme is used for authentication, then authentication functionality is achieved, but the system becomes vulnerable to side channel attacks where attackers can infer secret information by controlling challenge data and observing response data
Solution Approach 1:
The patent applies dynamics by making the encryption processing information changeable rather than static. The authentication apparatus and authentication target apparatus dynamically change encryption processing information based on sub-data that is updated according to a predetermined rule, ensuring that encryption parameters vary with each authentication attempt, thereby preventing attackers from using static analysis to infer secret information
Solution Approach 2:
The patent implements parameter changes by modifying encryption processing information (such as initial vectors or encryption keys) based on updated sub-data. This ensures that even when the same challenge data is used, the encryption parameters differ, making it impossible for attackers to correlate input-output pairs to derive secret authentication information through side channel attacks
2Productivity
If the same challenge data and authentication data are transmitted in multiple communications, then communication efficiency is improved, but the secrecy of authentication keys is compromised due to repeated patterns observable by attackers
Solution Approach 1:
The system maintains communication efficiency by using the same challenge data and authentication data structures, but introduces dynamics through changing encryption processing information based on updated sub-data. This ensures that while the data patterns remain consistent for efficiency, the encrypted transmissions differ each time, preserving key secrecy
Solution Approach 2:
The patent introduces sub-data as an intermediary element that mediates between the need for repeated authentication patterns (for efficiency) and the need for varying encryption (for security). The sub-data updates encryption processing information without altering the fundamental challenge-response structure, allowing both efficiency and security to coexist
Data Source
AI summary
An authentication method for authenticating an authentication target apparatus by an authentication apparatus is provided. The method includes: the authentication apparatus performing first encryption processing in accordance with first encryption processing information; the authentication target apparatus performing second decryption processing in accordance with second encryption processing information; the authentication target apparatus performing second encryption processing in accordance with the second encryption processing information; the authentication apparatus performing first decryption processing in accordance with the first encryption processing information. The authentication apparatus changes the first encryption processing information in accordance with a predetermined rule when either of the first encryption processing and the first decryption processing is performed, and the authentication target apparatus changes the second encryption processing information in accordance with the predetermined rule when either of the second encryption processing and the second decryption processing is performed.


