CN110536042A - Image forming apparatus and its control method, storage medium - Google Patents

Image forming apparatus and its control method, storage medium Download PDF

Info

Publication number
CN110536042A
CN110536042A CN201910832398.8A CN201910832398A CN110536042A CN 110536042 A CN110536042 A CN 110536042A CN 201910832398 A CN201910832398 A CN 201910832398A CN 110536042 A CN110536042 A CN 110536042A
Authority
CN
China
Prior art keywords
program
verified
imaging controller
safety
safety chip
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201910832398.8A
Other languages
Chinese (zh)
Other versions
CN110536042B (en
Inventor
尹爱国
覃祖料
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zhuhai Pantum Electronics Co Ltd
Original Assignee
Zhuhai Pantum Electronics Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhuhai Pantum Electronics Co Ltd filed Critical Zhuhai Pantum Electronics Co Ltd
Priority to CN201910832398.8A priority Critical patent/CN110536042B/en
Publication of CN110536042A publication Critical patent/CN110536042A/en
Priority to PCT/CN2020/095310 priority patent/WO2020259285A1/en
Application granted granted Critical
Publication of CN110536042B publication Critical patent/CN110536042B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N1/00Scanning, transmission or reproduction of documents or the like, e.g. facsimile transmission; Details thereof
    • H04N1/00002Diagnosis, testing or measuring; Detecting, analysing or monitoring not otherwise provided for
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N1/00Scanning, transmission or reproduction of documents or the like, e.g. facsimile transmission; Details thereof
    • H04N1/00002Diagnosis, testing or measuring; Detecting, analysing or monitoring not otherwise provided for
    • H04N1/00026Methods therefor
    • H04N1/00042Monitoring, i.e. observation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N1/00Scanning, transmission or reproduction of documents or the like, e.g. facsimile transmission; Details thereof
    • H04N1/00002Diagnosis, testing or measuring; Detecting, analysing or monitoring not otherwise provided for
    • H04N1/00071Diagnosis, testing or measuring; Detecting, analysing or monitoring not otherwise provided for characterised by the action taken
    • H04N1/00082Adjusting or controlling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N1/00Scanning, transmission or reproduction of documents or the like, e.g. facsimile transmission; Details thereof
    • H04N1/44Secrecy systems

Landscapes

  • Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • Biomedical Technology (AREA)
  • General Health & Medical Sciences (AREA)
  • Facsimiles In General (AREA)

Abstract

The present invention relates to a kind of image forming apparatus and its control method, storage medium, image forming apparatus includes imaging controller, is configured as control described image and forms device execution imaging operation;Nonvolatile memory is configured as storing program to be verified;Safety chip, it is configured as the program to be verified stored in reading non-volatile storage, it treats checking routine to carry out safety check and program to be verified is sent to the corresponding program loader to be verified of imaging controller, program loader to be verified starts to execute program to be verified after receiving program to be verified;Wherein, during safety chip treats checking routine progress safety check, if safety chip determines program to be verified and do not meet safety requirements, and when current imaging controller is carrying out program to be verified, safety chip, which controls imaging controller, to be stopped executing program to be verified.Above-mentioned image forming apparatus can be good at guaranteeing the safety of image forming apparatus processing information.

