e-ManualTopSite mapHelpGlossary

Category Top

Preventing Unauthorized Access

Increasing Security

Network Security

Key Pair and Server Certificate Settings for Encrypted SSL Communication

Generating a Key Pair and Server Certificate

Registering a Key Pair File and Server Certificate File Installed from a Computer

Editing Key Pairs and Server Certificates

Registering/Editing a CA Certificate File

Verifying Certificate Validity Using Certificate Revocation List

Network Settings/Management when Using an Advanced Box

MEAP Settings

Using the SSL

Printing Installed Application Information

Preventing Information Leakage

Digital Signatures

Setting/Confirming a Key Pair and Device Certificate

Confirming a Key Pair and User Certificate

Checking a Device Signature/User Signature Certificate

Setting a Rights Management Server

Forced Secure Watermark/Document Scan Lock

Secure Watermark (Forced Secure Watermark/Printer Driver Secure Watermark)

Adjusting the Secure Watermark Contrast

Document Scan Lock Settings

Specifying the Document Scan Lock Operational Settings
Setting the Document Scan Lock Mode
Adjusting the TL Code

Copy Set Numbering Options

Accepting Only Encrypted Secure Printing

Restricting the Send Function

Setting the Address Book

Mail Box Settings

Specifying Settings for All Mail Boxes

Specifying the Mail Box Security Settings

Setting the Control Panel Display

Managing the Setting Information Registered in the Machine

Specifying Management Settings for the Memory

Completely Erasing Unnecessary Data from the Memory

Initializing All Data/Settings

TPM Settings

Device Management

Using the USB Port

Device Information Settings

Specifying Device Information Distribution Settings

Registering/Deleting/Printing Distribution Destinations

Setting the Receiving Machine

Setting Automatic Distribution

Setting Manual Distribution

Checking/Printing the Communication Log

Limiting Functions

Remote UI

Clearing the Message Board

Saving a Log of Key Operations

Starting the Setup Guide

Retrieving Audit Logs

IEEE 2600 Security Standard

Top » Security » Specifying Management Settings for the Memory » TPM Settings
TPM Settings
0R9W-20W
If the TPM setting is activated and backed up on to the USB memory, you can safely store in the TPM chip the encryption key (TPM key) that encrypts confidential information such as the password, public key pair for SSL communication, and user certificate that are stored in the machine. Doing so, you can prevent important information for the machine from leaking. Also, you can recover the system if the TPM chip fails by restoring the TPM key.
IMPORTANT
Before activating the TPM setting, an administrator must confirm that the Administrator password has been changed from its default setting. If the password has not been changed from its default setting, users other than an administrator may be able to obtain the TPM backup key. Since the TPM key can only be backed up once, you cannot restore the TPM key.
Backup the TPM key immediately on to the USB memory after the TPM setting is activated.
For security reasons, you can only backup the TPM key once. Store the USB memory with the backup data in a safe place. Also, write down the password set when backing up and keep it in a safe place.
The security provided by TPM does not guarantee complete protection of the data and hardware. Note that Canon will not be liable for any failure or damages resulting from the use of this mode.
Insert the USB memory straight into the USB port. If the USB memory is inserted in an angle or if you insert a USB memory type not compliant with USB standard, the USB port may be damaged.
Do not remove the USB memory while backing up or restoring data. Doing so may cause damage to the USB memory, USB port, or the data inside of the USB memory. Also if the USB memory is removed when restoring, the machine may be damaged.
To use the USB memory, press [Preferences] (Settings/Registration) → [External Interface] → [USB Settings] → [Off] for <Use MEAP Driver for USB Storage Device>.

Setting TPM
This section explains how to activate the TPM setting.
1.
Press (Settings/Registration).
2.
Press [Management Settings] → [Data Management] → [TPM Settings].
3.
Press [Yes].
NOTE
If the TPM setting is activated, it may take longer to start the machine.
Backing Up the TPM Key
If the TPM setting is activated and the TPM chip fails, you cannot recover the confidential information since each type of confidential information is uniquely encrypted with the TPM key. Thus, immediately backup when the TPM setting is activated.
For backing up, use the commercially available USB memory.
1.
Press (Settings/Registration).
2.
Press [Management Settings] → [Data Management] → [TPM Settings].
3.
Press [Back Up TPM Key].
4.
Press [Password].
5.
Enter the password → press [OK].
6.
On the Confirm screen, enter the same password to confirm the password → press [OK] → [OK].
7.
Connect the USB memory to the machine → press [OK].
If the error screen appears, follow the instructions on the screen and backup again.
IMPORTANT
Before backing up, make sure that writing is allowed for the memory media connected to the machine.
Do not connect any other memory media.
Restoring the TPM Key
If the TPM chip fails, you can use the previously backed up data of the TPM key to restore the TPM key on to the new TPM chip. For information on TPM chip failure, contact your local authorized Canon dealer.
1.
Press (Settings/Registration).
2.
Press [Management Settings] → [Data Management] → [TPM Settings].
3.
Press [Restore TPM Key].
4.
Press [Password].
5.
Enter the password you specified when backing up → press [OK] → [OK].
6.
Connect the USB memory to the machine → press [OK].
If the error screen appears, follow the instructions on the screen and backup again.
IMPORTANT
Before restoring, make sure that the memory media you used for backing up is connected to the machine.
Do not connect any other memory media.
7.
Press [OK] → restart the system.

IMPORTANT
Restoring of the TPM key recovers the access to the memory that became inaccessible due to TPM chip failure and does not recover the memory.
If initialization is performed following the steps for "Initializing All Data/Settings," all of the data encrypted by the TPM key is completely erased and the TPM setting becomes inactive.
For the backup of the TPM key, it is recommended that you use a USB memory with free space of 10 MB or more.
You can use the USB memory that is commercially available.
The FAT32 file system is supported for USB memory.
The following USB memory and usage are not supported.
USB memory with a security function or a memory card reader that connects via USB
Using the USB memory with an extension cable
Using the USB memory via a USB hub
USB memory not compliant with the USB standard
You may not be able to use properly, depending on the USB memory you are using.
You cannot access the machine while backing up or restoring data in the USB memory.
The data on the machine is backed up on the USB memory after it has been encrypted. You cannot manage or browse the backed up data on the computer.
You cannot back up the TPM key for the following cases:
USB memory is write protected
USB memory is not connected
More than one USB memory is connected
Not enough free space in the connected USB memory
TPM key does not exist on the machine
You cannot restore the TPM key for the following cases:
USB memory is not connected
More than one USB memory is connected
A TPM key does not exist on the USB memory
The TPM key on the USB memory is not correct
NOTE
Settings specified from the control panel become effective after the machine is restarted, after the procedure. If <Perform Apply Setting Changes from Settings/Regist.> is displayed on the bottom of the touch panel display, you can press [Apply Set. Chng.] in (Settings/Registration) to restart the machine. For information on restarting the machine using the main power switch, see "Main Power and Energy Saver Key."