WO2019017920A1 - Rendering apparatus identities - Google Patents

Rendering apparatus identities Download PDF

Info

Publication number
WO2019017920A1
WO2019017920A1 PCT/US2017/042641 US2017042641W WO2019017920A1 WO 2019017920 A1 WO2019017920 A1 WO 2019017920A1 US 2017042641 W US2017042641 W US 2017042641W WO 2019017920 A1 WO2019017920 A1 WO 2019017920A1
Authority
WO
WIPO (PCT)
Prior art keywords
passphrase
user equipment
identity
rendering apparatus
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2017/042641
Other languages
French (fr)
Inventor
Joshua S. Schiffman
Luke T. MATHER
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Hewlett Packard Development Co LP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hewlett Packard Development Co LP filed Critical Hewlett Packard Development Co LP
Priority to US16/629,981 priority Critical patent/US20200153807A1/en
Priority to PCT/US2017/042641 priority patent/WO2019017920A1/en
Publication of WO2019017920A1 publication Critical patent/WO2019017920A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0863Generation of secret information including derivation or calculation of cryptographic keys or passwords involving passwords or one-time passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/061Network architectures or network communication protocols for network security for supporting key management in a packet data network for key exchange, e.g. in peer-to-peer networks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication
    • G06F21/46Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • G06F21/608Secure printing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0869Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/42Anonymization, e.g. involving pseudonyms