Description

Image forming apparatus and its control method, storage medium
Technical field
The present invention relates to definition technique fields, and in particular to a kind of image forming apparatus and its control method, storage Medium.
Background technique
With the progress of electronic science and technology, the development of image forming apparatus (Image forming apparatus) It is more and more mature, but as a kind of computer peripheral equipment, image forming apparatus is easy by criminal (such as hacker) Attack, by with scanning and/or facsimile function laser printer (one of image forming apparatus multiple types) for, The data of scanning or fax may all carry the confidential data of user, or even connect kernel component photosensitive drums in laser imaging On, it is also possible to carry user's confidential data to be printed;For these data once revealing, it is many unnecessary to bring to user Trouble;If being related to the office of company or government secret department, if the confidential data that image forming apparatus carries It is leaked, it is also possible to jeopardize company or government safety.Currently, safety chip is usually arranged to image forming apparatus in the prior art Controller (imaging controller 1) operation be monitored, but at present do not occur reliable scheme can be good at guarantee image Form the safety of device processing information.
Summary of the invention
The embodiment of the present invention provides a kind of image forming apparatus and its control method, storage medium, be able to solve it is current not Reliable scheme occur can be good at the problem of guaranteeing the safety of image forming apparatus processing information.
In a first aspect, the embodiment of the invention provides a kind of image forming apparatuses, comprising: imaging controller is configured as It controls described image and forms device execution imaging operation;
Nonvolatile memory is configured as storing program to be verified, and the program to be verified is that described image forms dress Set operation program used;
Safety chip is configured as reading the nonvolatile memory memory after described image forms device and powers on The program to be verified of storage carries out safety check to the program to be verified and is sent to the program to be verified described The corresponding program loader to be verified of imaging controller, the program loader to be verified are opened after receiving the program to be verified Begin to execute the program to be verified;
Wherein, during the safety chip carries out safety check to the program to be verified, if the safe core Piece determines that the program to be verified does not meet safety requirements, and presently described imaging controller is carrying out the program to be verified When, the safety chip, which controls the imaging controller, to be stopped executing the program to be verified.
Optionally, the safety chip during reading the program to be verified or reads the program to be verified After, safety check carried out to the program to be verified that has read, while by the program to be verified read be sent to it is described to Checking routine loader.
Optionally, the safety chip during reading the program to be verified or reads the program to be verified After, safety check first is carried out to the program to be verified read, only determines the program to be verified symbol read After closing safety requirements, the program to be verified read is just sent to the program loader to be verified.
Optionally, the program to be verified includes startup program, and the startup program is that imaging controller completion is opened Move required program;If the safety chip determines that the startup program does not meet safety requirements, and presently described imaging controls When device is carrying out the startup program, the safety chip, which first controls the imaging controller, to be stopped executing the starting journey Sequence, then control the imaging controller and reset, so that the imaging controller returns to original state;Alternatively, the safe core Piece, which first controls the imaging controller, to be stopped executing the startup program, then controls the imaging controller power-off.
Optionally, the safety chip is connect with the reset terminal of the imaging controller, and the safety chip is by institute The reset terminal for stating imaging controller sends reset enable signal and the imaging controller is resetted.
Optionally, it further includes power module and power switch that described image, which forms device, and the power switch is connected to institute It states between power module and the imaging controller, the safety chip is disconnected and/or generated by controlling the power switch The enable end of enabled invalid signals to the power module powers off imaging controller.
Optionally, the program to be verified includes at least one application program, if described in the safety chip is determining at least The first application program in one application program does not meet safety requirements, and the safety chip forbids the imaging controller to execute First application program.
Second aspect, the embodiment of the invention provides a kind of control method of image forming apparatus, described image forms dress It sets including imaging controller, nonvolatile memory and safety chip, wherein the imaging controller is configured as described in control Image forming apparatus executes imaging operation, and the nonvolatile memory is configured as storing program to be verified, described to be verified Program is that described image forms device operation program used;
The described method includes:
After described image, which forms device, to be powered on, the safety chip reads the institute stored in the nonvolatile memory Program to be verified is stated, the program to be verified is carried out safety check and the program to be verified is sent to the imaging to control The corresponding program loader to be verified of device processed, the program loader to be verified start to execute after receiving the program to be verified The program to be verified;
Wherein, during the safety chip carries out safety check to the program to be verified, if the safe core Piece determines that the program to be verified does not meet safety requirements, and presently described imaging controller is carrying out the program to be verified When, the safety chip, which controls the imaging controller, to be stopped executing the program to be verified.
It is described to read the program to be verified stored in the nonvolatile memory, the program to be verified is carried out Safety check and the program to be verified is sent to the corresponding program loader to be verified of the imaging controller, it is specific to wrap It includes:
The safety chip is during reading the program to be verified or after reading the program to be verified, Safety check is carried out to the program to be verified read, while the program to be verified read is sent to the program to be verified Loader.
Optionally, described to read the program to be verified stored in the nonvolatile memory, to described to be verified Program carries out safety check and the program to be verified is sent to the corresponding program load to be verified of the imaging controller Device specifically includes:
The safety chip is during reading the program to be verified or after reading the program to be verified, Safety check first is carried out to the program to be verified read, only determines that the program to be verified read meets safety and wants After asking, the program to be verified read is just sent to the program loader to be verified.
Optionally, the program to be verified includes startup program, and the startup program is that imaging controller completion is opened Move required program;
If the safety chip determines that the program to be verified does not meet safety requirements, and presently described imaging controls When device is carrying out the program to be verified, the safety chip, which controls the imaging controller, to be stopped executing the journey to be verified Sequence specifically includes:
If the safety chip determines that the startup program does not meet safety requirements, and presently described imaging controller is When executing the startup program, the safety chip, which first controls the imaging controller, to be stopped executing the startup program, then is controlled It makes the imaging controller to reset, so that the imaging controller returns to original state;Alternatively, the safety chip first controls The imaging controller stops executing the startup program, then controls the imaging controller power-off.
Optionally, the safety chip is connect with the reset terminal of the imaging controller, and the safety chip is by institute The reset terminal for stating imaging controller sends reset enable signal and the imaging controller is resetted.
