1460942625-1e3f94a1-b313-4ea5-88e4-048fa25b1a76

1. In a system of networked MFPs, an apparatus for controlling stored jobs comprising:
a) an MFP including a printer for printing stored jobs;
b) a storage device connected to said printer for storing jobs; and
c) a user interface device connected to said MFP with a printer for selecting job storage options wherein said options include a job retention expiration date, a default expiration date, an expiration date of never, and a notice to the user of an expiration date with the option to revise said expiration date.
2. The apparatus of claim 1 wherein said job retention expiration date includes a default expiration date selected from a group including 30, 60, 90, and 180 days.
3. The apparatus of claim 1 wherein said user interface device further includes a date tracker connected to the network for keeping track of the current date.
4. The apparatus of claim 3 wherein said date tracker is a connection to the Internet.
5. The apparatus of claim 1 wherein said user interface device includes notices to the user of job retention expiration dates as occurring.
6. The apparatus of claim 1 wherein said user interface device includes notices to the user of job retention expiration dates as occurring and automatic deletion of retained jobs on a selected expiration date.
7. In a printer, an apparatus for controlling stored jobs comprising:
a) a printer with a storage device for storing print jobs at the printer;
b) a printer control panel for accessing stored print jobs connected to said printer;
c) a job retention means connected to said printer control panel for setting a job retention expiration date wherein said job retention expiration date setting includes: a job retention expiration date, a default expiration date, an expiration date of never, and a notice to the user of an expiration date with the option to revise said expiration date; and
d) a clock means for keeping track of the current date connected to said job retention means.
8. The apparatus of claim 7 wherein said job retention means automatically deletes a particular stored job on the occurrence of the job retention expiration date for said particular job.
9. The apparatus of claim 7 wherein said clock means for keeping track of the current date is a connection to the Internet.
10. The apparatus of claim 7 wherein said job retention means lists stored jobs to be deleted on or before the job retention expiration date.
11. In a system of networked MFPs, a method of controlling stored jobs comprising the steps of:
a) providing a MFP on the network with a printer for printing stored jobs;
b) connecting a storage device to said printer for storing print jobs;
c) connecting a user interface to said MFP with a printer for selecting job storage options wherein said options include a job retention expiration date, a default job retention expiration date, an expiration date of never, and a notice to the user of an expiration date with the option to revise said expiration date;
d) adding a job to be stored to the storage device and selecting a job retention expiration date for said job to be stored.
12. The method of claim 11 wherein the default job retention expiration date is selected from a group including 30, 60, 90, and 180 days.
13. The method of claim 11 further comprising the steps of notifying the user of job retention expiration dates as occurring and subsequently automatically deleting retained jobs on the expiration date.
14. In a network of MFPs, a computer program product for controlling stored jobs, the computer program product comprising:
a) instructions for printing stored jobs on a MFP with a printer;
b) instructions for storing jobs on said MFP with said printer; and
c) instructions for a user interface for said MFP with a printer for selecting job storage options wherein said options include a job retention expiration date, a default expiration date, an expiration date of never, and a notice to the user of an expiration date with the option to revise said expiration date.
15. The computer program product of claim 14 wherein said default expiration date instructions include instructions for a default date selected from a group including 30, 60, 90, and 180 days.
