WO2020101799A1 - Sensitive media usage - Google Patents

Sensitive media usage Download PDF

Info

Publication number
WO2020101799A1
WO2020101799A1 PCT/US2019/051315 US2019051315W WO2020101799A1 WO 2020101799 A1 WO2020101799 A1 WO 2020101799A1 US 2019051315 W US2019051315 W US 2019051315W WO 2020101799 A1 WO2020101799 A1 WO 2020101799A1
Authority
WO
WIPO (PCT)
Prior art keywords
media
user
toe
sensitive
secure
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2019/051315
Other languages
French (fr)
Inventor
Dilip RATHNAKER
Viswanatha SHANKARANARAYANA
Rajdhar KUMAR
Dhanasekhar KOLAMALA
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Hewlett Packard Development Co LP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hewlett Packard Development Co LP filed Critical Hewlett Packard Development Co LP
Priority to US17/267,249 priority Critical patent/US20220350920A1/en
Publication of WO2020101799A1 publication Critical patent/WO2020101799A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6245Protecting personal data, e.g. for financial or medical purposes
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • G06F21/608Secure printing

Definitions

  • the present disclosure relates to toe control of sensitive media usage in a shared environment.
  • Shared resources include printers that many users can access and as such there is a risk of fraudulent use of shared resources.
  • Figure 1 shows a method to restrict user access to sensitive media to a rendering apparatus according to an example
  • Figure 2 shows a method to restrict user access to sensitive media to a rendering apparatus according to an example
  • Figure 3 shows a flow diagram for physically securing access to sensitive media in a printer input bin according to an example
  • Figure 4 shows a method for controlling the usage of sensitive media stored in a secure input bin according to an example
  • Figure 5 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example
  • Figure 6 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example
  • Figure 7 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example
  • Figure 8 shows a rendering apparatus according to an example
  • Figure 9 shows an example of a processor associated with a memory for performing a method for controlling usage of sensitive media stored in a secure input bin according to an example.
  • the disclosure relates to physically securing input bins wife sensitive media from unauthorized users. Tracking of sensitive prints on tills media throughout its life span can be provided. There is provided a method for the securing of sensitive media while loaded in an input tray.
  • the disclosure provides a system which prevents unauthorized access to secure input bins of a printer with sensitive media.
  • the system physically secures the access to the sensitive media In the printer input bin using electronically operated locks and sensors.
  • the system controls tee usage of the sensitive media stored in the secured input bins using encrypted key, Personal Identification Number (PIN) printing, digital certificate/signature or authorization agents.
  • PIN Personal Identification Number
  • the system tracks the prints form designated sensitive input tins. Therefore, there is provided a solution to secure unused sensitive media from being misused.
  • the input bins are physically secured to prevent the sensitive media from being picked up from input tins. Access to the sensitive media is secured by restricting the usage of the sensitive media while printing jobs. Access to sensitive media is tracked to detect any fraud or misuse.
  • FIG. 1 shows a method to restrict user access to sensitive media in a rendering apparatus according to an exarhpfe.
  • Sensitive media is considered to relate to media such as company letterheads, judicial papers, or papers with watermarks used to print sensitive information or legal documents.
  • a secure media tray having an electronic lock operated by firmware is provided.
  • a secure input bin relates to an Input tray or bin of a rendering apparatus or printer that is dedicated for the usage of sensitive media and hence made secure.
  • a print job is provided to the rendering apparatus.
  • Hie print job may be a sensitive print job to be printed on sensitive media where the job is of a sensitive nature.
  • user credentials are validated to confirm that the user is authorised to access the sensitive media.
  • An authorized or privileged user refers to a user who has the permission to operate the secure input tin and send sensitive jobs.
  • an authorisation code is obtained from the user.
  • the authorisation code may be one of a: private key; PIN; and digital certificate.
  • the authorisation code is validated.
  • the print job is rendered or printed using media from the secure media tray.
  • Figure 2 shows a method to restrict user access to sensitive media in a rendering apparatus according to an example.
  • die print job may be provided to the rendering apparatus through a print driver.
  • the print driver can encrypt the print job at the print driver with a private key.
  • the user may then enter the private key at the rendering apparatus and decrypt the print job using the private key.
  • the print driver may generate a PIN.
  • the print driver may add a digital certificate to the print job before providing the signed (Mint job to the rendering apparatus.
  • the user may load the print job onto the rendering apparatus from a portable storage device, such as a USB stick.
  • the prints from the designated sensitive input bins may be tracked.
  • user access to the secure media tray may be tracked.
  • any job that is printed using media from a secure input bin can be tracked (e g.“track and trace”).
  • Printers may participate in block- chains or use secure-in premises logging for trackabi!ity. Whenever secure input bins are involved, "track and trace" may be automatically invoked.
  • a snapshot of the printed document may be saved in encrypted format, which could be used for any forensic investigations later.
  • a snapshot of the print data related to the authorised print job may be stored in a memory.
  • FIG. 3 shows a flow diagram for physically securing access to sensitive media in a printer input bin according to an example.
  • access to sensitive media loaded in the secure input bin is restricted to sensitive ⁇ Mint jobs to be printed from foe secure input bin for authenticated users, i.e. authorized users with privileges are allowed to print on media from the secure input bin.
  • the sensitive media can be secured when it is loaded into the printer input ton.
  • a printer may have multiple input tins, where one or more of those input bins can be reserved to handle the sensitive media.
  • an input ton reserved for sensitive media comprises electronically operated locks controlled via printer firmware, i.e. the secure input bin can be locked physically through electronically operated locks that are controlled through firmware. Access to the secure input bin can then be provided to authorized users.
  • the secure input bin may comprise sensors that detect the loading and/or unloading of media from foe secure input ton, for example via a weight sensor or proximity sensor.
  • foe user can enter their credentials, for example in the printer front panel menu.
