Dynamic Encryption for Image Printer Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for replacement units in image forming apparatuses are vulnerable to side channel attacks, as attackers can infer secret information by controlling challenge data and observing response data, lacking measures to counter such attacks.

Innovation Solution

The authentication method involves encrypted communication between the authentication apparatus and the authentication target apparatus, where encryption processing information is changed with each communication, making it difficult for attackers to infer secret information by using selected verification and authentication information, and updating sub-data values to ensure different encryption processing information for each communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a challenge-response scheme is used for authentication, then authentication functionality is achieved, but the system becomes vulnerable to side channel attacks where attackers can infer secret information by controlling challenge data and observing response data

Engineering Contradiction:
Improveauthentication securityVSAvoidside channel attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the encryption processing information changeable rather than static. The authentication apparatus and authentication target apparatus dynamically change encryption processing information based on sub-data that is updated according to a predetermined rule, ensuring that encryption parameters vary with each authentication attempt, thereby preventing attackers from using static analysis to infer secret information

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by modifying encryption processing information (such as initial vectors or encryption keys) based on updated sub-data. This ensures that even when the same challenge data is used, the encryption parameters differ, making it impossible for attackers to correlate input-output pairs to derive secret authentication information through side channel attacks

Inventive Principle:
Principle #35Parameter changes

2Productivity

If the same challenge data and authentication data are transmitted in multiple communications, then communication efficiency is improved, but the secrecy of authentication keys is compromised due to repeated patterns observable by attackers

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidauthentication key secrecy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system maintains communication efficiency by using the same challenge data and authentication data structures, but introduces dynamics through changing encryption processing information based on updated sub-data. This ensures that while the data patterns remain consistent for efficiency, the encrypted transmissions differ each time, preserving key secrecy

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces sub-data as an intermediary element that mediates between the need for repeated authentication patterns (for efficiency) and the need for varying encryption (for security). The sub-data updates encryption processing information without altering the fundamental challenge-response structure, allowing both efficiency and security to coexist

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240205029A1Authentication apparatus, authentication target apparatus, image forming apparatus, replacement unit, and authentication method
Publication Date: 2024.06.20 CANON KK
  • US20240205029A1 patent drawing
  • US20240205029A1 patent drawing
  • US20240205029A1 patent drawing

AI summary

An authentication method for authenticating an authentication target apparatus by an authentication apparatus is provided. The method includes: the authentication apparatus performing first encryption processing in accordance with first encryption processing information; the authentication target apparatus performing second decryption processing in accordance with second encryption processing information; the authentication target apparatus performing second encryption processing in accordance with the second encryption processing information; the authentication apparatus performing first decryption processing in accordance with the first encryption processing information. The authentication apparatus changes the first encryption processing information in accordance with a predetermined rule when either of the first encryption processing and the first decryption processing is performed, and the authentication target apparatus changes the second encryption processing information in accordance with the predetermined rule when either of the second encryption processing and the second decryption processing is performed.