IP Library Granted Patent US 12706894
Granted Patent B2
US 12706894 · App. 18/039,730 · Granted Aug 11, 2026

Key distribution for a physical unclonable encryption system

Inventors: Lothar Seidemann (Ludwigshafen am Rhein, DE); Holger Kai Peter Jelich (Ludwigshafen am Rhein, DE)
Assignee: BASF SE
H04L63/061G06F3/1222G06F3/1238G06F3/1257G06F3/1267G06F3/1285H04L9/0869H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706894
App. No.
18/039,730
Granted
Aug 11, 2026
Kind
B2
Abstract

Disclosed here is a system and method to distribute symmetric encryption keys between respective nodes of a communication system. A node comprises a printing device that generates session key information or an encryption key based on changing printer control setting information and printer job information of the printing device. Operations comprise providing an initial session key information, which is used to encrypt an initial session package that includes first session key information for respective nodes. A node further generates, based on a second printer control setting and a second printer job setting, second session key information and sends a message that is encrypted with the first session key information. The message includes the second session key information. Respective session key information represents a unique identifier based on printer control setting information and printer job information of a printing device in a node as a physical unclonable function.

Claims (30)

1 . A computer-implemented method for distributing symmetric encryption keys in a communication system comprising a plurality of nodes, wherein each of the nodes comprises a printing device configured for generating at least one encryption key for encrypting data based on changing printer control setting and printer job, wherein each node comprises information about possible printer control settings and possible printer jobs, the method comprising the following steps:

a) providing an initial session key information via at least one secure channel to each node, wherein the initial session key information comprises an initial printer control setting and an initial printer job setting, wherein the initial session key information is different for each node;

b) providing as a one-time pad an initial session key package to each of the nodes encrypted with the respective node's initial session key information, wherein the initial session key package comprises a plurality of items of first session key information for communication of the respective receiving node with the other nodes of the communication system, wherein any two nodes have a common item of first session key information;

c) generating at each node second session key information for each of the other nodes, wherein the second session key information comprises a second printer control setting and a second printer job setting, wherein the second session key information generated by the respective node for the respective other nodes is different for each of the other nodes;

d) sending a message from one of the nodes to another one of the nodes, wherein the message is encrypted with the first session key information for communication between said node and said another one of the nodes, wherein the message comprises the second session key information generated by the node sending the message for the node receiving the message such that the node sending the message and the node receiving the message are able for encrypted communication with each other.

2 . The method according to claim 1 , wherein each printer job comprises at least one digital image of at least one physical object.

3 . The method according to claim 2 , wherein the generating of the encryption key comprises

selecting a printer control setting and a printer job and performing the printer job with the selected printer control setting, wherein the performing of the printer job comprises printing the digital image by mixing pigments;

scanning the mixed pigments and detecting at least one optical signal by using at least one detector of the printing device;

transforming the optical signal into the encryption key by using at least one data processing device of the printing device configured for applying at least one transformation algorithm to the optical signal.

4 . The method according to claim 1 , wherein an algorithmic random number generator is used for generating of the second session key information.

5 . The method according to claim 1 , wherein an individual number is assigned to each of the possible printer control settings and possible printer jobs.

6 . The method according to claim 1 , wherein the possible printer control settings and the possible printer jobs are stored in a database of the printing device.

7 . The method according to claim 1 , wherein the possible printer control settings comprise more than 10 6 printer control settings and the possible printer jobs comprise about 10 6 printer jobs.

8 . The method according to claim 1 , wherein step b) comprises decrypting the initial key package using the respective node's initial session key information provided in step a).

9 . The method according to claim 1 , wherein in steps a) to d) of the method solely symmetric encryption is used.

10 . A non-transitory computer readable medium comprising instructions which, when a program is executed by a computer of computer network cause the computer of computer network to perform the method for distributing symmetric encryption keys in a communication system comprising a plurality of nodes, wherein each of the nodes comprises a printing device configured for generating at least one encryption key for encrypting data based on changing printer control setting and printer job, wherein each node comprises information about possible printer control settings and possible printer jobs, the method comprising the following steps:

a) providing an initial session key information via at least one secure channel to each node, wherein the initial session key information comprises an initial printer control setting and an initial printer job setting, wherein the initial session key information is different for each node;

b) providing as a one-time pad an initial session key package to each of the nodes encrypted with the respective node's initial session key information, wherein the initial session key package comprises a plurality of items of first session key information for communication of the respective receiving node with the other nodes of the communication system, wherein any two nodes have a common item of first session key information;

c) generating at each node second session key information for each of the other nodes, wherein the second session key information comprises a second printer control setting and a second printer job setting, wherein the second session key information generated by the respective node for the respective other nodes is different for each of the other nodes;

d) sending a message from one of the nodes to another one of the nodes, wherein the message is encrypted with the first session key information for communication between said node and said another one of the nodes, wherein the message comprises the second session key information generated by the node sending the message for the node receiving the message such that the node sending the message and the node receiving the message are able for encrypted communication with each other.

11 . A communication system comprising: a plurality of nodes, wherein each of the nodes comprises a printing device configured for generating at least one encryption key for encrypting data based on changing printer control setting and printer job, wherein each node comprises information about possible printer control settings and possible printer jobs, wherein the communication system is configured for providing an initial session key information via at least one secure channel to each node, wherein the initial session key information comprises an initial printer control setting and an initial printer job setting, wherein the initial session key information is different for each node, wherein the communication system further comprises at least one center hub configured for providing as a one-time pad an initial session key package to each of the nodes encrypted with the respective node's initial session key information, wherein the initial session key package comprises a plurality of items of first session key information for communication of the respective receiving node with the other nodes of the communication system, wherein any two nodes have a common item of first session key information, wherein each of the nodes is configured for generating at each node second session key information for each of the other nodes, wherein the second session key information comprises a second printer control setting and a second printer job setting, wherein the second session key information generated by the respective node for the respective other nodes is different for each of the other nodes, wherein each of the nodes is configured for sending a message from one of the nodes to another one of the nodes, wherein the message is encrypted with the first session key information for communication between said node and said another one of the nodes, wherein the message comprises the second session key information generated by the node sending the message for the node receiving the message such that the node sending the message and the node receiving the message are able for encrypted communication with each other.

12 . The communication system according to claim 11 , wherein the communication system is configured for distributing symmetric encryption keys.

13 . An apparatus for distributing symmetric encryption keys in a communication system comprising a plurality of nodes, wherein each of the nodes comprises a printing device configured for generating at least one encryption key for encrypting data based on changing printer control setting and printer job, wherein each node comprises information about possible printer control settings and possible printer jobs, the apparatus comprising

a memory storing instructions; and

a processor configured to:

a) providing an initial session key information via at least one secure channel to each node, wherein the initial session key information comprises an initial printer control setting and an initial printer job setting, wherein the initial session key information is different for each node;

b) providing as a one-time pad an initial session key package to each of the nodes encrypted with the respective node's initial session key information, wherein the initial session key package comprises a plurality of items of first session key information for communication of the respective receiving node with the other nodes of the communication system, wherein any two nodes have a common item of first session key information;

c) generating at each node second session key information for each of the other nodes, wherein the second session key information comprises a second printer control setting and a second printer job setting, wherein the second session key information generated by the respective node for the respective other nodes is different for each of the other nodes;

d) sending a message from one of the nodes to another one of the nodes, wherein the message is encrypted with the first session key information for communication between said node and said another one of the nodes, wherein the message comprises the second session key information generated by the node sending the message for the node receiving the message such that the node sending the message and the node receiving the message are able for encrypted communication with each other.