  • the printer firmware validates foe entered user credentials. If foe user is an authorized one, foe firmware releases the lock of the secure input bin at block 306. After unlocking foe fray, foe privileged user is granted access to the secure media tray.
  • the authorised user is able to then load/unload sensitive or secure media into the secure media tray.
  • the secure media fray foe printer firmware engages the locking system at block 310. For example, sensors may detect when foe user has opened/closed the secure media tray. Once the tray gets locked, the sensitive media in the input ton gets secured from theft.
  • Sensors in foe secure input ton may detect if media has been either loaded or removed.
  • the following data is available which may be saved at block 312: details of foe user who has operated the secure input ton; date and time of operation; printer serial number; and foe kind of operation performed, i.e., loading or unloading media.
  • this operation sequence of unlocking of foe secure input ton and loading/unloading of media can be tracked. Records that contain meta data that includes the user identity, date and time of operation, printer identity/serial number, and any such useful information can be created.
  • sensors in the input tins could be used to detect the nature of the operation, i.e., loading or unloading media from the secure input bin.
  • the same could be used for tracking purpose.
  • inbuilt scanners and/or OCR controllers in toe printing device could be activated to fingerprint or take a snapshot of the media loaded. This can help to know what kind of sensitive media the user loaded. The information which is recorded would be helpful for tracking employees who have accessed media in any of toe common shared printers.
  • Figure 4 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example.
  • the access of sensitive media loaded in the secure input bin may be restricted through management of print jobs.
  • sensitive print jobs to be printed from toe secure input bin can be user authenticated.
  • Authorized users with privileges are allowed to print on media from toe secure input tin.
  • Print jobs from the secure input tin may be managed as follows.
  • the authorized user uses their private key known to them to encrypt the print job before sending toe job to toe printer.
  • the authorized user provides the private key to toe printer driver while choosing the sensitive job to be printed.
  • toe printer driver encrypts the sensitive job with toe user's private key.
  • toe printer driver sends toe encrypted job to the printer.
  • the printer receives toe sensitive job and saves it like a stored job.
  • the printer identifies toe sensitive job and prompts toe user to enter their credentials (and private key).
  • the user enters the credentials which may be via the printer front panel.
  • toe printer firmware then validates the user. If the user is not validated toe stored sensitive job may be deleted. If the user is validated toe printer prompts the user to enter their private key at block 414.
  • the user enters their private key.
  • the printer uses toe same key to decrypt the stored job.
  • toe printer prints the job using media from the secure input bin.
  • a snapshot of the print job may be saved into memory and may comprise encrypted meta data. According to an example, if the user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media bay.
  • Track and trace technology can be used to track and trace documents printed from any printer and also detect manipulations done cm (Minted documents. It also collects data such as toe identity of toe user who printed, the date and time of print toe printer on which the document was printed, print protocol used for printing, the IP address from where toe print job was sent, details of toe network and so on. The same could be leveraged here. Whenever secure input tins are involved, track and trace" could be automatically invoked.
  • FIG. 5 shows a method for controlling the usage of sensitive media stored in a secure input bin according to an example.
  • Personal identification Number (PIN) based printing and/or walk-up printing can be used to help achieve printouts not being left unattended since the user is at the printer when the print jobs are processed.
  • a stored job may be printed using PIN based printing.
  • an existing PIN printing workflow can be leveraged.
  • a privileged user sends a print job which may be a sensitive print job.
  • the printer driver generates a one-time usable PIN and notifies toe user and sends the print job to the printer.
  • toe printer upon receiving this job stores it like a normal stored job.
  • the printer determines if toe pint job is a sensitive print job and whether or not a secure input bin is to be used.
  • a track and trace may be enabled by the printer.
  • toe printer prompts the user to enter their credentials for authorisation to print from toe secure input bin.
  • toe privileged user inputs their credentials to authenticate themselves with valid credentials from the printer control panel.
  • toe user is provided with an option in the front panel menu to select the secure input bin and enter toe one-time PIN that is connected to the print job at block 518.
  • the user enters the PIN.
  • the printer validates the PIN.
  • the printer uses media from toe secure input bin to print toe print job, i.e. toe stored job gets printed from the media stacked in the secure tin.
  • a snapshot of the printed document may be saved at block 526.
  • the stored print job is deleted at block 528.
  • the secure input bin is not used.
  • the printer prompts the user to enter the PIN associated with the print job.
  • the user enters toe PIN.
  • the printer checks whether toe PIN is valid and if successfully validated, at block 536 the printer prints toe print job from a normal input bin (i.e. not a secure input bin).
  • the stored job is deleted. According to an example, if the user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media tray.
  • the workflow is ended at block 540.
  • FIG. 6 shows a method for controlling toe usage of sensitive media stored in a secure input tin according to an example.
  • a sensitive print job is sent by a privileged user to be printed from a secure input tin.
  • the printer driver adds a digital signature or digital certificate such that the print job will carry a digital signature or digital certificate.
  • print jobs that have toe option to associate themselves with a digital signature like IPP (Internet Print Protocol) could be used for digital authentication and authorization.
  • the sensitive job sent by the privileged user will carry a digital signature or a digital certificate.
  • toe printer drivers send toe signed print job to toe printer.
  • the printer identifies the sensitive print job and the printer firmware validates the user with the digital signature associated with the print job. If the certificate is valid and the user is authorised toe printer prints toe sensitive print job using media from toe secure input bin at block 612. A snapshot of the printed document may be saved at block 614. If toe certificate is not valid or the user is not authorised the printer will delete toe sensitive print job at block 616. According to an example, if toe user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media tray.
  • FIG. 7 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example.
  • the user inserts toe device into the printer.