16. The computer program product of claim 14 further comprising instructions for notifying a user of job retention expiration dates as occurring and for automatically deleting retained jobs after notification.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A Proof-of-Trust-System, comprising a first Identification Device and a second Identification Device, each of the first and second Identification Devices comprising:
a Token comprising a memory storing information of a person or object, such information comprising Identification Data comprising a first subset representing security Clearance Data used to indicate that the person or object is allowed to perform a valid action or obtain a valid status, said Identification Data being arranged to uniquely identify the person or object; and,
a Validator comprising a display, a processor unit, a Validator clock and Validator communication interface configured to interact with the Token and with a Connector of a Centralized System remote from the Devices and configured to securely transfer data during an Initialisation Phase between the Centralized System and the Validator through the Connector, such data comprising a clock synchronization signal to synchronize the Validator clock to a Centralized system clock of the Centralized System, and Clearance Rules specifying whether the Token, based on the Clearance Data stored in the Token, can be given a specific Clearance Status that indicates that the object or person is allowed to perform an action or obtain a valid status;
wherein the display is further adapted to display, during an Operational Phase, a first security code, referred to as the Indicator-of-Clearance code or IoC code, indicating the Clearance Status of the Token, whereby the first security code is generated by an Indicator-of-Clearance Function, such as a digital signature or hash function, programmed on the processor unit based on the Clearance Status and the Validator Clock,
wherein the data being securely transferred during the Initialisation Phase between the centralized system and the Validator comprises a set of Time Rules, said Time Rules causing the processor unit to calculate, by a Time Function programmed on the processor, a set of time intervals, referred to as Set-of-Time-Points, said Set-of-Time-Points being provided as input to the Indicator-of-Clearance Function such that respective Indicator-of-Clearance codes are generated for each of the time intervals, and
wherein the respective Indicator-of-Clearance codes for the first and second Identification Devices are identical and displayed simultaneously on the respective displays of the first and second Identification Devices associated with respective Tokens that are authentic and have the same valid Clearance Status.
2-5. (canceled)
6. A Proof-of-Trust-System according to claim 1, wherein the Time Rules further define a time limit period at which the Operational Phase ends and the Validator stops generating Indicator-of-Clearance codes until a new Initialisation Phase occurs.
7. (canceled)
8. A Proof-of-Trust-System according to claim 1, wherein the processor unit of each Validator is adapted so that each potential Indicator-of-Clearance code has a corresponding uniquely different Animated Indicator-of-Clearance Transition codified in a database of Animated Indicator-of-Clearance Transitions in the Validator and to be displayed on the display of the Validator prior to or concurrently with showing the new corresponding Indicator-of-Clearance code, and wherein the Animated Indicator-of-Clearance Transition database is identical for all Validators so that the same Animated Indicator-of-Clearance Transition appears in a synchronous manner on all Validators of Tokens with the same valid Clearance Status.
9. A Proof-of-Trust-System according to claim 1, wherein the data being transferred during the Initialisation Phase between the Centralized System and the Validator comprises a set of Indicator Rules used as additional input by the Indicator-of-Clearance function to generate the Indicator-of-Clearance code.
10. (canceled)
11. A Proof-of-Trust-System according to claim 1, wherein the Validator further comprises a memory for storing the Clearance Rules and if present Time Rules and Indicator Rules.
12. A Proof-of-Trust-System according to claim 1, wherein the Validator communication means used during the Initialisation Phase comprises exclusively wired communication means.
13. A Proof-of-Trust-System according to claim 1, wherein the Token and the Validator are integrated into a single device.
14. A Proof-of-Trust-System according to claim 1, wherein the Validator comprises an input device configured to receive further security information on the Owner of the Token and wherein the Validator is provided to compare the security information received via the input device with further security information from the Token on the Owner of the Token.
15. A Proof-of-Trust-System according to claim 14, wherein the further security information comprises biometric signature or knowledge data on the Owner of the Token and wherein the input device comprises a Biometric Reader for obtaining biometric signature or knowledge data from the carrier of the Identification Device.
16. A Proof-of-Trust-System according to claim 1, wherein some or all of the parts of the Proof-of-Trust-System, the Identification Device andor the Centralized System are tamper resistant.
17. A Proof-of-Trust-System according to claim 1, wherein the data transferred between the Centralized System and the Validator is encrypted through an end-to-end secure messaging channel.
18-24. (canceled)
25. A Proof-of-Trust-System according to claim 1, further comprising a Reference Device having a display and being connected to the Centralised System, the Reference Device being configured to display the IoC code of a Set-of-Valid-Tokens with a predefined Time Delay.