The third aspect, the embodiment of the invention provides a kind of storage medium, the storage medium includes the program of storage, In, equipment where controlling the storage medium in described program operation executes the above method.
Fourth aspect, it is described to deposit the embodiment of the invention provides a kind of image forming apparatus, including memory and processor Reservoir is used to control the execution of program instruction, described program instruction for storing the information including program instruction, the processor The step of above method is realized when being loaded and executed by processor.
It is appreciated that the present invention carries out safety check to imaging controller program to be executed by safety chip, when When program to be verified does not meet safety requirements, safety chip, which controls the imaging controller, to be stopped executing the program to be verified, So that imaging controller is in the process of running, the whole monitoring by safety chip, reliable guarantee image forming apparatus Safety, meanwhile, imaging controller program to be executed is sent to imaging controller by safety chip by the present invention, is not necessarily to Additionally configuring corresponding hardware circuit to allow imaging controller and safety chip to obtain simultaneously from nonvolatile memory Program to be verified, therefore circuit structure is further simplified, save cost.
Detailed description of the invention
Present invention will be further explained below with reference to the attached drawings and examples.
Fig. 1 is a kind of schematic block diagram for image forming apparatus that one embodiment of the invention provides;
Fig. 2-Fig. 6 is respectively a kind of hardware block diagram for image forming apparatus that a variety of different embodiments of the present invention provide;
Fig. 7 is a kind of flow chart of the control method for image forming apparatus that further embodiment of this invention provides;
Fig. 8 is the schematic block diagram for the image forming apparatus that further embodiment of this invention provides.
Specific embodiment
For a better understanding of the technical solution of the present invention, being retouched in detail to the embodiment of the present invention with reference to the accompanying drawing It states.
It will be appreciated that described embodiments are only a part of the embodiments of the present invention, instead of all the embodiments.Base Embodiment in the present invention, it is obtained by those of ordinary skill in the art without making creative efforts it is all its Its embodiment, shall fall within the protection scope of the present invention.
The term used in embodiments of the present invention is only to be not intended to be limiting merely for for the purpose of describing particular embodiments The present invention.In the embodiment of the present invention and the "an" of singular used in the attached claims, " described " and "the" It is also intended to including most forms, unless context clearly shows that other meanings.
It should be appreciated that term "and/or" used herein is only a kind of incidence relation for describing affiliated partner, indicate There may be three kinds of relationships, for example, A and/or B, can indicate: individualism A, exist simultaneously A and B, individualism B these three Situation.In addition, character "/" herein, typicallys represent the relationship that forward-backward correlation object is a kind of "or".
Attached drawing 1 is please referred to, the embodiment of the present invention provides a kind of image forming apparatus, comprising:
Imaging controller 1 is configured as control image forming apparatus and executes imaging operation;
Nonvolatile memory 3 is configured as storing program to be verified, and program to be verified runs institute for image forming apparatus Program;
Safety chip 2 is configured as after image forming apparatus powers on, store in reading non-volatile storage 3 to Checking routine, treats that checking routine carries out safety check and that program to be verified is sent to imaging controller 1 is corresponding to school Program loader is tested, program loader to be verified starts to execute program to be verified after receiving program to be verified;
Wherein, during safety chip 2 treats checking routine progress safety check, if safety chip 2 is determined to school It tests program and does not meet safety requirements, and when current imaging controller 1 is carrying out program to be verified, the control imaging of safety chip 2 Controller 1 stops executing program to be verified.
It should be noted that safety chip 2 treat checking routine carry out safety check can be it is static and or dynamic, For example, the program to be verified stored in 2 reading non-volatile storage 3 of safety chip, and be ready for sending it is right to imaging controller 1 The program loader to be verified answered;Such as it can also be and control is imaged after program loader to be verified receives program to be verified Device 1 starts to execute program to be verified.
It is appreciated that the present invention carries out safety check to 1 program to be executed of imaging controller by safety chip 2, When program to be verified does not meet safety requirements, safety chip 2, which controls imaging controller 1, to be stopped executing program to be verified, so that In the process of running, the whole monitoring by safety chip 2 can be good at guaranteeing image forming apparatus imaging controller 1 Safety, good reliability.Meanwhile 1 program to be executed of imaging controller is sent to by the present invention by safety chip 2 As controller 1, to allow imaging controller 1 with safety chip 2 simultaneously from non-without additionally configuring corresponding hardware circuit Volatile memory 3 obtains program to be verified, therefore further simplifies circuit structure, has saved cost.
Specifically, image forming apparatus indicates to print in the recording medium of such as printing paper for example by computer generation The device of print data.The example of image forming apparatus include but is not limited to duplicator, printer, facsimile machine, scanner and The multifunction peripheral of above functions is executed in one single.
Specifically, imaging controller 1 is SoC (System on Chip, system on chip), is configured as control image and is formed The image forming process operation of device, SoC are used to execute data transmit-receive, order transmitting-receiving, the relevant processing operation of engine control, for example, How application call interface unit (including but not limited to USB port, wired network port, wireless network port etc.) is passed through Come sending and receiving data, order, state etc., received print parameters can also be obtained by application program, and resolve to control engine Mechanism executes the order of specific function, for example, LSU exposure parameter, paper pick-up roller rotational parameters etc.;In addition, for there is user right The image forming apparatus SoC for authenticating perhaps encryption/decryption process function is also arranged to be able to execute user right certification or add Close/decryption processing function, and the interface unit in image forming apparatus can also receive the print job number for carrying out automatic drive device It is ordered according to printing, scanning, fax, or transmission scanning, facsimile data, printing, scanning, FAX mode information etc., Yi Jian Full chip 2 exchanges the information such as predetermined safety regulation, log with security monitoring service device.
Specifically, safety chip 2 includes trust computing administration module, forms imaging controller in device for monitoring image The corresponding operation activity of 1 (SoC);Trust computing (Trusted Computing) in safety chip 2, be for behavior safety and It is raw, it is widely used in computer and communication system, to improve the safety of system entirety.Information security includes four aspects: Equipment safety, data safety, content safety and behavior safety;For the behavior safety characteristic for further promoting image forming apparatus, This embodiment introduces trust computing functions;The corresponding functional module of safety chip 2 that the present embodiment refers to includes four kinds of functions: Program (or module) starting/operation monitoring function (such as white list strategy), registering functional, audit function, upgrading monitoring function, Specifically, safety chip 2 is responsible for the driving layer module of supervision image forming apparatus operating system (such as linux system) and is born The application layer program of duty supervision image forming apparatus, safety chip 2 only allows to run the driving and program within the scope of white list, non- Driving and program within the scope of white list do not allow to run;Safety chip 2 will record or report to be occurred on image forming apparatus Driving layer and application layer to image forming apparatus may be implemented in this way and supervised comprehensively for security incident behavior, can be effective Prevent the unsafe acts of the application program and device drives of imaging controller 1.