  • the printer then reads and displays the contents of the device.
  • the user selects the file to be printed.
  • the printer then prompts the user to specify the media onto which die job is to be printed and whether the media is from the secure input bin. If yes, the user is prompted at block 710 to enter his credentials.
  • the printer prints the job tram the secured bin at block 712.
  • the printer may be configured to prompt the user to choose a different bin or the selection can itself be automated for unauthorized users. According to an example, if the user is not authorised to print using the secure input bin, toe user can be allowed to print from a non-secure media tray.
  • UPD/Drivers can be enhanced to pass toe authorization information like Kerberos tickets or OAUTH cookie.
  • Universal Print Drivers (UPD) or discrete drivers may be enhanced to pass the authorization information like Kerberos tickets or OAUTH cookie.
  • the printer can validate this with toe preconfigured authorization agent and allow toe jobs to be printed.
  • a user can obtain a photo-copy of a document at a shared printer or multi-functional product having a secure input bin loaded with sensitive media.
  • a multi-functional product may support fax, photo-copy and ⁇ Mint having a secure input bin or media tray loaded with sensitive media (locked input bay).
  • the user is permitted to take a photo-copy using toe sensitive media if the user is authorised.
  • the authorised user can provide their credentials for authorisation. If the user is not an authorised user and does not have permission to use toe sensitive media, toe job can be redirected to another media tray or input bin loaded with normal media.
  • a printing device having a secure input tin with sensitive media may receive a fax and not be permitted to use sensitive media to print toe incoming fax.
  • FIG. 8 shows a rendering apparatus according to an example.
  • the apparatus 800 comprises a plurality of media trays 810, 815. At least one media bay is a secure media bay 815 for handling sensitive media.
  • An electronic lock 820 operated via firmware 830 is configured to permit access to the secure media tray 815 upon validation of a request for access from an authorised user 840.
  • the electronic lock permits authorised access or denies unauthorised access to the secure input bins and sensitive media.
  • Sensitive print jobs are linked to authorised users for access to sensitive media. For example, an authorised user may be issued with an access tag by an administrator.
  • a rendering apparatus may comprise a plurality of secure media trays wherein each tray may comprise a different type of sensitive media and/or a different user group(s).
  • the apparatus may comprise a processor configured to track toe use of sensitive media, for example via meta data linked to authorised users. Sensors may be provided on toe secure media tray. Whenever an authorised user accesses the secure media tray the processor may be configured to create a new record and store toe record in a blockchain (for example). As such, toe locking and unlocking of the secure media tray is monitored and each time sensitive media is loaded or unloaded at the secure media tray there is a record of that activity, A snapshot of the printed document may be recorded using a scanner linked to toe secure media tray. For example, inbuilt scanners and OCR controllers in the device could be activated to fingerprint or take snapshot of toe media loaded which would help to know what kind of media was loaded by the authorized user. Print data may be encrypted before being saved in a record. The snapshot of toe printed document can be saved in an encrypted format This would help to know what was printed by the user. This date would facilitate any forensic investigation in case of a fraud.
  • the tracking of prints from secure input bins monitors toe usage of sensitive media and help achieve restricted access by authorized users. Tracking is useful where privileged users misuse sensitive media and where a fraud occurs, forensic data can aid any investigation.
  • the method and apparatus provided remove cumbersome procedures and workflows to secure and restrict the usage of sensitive media. For example, toe burden of staff to "guard" media or the concerned authorities is removed whilst controlling sensitive media usage. Shared resources can be maintained instead of providing one or more dedicated printers to privileged or authorised users. Unused media is protected by firmware controlled electronic locks on the secure media trays to physically secure the media and prevent the media from being jacked up from the input bins. The access to sensitive media is secured by restricting the usage of the media while printing jobs, for example to restrict an amount or quota of sensitive media to an authorised user which may be linked to a print job and/or duration (week/month etc.).
  • the access to sensitive media and its usage can be tracked, generating sufficient data to investigate cases of fraud or misuse.
  • frauds may print a blank document to gain access to the sensitive media or print illegal data or false data.
  • the snapshots collected can provide vital data for investigation.
  • Availability of forensic data would also act as a deterrent to frauds.
  • the methods described can help achieve the presence of the user at the printer when toe printout is being generated from the secure input tin. For example, toe user can walk up to the printer to enter toe encryption key and user credentials to help achieve the user’s presence when the job is printed which secures toe printout from theft
  • Examples in toe present disclosure can be provided as methods, systems or machine-readable instructions, such as any combination of software, hardware, firmware or the like.
  • Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
  • the machine-readable instructioris may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams.
  • a processor or processing apparatus may execute the machine-readable instructions.
  • modules of apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry.
  • the term 'processor 1 is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may all be performed by a single processor or divided amongst several processors.
  • Such machine-readable instructions may also be stored in a computer readable storage that can guide the computer or other programmable data processing devices to operate in a specific mode.
  • the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor for restricting user access to sensitive media to a rendering apparatus.
  • Figure 9 shows an example of a processor 910 associated with a memory 920.
  • the memory 920 comprises computer readable instructions 930 which are executable by the processor 910 to restrict user access to sensitive media in a rendering apparatus.
  • the instructions 930 comprise:
  • Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by ftow(s) in the flow charts and/or block(s) in the block diagrams.
  • teachings herein may be implemented in tee form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions to * making a computer device implement tee methods recited in tee examples of the present disclosure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Databases & Information Systems (AREA)
  • Accessory Devices And Overall Control Thereof (AREA)

