IP Library › Granted Patent US 9,594,897
Granted Patent B2
US 9,594,897 · App. 14/242,236 · Granted Mar 14, 2017

Crum chip mountable in comsumable unit, image forming apparatus for authentificating the crum chip, and method thereof

Inventor: Sang-hyong Lee (Seoul, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
G06F21/44G03G21/1892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,594,897
App. No.
14/242,236
Granted
Mar 14, 2017
Kind
B2
Abstract

Provided herein is an image forming apparatus, comprising: a consumable unit where a CRUM (Customer Replaceable Unit Monitoring) chip is mounted; and a main body configured to perform at least one of a first authentication and a second authentication of the consumable unit, when the consumable unit is mounted, wherein the main body comprises: a main controller for performing the first authentication according to firmware stored in the image forming apparatus; and an authentication controller for using at least one ASIC (Application Specific Integrated Circuit) to perform the second authentication of the consumable unit. Accordingly, it is possible to effectively authenticate a consumable unit even when the image forming apparatus is hacked.

Claims (78)

1. An image forming apparatus, comprising:

a consumable unit where a custom replaceable unit monitor (CRUM) chip is mounted; and

a main body configured to perform a first authentication and a second authentication of the consumable unit, when the consumable unit is mounted,

wherein the main body comprises:

a main controller to perform the first authentication with respect to firmware stored in the image forming apparatus by transmitting an encoded signal including a first value to the CRUM chip, and by using a first Message Authentication Code (MAC) generated by a central processing unit (CPU) of the CRUM chip based on the first value and a second MAC generated by the main controller; and

an authentication controller to use at least one ASIC (Application Specific Integrated Circuit) to perform the second authentication of the consumable unit,

wherein the second authentication is performed using the at least one ASIC in parallel with performance of the first authentication, or is performed subsequent to performance of the first authentication if the first authentication succeeds.

2. The apparatus according to claim 1 , wherein:

the authentication controller performs the second authentication separately from the first authentication performed by the main controller, and

the main controller performs communication with the CRUM chip, when both the first authentication and the second authentication succeed.

3. The apparatus according to claim 1 , wherein:

the main controller and the authentication controller perform the first authentication and the second authentication, separately, when an event requiring performing an authentication is input, and

the event is an event where one of a power reset signal, replacement signal of the consumable unit, and an image forming job completion job is input.

4. The apparatus according to claim 1 , further comprising a system function controller configured to restrict functions of the consumable unit when at least one authentication of the first authentication and the second authentication fails, wherein the authentication controller comprises:

an interface to receive authentication information including a first authentication MAC from the CRUM chip;

an authentication processor configured to use the authentication information to generate a second authentication MAC, and compare the first authentication MAC with the second authentication MAC to verify the CRUM chip; and

a function restriction requester configured to transmit a function restriction request to the system function controller when the authentication of the CRUM chip fails.

5. The apparatus according to claim 4 , wherein the authentication processor comprises:

an electronic signature verifier to verify an electronic signature included in the authentication information;

a section key generator to generate a section key;

a MAC generator configured to use the section key to generate the second authentication MAC; and

a MAC verifier configured to compare the second authentication MAC with the first authentication MAC, and to provide a result of comparison to the function restriction requester,

wherein the at least one ASIC includes the electronic signature verifier, section key generator, MAC generator, and MAC verifier.

6. The apparatus according to claim 1 , wherein the CRUM chip comprises:

an interface configured to be connected to the main controller;

a memory to store information on the consumable unit;

the CPU configured to be connected to the main controller through the interface, and to perform the first authentication between the CPU and the main controller; and

an authentication ASIC configured to perform the second authentication between the authentication ASIC and the authentication controller,

wherein the CPU updates the information stored in the memory according to a signal transmitted from the main controller, when both the first authentication and the second authentication succeed.

7. The apparatus according to claim 1 , wherein the CRUM chip comprises:

an interface configured to be connected to the main controller;

a memory where an operating system (O/S) of the CRUM chip is stored separately from the main body O/S of the image forming apparatus; and

the CPU configured to use the O/S of the CRUM chip to perform the first authentication between the CPU and the main controller, and to perform the second authentication between the CPU and the authentication controller.

8. The apparatus according to claim 1 , wherein the main controller and authentication controller are separately connected to a bus, and each of the main controller and authentication controller communicate with the CRUM chip through the bus.

9. A custom replaceable unit monitor (CRUM) chip mountable on a consumable unit of an image forming apparatus, the CRUM chip comprising:

an interface configured to be connected to the image forming apparatus;

a memory to store information on the consumable unit;

a central processing unit (CPU) configured to perform, through the interface, a first authentication with respect to firmware stored in the image forming apparatus in association with a main controller mounted on the image forming apparatus by using a first Message Authentication Code (MAC) generated by the CPU based on first value included in an encoded signal received from the main controller, and by using a second MAC generated by the main controller; and

an authentication ASIC (Application Specific Integrated Circuit) configured to perform a second authentication in order to perform the second authentication in association with an authentication controller comprising at least one ASIC (Application Specific Integrated Circuit) mounted on the image forming apparatus,

wherein the second authentication is performed using the authentication ASIC in parallel with performance of the first authentication, or is performed subsequent to performance of the first authentication if the first authentication succeeds.

10. The CRUM chip according to claim 9 , wherein the CPU updates information stored in the memory of the CRUM chip according to a signal transmitted from the main controller, when both the first authentication and the second authentication succeed.

11. The CRUM chip according to claim 9 , wherein the ASIC in association with the authentication controller performs the second authentication separately from the first authentication performed by the central processing unit in association with the main controller.