Nonvolatile memory 3 is connect with safety chip 2, nonvolatile memory 3 can be NOR flash (flash memory), NAND flash (flash memory), EEPROM (erasable programmable read only memory), FRAM (ferroelectric memory), MRAM are (magnetic ) and NVSRAM (non-volatile static memory) etc. RAM.
Program loader to be verified for example can be RAM (random access memory), SRAM (static random access memory Device) and DDR (Double Data Rate synchronous DRAM) etc., program loader to be verified can be inside imaging controller 1 Loader, be also possible to the external load device connecting with imaging controller 1.
In one or more embodiments of the invention, program to be verified includes startup program, operating system (Operating System, OS) program and application program, wherein startup program is that imaging controller 1 is completed needed for starting Program, such as Boot program and Uboot program etc., Boot program and Uboot program are imaging control when image forming apparatus starts Device 1 processed needs bootstrap to be loaded, and the quantity of application program is at least one.In other embodiments, program to be verified It can also only include application program.
Attached drawing 2 is please referred to, in embodiments of the present invention, safety chip 2 passes through the first communication bus (such as institute in attached drawing 2 The spi bus 1 shown) and 3 communication connection of nonvolatile memory, for reading program to be verified out of nonvolatile memory 3, Safety chip 2 is used by the second communication bus (such as attached spi bus 2 shown in Fig. 2) and 1 communication connection of imaging controller In by read program to be verified be sent to the program loader to be verified built in imaging controller 1.
Further, in the present embodiment, safety chip 2 treats checking routine progress safety check and will be to be verified Program is sent to the corresponding program loader to be verified of imaging controller 1, can specifically include:
Safety chip 2 is during reading program to be verified or after reading program to be verified, to what is read Program to be verified carries out safety check, while the program to be verified read is sent to program loader to be verified.
Optionally, safety chip 2 can be after reading all programs to be verified, then start to treat checking routine into Row verification, and program to be verified is sent to program loader to be verified while verification;Alternatively, safety chip 2 read to During checking routine, safety check is carried out to the program to be verified currently read, and to be verified by what is currently read Program is sent to program loader to be verified and executes, alternatively, having read program to be verified part journey therein when safety chip 2 is every When sequence (such as Boot program), safety chip 2 just carries out security verification to the subprogram, while the subprogram being sent To program loader to be verified, the verification of other parts program (Uboot program, operating system program etc.) is then successively carried out again And it executes.
Optionally, during safety chip 2 can also be program to be verified, the program to be verified read is pacified Whole school tests, while the program to be verified read is sent to program loader to be verified;Still optionally further, with Boot program For, Boot program is divided into many segments, every segment is verified respectively, and every segment is sent to program load simultaneously Device can not be done directly the corresponding function of current Boot program since program loader receives many segments, so program Loader can't be done directly the corresponding starting of current Boot program, also can't directly threaten the safety of whole system; After safety chip 2 all completes verification to every segment program, such program loader is also almost with regard to receiving the entire Boot journey that is over Sequence, other programs to be verified are also similar.
It is appreciated that the present invention is by adopting when reading or verifying the program to be verified that imaging controller 1 needs to be implemented With the mode carried out synchronous with verification is executed, the speed that imaging controller 1 is run is improved, when program to be verified is startup program When, the starting speed of image forming apparatus can be accelerated, and then improve the usage experience of user.
In other embodiment, under the not high scene of the speed of service or starting rate request of image forming apparatus, Safety chip 2 treats that checking routine carries out safety check and that program to be verified is sent to imaging controller 1 is corresponding to school Program loader is tested, may include:
Safety chip 2 is during reading program to be verified or after reading program to be verified, first to having read Program to be verified carry out safety check will just have been read after the program to be verified for determining to have read meets safety requirements Program to be verified be sent to program loader to be verified.
Optionally, safety chip 2 can first read all programs to be verified, after all program ver-ify to be verified passes through, All programs to be verified are sent to program loader to be verified again, it, no longer will be to school if program ver-ify to be verified does not pass through It tests program and is sent to program loader to be verified.Alternatively, safety chip 2 successively treats the part program to be verified in checking routine (for example, successively verifying to Boot program, Uboot program, operating system program and application program) verifies, when the portion After dividing program ver-ify to be verified to pass through, then part program to be verified is sent to program loader to be verified and is executed, then again Carry out reading, verification and the execution of the program to be verified of next part.
It is directed to safety chip 2 above safety check is carried out to the program to be verified that has read, while will read Program to be verified is sent to the mode of program loader to be verified, further, if safety chip 2 is in the mistake for carrying out safety check Cheng Zhong, when determining that startup program or operating system program in program to be verified do not meet safety requirements, it is contemplated that imaging control The operating status of device 1 processed, may include following situations:
If current imaging controller 1 is carrying out startup program or operating system program or application program, safe core Piece 2, which first controls imaging controller 1, to be stopped executing startup program or operating system program or application program, then controls imaging control Device 1 resets, so that imaging controller 1 returns to original state;It or is that safety chip 2 first controls the stopping of imaging controller 1 Startup program or operating system program are executed, then controls the power-off of imaging controller 1.
If current imaging controller 1 is not carried out startup program or operating system program or application program, directly control Imaging controller 1 resets, so that imaging controller 1 returns to original state;It or is that safety chip 2 directly controls imaging Controller 1 powers off.
It is appreciated that when detecting that imaging controller 1 starts the startup program to be executed or operating system program is not inconsistent When closing safety requirements, control imaging controller 1 resets or power-off, it is ensured that the safety of image forming apparatus.
It should also be noted that, in one or more embodiments of the invention, if safety chip 2 determines at least one application The first application program in program does not meet safety requirements, and when current imaging controller 1 is carrying out application program, safe core Piece 2, which sends error signal control imaging controller 1, to be stopped executing the first application program;If safety chip 2 determines that at least one is answered Safety requirements is not met with the first application program in program, and current imaging controller 1 is not carrying out startup program, safety Chip 2 does not allow imaging controller 1 to start the execution to the first application program.
Further, it controls imaging controller 1 for safety chip 2 described above to reset, accordingly, the present invention is implemented Example provides following hardware plan:
Please continue to refer to attached drawing 2, safety chip 2 is connect with the reset terminal of imaging controller 1, safety chip 2 by As the reset terminal of controller 1 sends reset enable signal imaging controller 1 is resetted.
Specifically, the pin (GPIO4) of safety chip 2 passes sequentially through the first end (Y) and second end (Z) of first switch 4 It is connect with the reset terminal (Reset) of imaging controller 1, when image forming apparatus powers on, first switch 4 is on state.