Abstract

There is provided a method and apparatus to restrict user access to sensitive media in a rendering apparatus, comprising providing a secure media tray having an electronic lock operated by firmware, providing a print job to the rendering apparatus, validating user credentials to confirm a user is authorised to access the sensitive media, obtaining an authorisation code from the user, validating the authorisation code, and printing the print job using media from the secure media tray.

Description

SENSITIVE MEDIA USAGE
BACKGROUND
[01] The present disclosure relates to toe control of sensitive media usage in a shared environment. Shared resources include printers that many users can access and as such there is a risk of fraudulent use of shared resources.
BRIEF DESCRIPTION OF THE DRAWINGS
[02] Various features and advantages of certain examples will be apparent from the detailed description which follows, taken in conjunction with toe accompanying drawings, which together illustrate, by way of example only, a number of features, and wherein:
[03] Figure 1 shows a method to restrict user access to sensitive media to a rendering apparatus according to an example;
[04] Figure 2 shows a method to restrict user access to sensitive media to a rendering apparatus according to an example;
[05] Figure 3 shows a flow diagram for physically securing access to sensitive media in a printer input bin according to an example;
[06] Figure 4 shows a method for controlling the usage of sensitive media stored in a secure input bin according to an example;
[07] Figure 5 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example;
[08] Figure 6 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example;
[09] Figure 7 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example;
[010] Figure 8 shows a rendering apparatus according to an example; and [011] Figure 9 shows an example of a processor associated with a memory for performing a method for controlling usage of sensitive media stored in a secure input bin according to an example.
DETAILED DESCRIPTION
[012] In the following description, for purposes of explanation, numerous specific details of certain examples are set forth. Reference in the specification to "an example* or similar language means that a particular feature, structure, or characteristic described in connection with the example is included to at least that one example, but not necessarily to other examples.
[013] Shared resources such as printers pose a threat of misuse of sensitive media due to unrestricted access to printer input trays into which sensitive media can be loaded.
[014] The disclosure relates to physically securing input bins wife sensitive media from unauthorized users. Tracking of sensitive prints on tills media throughout its life span can be provided. There is provided a method for the securing of sensitive media while loaded in an input tray.
[015] Organizations print critical documents on letterheads. The printouts on letterheads that bear the company’s logo are often deemed as official documents and have a legal standing. Hence the usage of letterheads is restricted in most organizations. Organizations, especially to the government, use sensitive papers such as judicial papers or those with certain watermarks for printing confidential material or documents with legal binding. The content of tiie printouts from such media would be of sensitive nature. For instance, HR personnel may print job contracts with salary details for new employees or promotion/hike letters. The marketing department may print marketing orders or bid contracts with sensitive pricing details. The finance department may print tax bills or account receipts. Universities or schools may print certificates, marks sheets and question papers for students on sensitive media. A company’s legal cell may print a plethora of legal documents. All of these examples can use official letterheads. The documents printed would also be confidential and of a legally sensitive nature.
[016] Many of business establishments have shared printers. Office staff from multiple departments may use a common printer tn the floor. When the printer is a shared one, and certain departments loading sensitive media into the printer, there is a risk of unauthorized people picking up this kind of restricted media from the printer input bins or media trays. This poses a serious threat of misuse of such media. For example, personnel are exposed to the risks of misuse of sensitive media by loading the printer input bin with tee sensitive media and walking away to their desk to send the print job, which provides a good opportunity for theft of unguarded media. Further, leaving behind unused and excess sensitive media in input trays could also lead to its unlawful usage.
[01 T\ The disclosure provides a system which prevents unauthorized access to secure input bins of a printer with sensitive media. The system physically secures the access to the sensitive media In the printer input bin using electronically operated locks and sensors. The system controls tee usage of the sensitive media stored in the secured input bins using encrypted key, Personal Identification Number (PIN) printing, digital certificate/signature or authorization agents. The system tracks the prints form designated sensitive input tins. Therefore, there is provided a solution to secure unused sensitive media from being misused. The input bins are physically secured to prevent the sensitive media from being picked up from input tins. Access to the sensitive media is secured by restricting the usage of the sensitive media while printing jobs. Access to sensitive media is tracked to detect any fraud or misuse.
[018] There is provided a method and apparatus for (i) physically securing access to sensitive media in printer input bins; (ii) controlling the usage of sensitive media stored in secure input bins; and (iii) fracking the prints from designated sensitive media input bins, i.e. tracking users and the documents/sensitive media that are printed.
[019[ Figure 1 shows a method to restrict user access to sensitive media in a rendering apparatus according to an exarhpfe. Sensitive media is considered to relate to media such as company letterheads, judicial papers, or papers with watermarks used to print sensitive information or legal documents. At block 102 a secure media tray having an electronic lock operated by firmware is provided. A secure input bin relates to an Input tray or bin of a rendering apparatus or printer that is dedicated for the usage of sensitive media and hence made secure. At block 104 a print job is provided to the rendering apparatus. Hie print job may be a sensitive print job to be printed on sensitive media where the job is of a sensitive nature. At block 106 user credentials are validated to confirm that the user is authorised to access the sensitive media. An authorized or privileged user refers to a user who has the permission to operate the secure input tin and send sensitive jobs. At block 108 an authorisation code is obtained from the user. According to an example, the authorisation code may be one of a: private key; PIN; and digital certificate. At block 110 the authorisation code is validated. At block 112 the print job is rendered or printed using media from the secure media tray.
