Encryption Provider Registration for Image Forming Apparatus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing image forming apparatus lacks a mechanism to reflect the unavailability of the FIPS encryption module in the native environment on the FIPS encryption provider in the VM environment, leading to errors in encryption processing when the FIPS standard is not set, as the FIPS encryption provider cannot use the FIPS encryption module.
Innovation Solution
The apparatus registers encryption providers in different program environments and determines whether to register the FIPS encryption provider based on specific standard necessity information, ensuring that the appropriate encryption module is used for encryption processing, thereby preventing errors by selecting an encryption provider that matches the set encryption processing mode.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the FIPS encryption provider is registered in the VM environment, then encryption processing for extension functions can be performed, but errors occur when the FIPS encryption module is not loaded in the native environment
Solution Approach 1:
The system performs preliminary registration of encryption providers based on the loaded encryption module type. Before executing encryption processing, the control unit checks which encryption module is loaded (FIPS or non-FIPS) and accordingly registers only the compatible encryption provider in the VM environment. This preliminary action prevents mismatch errors by ensuring the registered provider matches the available module.
2Adaptability or versatility
If multiple encryption modules are provided to support various encryption standards, then encryption versatility is improved, but device complexity increases
Solution Approach 1:
The control unit serves as a universal manager that handles multiple encryption module types through a unified interface. It automatically detects which encryption module is loaded and configures the VM environment accordingly, allowing the same control unit to manage both FIPS and non-FIPS encryption modules without requiring separate management mechanisms for each type.
Data Source
AI summary
An image forming apparatus capable of suppressing occurrence of a problem in encryption processing. The image forming apparatus includes a plurality of encryption modules for executing encryption processing associated therewith, respectively, including a predetermined encryption module that executes a predetermined encryption processing when mode setting information is set to make the image forming apparatus compliant with a specific standard, for encryption processing. Encryption providers are registered, which are executed in a program environment different from that for the plurality of encryption modules, and are associated with the encryption modules, respectively. Encryption processing is executed via an encryption provider selected from the registered encryption providers by using an encryption module associated with the selected encryption provider. Whether or not to register an encryption provider associated with the predetermined encryption module is determined based on the encryption processing mode-setting information.