In the present embodiment, when program to be verified does not meet safety requirements, safety chip 2 needs to control imaging controller 1 when resetting, and safety chip 2 resets enable signal by pin (GPIO4) output, via the first end (Y) of first switch 4 and the Two ends (Z) control imaging controller 1 and reset, so that imaging controller 1 returns to the reset terminal (Reset) of imaging controller 1 Original state.
In the present embodiment, resetting enable signal is low level signal, in other embodiments, resets enable signal It can also be high level signal.
Optionally, first switch 4 includes but is not limited to MOS (metal-oxide-semiconductor, metal-oxide Object-semiconductor field effect transistor) pipe, triode, IGBT (Insulated Gate Bipolar Transistor, insulated gate pair Bipolar transistor) etc. any one in electronic switches.
Further, the mode that imaging controller 1 resets is controlled for above-mentioned safety chip 2, accordingly, the present invention is real It applies example and provides following hardware plan:
Attached drawing 3 is please referred to, image forming apparatus further includes power module and power switch 6, and power switch 6 is connected to power supply It between module and imaging controller 1, is arranged at and powers for imaging controller 1, safety chip 2 is disconnected by control power switch 6 The enable end for opening and/or generating enabled invalid signals to power module powers off imaging controller 1.
It, can also be with it is understood that power module, for exporting direct current, power module can be single power supply unit It is to be composed of multiple independent power supply units.Power module can not only power for imaging controller 1, can also be safety Other hardware modules power supply in the power supply of chip 2 or image forming apparatus.
In the present embodiment, power module include multiple first power source units (A1, A2 as shown in Fig. 3, A3......An) and multiple second power source units (B1, B2, B3......Bn as shown in Fig. 3), wherein the first power supply Unit is configured to the power supply of safety chip 2, and second power source unit is configured to the power supply of imaging controller 1.
Accordingly, power switch 6 is variable connector, including multiple switch unit (for convenience of describing, hereinafter by power switch Each switch unit in 6 is known as first switch unit), the first end (Y) and a second source of each first switch unit The power output end of unit connects, the power pins of second end (Z) and imaging controller 1 of each first switch unit (Powerin) it connects.In the present embodiment, image forming apparatus further includes second switch 5, and each first switch unit makes Energy end (EN) is connect with the first end (Y) of second switch 5, the second end of pin (GPIOx) and second switch 5 of safety chip 2 (Z) it connects.When image forming apparatus powers on, be connected between the first end (Y) and second end (Z) of second switch 5.
When program to be verified does not meet safety requirements, and safety chip 2 needs to control the power-off of imaging controller 1, safe core Piece 2 can export enabled invalid signals by pin (GPIOx), and enabled invalid signals are transmitted to power supply by second switch 5 and open The enable end (EN) for closing 6, so that between the first end (Y) and second end (Z) of each first switch unit in power switch 6 Access disconnects, and then multiple second power source units in power module power off imaging controller 1.
In the present embodiment, power switch 6 and second switch 5 are both configured to when enable end receives high level signal It is enabled that effectively it is invalid to enable when receiving low level signal, therefore, each switch unit in power switch 6 and second switch 5 It can be by PNP triode or PMOS tube as switch.
Attached drawing 4 is please referred to, in other embodiments of the present invention, multiple second power source units are (as of figure 4 B1, B2, B3......Bn) it can be connected with a part by the power pins (Power in) of power switch 6 and imaging controller 1 It connects, another part is directly connect with the power pins of imaging controller 1 (Power in), and the electricity directly with imaging controller 1 The power supply enable end (EN) of second power source unit of source pin (Power in) connection is connect with the first end (Y) of second switch 5, Therefore, when program to be verified does not meet safety requirements, and safety chip 2 needs to control the power-off of imaging controller 1, safety chip 2 Pin (GPIOx) can export enabled invalid signals control section second power source unit simultaneously power supply enable end (EN) it is enabled Invalid and power switch 6 disconnects, to realize the purpose of the control power-off of imaging controller 1.
Attached drawing 5 is please referred to, in other embodiments of the present invention, safety chip 2 and imaging controller 1 can be with common portions (AB1, AB2, AB3......ABn in such as attached drawing 5, for convenience of distinguishing, referred to hereinafter as shared partial power is third to independent power source Power supply unit), wherein the output end of third power supply unit was both connect with the power pins of safety chip 2, further through power switch 6 connect with the power pins of imaging controller 1, and second power source unit passes through the power pins of power switch 6 and imaging controller 1 (Powerin) it connects.Therefore, when program to be verified does not meet safety requirements, it is disconnected that safety chip 2 needs to control imaging controller 1 When electric, safety chip 2 can export enabled invalid signals by pin (GPIOx), and enabled invalid signals are passed by second switch 5 The enable end (EN) of power switch 6 is transported to, so that the first end (Y) and second of each first switch unit in power switch 6 The access between (Z) is held to disconnect, and then multiple second power source units in power module and third power supply unit stop as imaging Controller 1 is powered.
Attached drawing 6 is please referred to, in other embodiments of the present invention, safety chip 2 and 1 common sparing of imaging controller When three power supply units, the output end of third power supply unit was both connect with the power pins of safety chip 2, further through power switch 6 It is connect with the power pins of imaging controller 1, and second power source unit a part passes through power switch 6 and imaging controller 1 Power pins (Powerin) connection, another part are directly connect with the power pins of imaging controller 1 (Power in), and straight It is opened with second the power supply enable end (EN) for connecing the second power source unit connecting with the power pins of imaging controller 1 (Power in) Close 5 first end (Y) connection;Therefore, when program to be verified does not meet safety requirements, safety chip 2 needs to control imaging control When device 1 powers off, safety chip 2 can export enabled invalid signals by pin (GPIOx), and enabled invalid signals are opened by second It closes 5 and is transmitted to the enable end (EN) of power switch 6 and the enable end (EN) of part second power source unit, so that power switch 6 In each first switch unit first end (Y) and second end (Z) between access disconnect and part second power source unit Enable end it is enabled invalid, and then multiple second power source units in power module and third power supply unit stop as imaging control Device 1 is powered.
It should be noted that numerous embodiments listed above are merely illustrative, the present invention can also have other a variety of phases The embodiment answered, does not describe one by one herein.
Further, it may include: that safety chip 2 is read that safety chip 2, which treats checking routine and carries out the process of safety check, Program to be verified is taken, arithmetic check information is generated, it is whether full by comparison calculation check information and preset safety check information Sufficient predetermined relationship judges whether program to be verified meets safety requirements, for example, safety chip 2 by itself computing circuit or Person's operation part treats checking routine and carries out logical operation, obtains arithmetic check information, safety chip 2 further passes through logic Comparison circuit or logical comparison code, are compared arithmetic check information and safety check information, judge that arithmetic check is believed Whether breath and safety check information meet predetermined relationship (such as equal), if it is satisfied, then determine program to be verified be it is complete, It is not modified, meets safety requirements, if conditions are not met, then determining that program to be verified is to be modified, do not meet safety It is required that.