12. A custom replaceable unit monitor (CRUM) chip mountable on a consumable unit of an image forming apparatus, the CRUM chip comprising:

an interface configured to be connected to the image forming apparatus;

a memory where an operating system (O/S) of the CRUM chip is stored separately from a main body O/S of the image forming apparatus;

a central processing unit (CPU) configured to be connected to the image forming apparatus through the interface, configured to use the O/S of the CRUM chip to perform, through the interface, a first authentication with respect to firmware stored in the image forming apparatus in association with a main controller mounted on the image forming apparatus through the interface by using a first Message Authentication Code (MAC) generated by the CPU based on first value included in an encoded signal received from the main controller, and by using a second MAC generated by the main controller, and configured to use the O/S of the CRUM chip to perform a second authentication in association with an authentication controller mounted on the image forming apparatus,

wherein the second authentication is performed using at least one ASIC (Application Specific Integrated Circuit) of the authentication controller, and is performed in parallel with performance of the first authentication, or is performed subsequent to performance of the first authentication if the first authentication succeeds.

13. The CRUM chip according to claim 12 , wherein the authentication controller using the at least one ASIC performs the second authentication separately from the first authentication performed by the main controller according to the firmware.

14. A method for authenticating a consumable unit of an image forming apparatus, the method comprising:

determining whether an event requiring an authentication of a consumable unit mounted on the image forming apparatus occurred;

in response to determining that the event occurred:

performing a first authentication with respect to firmware stored in the image forming apparatus by executing computer readable instructions stored in the image forming apparatus by a main controller mounted on the image forming apparatus; and

performing a second authentication of the consumable unit separately from the main controller by an authentication controller comprising at least one ASIC (Application Specific Integrated Circuit),

wherein

the performing the first authentication includes the main controller transmitting an encoded signal including a first value to the consumable unit, and the main controller using a first Message Authentication Code (MAC) generated by the consumable unit based on the first value and a second MAC generated by the main controller, and

the performing the second authentication is performed using the at least one ASIC in parallel with performing the first authentication, or is performed subsequent to performing the first authentication if the first authentication succeeds.

15. The method according to claim 14 , further comprising:

completing the authentication of the consumable unit when the first authentication and the second authentication succeed; and

processing the authentication of the consumable unit as a failure when at least one of the first authentication and the second authentication fails.

16. The method according to claim 14 , wherein the event is an event where at least one of a power reset signal, replacement signal of the consumable unit, and image forming job completion signal is input.

17. The method according to claim 14 , wherein the performing the second authentication comprises:

receiving authentication information comprising a first authentication MAC from a CRUM chip of the consumable unit;

generating a second authentication MAC using the authentication information; and

comparing the first authentication MAC and the second authentication MAC to authenticate the CRUM chip.

18. The method according to claim 17 , wherein the comparing the first authentication MAC and the second authentication MAC comprises:

verifying an electronic signature included in the authentication information using an electronic signature authentication ASIC;

generating a section key using a section key generation ASIC, when the electronic signature is verified;

generating the second authentication MAC using the section key in a MAC generation ASIC; and

comparing the second authentication MAC and the first authentication MAC in a MAC verification ASIC.

19. A method for authenticating a consumable unit of an image forming apparatus, the method comprising:

determining whether or not an event requiring an authentication of a consumable unit mounted on the image forming apparatus occurred;

in response to determining that the event occurred:

performing a first authentication with respect to firmware stored in the image forming apparatus by executing computer readable instructions stored in the image forming apparatus by a main controller mounted on the image forming apparatus; and

performing a second authentication of the consumable unit separately from the main controller by using an authentication controller, which is a processing element separate from the main controller,

wherein

the performing the first authentication includes the main controller transmitting an encoded signal including a first value to the consumable unit, and the main controller using a first Message Authentication Code (MAC) generated by the consumable unit based on the first value and a second MAC generated by the main controller, and

the performing the second authentication is performed in parallel with performing the first authentication, or is performed subsequent to performing the first authentication if the first authentication succeeds.

20. At least one non-transitory computer readable medium storing computer readable instructions that control at least one processing element to implement the method of claim 19 .

Assignments (6)
CONFIRMATORY ASSIGNMENT EFFECTIVE NOVEMBER 1, 2018 Recorded Oct 17, 2019
From: HP PRINTING KOREA CO., LTD.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 050747/0080 →
CHANGE OF LEGAL ENTITY EFFECTIVE AUG. 31, 2018 Recorded Oct 16, 2019
From: HP PRINTING KOREA CO., LTD.
To: HP PRINTING KOREA CO., LTD.
Reel/Frame 050938/0139 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DOCUMENTATION EVIDENCING THE CHANGE OF NAME PREVIOUSLY RECORDED ON REEL 047370 FRAME 0405. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Nov 21, 2018
From: S-PRINTING SOLUTION CO., LTD.
To: HP PRINTING KOREA CO., LTD.
Reel/Frame 047769/0001 →
CHANGE OF NAME Recorded Aug 17, 2018
From: S-PRINTING SOLUTION CO., LTD.
To: HP PRINTING KOREA CO., LTD.
Reel/Frame 047370/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2017
From: SAMSUNG ELECTRONICS CO., LTD
To: S-PRINTING SOLUTION CO., LTD.
Reel/Frame 041852/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2014
From: LEE, SANG-HYONG
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 032574/0859 →
Priority Claims (1)
KR 10-2013-0113733 · Sep 25, 2013 · national
Continuity (1)
Related Publication 20150089630A1 · Mar 26, 2015