Definitions

  • An IT department can manage the identities of rendering apparatus, such as 2D and 3D printers for example, and a pull-print process exists in which a user's print job is held on a server or a user's workstation and released by the user at a printing device. Users manually enrol identities of rendering apparatus onto a workstation.
  • Figure 1 is a schematic representation of a method for registering the identity of a rendering apparatus according to an example
  • Figure 2 is a flow chart of a method according to an example.
  • Figure 3 is a schematic representation of a system according to an example.
  • a non-enterprise or infrastructure print environment or a traditional IP-based network users may not have a way to bind the observation of a physical rendering apparatus, such as a 2D or 3D printer, with cryptographic key material used to communicate securely with it.
  • a physical rendering apparatus such as a 2D or 3D printer
  • users may not have an automated method for discovering a printer identity and having it available at their printing device (workstation or laptop for example). Collecting a name or IP address of a printer may not be sufficient to ensure that the printer the workstation connects to is the same one that the user found because such identifiers may not be bound to the physical printer.
  • a method of using a passphrase to establish a shared key that can be deployed over a peer-to-peer or networking transport protocol to transfer an identity and address of a rendering apparatus, such as a printer, to user equipment, such as a mobile device.
  • a user can then securely enrol that render apparatus at their workstation with a minimum of effort and with the assurance that the identity matches the physical printer they observed.
  • a password authenticated key exchange can be performed between a rendering apparatus and user equipment to agree a temporary shared key.
  • the key can be used to transport an identity of the rendering appratus (such as a certificate, or a public key and associated metadata for example) to user equipment (UE).
  • UE user equipment
  • the UE can then transport the identity and enrol it back at the user's workstation. That is, in an example, the UE can configure parameters used for communicating with a rendering apparatus. This can include setting records in an OS, displaying Ul elements, and verifying the apparatus identity.
  • FIG. 1 is a schematic representation of a method for registering the identity of a rendering apparatus according to an example.
  • a passphrase 109 is generated using a processor 103 of a rendering apparatus 101.
  • the passphrase may be an alphanumeric sequence, a sequence of letters or words or other text.
  • the validity of the passphrase is attested to 111 at user equipment 105 or the passphrase is submitted to user equipment 105. For example, a user may manually input the passphrase at the user equipment 105 or provide a confirmation that a passphrase provided and displayed by the user equipment 105 matches the passphrase 109, which may be displayed on a display of the rendering appratus 101.
  • a rendering apparatus identity 102 is encrypted using a cryptographic session key 120 agreed on the basis of the passphrase 109 to provide an encrypted rendering apparatus identity 110.
  • the rendering apparatus identity 110 is transferred from the user equipment to a user apparatus 107, such as a workstation after having been transferred 113 from the rendering apparatus 101 to the user equipment 105. That is, the user can transport the encrypted identity to their workstation. It can be decrypted 108 using the user equipment, which has the shared session key, and the decrypted identity 102 can be transferred from the user equipment 105 to the rendering apparatus 107.
  • Figure 2 is a flow chart of a method according to an example.
  • the user wishes to enrol a printer identity at their workstation, they can perform the following stops:
  • a user carries their mobile device to a printer.
  • the user presses a button on the printer in block 203 or sends a request from their mobile device to the printer to request it to initiate a PAKE in block 203.
  • the printer generates a human-readable passphrase 206 and shows the password using an on-device display.
  • the user enters the same passphrase (or confirms that a passphrase displayed on its device is the same, depending on the particular PAKE used).
  • a session key 210 is generated on the basis of the passphrase.
  • the key may be generated using a PAKE process, such as SPAKE2 for example).
  • the freshly derived session 210 key is used to encrypt the printer's identity material 212 (certificate or public key and metadata for example) to provide an encrypted version of the identity 214 which is transferred to the mobile device in block 213.
  • An example of the transport process is for the mobile device and printer to exchange random information to produce a session key S.
  • the printer then encrypts the identity I using an authenticated encryption scheme like AES- GCM. This produces an encrypted identity C and an associated integrity tag, T.
  • the printer sends C+T to the mobile device, which then validates T and decrypts C using S.
  • the user can initiate the transfer of the identity material 214 from the mobile device to their workstation in block 215.
  • the workstation can then validate the printer's identity (e.g., certificate) against a trust CA certificate and the user can assess other attributes about the printer that are present in the identity.