Safety check information includes but is not limited to a preset check code, is preset in the safety check information in the present invention Check code can be and be directly stored in advance, be also possible to preparatory (for example, before factory) to complete information to be verified, Verification is carried out and by obtained check results as safety check information using preset rules, and the safety check information is stored. When needing to carry out security verification (for example, when use process post sales needs to start), safety chip 2 is wanted according to above-mentioned It asks, reads program to be verified and safety check information, and treat checking routine and carry out logical operation, obtain arithmetic check information, Then arithmetic check information and safety check information are compared, and then obtain check results.
The embodiment of the invention also provides a kind of control method of image forming apparatus, image forming apparatus includes imaging control Device, nonvolatile memory and safety chip processed, wherein imaging controller is configured as control image forming apparatus and executes imaging Operation, nonvolatile memory are configured as storing program to be verified, and program to be verified is that image forming apparatus operation is used Program;
Attached drawing 7 is please referred to, the control method of image forming apparatus includes:
Step S01: after image forming apparatus powers on, to be stored in safety chip reading non-volatile storage to school Test program.
Step S02: treating checking routine progress safety check and it is corresponding that program to be verified is sent to imaging controller Program loader to be verified;
Step S03: program loader to be verified starts to execute program to be verified after receiving program to be verified;Wherein, In During safety chip treats checking routine progress safety check, if safety chip determines that program to be verified does not meet safety and wants Ask, and when current imaging controller is carrying out program to be verified, safety chip control imaging controller stop executing it is to be verified Program.
Further, the program to be verified stored in reading non-volatile storage treats checking routine and carries out safe school It tests and program to be verified is sent to the corresponding program loader to be verified of imaging controller, specifically include:
Safety chip is during reading program to be verified or after reading program to be verified, to read to Checking routine carries out safety check, while the program to be verified read is sent to program loader to be verified.
Further, the program to be verified stored in reading non-volatile storage treats checking routine and carries out safe school It tests and program to be verified is sent to the corresponding program loader to be verified of imaging controller, specifically include:
Safety chip is during reading program to be verified or after reading program to be verified, first to having read Program to be verified carries out safety check will just read after only determining that the program to be verified read meets safety requirements Program to be verified be sent to program loader to be verified.
Further, program to be verified includes startup program, and startup program is journey needed for imaging controller completes starting Sequence;
If safety chip determines program to be verified and does not meet safety requirements, and current imaging controller be carrying out it is to be verified When program, safety chip, which controls imaging controller, to be stopped executing program to be verified, is specifically included:
If safety chip determines that startup program does not meet safety requirements, and current imaging controller is carrying out startup program When, safety chip, which first controls imaging controller, to be stopped executing startup program, then controls imaging controller reset, so that imaging control Device processed returns to original state;Stop executing startup program alternatively, safety chip first controls imaging controller, then controls imaging control Device power-off.
Further, the reset terminal of safety chip and imaging controller connects, and safety chip is by imaging controller Reset terminal sends reset enable signal and imaging controller is resetted.
It should be noted that the control method of the image forming apparatus provided in the embodiment of the present invention is more specifically The bright corresponding contents that may refer to image forming apparatus provided in an embodiment of the present invention are no longer retouched one by one herein to avoid repeating It states.
The present embodiment provides a kind of computer readable storage medium, computer is stored on the computer readable storage medium Program realizes the control method of image forming apparatus in embodiment when the computer program is executed by processor, to avoid repeating, It does not repeat one by one herein.Alternatively, realizing in embodiment each mould in image forming apparatus when the computer program is executed by processor Block/unit function does not repeat one by one herein to avoid repeating.
Attached drawing 8 is please referred to, the embodiment of the present invention provides a kind of image forming apparatus 50, the image forming apparatus of the embodiment 50 include: processor 51, memory 52 and are stored in the program 53 that can be run in memory 52 and on processor 51, the journey The control method of the image forming apparatus in embodiment is realized when sequence 53 is executed by processor 51, it is different herein to avoid repeating One repeats.
Image forming apparatus 50 may include, but are not limited to processor 51, memory 52.Those skilled in the art can manage Solution, Fig. 8 is only the example of image forming apparatus 50, does not constitute the restriction to image forming apparatus 50, may include than figure Show more or fewer components, perhaps combine certain components or different components, such as electronic equipment can also include input Output equipment, network access equipment, bus etc..
Processor 51 can be central processing unit (Central Processing Unit, CPU), can also be other General processor, digital signal processor (Digital Signal Processor, DSP), specific integrated circuit (Application Specific Integrated Circuit, ASIC), field programmable gate array (Field- Programmable Gate Array, FPGA) either other programmable logic device, discrete gate or transistor logic, Discrete hardware components etc..General processor can be microprocessor or the processor is also possible to any conventional processor Deng.
It is apparent to those skilled in the art that for convenience and simplicity of description, the system of foregoing description, The specific work process of device and unit, can refer to corresponding processes in the foregoing method embodiment, and details are not described herein.
In several embodiments provided by the present invention, it should be understood that disclosed system, device and method can be with It realizes by another way.For example, the apparatus embodiments described above are merely exemplary, for example, the division of unit, Only a kind of logical function partition, there may be another division manner in actual implementation, for example, multiple units or components can be with In conjunction with or be desirably integrated into another system, or some features can be ignored or not executed.Another point, it is shown or discussed Mutual coupling, direct-coupling or communication connection can be through some interfaces, the INDIRECT COUPLING of device or unit or Communication connection can be electrical property, mechanical or other forms.
Unit may or may not be physically separated as illustrated by the separation member, shown as a unit Component may or may not be physical unit, it can and it is in one place, or may be distributed over multiple networks On unit.It can some or all of the units may be selected to achieve the purpose of the solution of this embodiment according to the actual needs.
It, can also be in addition, the functional units in various embodiments of the present invention may be integrated into one processing unit It is that each unit physically exists alone, can also be integrated in one unit with two or more units.Above-mentioned integrated list Member both can take the form of hardware realization, can also realize in the form of hardware adds SFU software functional unit.
The above-mentioned integrated unit being realized in the form of SFU software functional unit can store and computer-readable deposit at one In storage media.Above-mentioned SFU software functional unit is stored in a storage medium, including some instructions are used so that a computer It is each that device (can be personal computer, server or network equipment etc.) or processor (Processor) execute the present invention The part steps of embodiment method.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic or disk etc. is various to deposit Store up the medium of program code.
The above is merely preferred embodiments of the present invention, be not intended to limit the invention, it is all in spirit of the invention and Within principle, any modification, equivalent substitution, improvement and etc. done be should be included within the scope of the present invention.