[020] Figure 2 shows a method to restrict user access to sensitive media in a rendering apparatus according to an example. At block 201 die print job may be provided to the rendering apparatus through a print driver. According to an example, the print driver can encrypt the print job at the print driver with a private key. The user may then enter the private key at the rendering apparatus and decrypt the print job using the private key. According to an example, the print driver may generate a PIN. According to an example, the print driver may add a digital certificate to the print job before providing the signed (Mint job to the rendering apparatus. According to an example, the user may load the print job onto the rendering apparatus from a portable storage device, such as a USB stick.
[021] According to an example, the prints from the designated sensitive input bins may be tracked. At block 220 user access to the secure media tray may be tracked. For example, any job that is printed using media from a secure input bin can be tracked (e g.“track and trace"). Printers may participate in block- chains or use secure-in premises logging for trackabi!ity. Whenever secure input bins are involved, "track and trace" may be automatically invoked.
[022] At block 230 a snapshot of the printed document may be saved in encrypted format, which could be used for any forensic investigations later. A snapshot of the print data related to the authorised print job may be stored in a memory.
[023] Figure 3 shows a flow diagram for physically securing access to sensitive media in a printer input bin according to an example. In this example, access to sensitive media loaded in the secure input bin is restricted to sensitive {Mint jobs to be printed from foe secure input bin for authenticated users, i.e. authorized users with privileges are allowed to print on media from the secure input bin. The sensitive media can be secured when it is loaded into the printer input ton. A printer may have multiple input tins, where one or more of those input bins can be reserved to handle the sensitive media.
[024] According to an example, an input ton reserved for sensitive media comprises electronically operated locks controlled via printer firmware, i.e. the secure input bin can be locked physically through electronically operated locks that are controlled through firmware. Access to the secure input bin can then be provided to authorized users. The secure input bin may comprise sensors that detect the loading and/or unloading of media from foe secure input ton, for example via a weight sensor or proximity sensor.
[025] At block 302 foe user can enter their credentials, for example in the printer front panel menu. At block 304 the printer firmware validates foe entered user credentials. If foe user is an authorized one, foe firmware releases the lock of the secure input bin at block 306. After unlocking foe fray, foe privileged user is granted access to the secure media tray. At block 308 the authorised user is able to then load/unload sensitive or secure media into the secure media tray. Once foe user doses the secure media fray foe printer firmware engages the locking system at block 310. For example, sensors may detect when foe user has opened/closed the secure media tray. Once the tray gets locked, the sensitive media in the input ton gets secured from theft. Sensors in foe secure input ton may detect if media has been either loaded or removed. At the end of this operation sequence the following data is available which may be saved at block 312: details of foe user who has operated the secure input ton; date and time of operation; printer serial number; and foe kind of operation performed, i.e., loading or unloading media. As such, this operation sequence of unlocking of foe secure input ton and loading/unloading of media can be tracked. Records that contain meta data that includes the user identity, date and time of operation, printer identity/serial number, and any such useful information can be created.
[026] According to an example, sensors in the input tins could be used to detect the nature of the operation, i.e., loading or unloading media from the secure input bin. The same could be used for tracking purpose. For example, inbuilt scanners and/or OCR controllers in toe printing device could be activated to fingerprint or take a snapshot of the media loaded. This can help to know what kind of sensitive media the user loaded. The information which is recorded would be helpful for tracking employees who have accessed media in any of toe common shared printers.
[027] Figure 4 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example. The access of sensitive media loaded in the secure input bin may be restricted through management of print jobs. For example, sensitive print jobs to be printed from toe secure input bin can be user authenticated. Authorized users with privileges are allowed to print on media from toe secure input tin. Print jobs from the secure input tin may be managed as follows. At block 402 the authorized user uses their private key known to them to encrypt the print job before sending toe job to toe printer. The authorized user provides the private key to toe printer driver while choosing the sensitive job to be printed. At block 404 toe printer driver encrypts the sensitive job with toe user's private key. At block 406 toe printer driver sends toe encrypted job to the printer. At block 408 the printer receives toe sensitive job and saves it like a stored job. The printer identifies toe sensitive job and prompts toe user to enter their credentials (and private key). At block 410 the user enters the credentials which may be via the printer front panel. At block 412 toe printer firmware then validates the user. If the user is not validated toe stored sensitive job may be deleted. If the user is validated toe printer prompts the user to enter their private key at block 414. At block 416 the user enters their private key. At block 418 upon successful validation the printer uses toe same key to decrypt the stored job. At block 420 toe printer prints the job using media from the secure input bin. At block 422 a snapshot of the print job may be saved into memory and may comprise encrypted meta data. According to an example, if the user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media bay.
[028] “Track and trace” technology can be used to track and trace documents printed from any printer and also detect manipulations done cm (Minted documents. It also collects data such as toe identity of toe user who printed, the date and time of print toe printer on which the document was printed, print protocol used for printing, the IP address from where toe print job was sent, details of toe network and so on. The same could be leveraged here. Whenever secure input tins are involved, track and trace" could be automatically invoked.