  • An example would be information about the location and capabilities of the printer, if the user is satisfied with these attributes, they can then instruct the workstation to complete the printer enrolment process.
  • the printer is now authenticated for use from user's workstation.
  • the PAKE can be used over any transport protocol - peer-to-peer or infrastructure.
  • FIG. 3 is a schematic representation of a system according to an example.
  • a rendering apparatus 301 such as a printer for example, comprises a processor 303 and a memory 305.
  • Memory 305 stores data representing a passphrase 307 that has been agreed between the rendering apparatus 301 (or configured by a user or administrator for example) and user equipment 309.
  • Rendering apparatus further comprises a display 306.
  • User equipment 309 comprises a processor 311 and a memory 313.
  • Memory 313 can store data representing the passphrase 307 that has been agreed between the rendering apparatus 301 and user equipment 309 as noted above.
  • User equipment 309 further comprises an input device 317 and a display 319.
  • the validity of the passphrase 307 is attested to at user equipment 309. In an example, this can be by the passphrase 307 being displayed on display 306 of rendering apparatus 301 for a user. The user can then confirm whether the displayed passphrase 307 matches the passphrase that can be displayed using display 319 of user equipment 309.
  • the mutual display of the passphrase can be triggered automatically as the user equipment approaches the vicinity of the apparatus 301 (e.g. user equipment 309 may poll rendering apparatus 301 or vice versa), or may be triggered by the user selecting an appropriate function of the rendering apparatus 301.
  • the validity of the passphrase 307 can be attested to at User equipment 309 by submitting the passphrase 307 to the User equipment 309.
  • the rendering apparatus 301 can display the passphrase 307 using display 306.
  • a user can use input device 317 to input the passphrase to the user equipment 309 where the processor 311 can verify that the passphrase matches with one stored in memory 313 for example.
  • the passphrase once validated, can be used as part of a PAKE protocol to generate a session key 320 than can be used to encrypt an identity 321 of the rendering apparatus 301 to generate an encrypted rendering apparatus identity 323.
  • User equipment 309 can then be transported to a workstation or device 315 where the encrypted rendering apparatus identity 323 can be decrypted using session key 320 and transferred to the workstation or device 315 to enable the rendering apparatus to be enrolled.
  • a temporary key can be accomplished through visual media such as a QR code on the rendering device's LCD or through a rendering of the key in physical space (e.g., a paper print out or a 3D rendering). The user could then capture this rendering with a camera (e.g., on a mobile phone) and translate the code into a key.
  • the code would also contain information that would be used to contact the apparatus such as the IP address or the name of a WiFi direct network.
  • the apparatus could generate a one-time use password to access a private WiFi Direct network. This would enable the user's mobile device to contact the apparatus directly and obtain the identity.
  • the SPAKE2 key exchange algorithm can be implemented on printer and mobile application (Android; iOS) software.
  • the communication between the printer and mobile device can use any transport protocol without security, in an example, the user equipment (mobile device) can use a pre-existing Bluetooth classic pairing with their workstation to transfer the identity and register it with their desktop software,
  • the encryption of the identity with the temporary key provides a logical binding between the delivered identity and the physical device that presented the temporary key.
  • This binding is what enables a user to associate an incorporeal identity, such as a cryptographic key, and real world object While this binding does not prove the identity of the device (this is the responsibility of a certificate verification protocol), it gives the user confidence in the device that bares that identity.
  • Examples in the present disclosure can be provided as methods, systems or machine-readable instructions.
  • Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
  • the machine-readable instructions may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams.
  • a processor or processing apparatus may execute the machine-readable instructions.
  • modules of apparatus for example, user equipment and rendering apparatus
  • modules of apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry.
  • the term 'processor* is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc.
  • the methods and modules may all be performed by a single processor or divided amongst several processors.
  • Such machine-readable instructions may also be stored in a computer readable storage that can guide the computer or other programmable data processing devices to operate in a specific mode.
  • the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
  • memory 305, 313 can comprise machine-readable instructions which are executable by processor 303, 311.
  • the instructions can comprise instructions to:
  • Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide a operation for realizing functions specified by ftow(s) in the flow charts and/or block(s) in the block diagrams.
  • teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Health & Medical Sciences (AREA)
  • Accessory Devices And Overall Control Thereof (AREA)