Claims (16)

1. a kind of image forming apparatus characterized by comprising
Imaging controller is configured as control described image and forms device execution imaging operation;
Nonvolatile memory is configured as storing program to be verified, and the program to be verified is that described image forms device fortune Row program used;
Safety chip is configured as reading storage in the nonvolatile memory after described image forms device and powers on The program to be verified carries out safety check to the program to be verified and the program to be verified is sent to the imaging The corresponding program loader to be verified of controller, the program loader to be verified start to hold after receiving the program to be verified The row program to be verified;
Wherein, during the safety chip carries out safety check to the program to be verified, if the safety chip is true The fixed program to be verified does not meet safety requirements, and when presently described imaging controller is carrying out the program to be verified, The safety chip, which controls the imaging controller, to be stopped executing the program to be verified.
2. image forming apparatus as described in claim 1, which is characterized in that the safety chip is reading the journey to be verified During sequence or after reading the program to be verified, safety check is carried out to the program to be verified read, simultaneously The program to be verified read is sent to the program loader to be verified.
3. image forming apparatus as described in claim 1, which is characterized in that the safety chip is reading the journey to be verified During sequence or after reading the program to be verified, safety check first is carried out to the program to be verified read, when After determining that the program to be verified read meets safety requirements, the program to be verified read is just sent to institute State program loader to be verified.
4. image forming apparatus as claimed in claim 1 or 2, which is characterized in that the program to be verified includes startup program, The startup program is program needed for the imaging controller completes starting;
If the safety chip determines that the startup program does not meet safety requirements, and presently described imaging controller is carrying out When the startup program, the safety chip, which first controls the imaging controller, to be stopped executing the startup program, then controls institute Imaging controller reset is stated, so that the imaging controller returns to original state;Alternatively, described in the safety chip first controls Imaging controller stops executing the startup program, then controls the imaging controller power-off.
5. image forming apparatus as claimed in claim 4, which is characterized in that the safety chip and the imaging controller Reset terminal connection, the safety chip by the reset terminal of the imaging controller send reset enable signal make it is described at As controller resets.
6. image forming apparatus as claimed in claim 4, which is characterized in that it further includes power module that described image, which forms device, And power switch, the power switch are connected between the power module and the imaging controller, the safety chip is logical It crosses to control the power switch and disconnect and/or generate the enable end of enabled invalid signals to the power module and makes that control is imaged Device power-off.
7. image forming apparatus as claimed in claim 1 or 2, which is characterized in that the program to be verified includes at least one Application program, if the safety chip determines that the first application program at least one described application program does not meet safety and wants It asks, the safety chip forbids the imaging controller to execute first application program.
8. a kind of control method of image forming apparatus, which is characterized in that described image formed device include imaging controller, it is non- Volatile memory and safety chip, wherein the imaging controller be configured as control described image formed device execute at As operation, the nonvolatile memory is configured as storing program to be verified, and the program to be verified is formed for described image Device operation program used;
The described method includes:
After described image, which forms device, to be powered on, the safety chip read store in the nonvolatile memory it is described to Checking routine carries out safety check to the program to be verified and the program to be verified is sent to the imaging controller Corresponding program loader to be verified, the program loader to be verified start described in execution after receiving the program to be verified Program to be verified;
Wherein, during the safety chip carries out safety check to the program to be verified, if the safety chip is true The fixed program to be verified does not meet safety requirements, and when presently described imaging controller is carrying out the program to be verified, The safety chip, which controls the imaging controller, to be stopped executing the program to be verified.
9. control method as claimed in claim 8, which is characterized in that described to read storage in the nonvolatile memory The program to be verified carries out safety check to the program to be verified and the program to be verified is sent to the imaging The corresponding program loader to be verified of controller, specifically includes:
The safety chip is during reading the program to be verified or after reading the program to be verified, to The program to be verified read carries out safety check, while the program to be verified read is sent to the program to be verified and is loaded Device.
10. control method as claimed in claim 8, which is characterized in that described to read storage in the nonvolatile memory The program to be verified, to the program to be verified carry out safety check and by the program to be verified be sent to it is described at As the corresponding program loader to be verified of controller, specifically include:
The safety chip is first right during reading the program to be verified or after reading the program to be verified The program to be verified read carries out safety check, only determines that the program to be verified read meets safety requirements Afterwards, the program to be verified read is just sent to the program loader to be verified.
11. control method as claimed in claim 8 or 9, which is characterized in that the program to be verified includes startup program, institute Stating startup program is program needed for the imaging controller completes starting;
If the safety chip determines that the program to be verified does not meet safety requirements, and presently described imaging controller is just When executing the program to be verified, the safety chip, which controls the imaging controller, to be stopped executing the program to be verified, It specifically includes:
If the safety chip determines that the startup program does not meet safety requirements, and presently described imaging controller is carrying out When the startup program, the safety chip, which first controls the imaging controller, to be stopped executing the startup program, then controls institute Imaging controller reset is stated, so that the imaging controller returns to original state, alternatively, described in the safety chip first controls Imaging controller stops executing the startup program, then controls the imaging controller power-off.
12. control method as claimed in claim 11, which is characterized in that the safety chip is answered with the imaging controller The connection of position end, the safety chip make the imaging by sending reset enable signal to the reset terminal of the imaging controller Controller resets.
13. control method as claimed in claim 11, which is characterized in that described image formed device further include power module and Power switch, the power switch are connected between the power module and the imaging controller, and the safety chip passes through The enable end for controlling the power switch disconnection and/or generation enabled invalid signals to the power module makes imaging controller Power-off.
14. control method as claimed in claim 8 or 9, which is characterized in that the program to be verified includes at least one application Program, it is described to read the program to be verified stored in the nonvolatile memory, the program to be verified is pacified Whole school tests and the program to be verified is sent to the corresponding program loader to be verified of the imaging controller, specific to wrap It includes:
If the safety chip determines that the first application program at least one described application program does not meet safety requirements, described Safety chip forbids the imaging controller to execute first application program.
15. a kind of storage medium, the storage medium includes the program of storage, wherein in described program operation described in control Equipment executes method described in 8 to 14 any one where storage medium.
16. a kind of image forming apparatus, including memory and processor, the memory is for storing the letter including program instruction Breath, the processor are used to control the execution of program instruction, it is characterised in that: described program instruction is loaded and executed by processor Method described in Shi Shixian claim 8 to 14 any one.
CN201910832398.8A 2019-06-28 2019-09-04 Image forming apparatus, control method thereof, and storage medium Active CN110536042B (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201910832398.8A CN110536042B (en) 2019-09-04 2019-09-04 Image forming apparatus, control method thereof, and storage medium
PCT/CN2020/095310 WO2020259285A1 (en) 2019-06-28 2020-06-10 Image forming apparatus and securty control system for image forming apparatus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910832398.8A CN110536042B (en) 2019-09-04 2019-09-04 Image forming apparatus, control method thereof, and storage medium