[029] Figure 5 shows a method for controlling the usage of sensitive media stored in a secure input bin according to an example. Personal identification Number (PIN) based printing and/or walk-up printing can be used to help achieve printouts not being left unattended since the user is at the printer when the print jobs are processed. A stored job may be printed using PIN based printing. For example, an existing PIN printing workflow can be leveraged. At block 502 a privileged user sends a print job which may be a sensitive print job. At block 504 the printer driver generates a one-time usable PIN and notifies toe user and sends the print job to the printer. At block 506 toe printer upon receiving this job stores it like a normal stored job. At block 508 the printer determines if toe pint job is a sensitive print job and whether or not a secure input bin is to be used. At block 510 a track and trace may be enabled by the printer. At block 512 toe printer prompts the user to enter their credentials for authorisation to print from toe secure input bin. At block 514 toe privileged user inputs their credentials to authenticate themselves with valid credentials from the printer control panel. Upon validation at block 516, toe user is provided with an option in the front panel menu to select the secure input bin and enter toe one-time PIN that is connected to the print job at block 518. At block 520 the user enters the PIN. At block 522 the printer validates the PIN. At block 524 upon successful validation the printer uses media from toe secure input bin to print toe print job, i.e. toe stored job gets printed from the media stacked in the secure tin. A snapshot of the printed document may be saved at block 526. The stored print job is deleted at block 528. At block 508 if the print job is a not a sensitive print job but instead is a normal print job. the secure input bin is not used. Similarly, at block 516 if the user credentials are incorrector are not valid such that the user is not authorised to print on media from the secure input bin, the secure input bin is not used. At block 530 the printer prompts the user to enter the PIN associated with the print job. At block 532 the user enters toe PIN. At block 534 the printer checks whether toe PIN is valid and if successfully validated, at block 536 the printer prints toe print job from a normal input bin (i.e. not a secure input bin). At block 538 the stored job is deleted. According to an example, if the user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media tray. The workflow is ended at block 540.
[030] Figure 6 shows a method for controlling toe usage of sensitive media stored in a secure input tin according to an example. At block 602 a sensitive print job is sent by a privileged user to be printed from a secure input tin. At block 604 the printer driver adds a digital signature or digital certificate such that the print job will carry a digital signature or digital certificate. For example, print jobs that have toe option to associate themselves with a digital signature, like IPP (Internet Print Protocol) could be used for digital authentication and authorization. The sensitive job sent by the privileged user will carry a digital signature or a digital certificate. At block 606 toe printer drivers send toe signed print job to toe printer. At block 608 the printer identifies the sensitive print job and the printer firmware validates the user with the digital signature associated with the print job. If the certificate is valid and the user is authorised toe printer prints toe sensitive print job using media from toe secure input bin at block 612. A snapshot of the printed document may be saved at block 614. If toe certificate is not valid or the user is not authorised the printer will delete toe sensitive print job at block 616. According to an example, if toe user is not authorised to print using the secure input bin, the user can be allowed to print from a non-secure media tray.
[031] Figure 7 shows a method for controlling toe usage of sensitive media stored in a secure input bin according to an example. When an authorized user wants to print a file stored in a USB storage device, at block 702 the user inserts toe device into the printer. At block 704 the printer then reads and displays the contents of the device. At block 706 the user selects the file to be printed. At block 708 the printer then prompts the user to specify the media onto which die job is to be printed and whether the media is from the secure input bin. If yes, the user is prompted at block 710 to enter his credentials. Upon successful validation, the printer prints the job tram the secured bin at block 712. If an unauthorized user accidentally selects any of the sensitive bins, the printer may be configured to prompt the user to choose a different bin or the selection can itself be automated for unauthorized users. According to an example, if the user is not authorised to print using the secure input bin, toe user can be allowed to print from a non-secure media tray.
[032] According to an example, UPD/Drivers can be enhanced to pass toe authorization information like Kerberos tickets or OAUTH cookie. Alternatively, Universal Print Drivers (UPD) or discrete drivers may be enhanced to pass the authorization information like Kerberos tickets or OAUTH cookie. The printer can validate this with toe preconfigured authorization agent and allow toe jobs to be printed.
[033] According to an example, a user can obtain a photo-copy of a document at a shared printer or multi-functional product having a secure input bin loaded with sensitive media. A multi-functional product may support fax, photo-copy and {Mint having a secure input bin or media tray loaded with sensitive media (locked input bay). The user is permitted to take a photo-copy using toe sensitive media if the user is authorised. The authorised user can provide their credentials for authorisation. If the user is not an authorised user and does not have permission to use toe sensitive media, toe job can be redirected to another media tray or input bin loaded with normal media. According to an example, a printing device having a secure input tin with sensitive media may receive a fax and not be permitted to use sensitive media to print toe incoming fax.
[034] Figure 8 shows a rendering apparatus according to an example. The apparatus 800 comprises a plurality of media trays 810, 815. At least one media bay is a secure media bay 815 for handling sensitive media. An electronic lock 820 operated via firmware 830 is configured to permit access to the secure media tray 815 upon validation of a request for access from an authorised user 840. The electronic lock permits authorised access or denies unauthorised access to the secure input bins and sensitive media. Sensitive print jobs are linked to authorised users for access to sensitive media. For example, an authorised user may be issued with an access tag by an administrator. According to an example, a rendering apparatus may comprise a plurality of secure media trays wherein each tray may comprise a different type of sensitive media and/or a different user group(s).