26. A method for validating information displayed on the first or second Identification Devices according to claim 1, comprising the steps of:
initialising the Validator during the Initialisation Phase, the initialising comprising the steps of:
presenting a Token containing information of a person or object to the Validator, such information comprising Identification Data comprising a first subset representing Clearance Data, which Identification Data uniquely identifies the person or object;
connecting the Token to the Validator through the Validator communication interface, thereby allowing the Validator to access the information stored in the memory of the Token;
connecting the Validator to a Connector of a Centralized System through the Validator communication interface; and
transferring data between the Validator and the Centralized System through the Connector, such data comprising a clock synchronization signal to synchronize the Validator clock to a Centralized system clock of the Centralized System, and Clearance Rules specifying whether the Token, based on the Clearance Data stored in the Token can be given a specific Clearance Status that indicates that the object or person is allowed to perform a valid action or obtain a valid status; the method further comprising the step of
operating the Validator (20) during an Operational Phase for validating the information in a Token, the operating the Validator during the Operational Phase comprising the step of: generating a first security code, referred to as the Indicator-of-Clearance code, indicating the Clearance Status of the Token, whereby the first security code is generated by an Indicator-of-Clearance Function programmed on the processor unit based on the Clearance Status and the Validator Clock.
27-29. (canceled)
30. The method according to claim 26, wherein the processor unit of each Validator is configured so that each potential Indicator-of-Clearance code has a corresponding uniquely different Animated Indicator-of-Clearance Transition codified in a database of Animated Indicator-of-Clearance Transitions in the Validator and wherein the Animated Indicator-of-Clearance Transitions are displayed on the display of the Validator prior to or concurrently with showing the new corresponding Indicator-of-Clearance code, and wherein the Animated Indicator-of-Clearance Transition database is identical for all Validators so that the same Animated Indicator-of-Clearance Transition appears in a synchronous manner on all Validators of Tokens with the same valid Clearance Status.
31. The method according to claim 26, wherein the data being transferred during the Initialisation Phase between the Centralized System and the Validator comprises a set of Indicator Rules used as additional input by the Indicator-of-Clearance function to generate the Indicator-of-Clearance code.
32-34. (canceled)
35. The method according to claim 26, wherein the data being transferred during the Initialisation Phase between the centralized system and the Validator comprises a set of Time Rules, the processor unit, enabled by the Time Rules, calculating by a Time Function programmed on the processor, a set of time intervals, referred to as Set-of-Time-Points, said Set-of-Time-Points being provided as input to the Indicator-of-Clearance Function such that respective Indicator-of-Clearance codes are generated for each of the time intervals.
36. (canceled)
37. A system for validating one or more identification tokens, comprising:
a first token including first identification data and a second token including second identification data;
a first validator device and a second validator device, each of the first and second validator devices including a display, a processor unit, a validator clock, and one or more communication interfaces;
each of the respective one or more communication interfaces of the first and second validator devices being configured to (a) receive, from a centralized clock of a centralize system remote from the first and second validator devices, a respective clock synchronization signal to synchronize the validator clock to the respective centralized system clock, (b) receive, from the centralized system, clearance rules specifying whether the respective first and second tokens can be granted a clearance status indicating that a person or object with which the respective first and second validator devices is associated is allowed to perform an action or to obtain a valid status, and (c) access identification data from the respective first and second tokens to apply the clearance rules to determine whether to grant a clearance status to the person or object with which the respective first and second validator devices is associated based on the accessed identification data;
the processor unit of the first validator device being programmed to generate a security code of the first validator device by a programmed function having a substantially unpredictable output based on the granted clearance status associated with the first token and a time point from the synchronized validator clock of the first validator device;
the processor unit of the second validator device being programmed to generate a security code of the second validator device, by the same programmed function producing the same unpredictable output as the programmed function executed by the processor unit of the first validator device, based on the granted clearance status associated with the second token and the same time point from the synchronized validator clock of the second validator device;
wherein each of the respective displays of the first and second validator devices synchronously displays the same security code based on the unpredictable output from the programmed function in response to the first validator having granted a clearance status to the first token that is equal to the clearance status granted by the second validator to the second token.
38. The system of claim 37, wherein the first token is merged with the first validator device to form a first identification device, and wherein the second token is merged with the second validator device to form a second identification device.
39. The system of claim 37, wherein the identification data includes clearance data.