7.6

Table Of Contents
l In the event where 2 requests are made simultaneously on the same record, SQLServer will drop the most com-
plex request. Resubmitting the PGCfor processing should resolve this issue. This, however, should happen only
rarely.
l When configuring the ODBCconnection, your must use the Microsoft version of the driver, and not the Native
SQLversion of the driver. This is due to a technical limitation of the native driver that interferes with the Plan-
etPress Suite database requests.
Specifically for PlanetPress Capture, these considerations mean the following:
l In Microsoft Access, the total size of stored document cannot be larger than 2GB and this database will be very
unstable in implementation with more than a few thousand pattern sequences being used simultaneously. It is only sug-
gested for small implementation with less than 10 pens, or for demos.
l In MySQL, the 16 megs packet size limit can be an issue if the PDFs created by Capture are larger than this size; An
error saying "MySQLServer has gone away" would appear in this case. This can be fixed by configuring the max_
allowed_packet setting in the MySQLConfiguration(Reference).
l Also in MySQL, if a timeout occurs on simultaneous record access, resubmitting the PGCfor processing should resolve
the issue.
l In SQLServer, if one of your requests is dropped because of simultaneous accesses, resubmitting the PGCshould
resolve the issue.
Security Considerations
PlanetPress Capture introduces new and efficient methods for digitally capturing the contents of ink layed out on physical
paper. However, because of its nature, some end users may voice concerns about security and privacy. Are signatures
secure? Could their transmission be intercepted? How can the contents of the Anoto digital pen be protected from malicious
users?
Before addressing these concerns, it must be pointed out that these security issues are not introduced by this new technology.
In fact, they are essentially the same concerns that arise with plain pen and paper: if the signed document can be scanned,
then any markings on the page can be extracted and reused by anyone with even limited technical skills. In addition, the
signed document has, by definition, a longer life span than the temporary storage location of the digital pen. Consequently, it is
still the most vulnerable piece of the workflow and as such, it should be the first objective of any security effort.
In other words, as long as the physical piece of paper bearing markings is accessible to malicious users, no amount of security
protocols can protect the signed contents. It is only after the paper trail has been secured that the security and privacy issues
specific to PlanetPress Capture should be addressed.
Because PlanetPress Capture relies on external data and communication and because it may be used to process sensitive and
legal information, it is important to understand the security implications of any PlanetPress Capture implementation. Most of
the security concerns regarding Capture are external to it. This means the security that is implemented both on your network
and physical premises are critical to the security of your PlanetPress implementation.
Here are a few notable points with the security of PlanetPress Capture on a network:
l PGC Files, while not written in plain text, are not encrypted and are readable through either PlanetPress Production
(even a server that did not generate the document associated with it), or through third-party applications using the
Anoto SDK. This means if someone gains access to your PGC storage folder, they may be able to read the signatures,
checkmarks and other information contained in it and reproduce them on a document of their choice. It is always better
to secure this folder properly. You could also use third-party encryption software to secure the files, and decrypt them
as necessary for reprocessing.
l The transfer between the Anoto penDirector and PlanetPress Production is not encrypted due to a limitation of pen-
Director which does not support SSL connections. This means someone located anywhere between penDirector and
Special Workflow Types