[035] The apparatus may comprise a processor configured to track toe use of sensitive media, for example via meta data linked to authorised users. Sensors may be provided on toe secure media tray. Whenever an authorised user accesses the secure media tray the processor may be configured to create a new record and store toe record in a blockchain (for example). As such, toe locking and unlocking of the secure media tray is monitored and each time sensitive media is loaded or unloaded at the secure media tray there is a record of that activity, A snapshot of the printed document may be recorded using a scanner linked to toe secure media tray. For example, inbuilt scanners and OCR controllers in the device could be activated to fingerprint or take snapshot of toe media loaded which would help to know what kind of media was loaded by the authorized user. Print data may be encrypted before being saved in a record. The snapshot of toe printed document can be saved in an encrypted format This would help to know what was printed by the user. This date would facilitate any forensic investigation in case of a fraud.
[036] The tracking of prints from secure input bins monitors toe usage of sensitive media and help achieve restricted access by authorized users. Tracking is useful where privileged users misuse sensitive media and where a fraud occurs, forensic data can aid any investigation.
[037] The method and apparatus provided remove cumbersome procedures and workflows to secure and restrict the usage of sensitive media. For example, toe burden of staff to "guard" media or the concerned authorities is removed whilst controlling sensitive media usage. Shared resources can be maintained instead of providing one or more dedicated printers to privileged or authorised users. Unused media is protected by firmware controlled electronic locks on the secure media trays to physically secure the media and prevent the media from being jacked up from the input bins. The access to sensitive media is secured by restricting the usage of the media while printing jobs, for example to restrict an amount or quota of sensitive media to an authorised user which may be linked to a print job and/or duration (week/month etc.). The access to sensitive media and its usage can be tracked, generating sufficient data to investigate cases of fraud or misuse. For example, frauds may print a blank document to gain access to the sensitive media or print illegal data or false data. The snapshots collected can provide vital data for investigation. Availability of forensic data would also act as a deterrent to frauds. The methods described can help achieve the presence of the user at the printer when toe printout is being generated from the secure input tin. For example, toe user can walk up to the printer to enter toe encryption key and user credentials to help achieve the user’s presence when the job is printed which secures toe printout from theft
[038] Examples in toe present disclosure can be provided as methods, systems or machine-readable instructions, such as any combination of software, hardware, firmware or the like. Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
[039] The present disclosure is described with reference to flow charts and/or block diagrams of toe method, devices and systems according to examples of the present disclosure. Although toe flow diagrams described above show a specific order of execution, the order of execution may differ from that which is depicted. Blocks described in relation to one flow chart may be combined with those of another flow chart. In some examples, some blocks of toe flow diagrams may not be necessary and/or additional blocks may be added. It shall be understood that each flow and/or block in toe flow charts and/or block diagrams, as well as combinations of the flows and/or diagrams in the flow charts and/or block diagrams can be realized by machine readable instructions.
[040] The machine-readable instructioris may, for example, be executed by a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams. In particular, a processor or processing apparatus may execute the machine-readable instructions. Thus, modules of apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry. The term 'processor1 is to be interpreted broadly to include a CPU, processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may all be performed by a single processor or divided amongst several processors.
[041] Such machine-readable instructions may also be stored in a computer readable storage that can guide the computer or other programmable data processing devices to operate in a specific mode.
[042] For example, the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor for restricting user access to sensitive media to a rendering apparatus.
[043] Figure 9 shows an example of a processor 910 associated with a memory 920. The memory 920 comprises computer readable instructions 930 which are executable by the processor 910 to restrict user access to sensitive media in a rendering apparatus. The instructions 930 comprise:
Instructions to provide a secure media tray having an electronic lock operated by firmware;
Instructions to provide a print job to the rendering apparatus;
Instructions to validate user credentials to confirm a user is authorised to access the sensitive media;
Instructions to obtain an authorisation code from the user;
Instructions to validate foe authorisation code; and
Instructions to print the print job using media from the secure media tray.
[044] Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by ftow(s) in the flow charts and/or block(s) in the block diagrams.
[045] Further, the teachings herein may be implemented in tee form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions to* making a computer device implement tee methods recited in tee examples of the present disclosure.
[046] While tee method, apparatus and related aspects have been described with reference to certain examples, various modifications, changes, omissions, and substitutions can be made without departing from tee spirit of tee present disclosure. In particular, a feature or block from one example may be combined with or substituted by a feature/block of another example.
[047] The word "comprising" does not exclude the presence of elements other than those listed in a claim, "a" or "an" does not exclude a plurality, and a single processor or other unit may fulfil the functions of several units recited in tee claims.
[048] The features of any dependent claim may be combined with tee features of any of tee independent claims or other dependent claims.

