EP1197828A1

Remote printing of secure and/or authenticated documents

Abstract

A method for the remote printing of a document by use of a network, the method including receiving at a server the document as sent from a sender; the server forwarding the document to a recipient; the document being authenticated prior to being forwarded to the recipient; and the server receiving instructions from the sender regards printing controls and the server implementing those controls on the recipient. A hardware device to support the printing controls is also disclosed.

EP1197828A1, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Projected expiry passed 16 July 2021, 5.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

42 claims: 22 independent, 20 dependent

  1. 1
    A method for the remote printing of a document by use of a network, the method including the steps of:(a) receiving at a server the document as sent from a sender;(b) the server forwarding the document to a recipient;(c) the document being authenticated prior to being forwarded to the recipient;characterised in that (d) the server receives instructions from the sender regards printing controls and the server implementing those controls on the recipient.
  2. 2
    A method for the remote printing a document by use of a network, the method including the steps of:(d) a sender sending the document to a server to enable the server to forward the document to a recipient;(e) the document being authenticated by the sender prior to sending it to the server;characterised in that (f) the sender sends to the server instructions for controlling the printing of the document to enable the server to implement those controls on the recipient.
  3. 3
    A method for printing of an authenticated document received remotely by use of a network. the method including the steps of a recipient receiving the authenticated document from a server, the server having received the authenticated document from a sender;characterised in that the server provides implementation of printing controls on the recipient, the server having received the printing controls from the sender.
  4. 4
    A method as claimed in any one of claims 1 to 3, characterised in that the printing controls include the ensuring that the document as printed has a content that is exactly the same as the document content as sent by the sender.
  5. 5
    A method as claimed in any one of claims 1 to 4, characterised in that the printing controls include one or more selected from the group consisting of:anti-forgery controls, anti-copying controls and controls on a number of copies of the document that are to be printed.
  6. 6
    A method as claimed in any one of claims 1 to 5, characterised in that the recipient includes a printer, the server providing the printing controls to the printer for the printing of the document, and the server enables a secure document delivery from the sender through the server to the recipient.
  7. 7
    A method as claimed in any one of claims 1 to 6, characterised in that the server is a trusted agent to the sender in printing control and is a trusted third party in document verification services, the server storing a hash of the document, and at least one content feature of the document, and uses them for document verification.
  8. 10
    A method as claimed in any one of claims 1 to 9, characterised in that the method uses a public key infrastructure to provide nonrepudiation, privacy and security in the delivery of the document.
  9. 12
    A method as claimed in any one of claims 1 to 11, characterised in that the sender is registered with the server before the sender can send the document, and the recipient is registered with the server before the recipient can receive the document.
  10. 13
    A method as claimed in any one of claims 8 to 12, characterised in that a document hash and the content features are sent with the document for validation, and a hash and content feature of the document are kept in the server for future verification.
  11. 14
    A method as claimed in any one of claims 1 to 8, characterised in that the method uses a secure document transfer channel provided by Secure Socket Layer protocol, and authentication of the sender and the recipient is by using user identity and at least one password.
  12. 15
    A method as claimed in any one of claims 1 to 8, characterised in that the method uses encryption techniques for secure document delivery, a key to decrypt the document being sent directly to the recipient by a carrier means selected from the group consisting of email, telephone, mail, courier and personal delivery, and the document as printed is protected against unauthorised copying and forgery by using an authentication means selected from the group consisting of:optical watermark, special ink, special paper and special printing materials.
  13. 20
    A method as claimed in any one of claims 1 to 17, characterised in that there is included client software that is downloaded to a machine of the recipient for the printing of the document, the recipient being trusted in the printing control process to minimise attack on the client software, the server communicating with the printer through the client software to verify the printer serial number and internet protocol address, check the status of the printer, locks a control panel of the printer, sets all necessary printer settings, sends to the printer the document and instructions for printing the document, and reset settings after the printing process is completed, and to create the audit trail record in the server.
  14. 24
    A method as claimed in any one of claims 1 to 23, characterised in that the printing controls are implemented in response to the recipient requesting the printing of the document.
  15. 25
    A method as claimed in any one of claims 1 to 16, characterised in that the printing control is carried-out off-line, the server not participating in the printing process.
  16. 29
    A method as claimed as claimed in any one of claims 8 to 28, characterised in that the controls include the issuing of a license for the recipient to print the document, the license including a number of copies of the document authorized for printing, each license having a license key, the license key being used to encrypt the unique seal;the license keys being sent to the recipient by the server in an encrypted form and being installed in the hardware device.
  17. 33
    A method as claimed in any one of claims 29 to 32, characterised in that prior to the sender sending the document, the sender's common seal, a timestamp for sending, and the expiry date, are encrypted with a first session key to give an encrypted result, and the encrypted result and the document are encrypted with a second session key to give a second encrypted result, a hash result being included in the second encrypted result to provide a means for checking data integrity.
  18. 34
    A method as claimed in any one of claims 29 to 33, characterised in that the print controls can be to view the document but not to print the document, a license not being required for viewing.
  19. 35
    A method as claimed in any one of claims 8 to 34, characterised in that the expiry date is checked before printing of the document is authorized and, if the expiry date has passed, printing of the document is not allowed.
  20. 36
    A method as claimed in any one of claims 1 to 35, characterised in that the sender and the server are the same, all functions of the sender being performed by the server.
  21. 39
    A method as claimed in any one of claims 25 to 38, characterised in that there is provided a secure software program to implement the printing controls at the recipient, the software program being implemented in a distributed manner to assist in preventing software attacks, the secure memory for the licence keys and audit trails also being implemented in a distributed manner.
  22. 40
    A hardware device for use with a user's machine to enable control of printing of at least one document by the machine, the hardware device including a secure memory, a delete-after-read memory, a central processing unit with an on-chip program, and an interface.
Independent claims22