Abstract

L'invention concerne un procédé d'enregistrement de l'identité d'un appareil de rendu, le procédé consistant à générer une phrase de passe à l'aide d'un processeur de l'appareil de rendu, à attester la validité de la phrase de passe au niveau d'un équipement d'utilisateur ou à soumettre la phrase de passe à l'équipement d'utilisateur, à chiffrer une identité d'appareil de rendu à l'aide d'une clé de session cryptographique convenue sur la base de la phrase de passe, et à transférer l'identité d'appareil de rendu de l'équipement d'utilisateur vers un appareil d'utilisateur.The invention relates to a method for registering the identity of a rendering apparatus, the method of generating a passphrase using a processor of the rendering apparatus, to attest the validity of the passphrase at a user equipment or submitting the passphrase to the user equipment, encrypting a renderer identity using an agreed cryptographic session key on the user equipment; base of the passphrase, and to transfer the rendering identity of the user equipment to a user device.

Description

RENDERING APPARATUS IDENTITIES
BACKGROUND
[0001] An IT department can manage the identities of rendering apparatus, such as 2D and 3D printers for example, and a pull-print process exists in which a user's print job is held on a server or a user's workstation and released by the user at a printing device. Users manually enrol identities of rendering apparatus onto a workstation.
BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Various features of certain examples will he apparent from the detailed description which follows, taken in conjunction with the accompanying drawings, which together illustrate, by way of example only, a number of features, and wherein:
[0003] Figure 1 is a schematic representation of a method for registering the identity of a rendering apparatus according to an example;
[0004] Figure 2 is a flow chart of a method according to an example; and
[0005] Figure 3 is a schematic representation of a system according to an example.
DETAILED DESCRIPTION
[0006] in the following description, for purposes of explanation, numerous specific details of certain examples are set forth. Reference in the specification to "an example" or similar language means that a particular feature, structure, or characteristic described in connection with the example is included in at least that one example, but not necessarily in other examples.
[0007] In, for example, a non-enterprise or infrastructure print environment or a traditional IP-based network, users may not have a way to bind the observation of a physical rendering apparatus, such as a 2D or 3D printer, with cryptographic key material used to communicate securely with it. Also, in such an environment, users may not have an automated method for discovering a printer identity and having it available at their printing device (workstation or laptop for example). Collecting a name or IP address of a printer may not be sufficient to ensure that the printer the workstation connects to is the same one that the user found because such identifiers may not be bound to the physical printer.
[0008] According to an example, there is provided a method of using a passphrase to establish a shared key that can be deployed over a peer-to-peer or networking transport protocol to transfer an identity and address of a rendering apparatus, such as a printer, to user equipment, such as a mobile device. A user can then securely enrol that render apparatus at their workstation with a minimum of effort and with the assurance that the identity matches the physical printer they observed.
[0009] In an example, a password authenticated key exchange (PAKE) can be performed between a rendering apparatus and user equipment to agree a temporary shared key. The key can be used to transport an identity of the rendering appratus (such as a certificate, or a public key and associated metadata for example) to user equipment (UE). The UE can then transport the identity and enrol it back at the user's workstation. That is, in an example, the UE can configure parameters used for communicating with a rendering apparatus. This can include setting records in an OS, displaying Ul elements, and verifying the apparatus identity.
[0010] Use of the PAKE authenticates the identity with the physical rendering appratus, as the user confirms that a passphrase displayed on the apparatus is the same as one they observe on the UE.
[0011] Figure 1 is a schematic representation of a method for registering the identity of a rendering apparatus according to an example. A passphrase 109 is generated using a processor 103 of a rendering apparatus 101. The passphrase may be an alphanumeric sequence, a sequence of letters or words or other text. [0012] The validity of the passphrase is attested to 111 at user equipment 105 or the passphrase is submitted to user equipment 105. For example, a user may manually input the passphrase at the user equipment 105 or provide a confirmation that a passphrase provided and displayed by the user equipment 105 matches the passphrase 109, which may be displayed on a display of the rendering appratus 101.
[0013] A rendering apparatus identity 102 is encrypted using a cryptographic session key 120 agreed on the basis of the passphrase 109 to provide an encrypted rendering apparatus identity 110. The rendering apparatus identity 110 is transferred from the user equipment to a user apparatus 107, such as a workstation after having been transferred 113 from the rendering apparatus 101 to the user equipment 105. That is, the user can transport the encrypted identity to their workstation. It can be decrypted 108 using the user equipment, which has the shared session key, and the decrypted identity 102 can be transferred from the user equipment 105 to the rendering apparatus 107.
[0014] Figure 2 is a flow chart of a method according to an example. When the user wishes to enrol a printer identity at their workstation, they can perform the following stops:
[0015] In block 201, a user carries their mobile device to a printer. The user presses a button on the printer in block 203 or sends a request from their mobile device to the printer to request it to initiate a PAKE in block 203. In block 205, the printer generates a human-readable passphrase 206 and shows the password using an on-device display. In block 207, the user enters the same passphrase (or confirms that a passphrase displayed on its device is the same, depending on the particular PAKE used).
[0016] In block 209, a session key 210 is generated on the basis of the passphrase. The key may be generated using a PAKE process, such as SPAKE2 for example). In block 211, the freshly derived session 210 key is used to encrypt the printer's identity material 212 (certificate or public key and metadata for example) to provide an encrypted version of the identity 214 which is transferred to the mobile device in block 213.
[0017] An example of the transport process is for the mobile device and printer to exchange random information to produce a session key S. The printer then encrypts the identity I using an authenticated encryption scheme like AES- GCM. This produces an encrypted identity C and an associated integrity tag, T. The printer sends C+T to the mobile device, which then validates T and decrypts C using S.
[0018] When the user returns to their workstation, they can initiate the transfer of the identity material 214 from the mobile device to their workstation in block 215. The workstation can then validate the printer's identity (e.g., certificate) against a trust CA certificate and the user can assess other attributes about the printer that are present in the identity. An example would be information about the location and capabilities of the printer, if the user is satisfied with these attributes, they can then instruct the workstation to complete the printer enrolment process. The printer is now authenticated for use from user's workstation. The PAKE can be used over any transport protocol - peer-to-peer or infrastructure.
[0019] Figure 3 is a schematic representation of a system according to an example. A rendering apparatus 301 , such as a printer for example, comprises a processor 303 and a memory 305. Memory 305 stores data representing a passphrase 307 that has been agreed between the rendering apparatus 301 (or configured by a user or administrator for example) and user equipment 309. Rendering apparatus further comprises a display 306.
[0020] User equipment 309 comprises a processor 311 and a memory 313. Memory 313 can store data representing the passphrase 307 that has been agreed between the rendering apparatus 301 and user equipment 309 as noted above. User equipment 309 further comprises an input device 317 and a display 319.
[0021] As described above, the validity of the passphrase 307 is attested to at user equipment 309. In an example, this can be by the passphrase 307 being displayed on display 306 of rendering apparatus 301 for a user. The user can then confirm whether the displayed passphrase 307 matches the passphrase that can be displayed using display 319 of user equipment 309. The mutual display of the passphrase can be triggered automatically as the user equipment approaches the vicinity of the apparatus 301 (e.g. user equipment 309 may poll rendering apparatus 301 or vice versa), or may be triggered by the user selecting an appropriate function of the rendering apparatus 301.
[0022] In an example, the validity of the passphrase 307 can be attested to at User equipment 309 by submitting the passphrase 307 to the User equipment 309. For example, the rendering apparatus 301 can display the passphrase 307 using display 306. A user can use input device 317 to input the passphrase to the user equipment 309 where the processor 311 can verify that the passphrase matches with one stored in memory 313 for example.
[0023] The passphrase, once validated, can be used as part of a PAKE protocol to generate a session key 320 than can be used to encrypt an identity 321 of the rendering apparatus 301 to generate an encrypted rendering apparatus identity 323. User equipment 309 can then be transported to a workstation or device 315 where the encrypted rendering apparatus identity 323 can be decrypted using session key 320 and transferred to the workstation or device 315 to enable the rendering apparatus to be enrolled.
[0024] There are several additional approaches for delivering the printer identity to the user. Delivery of a temporary key can be accomplished through visual media such as a QR code on the rendering device's LCD or through a rendering of the key in physical space (e.g., a paper print out or a 3D rendering). The user could then capture this rendering with a camera (e.g., on a mobile phone) and translate the code into a key. The code would also contain information that would be used to contact the apparatus such as the IP address or the name of a WiFi direct network.
[0025] As an alternative to the temporary key, the apparatus could generate a one-time use password to access a private WiFi Direct network. This would enable the user's mobile device to contact the apparatus directly and obtain the identity. [0026] The SPAKE2 key exchange algorithm can be implemented on printer and mobile application (Android; iOS) software. The communication between the printer and mobile device can use any transport protocol without security, in an example, the user equipment (mobile device) can use a pre-existing Bluetooth classic pairing with their workstation to transfer the identity and register it with their desktop software,
[0027] it is worth noting that the encryption of the identity with the temporary key provides a logical binding between the delivered identity and the physical device that presented the temporary key. This binding is what enables a user to associate an incorporeal identity, such as a cryptographic key, and real world object While this binding does not prove the identity of the device (this is the responsibility of a certificate verification protocol), it gives the user confidence in the device that bares that identity.
[0028] Examples in the present disclosure can be provided as methods, systems or machine-readable instructions. Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
[0029] The present disclosure is described with reference to flow charts and/or block diagrams of the method, devices and systems according to examples of the present disclosure. Although the flow diagrams described above show a specific order of execution, the order of execution may differ from that which is depicted. Blocks described in relation to one flow chart may be combined with those of another flow chart. In some examples, some blocks of the flow diagrams may not be necessary and/or additional blocks may be added. It shall be understood that each flow and/or block in the flow charts and/or block diagrams, as well as combinations of the flows and/or diagrams in the flow charts and/or block diagrams can be realized by machine readable instructions.
[0030] The machine-readable instructions may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams. In particular, a processor or processing apparatus may execute the machine-readable instructions. Thus, modules of apparatus (for example, user equipment and rendering apparatus) may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry. The term 'processor* is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may all be performed by a single processor or divided amongst several processors.
[0031] Such machine-readable instructions may also be stored in a computer readable storage that can guide the computer or other programmable data processing devices to operate in a specific mode.
[0032] For example, the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
[0033] With reference to figure 3 for example, memory 305, 313 can comprise machine-readable instructions which are executable by processor 303, 311. The instructions can comprise instructions to:
[0034] generate a passphrase using a processor of the rendering apparatus;
[0035] attest to the validity of the passphrase at user equipment or submitting the passphrase to the user equipment;
[0036] encrypt a rendering apparatus identity using a cryptographic session key agreed on the basis of the passphrase; and
[0037] transfer the rendering apparatus identity from the user equipment to a user apparatus.
[0038] Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide a operation for realizing functions specified by ftow(s) in the flow charts and/or block(s) in the block diagrams.
[0039] Further, the teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.
[0040] While the method, apparatus and related aspects have been described with reference to certain examples, various modifications, changes, omissions, and substitutions can be made without departing from the spirit of the present disclosure. In particular, a feature or block from one example may be combined with or substituted by a feature/block of another example.
[0041] The word "comprising" does not exclude the presence of elements other than those listed in a claim, "a" or "an" does not exclude a plurality, and a single processor or other unit may fulfil the functions of several units recited in the claims.
[0042] The features of any dependent claim may be combined with the features of any of the independent claims or other dependent claims.

Claims

1. A method for registering the identity of a rendering apparatus, the method comprising: generating a passphrase using a processor of the rendering apparatus; attesting to the validity of the passphrase at user equipment or submitting the passphrase to the user equipment; encrypting a rendering apparatus identity using a cryptographic session key agreed on the basis of the passphrase; and transferring the rendering apparatus identity from the user equipment to a user apparatus.
2. A method as claimed in claim 1 , further comprising; decrypting the encrypted rendering apparatus identity using the cryptographic session key.
3. A method as claimed in claim 2, wherein the encrypted rendering apparatus identity is decrypted at the user equipment.
A method as claimed in claim 1 , wherein the passphrase is generated of a password authenticated key exchange protocol.
5. A method as claimed in claim 1 , wherein attesting to the validity of the passphrase at user equipment further comprises: entering the passphrase to the user equipment; and comparing the entered passphrase to a pre-defined agreed passphrase stored in a memory of the user equipment
6. A method as claimed in claim 1 wherein attesting to the validity of the passphrase at user equipment further comprises: providing a confirmation that the generated passphrase is the same as a pre-defined agreed passphrase stored in a memory of the user equipment.
7. A method as claimed in claim 1 , further comprising using the identity of the rendering apparatus to enable secure communication with the user equipment.
8. User equipment comprising a processor to: attest to the validity of a passphrase or receive an input representing the passphrase; encrypt a rendering apparatus identity using a cryptographic session key agreed on the basis of the passphrase; and transfer the rendering apparatus identity from the user equipment to a user apparatus.
9. User equipment as claimed in claim 8, the processor further to: decrypt the encrypted rendering apparatus identity using the
cryptographic session key.
10. User equipment as claimed in claim 8, the processor further to: compare the entered passphrase to a pre-defined agreed passphrase stored in a memory of the user equipment
11. User equipment as claimed in claim 8, the processor to: use the identity of the rendering apparatus to enable secure
communication with the user equipment.
12. A non-transitory machine-readable storage medium encoded with instructions executable by a processor of user equipment, the machine- readable storage medium comprising: instructions to: attest to the validity of a passphrase or receive an input representing the passphrase; encrypt a rendering apparatus identity using a cryptographic session key agreed on the basis of the passphrase; and transfer the rendering apparatus identity from the user equipment to a user apparatus.
13. A non-transitory machine-readable storage medium as claimed in claim 12, further comprising instructions to decrypt the encrypted rendering apparatus identity using the cryptographic session key.
14. A non-transitory machine-readable storage medium as claimed in claim 12, further comprising instructions to compare the entered passphrase to a predefined agreed passphrase stored in a memory of the user equipment.
15. A ποπ-transitory machine-readable storage medium as claimed in claim 12, further comprising instructions to use the identity of the rendering apparatus to enable secure communication with the user equipment
PCT/US2017/042641 2017-07-18 2017-07-18 Rendering apparatus identities Ceased WO2019017920A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US16/629,981 US20200153807A1 (en) 2017-07-18 2017-07-18 Rendering apparatus identities
PCT/US2017/042641 WO2019017920A1 (en) 2017-07-18 2017-07-18 Rendering apparatus identities

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/US2017/042641 WO2019017920A1 (en) 2017-07-18 2017-07-18 Rendering apparatus identities

Publications (1)

Publication Number Publication Date
WO2019017920A1 true WO2019017920A1 (en) 2019-01-24

Family

ID=65016319

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2017/042641 Ceased WO2019017920A1 (en) 2017-07-18 2017-07-18 Rendering apparatus identities

Country Status (2)

Country Link
US (1) US20200153807A1 (en)
WO (1) WO2019017920A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070083750A1 (en) * 2003-09-03 2007-04-12 Sony Corporation Device authentication system
US7248693B1 (en) * 2000-01-13 2007-07-24 Hewlett-Packard Development Company, L.P. Secure network-based system for the distributed printing of documents
US7984298B2 (en) * 2006-01-24 2011-07-19 Huawei Technologies Co., Ltd. Method, system and authentication centre for authenticating in end-to-end communications based on a mobile network
US9674162B1 (en) * 2015-03-13 2017-06-06 Amazon Technologies, Inc. Updating encrypted cryptographic key pair

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101833346B1 (en) * 2011-11-03 2018-03-02 에스프린팅솔루션 주식회사 Electronic apparatus, cloud server and method for controlling printing thereof

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7248693B1 (en) * 2000-01-13 2007-07-24 Hewlett-Packard Development Company, L.P. Secure network-based system for the distributed printing of documents
US20070083750A1 (en) * 2003-09-03 2007-04-12 Sony Corporation Device authentication system
US7984298B2 (en) * 2006-01-24 2011-07-19 Huawei Technologies Co., Ltd. Method, system and authentication centre for authenticating in end-to-end communications based on a mobile network
US9674162B1 (en) * 2015-03-13 2017-06-06 Amazon Technologies, Inc. Updating encrypted cryptographic key pair

Also Published As

Publication number Publication date
US20200153807A1 (en) 2020-05-14

Similar Documents

Publication Publication Date Title
CN110493261B (en) Verification code obtaining method based on block chain, client, server and storage medium
CN111756737B (en) Data transmission method, device, system, computer equipment and readable storage medium
EP3232634B1 (en) Identity authentication method and device
US20180091505A1 (en) Distributed storage of authentication data
CN106302606B (en) Across the application access method and device of one kind
RU2018103181A (en) CONFIDENTIAL AUTHENTICATION AND SECURITY
CN106060078B (en) User information encryption method, register method and verification method applied to cloud platform
US11164186B2 (en) Methods, systems, and devices for managing digital assets
US9942042B1 (en) Key containers for securely asserting user authentication
CA3120090A1 (en) Systems, methods, and apparatuses for network management
JP2009526322A5 (en)
CN113572728B (en) Method, device, equipment and medium for authenticating Internet of things equipment
JP2019501431A5 (en)
JP2018528691A (en) Method and apparatus for multi-user cluster identity authentication
KR20110140122A (en) Methods for producing products with certificates and keys
US11480945B2 (en) Production device for production of an object for user permitted to print pre-defined number of copies of the object including encrypted token, and decrypted by the production device for determining user access right
CN110505185A (en) Auth method, equipment and system
CN102984273A (en) Encryption method, decryption method, encryption device and decryption device of virtual disk and cloud server
JP2024516961A5 (en)
WO2017028595A1 (en) Payment verification method, terminal, and server
CN115941328A (en) Encryption processing method, device and system for shareable user data
CN108234125B (en) System and method for identity authentication
CN117595996A (en) An electronic signature processing method, device, electronic equipment and storage medium
CN107409043B (en) Distributed processing of products based on centrally encrypted storage data
CN109446793B (en) Account encryption method and device based on Windows agent

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17918662

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17918662

Country of ref document: EP

Kind code of ref document: A1