Claims

1. A method to restrict user access to sensitive media in a rendering apparatus, comprising:
providing a secure media tray having an electronic lock operated by firmware;
providing a print job to the rendering apparatus;
validating user credentials to confirm a user is authorised to access file sensitive media;
obtaining an authorisation code from the user;
validating the authorisation code; and
printing the print job using media from the secure media fray.
2. A method according to claim 1 , wherein the authorisation code is one of a: private key; PIN; and digital certificate.
3. A method according to claim 2, comprising providing the print job id the rendering apparatus through a print driver.
4. A method according to claim 3, comprising encrypting the print job at the print driver with a private key.
5. A method according to claim 4, comprising the user entering the private key at the rendering apparatus and decrypting the print job using the private key.
6. A method according to claim 3, comprising the print driver generating a
PIN.
7. A method according to claim 3, comprising the print driver adding a digital certificate to the print job before providing the signed print job to the rendering apparatus.
8. A method according to claim 1 , comprising toe user loading toe print job onto the rendering apparatus from a portable storage device.
9. A method according to claim 1 , comprising controlling the electronic lock on the secure media tray to allow toe user physical access to toe secure media tray.
10, A method according to claim 1. comprising tracking user access to toe secure media tray.
11. A method according to claim 1 , comprising storing a snapshot of print data related to the authorised print job in a memory.
12. A rendering apparatus, comprising:
a plurality of media trays, wherein at least one media tray is a secure media tray for handling sensitive media; and
an electronic lock operated via firmware and configured to permit access to the secure media tray upon validation of a request for access from an authorised user.
13. An apparatus according to claim 12, further comprising a processor configured to track use of toe sensitive media from the secure media bay.
14. An apparatus according to claim 12, further comprising sensors on the secure media tray configured to detect media being loaded or unloaded from the secure media bay.
15. A non-transitory machine-readable storage medium encoded with instructions executable by a processor for restricting user access to sensitive media in a rendering apparatus, the machine-readable storage medium comprising instructions to:
operate a firmware controlled electronic lock on a secure media tray; provide a print job to the rendering apparatus;
validate user credentials to confirm a user is authorised to access toe sensitive media; obtain an authorisation code from the user;
validate the authorisation code; and
print the print job using media from the secure media tray.
PCT/US2019/051315 2018-11-16 2019-09-16 Sensitive media usage Ceased WO2020101799A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US17/267,249 US20220350920A1 (en) 2018-11-16 2019-09-16 Sensitive media usage

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
IN201841043198 2018-11-16
ININ201841043198 2018-11-16

Publications (1)

Publication Number Publication Date
WO2020101799A1 true WO2020101799A1 (en) 2020-05-22

Family

ID=70731838

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2019/051315 Ceased WO2020101799A1 (en) 2018-11-16 2019-09-16 Sensitive media usage

Country Status (2)

Country Link
US (1) US20220350920A1 (en)
WO (1) WO2020101799A1 (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11778112B2 (en) * 2022-01-19 2023-10-03 Xerox Corporation Methods and systems for reserving a tray for special media printing while submitting a document for printing

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6918042B1 (en) * 1997-11-26 2005-07-12 International Business Machines Corporation Secure configuration of a digital certificate for a printer or other network device
US20050177739A1 (en) * 2004-02-06 2005-08-11 Ferlitsch Andrew R. Systems and methods for securing an imaging job
US9760697B1 (en) * 2013-06-27 2017-09-12 Interacvault Inc. Secure interactive electronic vault with dynamic access controls

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7755794B2 (en) * 2003-10-22 2010-07-13 Hewlett-Packard Development Company, L.P. Tray access lock
US9747064B2 (en) * 2015-09-30 2017-08-29 Konica Minolta Laboratory U.S.A., Inc. Method and system for determining the tray with the best paper registration for a print job

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6918042B1 (en) * 1997-11-26 2005-07-12 International Business Machines Corporation Secure configuration of a digital certificate for a printer or other network device
US20050177739A1 (en) * 2004-02-06 2005-08-11 Ferlitsch Andrew R. Systems and methods for securing an imaging job
US9760697B1 (en) * 2013-06-27 2017-09-12 Interacvault Inc. Secure interactive electronic vault with dynamic access controls

Also Published As

Publication number Publication date
US20220350920A1 (en) 2022-11-03

Similar Documents

Publication Publication Date Title
US12267308B2 (en) Method and system for digital rights management of documents
JP6932175B2 (en) Personal number management device, personal number management method, and personal number management program
US20070220614A1 (en) Distributed access to valuable and sensitive documents and data
US20160078247A1 (en) Security evaluation systems and methods for secure document control
US20070061889A1 (en) System and method for controlling distribution of electronic information
US8683569B1 (en) Application access control system
US9645775B2 (en) Printing composite documents
US20130174216A1 (en) Application of Differential Policies to at Least One Digital Document
US8032921B2 (en) Computer-readable recording medium storing access rights management program, access rights management apparatus, and access rights management method
US9444628B2 (en) Providing differential access to a digital document
CN102006302A (en) Method for identifying security classification of electronic file
JP2006260023A (en) Printing system and print control method
US8060578B2 (en) Output information management system
US11941262B1 (en) Systems and methods for digital data management including creation of storage location with storage access ID
JP4719420B2 (en) Permission grant method, access permission processing method, program thereof, and computer apparatus
CA2965156A1 (en) Security evaluation systems and methods for secure document control
US20220350920A1 (en) Sensitive media usage
US11991281B1 (en) Systems and methods for digital data management including creation of storage location with storage access id
JP3690685B1 (en) Electronic file management system and electronic file management program
JP3809495B1 (en) Software management system
JP4548159B2 (en) Printing system, printing control method, and server apparatus
JP7775177B2 (en) Security token management system, security token management method, and program
JP5021379B2 (en) Print document export prevention system
Morper Security Starts at Admissions, But Can’t End After Discharge
Nurhidayat et al. The Utilization of the Saudi Visa Bio Application in the Management of Hajj Pilgrim Biometric Data by Ministry of Religious Affairs of Tulungagung Regency

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19884540

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19884540

Country of ref document: EP

Kind code of ref document: A1