
2
2
2-13
2-13
Technology > Controller System > Controls > Security Features (Encryption Key, Certificate, Password Protection)
Technology > Controller System > Controls > Security Features (Encryption Key, Certificate, Password Protection)
■
Security Features (Encryption Key, Certificate, Password
Protection)
●
Overview
The main controller PCB 1 of the host machine holds a new PCB named “TPM PCB”. “TPM”
stands for “Trusted Platform Module”, which collectively refers to the chip set for generating
and storing encryption keys and computing public key encryption.
Main Controller PCB1
TPM PCB
The TPM PCB protects security information (passwords, certificates, and encryption keys)
stored in the HDD and SRAM. Note that this PCB does not protect set, registered or stored
data other than security information.
The TPM key embedded in the chip is used to encrypt / decrypt security information. The
TPM key is protected from illegal access in a virtually perfect manner, thus the security
information of the host machine is securely protected even in the following conditions.
• When the HDD and / or the main controller PCB is taken out from the host machine and
installed in the MFP with the different serial number (the model information held in the TPM
PCB is specific to the machine originally enabled the TPM setting)
• When the system of the host machine is hacked via the network
Enable this function in Setting / Registration mode.
Management Setting > Data Management > TPM Setting -> ON (OFF by default)
F-2-21
●
Configuration of Security Information
The security functionality behaves differently depending on the TPM setting on the UI.
This machine provides the two types of TPM settings. See the figure below for the security
information flow in each setting.
TPM PCB
TPM Key
Backup Key
for TPM failure
Public Key
Common
Key
Password
HDD
- When the TPM setting is ON
Backup
USB flash drive
Password
SRAM
Backup for
Common Key
(Temporarily stored in HDD)
When the TPM setting is ON, the TPM key is enabled to secure information with the three
keys. Therefore, the security information held in each machine is safely protected.
The security information in this setting can be accessed by the three keys and multiple
passwords stored in the SRAM and HDD.
Each data is stored in the specified location (enclosed with blue dots in the figure above).
Since the data in the upper layer are linked to those in the lower layer, security information is
activated only when data in all the layers are linked.
For the backup purpose, the backup key is temporarily stored also in the HDD to be prepared
for a TPM failure (only for the initial failure after the TPM setting is ON).
This key can be backed up using the USB flash drive. Once backed up, the backup key is
deleted from the HDD.
The common key information is stored in the HDD as well as the SRAM. The common key
stored in the SRAM is cleared when the main controller PCB 2 (SRAM) is replaced or after
MN-CON clear. However, the common key stored in the HDD automatically restores that in
the SRAM so that the security information is decodable even after servicing. Note that the
F-2-22
Содержание imageRUNNER ADVANCE C5255
Страница 17: ...1 1 Product Overvew Product Overvew Product Lineup Feature Specification Name of Parts Operation ...
Страница 310: ...3 3 Periodical Service Periodical Service Consumable Parts Replacement Parts and Cleaning Parts Cleaning Parts ...
Страница 528: ...5 5 Adjustment Adjustment Main Controller Image Formation System Pickup Feed System ...
Страница 692: ...7 7 Error Jam Alarm Error Jam Alarm Overview Error Code Jam Code Alarm Code ...
Страница 821: ...8 8 Service Mode Service Mode Overview COPIER FEEDER SORTER BOARD ...