Printer Identity Security via PKI Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Printing devices are increasingly vulnerable to unauthorized access and reconfiguration, leading to potential data breaches and damage, as they become more interconnected, making it difficult to ensure their security and authenticity.

Innovation Solution

A method and system for establishing a unique and secure identity for printing devices at the manufacturing stage, using Public Key Infrastructure (PKI) with unique private and public keys stored in a secure memory portion, to authenticate operations and prevent unauthorized firmware, hardware, or software configurations, thereby enhancing security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If printing devices are made more interconnected to improve functionality and connectivity, then the device's adaptability and ease of operation are improved, but the device becomes more vulnerable to unauthorized access and security attacks

Engineering Contradiction:
ImproveinterconnectivityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a secure identity and cryptographic credentials for the printing device during the manufacturing process, before the device is deployed to the field. This pre-configured security identity includes private keys stored in secure memory and digital certificates that enable the device to authenticate itself and protect against unauthorized access. By performing security configuration in advance at the factory, the device is hardened against attacks before it becomes vulnerable in the field.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are strengthened to protect against unauthorized access, then the device's reliability is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements the nested doll principle by embedding a secure memory portion within the printing device that contains cryptographic credentials and identity information. This nested secure element provides a layered security architecture where the secure memory is embedded within the broader device system, creating a protected core that stores sensitive information while the rest of the device operates normally. This nesting approach enhances security without requiring complete redesign of the entire device architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If a secure identity is established at manufacturing to prevent unauthorized configurations, then the device's reliability is improved, but the manufacturing process complexity increases

Engineering Contradiction:
Improvefirmware authenticityVSAvoidmanufacturing process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a certificate authority (CA) that acts as a trusted third party during the manufacturing process. The CA issues digital certificates to the printing device based on the device's unique identity, creating a chain of trust that verifies firmware authenticity. This intermediary CA system simplifies the manufacturing process by providing a standardized method for establishing security credentials, rather than requiring each manufacturer to implement their own complex verification systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20210064767A1Printer identity and security
Publication Date: 2021.03.04 ENTRUST CORP
  • US20210064767A1 patent drawing
  • US20210064767A1 patent drawing
  • US20210064767A1 patent drawing

AI summary

A system and method for establishing a secure identity for a printing device at the time of manufacturing is provided. The method includes obtaining a first private key for use with a first operation of the printing device and obtaining a second private key for use with a second operation of the printing device. The method also includes loading the first private key into a secure memory portion of the printing device during manufacturing of the printing device, and loading the second private key into the secure memory portion of the printing device during manufacturing of the printing device.