Publications (2)

Publication Number Publication Date
CN110536042A true CN110536042A (en) 2019-12-03
CN110536042B CN110536042B (en) 2021-09-28

Family

ID=68666824

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910832398.8A Active CN110536042B (en) 2019-06-28 2019-09-04 Image forming apparatus, control method thereof, and storage medium

Country Status (1)

Country Link
CN (1) CN110536042B (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111614859A (en) * 2020-05-18 2020-09-01 珠海奔图电子有限公司 Image forming apparatus, security control method thereof, and storage medium
CN112104791A (en) * 2020-09-10 2020-12-18 珠海奔图电子有限公司 Image forming control method, image forming apparatus, and electronic device
WO2020259285A1 (en) * 2019-06-28 2020-12-30 珠海奔图电子有限公司 Image forming apparatus and securty control system for image forming apparatus
CN112445444A (en) * 2020-11-27 2021-03-05 珠海奔图电子有限公司 Image forming apparatus and security control system
CN112445440A (en) * 2020-11-20 2021-03-05 珠海奔图电子有限公司 Image forming apparatus, start control method thereof and storage medium

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080313453A1 (en) * 2006-06-22 2008-12-18 James Ronald Booth Boot Validation in Imaging Devices
CN108227426A (en) * 2018-01-26 2018-06-29 珠海奔图电子有限公司 Safe and reliable image forming apparatus and its control method, imaging system and method
CN108399339A (en) * 2018-02-12 2018-08-14 广东为辰信息科技有限公司 A kind of credible startup method based on safety chip

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080313453A1 (en) * 2006-06-22 2008-12-18 James Ronald Booth Boot Validation in Imaging Devices
CN108227426A (en) * 2018-01-26 2018-06-29 珠海奔图电子有限公司 Safe and reliable image forming apparatus and its control method, imaging system and method
CN108399339A (en) * 2018-02-12 2018-08-14 广东为辰信息科技有限公司 A kind of credible startup method based on safety chip

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020259285A1 (en) * 2019-06-28 2020-12-30 珠海奔图电子有限公司 Image forming apparatus and securty control system for image forming apparatus
CN111614859A (en) * 2020-05-18 2020-09-01 珠海奔图电子有限公司 Image forming apparatus, security control method thereof, and storage medium
CN112104791A (en) * 2020-09-10 2020-12-18 珠海奔图电子有限公司 Image forming control method, image forming apparatus, and electronic device
CN112445440A (en) * 2020-11-20 2021-03-05 珠海奔图电子有限公司 Image forming apparatus, start control method thereof and storage medium
CN112445440B (en) * 2020-11-20 2023-02-17 珠海奔图电子有限公司 Image forming apparatus, start control method thereof and storage medium
CN112445444A (en) * 2020-11-27 2021-03-05 珠海奔图电子有限公司 Image forming apparatus and security control system

Also Published As

Publication number Publication date
CN110536042B (en) 2021-09-28

Similar Documents

Publication Publication Date Title
CN110536042A (en) Image forming apparatus and its control method, storage medium
US10254337B2 (en) System and method for establishing a trusted diagnosis/debugging agent over a closed commodity device
US11843705B2 (en) Dynamic certificate management as part of a distributed authentication system
CN107025406B (en) Motherboard, computer-readable storage device, and firmware verification method
TWI277904B (en) Method, recording medium and system for protecting information
US7937575B2 (en) Information processing system, program product, and information processing method
CN102063591B (en) Methods for updating PCR (Platform Configuration Register) reference values based on trusted platform
Sadeghi et al. TCG inside? A note on TPM specification compliance
CN111008379A (en) Firmware safety detection method of electronic equipment and related equipment
JP6949843B2 (en) Hardware integrity check
US9208292B2 (en) Entering a secured computing environment using multiple authenticated code modules
US11106798B2 (en) Automatically replacing versions of a key database for secure boots
CN114817105B (en) Device enumeration method, device, computer device and storage medium
CN112688907A (en) Combined type equipment remote certification mode negotiation method and related equipment
CN110334522A (en) Start the method and device of measurement
CN110390201A (en) The method of computer system and initializing computer system
CN113568799A (en) Simulation of physical security devices
CN111177709A (en) Execution method and device of terminal trusted component and computer equipment
CN114969713A (en) Equipment verification method, equipment and system
CN113448681B (en) Registration method, equipment and storage medium of virtual machine monitor public key
CN210804374U (en) Image forming apparatus and security control system for image forming apparatus
WO2020259285A1 (en) Image forming apparatus and securty control system for image forming apparatus
CN112352240A (en) Data processing device, system and method for certifying or checking the security of a data processing device
TWI833653B (en) System-on-chip, a method for the same, and a computing device
CN115827522A (en) BIOS setting method, BIOS chip and electronic equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant