WO2020046282A1 - Encrypting data - Google Patents

Encrypting data Download PDF

Info

Publication number
WO2020046282A1
WO2020046282A1 PCT/US2018/048347 US2018048347W WO2020046282A1 WO 2020046282 A1 WO2020046282 A1 WO 2020046282A1 US 2018048347 W US2018048347 W US 2018048347W WO 2020046282 A1 WO2020046282 A1 WO 2020046282A1
Authority
WO
WIPO (PCT)
Prior art keywords
segment
footer
size
data
section
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2018/048347
Other languages
French (fr)
Inventor
Joshua Serratelli SCHIFFMAN
Thalia LAING
Gaetan WATTIAU
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Hewlett Packard Development Co LP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hewlett Packard Development Co LP filed Critical Hewlett Packard Development Co LP
Priority to US17/047,291 priority Critical patent/US20210176037A1/en
Priority to PCT/US2018/048347 priority patent/WO2020046282A1/en
Publication of WO2020046282A1 publication Critical patent/WO2020046282A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H04L9/3242Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer
    • G06F3/1201Dedicated interfaces to print systems
    • G06F3/1202Dedicated interfaces to print systems specifically adapted to achieve a particular effect
    • G06F3/1211Improving printing performance
    • G06F3/1212Improving printing performance achieving reduced delay between job submission and print start
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer
    • G06F3/1201Dedicated interfaces to print systems
    • G06F3/1202Dedicated interfaces to print systems specifically adapted to achieve a particular effect
    • G06F3/1222Increasing security of the print job
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer
    • G06F3/1201Dedicated interfaces to print systems
    • G06F3/1223Dedicated interfaces to print systems specifically adapted to use a particular technique
    • G06F3/1237Print job management
    • G06F3/1238Secure printing, e.g. user identification, user rights for device usage, unallowed content, blanking portions or fields of a page, releasing held jobs
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer
    • G06F3/1201Dedicated interfaces to print systems
    • G06F3/1223Dedicated interfaces to print systems specifically adapted to use a particular technique
    • G06F3/1237Print job management
    • G06F3/1244Job translation or job parsing, e.g. page banding
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/12Digital output to print unit, e.g. line printer, chain printer
    • G06F3/1201Dedicated interfaces to print systems
    • G06F3/1278Dedicated interfaces to print systems specifically adapted to adopt a particular infrastructure
    • G06F3/1285Remote printer device, e.g. being remote from client or server
    • GPHYSICS
    • G09EDUCATION; CRYPTOGRAPHY; DISPLAY; ADVERTISING; SEALS
    • G09CCIPHERING OR DECIPHERING APPARATUS FOR CRYPTOGRAPHIC OR OTHER PURPOSES INVOLVING THE NEED FOR SECRECY
    • G09C1/00Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
    • G09C1/06Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system wherein elements corresponding to the signs making up the clear text are operatively connected with elements corresponding to the signs making up the ciphered text, the connections, during operation of the apparatus, being automatically and continuously permuted by a coding or key member
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0637Modes of operation, e.g. cipher block chaining [CBC], electronic codebook [ECB] or Galois/counter mode [GCM]

Definitions

  • Authenticated encryption is used to protect print job data confidentiality and integrity.
  • Bulk encryption of a print job can be used, where a client can encrypt an entire job before sending it to a printer, then the printer can decrypt and verify the entire job before printing.
  • Figure 1 shows the structure of a PRinterMAC segment according to an example
  • Figure 2 shows PRinterMAC encryption according to an example
  • Figure 3 shows an encryption process according to an example
  • Figure 4 shows a whole encryption process according to an example
  • Figure 5 shows a decryption process according to an example
  • Figure 8 shows a method for encrypting data representing a rendering task according to an example
  • Figure 7 shows a processor associated with a memory comprising computer readable instructions for executing a method for encrypting data representing a rendering task according to an example.
  • Authenticated encryption schemes both encrypt data for confidentiality and provide a message authentication code (MAC) to verify data integrity.
  • a MAC tag can be computed over the whole decryption process before it can be validated.
  • a receiver may wait to receive and process an entire ciphertext before checking the authenticity of the data.
  • the delay to verify delays the time to print until the entire job is decrypted and verified. For large Jobs, this delay can have significant impact on first page out (FPO) performance, which may lead to users disabling encryption or using a less secure mode. This problem is also relevant to any data flows to and from printers (e.g. scanning) that are processed immediately.
  • interMAC A data segmentation scheme called interMAC is known that inserts MAC tags into a data stream to protect against adversaries that could re-order, truncate, or otherwise trick the recipient into receiving infinitely long messages.
  • interMAC uses a fixed segment size, agreed upon by both parties ahead of time, to achieve boundary hiding of the segment size from outside parties. However, this size may be discoverable since a common value may be used for performance.
  • the interMAC scheme assumes that the data is a multiple of the segment size and can use padding of the data if it is not.
  • FIG. 1 shows the structure of a PRinterMAC segment according to an example.
  • a segment may comprise a payload section 110 and a footer portion 120, 130.
  • a segment 100 may comprise: the payload or plaintext section 110; a footer section 120; and a footer size section 130.
  • the footer portion may comprise a footer section 120 and a footer size section 130.
  • the plaintext section (Pj.i) 110 contains the data to be encrypted.
  • the footer section 120 if present, contains the size of the next segment ⁇ ,).
  • the footer size section 130 contains the size of the footer section 120 or other metadata.
  • the footer size section 130 can be fixed so that a recipient knows how much data to parse, for example, a 1-byte long section. This value is used to encode information such as: the size of the next segment (, ⁇ ; whether the stream is finished; whether a logical portion is finished; or whether the next segment 0) is a dummy value.
  • a first or initialization segment can be used to bootstrap the data stream.
  • the initialization segment can be a fixed size segment that contains no plaintext data but is used to indicate the size of the second segment.
  • Each segment 100 comprises a footer 120 that indicates the size of the next segment to process or whether the data stream has finished.
  • the sender can start the stream by sending a fixed size initialization segment to indicate to a recipient how large the first segment will be.
  • the recipient may decrypt and authenticate the segment and immediately process (e.g. print) the data.
  • the segment size can be tuned to provide improved performance (e.g. smaller segments initially and larger later).
  • a strategy can be applied to obfuscate the boundary of the data's contents such as randomizing segment size, inserting dummy segments, or adjusting segments on a contextual level (e.g per page, per job).
  • This provides boundary hiding which can be useful when knowledge about the size of the data may be meaningful and where encryption alone cannot hide such metadata.
  • PRinterMAC enables the security property of boundary-hiding for practical use cases, As such, segments can be variably sized and their respective sizes can be generated independently, i.e. that is for any raj the size of is independent from the size of
  • IO203 PRinterMAC can generate segments from the plaintext and can encrypt and send these segments separately.
  • Figure 2 describes PRinterMAC encryption according to an example. Each segment may be encrypted using the same key but with different initialisation vectors (IV) and/or different additional authenticated data (AAD).
  • IV initialisation vectors
  • AAD additional authenticated data
  • the PRinterMAC construction may use a compound initialization vector construction to provide protection against an adversary that may attempt to re-order the segments, truncate the message, or repiay the data.
  • initialization vectors may be generated from three values including a nonce, a message counter and a segment counter.
  • a nonce may relate to a random value that does not change for a session.
  • a message counter may relate to a counter that is incremented after each logical portion or message, i.e. the message counter is incremented after a logical portion is completed.
  • a segment counter may relate to a counter that is incremented after each segment, i.e. each segment may increment the segment counter,
  • a logical portion may be defined as an entire job. Thus, multiple jobs can be included in a single stream and the printer can increment the counter after each one is received. Alternatively, a printed page can act as a logical portion.
  • the initialization vector can be generated as: where is the concatenation operation.
  • additional authenticated data relates to a value that is authenticated but not encrypted.
  • the additional authenticated data may be taken as an input to generate a MAC tag. Without the correct additional authenticated data, the ciphertext may not be authenticated.
  • the additional authenticated data can be generated by: [024] Generating initialisation vectors and additional authenticated data mitigates attacks that replace one segment with another, since the Initialisation vectors and additions! authenticated data for two different segments are different. Consequently, the decryption would not otherwise succeed in such an attack.
  • the initialisation vectors and the additional authenticated data are implied by the PRinterMAC construction such that they are predictable by the receiver. As such, the initialisation vectors and the additional authenticated data may not be sent with the ciphertext.
  • the encryption process will now be described according to the example of Figure 3.
  • a single segment may be encrypted.
  • the segment counter value i may be Incremented by one for each segment.
  • Inputs to the encryption process may comprise:
  • a MAC tag 360, % is associated to the encrypted segment 370 or ciphertext segment r,.
  • the segment counter is incremented, then the next generated segment counter plaintext is taken and encrypted (EOC A E) with the initialisation vectors (!V) and the additional authenticated data (AAD)
  • the rendering task may be represented by plaintext 410.
  • the plaintext is received as input and is split into N payloads or plaintext sections 420, 430, 440, 450 ⁇ of potentially differing sizes): Pi, P 3 ⁇ 4 ... P N .
  • the initialization segment 410 comprises the initialisation vectors.
  • the initialisation segment may, for example, comprise an eight-byte footer portion 416 comprising a one- byte footer size section 417. As shown, this footer size section 417 is defined to be a“7" in the initialization segment 410, which defines the length of the footer in the current segment 422 as seven-bytes iong.
  • the initialization segment 410 is encrypted using authenticated encryption 418 with the message counter, m, and segment counter, #, 41 1 input as associated data
  • a MAC tag 412, (to) is associated to the encrypted segment 413 (Co) or ciphertext segment.
  • the footer size section for each and every segment may be one-byte size.
  • the footer 419 (of the same segment) may be empty if the footer size section has an entry of “0”, meaning that the next segment is the same size as the current segment. Similarly, if the footer size section has an entry of “255”, the footer (of the same segment) is empty, meaning that the current segment is the final segment and there is no next segment. In other cases, if the footer size segment is any other value (from 1 to 254), the footer section is not empty
  • the segment counter value (/ ' ) is incremented. Then, the next (first) segment 422 for the generated segment counter value (i-1) is taken and encrypted (AE) with the initialisation vectors (IV) and the additional authenticated data (AAD).
  • the length of the subsequent plaintext section (R) 430 (variable), the size of the footer 436 and the fixed-length footer size section (e.g. of one-byte) are considered.
  • Pi 430 is the same size as the current plaintext section (Pi) 420
  • the footer size section 426 (which may itself have a size of one-byte) can be marked as“0" and the footer section 424 wiii be empty (which is the case in the example shown here).
  • the current plaintext section (Pi) 420, the empty footer section 424 and the“G * footer size section 426 are encrypted using authentication encryption 427.
  • the encryption uses the message counter, m, and segment counter value, /, 421 (incremented by 1 ⁇ as associated data.
  • a MAC tag 429, (3 ⁇ 4 ⁇ is associated to the first encrypted segment 423 (Ch) or ciphertext segment
  • This encryption process continues to construct the subsequent, fth segment 432, considering the size of the subsequent N-1 segment 442 For example, if the subsequent plaintext section 440 (PN-1 ) is the same size as the current plaintext section (PO 430, the footer size section 436 is "0” and the footer section 434 is empty. However, if the subsequent plaintext section (P> 3 ⁇ 4 . ) 440 is a different size to the current plaintext section (PO 430, the footer size section 436 (associated with PN- I ) is defined to show how many bytes the footer is (this is how many bytes are required to define the size of PN-I).
  • the plaintext PN-I 440, the footer section 434 (defining how long PN-I is) and the footer size section 436 ⁇ defining how long the footer section is) are then aii encrypted using authenticated data 437 (with the message and segment counter 431 as associated data).
  • the encryption uses the message counter, m, and segment counter value, 431 (incremented by 1 ) as associated data.
  • a MAC tag 439, (fi) is associated to the /th encrypted segment 433 (C s ) or ciphertext segment.
  • FIG. 5 shows a decryption process according to an example.
  • the PRinferMAC decryption can occur where the receiver gets the initialization segment and decrypts it. For example, in biock 500 the receiver reads the size of the next segment from the footer size section. Then, for each segment; at biock 510 the receiver increments the segment counter and generates the corresponding AAD and IV; at biock 520 the receiver takes the number of bytes indicated in the previous segment and bytes for the MAC tag; and at block 530 the receiver examines the footer size field from the end of the segment. The receiver then determines any metadata for processing the next segment.
  • Figure 6 shows a method for encrypting data representing a rendering task according to an example.
  • the method may comprise segmenting the data to form multiple variably sized segments.
  • Each segment may comprise a payload and a footer portion.
  • the footer portion may comprise at least a fixed- length footer size section indicating the size of a footer encoding the size of a subsequent segment.
  • the payload of a segment may be encrypted using data associated with that segment and the task.
  • the PRinterMAC may be Implemented using any authenticated encryption scheme such as AES-CCM, AES-GCM, and ChaCha20-Poiy1305.
  • the application may extend beyond sending data to a printer, for example, other applications may comprise;
  • the logical portions may be defined as pages, paragraphs, 3D object layers, color channels, or other delineations that can be processed immediately upon receipt,
  • Per- packet or per-message encryption schemes may use a combination of encryption and authentication schemes that are subject to manipulation or lack efficiency, where some examples include SSFf encryptions, SPsec ESP and AH protection, and encrypted sessions like TLS,
  • the present disclosure improves MAC tag construction and adapts if to a printing context. This is achieved by eliminating negotiated segment lengths and padding.
  • Various strategies for boundary hiding are provided, including randomization and context aware selection which allows for segments that can be fully processed on their own ⁇ such as a fully printable document page).
  • the method provided defines an initialisation vector that works with the segment length strategy.
  • the PRinterMAG construction can reduce the ciphertext size under some selection of parameters, which improves the efficiency over MAC tag. This improves user experience of authenticated encryption which can otherwise cause noticeable slowdown to the printing experience and otherwise affects the perceived “first page out” (FRO) time and may lead to users disabling encryption.
  • FRO first page out
  • a print job can be encrypted, but the process slows the print process considerably and affects the perceived first page out (FPO) time, in order to maintain confidentiality and integrity whilst improving FPO time, a Job may be segmented into multiple segments, each having different sizes from one another in order to prevent boundary observations.
  • the payload or plaintext of each segment can be encrypted and the encoded segment is provided with data providing insight into the next segment of the job in question.
  • the approach described herein enables the printer to readily retrieve a print job without pre-negotiated print segment length information.
  • the methods described are applicable to 30 print jobs as well as 2D printing, i.e. there is provided an encryption scheme suitable for applications over and above a generic rendering task.
  • the PRinterMAC construction described herein reduces the first page out time.
  • the construction provides: boundary hiding of print job context, which makes it difficult for attackers to observe or alter the data in a meaningful way (e.g. randomized, jobs, pages, variable, dummy segment or footer to ignore segment); IV generation in the context of print (page and job ievei counters); and handling of unknown length inputs / ' payloads (DOS protection).
  • the methods described can be applicable to other rendering tasks, such as scanned jobs (i.e. scanning in the other direction client / cloud compared to printing a Job), where the rendering time is reduced for the recipient due to the segmented data encryption scheme.
  • the segmented data encryption scheme may be applied to other data streams beyond rendering tasks.
  • PRinterfvlAC enables data security of a rendering task or print job without increasing the time to first page out as the data size grows. Trie first page out time being reduced enhances customer experience by providing a seamless, efficient printing experience where a customer does not wait at the printer to receive their print job for too long.
  • Examples in the present disclosure can be provided as methods, systems or machine-readable instructions, such as any combination of software, hardware, firmware or the like.
  • Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
  • the machine-readable instructions may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams.
  • a processor or processing apparatus may execute the machine-readable instructions.
  • modules of apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry.
  • the term 'processor' is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc.
  • the methods and modules may ail be performed by a single processor or divided amongst several processors.
  • Such machine-readable instructions may aiso be stored in a computer readable storage that cars guide the computer or other programmable data processing devices to operate in a specific mode.
  • the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
  • Figure 7 shows an example of a processor 710 associated with a memory 720.
  • the memory 720 comprises computer readable instructions 730 which are executable by the processor 710.
  • the instructions 730 comprise:
  • each segment comprises a payload, and a footer portion, the footer portion comprising at least a fixed-length footer size section indicating the size of a footer encoding the size of a subsequent segment;
  • Instructions to encrypt the payload of a segment using data associated with that segment and the task are provided.
  • Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by flow(s) in the flow charts and/or biock ⁇ s ⁇ in the block diagrams.
  • teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Human Computer Interaction (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Power Engineering (AREA)
  • Accessory Devices And Overall Control Thereof (AREA)

Abstract

There is disclosed a method for encrypting data representing a rendering task, the method comprising segmenting the data to form multiple variably sized segments, wherein each segment comprises a payload, and a footer portion comprising at least a footer size section indicating the size of a footer encoding the size of a subsequent segment, and encrypting each segment using data associated with that segment and the rendering task.

Description

ENCRYPTING DATA
BACKGROUND
[01] Authenticated encryption is used to protect print job data confidentiality and integrity. Bulk encryption of a print job can be used, where a client can encrypt an entire job before sending it to a printer, then the printer can decrypt and verify the entire job before printing.
BRIEF DESCRIPTION OF THE DRAWINGS
[02] Various features and advantages of certain examples will be apparent from the detailed description which follows, taken in conjunction with the accompanying drawings, which together illustrate, by way of example, a number of features, and wherein;
[03] Figure 1 shows the structure of a PRinterMAC segment according to an example;
[04] Figure 2 shows PRinterMAC encryption according to an example;
[05] Figure 3 shows an encryption process according to an example;
[06] Figure 4 shows a whole encryption process according to an example;
[07] Figure 5 shows a decryption process according to an example;
[08] Figure 8 shows a method for encrypting data representing a rendering task according to an example; and
[09] Figure 7 shows a processor associated with a memory comprising computer readable instructions for executing a method for encrypting data representing a rendering task according to an example.
DETAILED DESCRIPTION [010] In the following description, for purposes of explanation, numerous specific details of certain examples are set forth. Reference in the specification to "an example" or similar language means that a particular feature, structure, or characteristic described in connection with the example is included in at least that one example, but not necessarily in other examples.
[011] Authenticated encryption schemes both encrypt data for confidentiality and provide a message authentication code (MAC) to verify data integrity. A MAC tag can be computed over the whole decryption process before it can be validated. Thus, a receiver may wait to receive and process an entire ciphertext before checking the authenticity of the data. In a printing context, the delay to verify delays the time to print until the entire job is decrypted and verified. For large Jobs, this delay can have significant impact on first page out (FPO) performance, which may lead to users disabling encryption or using a less secure mode. This problem is also relevant to any data flows to and from printers (e.g. scanning) that are processed immediately.
[012] A data segmentation scheme called interMAC is known that inserts MAC tags into a data stream to protect against adversaries that could re-order, truncate, or otherwise trick the recipient into receiving infinitely long messages. For example, interMAC uses a fixed segment size, agreed upon by both parties ahead of time, to achieve boundary hiding of the segment size from outside parties. However, this size may be discoverable since a common value may be used for performance. In addition, the interMAC scheme assumes that the data is a multiple of the segment size and can use padding of the data if it is not.
[013] This disclosure describes a construction called“PRinterMAC” that splits a print Job into smaller segments that can be transmitted and decrypted independently and immediately. An encryption and decryption function are described. There is provided a method for applying authenticated encryption to large print jobs that enables immediate transmission at the sender and immediate processing at the receiver after the first segment is processed. The construction breaks the data into smaller segments (potentially of varying size) and applies authenticated encryption to the segments individually. [014] Figure 1 shows the structure of a PRinterMAC segment according to an example. A segment may comprise a payload section 110 and a footer portion 120, 130. As shown, a segment 100 may comprise: the payload or plaintext section 110; a footer section 120; and a footer size section 130. The footer portion may comprise a footer section 120 and a footer size section 130. The plaintext section (Pj.i) 110 contains the data to be encrypted. The footer section 120, if present, contains the size of the next segment {,). The footer size section 130 contains the size of the footer section 120 or other metadata.
[015] The footer size section 130 can be fixed so that a recipient knows how much data to parse, for example, a 1-byte long section. This value is used to encode information such as: the size of the next segment (,}; whether the stream is finished; whether a logical portion is finished; or whether the next segment 0) is a dummy value.
[018] According to an example, a first or initialization segment can be used to bootstrap the data stream. For example, the initialization segment can be a fixed size segment that contains no plaintext data but is used to indicate the size of the second segment.
[017] Each segment 100 comprises a footer 120 that indicates the size of the next segment to process or whether the data stream has finished. The sender can start the stream by sending a fixed size initialization segment to indicate to a recipient how large the first segment will be. As each segment 100 is received, the recipient may decrypt and authenticate the segment and immediately process (e.g. print) the data.
[018] According to an example, the segment size can be tuned to provide improved performance (e.g. smaller segments initially and larger later).
[019] According to an example, a strategy can be applied to obfuscate the boundary of the data's contents such as randomizing segment size, inserting dummy segments, or adjusting segments on a contextual level (e.g per page, per job). This provides boundary hiding which can be useful when knowledge about the size of the data may be meaningful and where encryption alone cannot hide such metadata. According to an example, PRinterMAC enables the security property of boundary-hiding for practical use cases, As such, segments can be variably sized and their respective sizes can be generated independently, i.e. that is for any raj the size of is independent from the size of
IO203 PRinterMAC can generate segments from the plaintext and can encrypt and send these segments separately. Figure 2 describes PRinterMAC encryption according to an example. Each segment may be encrypted using the same key but with different initialisation vectors (IV) and/or different additional authenticated data (AAD). For example, the PRinterMAC construction may use a compound initialization vector construction to provide protection against an adversary that may attempt to re-order the segments, truncate the message, or repiay the data.
[021] According to an example, initialization vectors may be generated from three values including a nonce, a message counter and a segment counter. A nonce may relate to a random value that does not change for a session. A message counter may relate to a counter that is incremented after each logical portion or message, i.e. the message counter is incremented after a logical portion is completed. A segment counter may relate to a counter that is incremented after each segment, i.e. each segment may increment the segment counter, A logical portion may be defined as an entire job. Thus, multiple jobs can be included in a single stream and the printer can increment the counter after each one is received. Alternatively, a printed page can act as a logical portion.
[022] According to an example, for segment i, the initialization vector can be generated as:
Figure imgf000005_0001
where is the concatenation operation.
[023] According to an example, additional authenticated data relates to a value that is authenticated but not encrypted. The additional authenticated data may be taken as an input to generate a MAC tag. Without the correct additional authenticated data, the ciphertext may not be authenticated. For example, for segment I the additional authenticated data can be generated by:
Figure imgf000005_0002
[024] Generating initialisation vectors and additional authenticated data mitigates attacks that replace one segment with another, since the Initialisation vectors and additions! authenticated data for two different segments are different. Consequently, the decryption would not otherwise succeed in such an attack.
[025] According to an example, the initialisation vectors and the additional authenticated data are implied by the PRinterMAC construction such that they are predictable by the receiver. As such, the initialisation vectors and the additional authenticated data may not be sent with the ciphertext.
[026] The encryption process will now be described according to the example of Figure 3. A single segment may be encrypted. The segment counter value i may be Incremented by one for each segment. Inputs to the encryption process may comprise:
Figure imgf000006_0001
y p
[027] A MAC tag 360, % is associated to the encrypted segment 370 or ciphertext segment r,. When a segment is encrypted, the segment counter is incremented, then the next generated segment counter plaintext is taken and encrypted (EOCAE) with the initialisation vectors (!V) and the additional authenticated data (AAD)
[028] The whole encryption process is shown in Figure 4 according to an example. 4
[029] The rendering task may be represented by plaintext 410. The plaintext is received as input and is split into N payloads or plaintext sections 420, 430, 440, 450 {of potentially differing sizes): Pi, P¾ ... PN. Each of the plaintext sections to be used for constructing N respective segments.
£030] An initialization segment 410 (Po) is formed first. The initialization segment 410 comprises the initialisation vectors. The initialisation segment may, for example, comprise an eight-byte footer portion 416 comprising a one- byte footer size section 417. As shown, this footer size section 417 is defined to be a“7" in the initialization segment 410, which defines the length of the footer in the current segment 422 as seven-bytes iong. The initialization segment 410 is encrypted using authenticated encryption 418 with the message counter, m, and segment counter, #, 41 1 input as associated data A MAC tag 412, (to) is associated to the encrypted segment 413 (Co) or ciphertext segment.
[031] According to an example, the footer size section for each and every segment may be one-byte size.
[032] According to an exampie, the footer 419 (of the same segment) may be empty if the footer size section has an entry of “0", meaning that the next segment is the same size as the current segment. Similarly, if the footer size section has an entry of “255”, the footer (of the same segment) is empty, meaning that the current segment is the final segment and there is no next segment. In other cases, if the footer size segment is any other value (from 1 to 254), the footer section is not empty
[033] Now that the initialisation segment 416 has been encrypted, the segment counter value (/') is incremented. Then, the next (first) segment 422 for the generated segment counter value (i-1) is taken and encrypted (AE) with the initialisation vectors (IV) and the additional authenticated data (AAD).
[034] To construct the first segment 422, the length of the subsequent plaintext section (R) 430 (variable), the size of the footer 436 and the fixed-length footer size section (e.g. of one-byte) are considered. If Pi 430 is the same size as the current plaintext section (Pi) 420, then the footer size section 426 (which may itself have a size of one-byte) can be marked as“0" and the footer section 424 wiii be empty (which is the case in the example shown here). The current plaintext section (Pi) 420, the empty footer section 424 and the“G* footer size section 426 are encrypted using authentication encryption 427. The encryption uses the message counter, m, and segment counter value, /, 421 (incremented by 1} as associated data. A MAC tag 429, (¾} is associated to the first encrypted segment 423 (Ch) or ciphertext segment
[035] This encryption process continues to construct the subsequent, fth segment 432, considering the size of the subsequent N-1 segment 442 For example, if the subsequent plaintext section 440 (PN-1 ) is the same size as the current plaintext section (PO 430, the footer size section 436 is "0” and the footer section 434 is empty. However, if the subsequent plaintext section (P>¾. ) 440 is a different size to the current plaintext section (PO 430, the footer size section 436 (associated with PN-I ) is defined to show how many bytes the footer is (this is how many bytes are required to define the size of PN-I). The plaintext PN-I 440, the footer section 434 (defining how long PN-I is) and the footer size section 436 {defining how long the footer section is) are then aii encrypted using authenticated data 437 (with the message and segment counter 431 as associated data). The encryption uses the message counter, m, and segment counter value, 431 (incremented by 1 ) as associated data. A MAC tag 439, (fi) is associated to the /th encrypted segment 433 (Cs) or ciphertext segment.
[036] This encryption process continues until, finally, the last segment 452, PN, is reached and there wiii be no subsequent segment. In this case, the footer size section 456 value may be“2557 indicating that this is the final segment 452 to be constructed, and the footer section 454 is empty. As before, the final segment 452 is encrypted using authenticated data with the message and segment counter 451 as associated data.
[037] Figure 5 shows a decryption process according to an example. Once the PRinterMAC encryption has been defined, the PRinferMAC decryption can occur where the receiver gets the initialization segment and decrypts it. For example, in biock 500 the receiver reads the size of the next segment from the footer size section. Then, for each segment; at biock 510 the receiver increments the segment counter and generates the corresponding AAD and IV; at biock 520 the receiver takes the number of bytes indicated in the previous segment and bytes for the MAC tag; and at block 530 the receiver examines the footer size field from the end of the segment. The receiver then determines any metadata for processing the next segment. For example, it could indicate that the length of the next segment, the size of the segment does not change, special handling behaviour (e.g. dummy segment) or this is the last segment. At block 540 all of the data bytes before the footer section is decrypted and outputted.
[038] Figure 6 shows a method for encrypting data representing a rendering task according to an example. The method may comprise segmenting the data to form multiple variably sized segments. Each segment may comprise a payload and a footer portion. The footer portion may comprise at least a fixed- length footer size section indicating the size of a footer encoding the size of a subsequent segment. The payload of a segment may be encrypted using data associated with that segment and the task.
[039] According to an example, the PRinterMAC may be Implemented using any authenticated encryption scheme such as AES-CCM, AES-GCM, and ChaCha20-Poiy1305. The application may extend beyond sending data to a printer, for example, other applications may comprise;
Scanning data on a printer and sending it to a client for rendering
3D print data {3MF files)
Cloud print workflows that render the data before printing
[040] According to an example, the logical portions may be defined as pages, paragraphs, 3D object layers, color channels, or other delineations that can be processed immediately upon receipt,
[041] Per- packet or per-message encryption schemes may use a combination of encryption and authentication schemes that are subject to manipulation or lack efficiency, where some examples include SSFf encryptions, SPsec ESP and AH protection, and encrypted sessions like TLS, The present disclosure improves MAC tag construction and adapts if to a printing context. This is achieved by eliminating negotiated segment lengths and padding. Various strategies for boundary hiding are provided, including randomization and context aware selection which allows for segments that can be fully processed on their own {such as a fully printable document page). The method provided defines an initialisation vector that works with the segment length strategy.
[042] The PRinterMAG construction can reduce the ciphertext size under some selection of parameters, which improves the efficiency over MAC tag. This improves user experience of authenticated encryption which can otherwise cause noticeable slowdown to the printing experience and otherwise affects the perceived “first page out” (FRO) time and may lead to users disabling encryption. For example, a print job can be encrypted, but the process slows the print process considerably and affects the perceived first page out (FPO) time, in order to maintain confidentiality and integrity whilst improving FPO time, a Job may be segmented into multiple segments, each having different sizes from one another in order to prevent boundary observations. The payload or plaintext of each segment can be encrypted and the encoded segment is provided with data providing insight into the next segment of the job in question. The approach described herein enables the printer to readily retrieve a print job without pre-negotiated print segment length information. The methods described are applicable to 30 print jobs as well as 2D printing, i.e. there is provided an encryption scheme suitable for applications over and above a generic rendering task.
[043] Compared to encrypting and then decrypting the print job as one large object, the PRinterMAC construction described herein reduces the first page out time. The construction provides: boundary hiding of print job context, which makes it difficult for attackers to observe or alter the data in a meaningful way (e.g. randomized, jobs, pages, variable, dummy segment or footer to ignore segment); IV generation in the context of print (page and job ievei counters); and handling of unknown length inputs /' payloads (DOS protection).
[044] According to an example, the methods described can be applicable to other rendering tasks, such as scanned jobs (i.e. scanning in the other direction client / cloud compared to printing a Job), where the rendering time is reduced for the recipient due to the segmented data encryption scheme. The segmented data encryption scheme may be applied to other data streams beyond rendering tasks. [045] PRinterfvlAC enables data security of a rendering task or print job without increasing the time to first page out as the data size grows. Trie first page out time being reduced enhances customer experience by providing a seamless, efficient printing experience where a customer does not wait at the printer to receive their print job for too long.
[048] Examples in the present disclosure can be provided as methods, systems or machine-readable instructions, such as any combination of software, hardware, firmware or the like. Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
[047] The present disclosure is described with reference to flow charts and/or block diagrams of the method, devices and systems according to exampies of the present disclosure. Although the flow diagrams described above show a specific order of execution, the order of execution may differ from that which is depicted. Blocks described in relation to one flow chart may be combined with those of another flow chart. In some examples, some blocks of the flow diagrams may not be necessary and/or additional blocks may be added. It shall be understood that each flow and/or block in the flow charts and/or block diagrams, as well as combinations of the flows and/or diagrams in the flow charts and/or block diagrams can be realized by machine readable instructions.
[048] The machine-readable instructions may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams. In particular, a processor or processing apparatus may execute the machine-readable instructions. Thus, modules of apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry. The term 'processor' is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may ail be performed by a single processor or divided amongst several processors. [049] Such machine-readable instructions may aiso be stored in a computer readable storage that cars guide the computer or other programmable data processing devices to operate in a specific mode.
[050] For example, the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
[051] Figure 7 shows an example of a processor 710 associated with a memory 720. The memory 720 comprises computer readable instructions 730 which are executable by the processor 710. The instructions 730 comprise:
Instructions to segment the data to form multiple variably sized segments, wherein each segment comprises a payload, and a footer portion, the footer portion comprising at least a fixed-length footer size section indicating the size of a footer encoding the size of a subsequent segment; and
Instructions to encrypt the payload of a segment using data associated with that segment and the task.
[052] Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by flow(s) in the flow charts and/or biock{s} in the block diagrams.
[053] Further, the teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.
[054] While the method, apparatus and related aspects have been described with reference to certain examples, various modifications, changes, omissions, and substitutions can be made without departing from the spirit of the present disclosure. In particular, a feature or block from one example may be combined with or substituted by a feature/block of another example.
[055] The word "comprising" does not exclude the presence of elements other than those listed in a claim, "a" or "an” does not exclude a plurality, and a single processor or other unit may fulfil the functions of several units recited in the claims.
[058] The features of any dependent claim may be combined with the features of any of the independent claims or other dependent claims.

Claims

1 A method for encrypting data representing a rendering task, the method comprising: segmenting the data to form muitipie variably sized segments, wherein each segment comprises: a payioad; and a footer portion comprising at least a footer size section indicating the size of a footer encoding the size of a subsequent segment; and encrypting each segment using data associated with that segment and the rendering task.
2. A method according to ciaim 1 s wherein the footer portion further comprises a footer encoding the size of a subsequent segment.
3. A method according to claim 1 , wherein the payioad comprises plaintext.
4. A method according to claim 1 , wherein the footer size section has a fixed-length of one-byte.
5 A method according to claim 1 , wherein the footer portion defines an amount of data to parse for each respective segment.
6. A method according to ciaim 1 , wherein the footer is empty when the footer size section indicates that the size of the footer encoding the subsequent section is 0 or 255 bytes.
7 A method according to claim 1 , wherein each segment is variably sized such that the sizes of respective segments are generated independently of other segments.
8. A method according to claim 1 , wherein each segment is generated from plaintext and subsequently encrypted.
9 A method according to claim 1 , wherein each segment is encrypted using a different initialisation vector.
10. A method according to claim 9, wherein each initialisation vector generated from a nonce, a message counter, and a segment counter.
11. A method according to claim 1 , wherein each segment is encrypted using a different authenticated data value.
12 A method according to claim 1 , wherein each segment is sent to a receiver separately from other segments.
13. A non-transitory machine-readable storage medium encoded with instructions executable by a processor for encrypting data representing a rendering task, the machine-readable storage medium comprising instructions to: segment the data to form multiple variably sized segments, wherein each segment comprises: a payload; and a footer size section indicating the size of a footer encoding the size of a subsequent segment; and encrypt each segment using data associated with that segment and the rendering task.
14. A storage medium according to claim 13, further comprising instructions to encrypt each segment using a different initialisation vector.
15. A storage medium according to claim 13, further comprising instructions to encrypt each segment using a different authenticated data value.
PCT/US2018/048347 2018-08-28 2018-08-28 Encrypting data Ceased WO2020046282A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US17/047,291 US20210176037A1 (en) 2018-08-28 2018-08-28 Encrypting data
PCT/US2018/048347 WO2020046282A1 (en) 2018-08-28 2018-08-28 Encrypting data

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/US2018/048347 WO2020046282A1 (en) 2018-08-28 2018-08-28 Encrypting data

Publications (1)

Publication Number Publication Date
WO2020046282A1 true WO2020046282A1 (en) 2020-03-05

Family

ID=69642910

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2018/048347 Ceased WO2020046282A1 (en) 2018-08-28 2018-08-28 Encrypting data

Country Status (2)

Country Link
US (1) US20210176037A1 (en)
WO (1) WO2020046282A1 (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12418401B2 (en) * 2023-04-24 2025-09-16 General Dynamics Mission Systems, Inc. Full parallelization and enablement of random order computation of cryptographic hashes

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040181661A1 (en) * 2003-03-13 2004-09-16 Sharp Laboratories Of America, Inc. Print processor and spooler based encryption
US20060274355A1 (en) * 2005-06-01 2006-12-07 Sharp Laboratories Of America, Inc. Secured release system to transmit and image a print job
US7561294B2 (en) * 2006-02-06 2009-07-14 Xerox Corporation Mobile device-enabled secure release of print jobs using parallel decryption
US20180150619A1 (en) * 2016-11-28 2018-05-31 Ricoh Company, Ltd. Piecewise encryption for content in print jobs

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6999193B2 (en) * 2001-03-29 2006-02-14 International Business Machines Corporation Computer generated report printing method and system
US9537657B1 (en) * 2014-05-29 2017-01-03 Amazon Technologies, Inc. Multipart authenticated encryption
US9948454B1 (en) * 2015-04-29 2018-04-17 Open Portal Enterprises (Ope) Symmetric data encryption system and method
US10522155B2 (en) * 2017-02-21 2019-12-31 Cirrus Logic, Inc. Pulse code modulation (PCM) data-marking

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040181661A1 (en) * 2003-03-13 2004-09-16 Sharp Laboratories Of America, Inc. Print processor and spooler based encryption
US20060274355A1 (en) * 2005-06-01 2006-12-07 Sharp Laboratories Of America, Inc. Secured release system to transmit and image a print job
US7561294B2 (en) * 2006-02-06 2009-07-14 Xerox Corporation Mobile device-enabled secure release of print jobs using parallel decryption
US20180150619A1 (en) * 2016-11-28 2018-05-31 Ricoh Company, Ltd. Piecewise encryption for content in print jobs

Also Published As

Publication number Publication date
US20210176037A1 (en) 2021-06-10

Similar Documents

Publication Publication Date Title
US9172529B2 (en) Hybrid encryption schemes
US8543820B2 (en) Tag generation apparatus, tag verification apparatus, communication system, tag generation method, tag verification method, and recording medium
KR102609221B1 (en) Methods and systems for improved authenticated encryption in counter-based cryptographic systems
US8577032B2 (en) Common key block encryption device, common key block encryption method, and program
US20180139041A1 (en) Data encryption apparatus and method, and data decryption apparatus and method
CA3051928A1 (en) Equivocation augmentation
JP7367860B2 (en) Authentication encryption device, authentication decryption device, authentication encryption system, method and program
US20150110269A1 (en) Encryption device, decryption device, encryption method, decryption method, and program
CN107534558B (en) Method for protecting the information security of data transmitted via a data bus and data bus system
KR20190020988A (en) Computer-executable lightweight white-box cryptographic method and apparatus thereof
WO2014136386A1 (en) Tag generation device, tag generation method, and tag generation program
US20150127950A1 (en) Method of encrypting data
Knudsen Block Ciphers—a survey
Kampanakis et al. Practical challenges with AES-GCM and the need for a new cipher
EP3131230B1 (en) Encryption method, program, and system
Amorado et al. Enhanced data encryption standard (DES) algorithm based on filtering and striding techniques
US8891761B2 (en) Block encryption device, decryption device, encrypting method, decrypting method and program
Andreeva et al. AES-COPA v.
EP2571192A1 (en) Hybrid encryption schemes
WO2020046282A1 (en) Encrypting data
CN107483387A (en) A kind of method of controlling security and device
KR101583285B1 (en) Block cipher method using expansion key and apparatus thereof
Kumar et al. Analysis of hybrid cryptography for secure exchange of information
KR20210049412A (en) Communication method and system through cbc encryption and decryption
Gueron et al. SimpleENC and SimpleENCsmall--an Authenticated Encryption Mode for the Lightweight Setting

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18932273

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18932273

Country of ref document: EP

Kind code of ref document: A1