Information processing apparatus and its startup method

By introducing new components into the information processing device, executing the boot program with the first CPU and determining the verification method settings, the problem of the failure to detect external memory tampering and OTP-ROM writing time in the prior art is solved, and efficient program checksum security improvement is achieved.

CN113190879BActive Publication Date: 2025-06-27CANON KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110100933.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-01-29
Filing Date
2021-01-26
Publication Date
2025-06-27
Estimated Expiration
2041-01-26

AI Technical Summary

Technical Problem

In the prior art, the contents of external memory cannot be detected when they are tampered, resulting in the execution of programs that are subject to tampering. The storage security settings in the OTP-ROM require a long time to write, which increases manufacturing costs.

Method used

By introducing new components into the information processing device, the boot program is executed by the first CPU and the verification method setting is determined, written to the second nonvolatile memory, and the device is started by the second CPU after the verification method is set, reducing the amount of stored programs.

Benefits of technology

It realizes that the efficiency and security of program verification are improved without increasing complexity and cost, and reduces the writing time and cost of OTP-ROM.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113190879B_ABST
    Figure CN113190879B_ABST
Patent Text Reader

Abstract

The present invention relates to an information processing apparatus and a method for starting the same. The information processing apparatus includes a first CPU, a second CPU, a first non-volatile memory that stores a boot program to be executed by the first CPU at startup, and a second non-volatile memory that stores the first boot program and a second boot program for a verification program. The first CPU determines whether a verification method is set in the first non-volatile memory. If not, the first CPU executes the first boot program and writes the setting of the verification method to the second non-volatile memory. If the verification method is set, the first CPU executes the second boot program according to the setting, and when the processing of the second boot program ends normally, the second CPU starts the information processing apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus and a method for starting the same. Background Art

[0002] Attacks that abuse a computer by maliciously exploiting software vulnerabilities and tampering with software have become a problem.

[0003] An information processing apparatus including a first CPU, a second CPU, and a nonvolatile memory for storing a program to be executed by the second CPU is described in International Publication No. 2009 / 013825. In this information processing apparatus, the first CPU reads out a program to be executed by the second CPU from the nonvolatile memory, verifies whether the program has been tampered with, and outputs the program to the second CPU according to the verification result. In this way, the second CPU executes a program that has not been tampered with, thereby improving security.

[0004] In a system that reads a program from an external memory and verifies whether the program has been tampered with, verification is performed to ensure that the program itself has not been tampered with. However, if the content of the external memory is tampered with without a tampering detection setting, the tampering cannot be detected, and there is a problem that a tampered program is allowed to be executed. Therefore, it is necessary to store a startup program that is the basis of security and security settings related to an encryption public key, an encryption method, etc. used by the program in a storage device with durability. This is because if there is a vulnerability in the security of the startup program that is the basis of security, the security of the entire system cannot be guaranteed. Therefore, they are usually stored in a storage device such as a ROM that cannot be rewritten.

[0005] On the other hand, a configuration is desired in which security settings related to a public key and an encryption method can be changed according to the shipping destination and application of a product. Therefore, there are cases where these settings are stored in a storage device called an OTP-ROM (one-time programmable ROM) that can be rewritten only once. In this case, security settings related to a public key and an encryption method need to be written to the OTP-ROM. Therefore, for example, it is necessary to prepare a program in the OTP-ROM that can be read by a boot program and can operate in the initial state of the OTP-ROM. Writing such a program to the OTP-ROM takes a long time, and there are also problems from the perspective of manufacturing cost. Summary of the Invention

[0006] An aspect of the present invention is to eliminate the above problems in the prior art.

[0007] A feature of the present invention is to provide a technique for reducing the amount of programs to be stored in a nonvolatile memory that stores a boot program by starting a program for constructing program verification settings when the device is a new component.

[0008] According to a first aspect of the present invention, there is provided an information processing apparatus, the information processing apparatus including: a first CPU; a second CPU; a first non-volatile memory storing a boot program to be executed by the first CPU at startup; and a second non-volatile memory storing the first boot program and a second boot program for a verification program, wherein the first CPU determines whether to set a verification method indicating encryption in the first non-volatile memory as a setting for verifying program tampering, in a case where the verification method is not set, executes the first boot program, and writes the setting of the verification method into the second non-volatile memory, and in a case where the verification method is set, the first CPU executes the second boot program according to the setting, and when the processing of the second boot program ends normally, the second CPU starts the information processing apparatus.

[0009] According to a second aspect of the present invention, there is provided a startup method for an information processing apparatus, the information processing apparatus including a first CPU, a second CPU, a first non-volatile memory storing a boot program to be executed by the first CPU, and a second non-volatile memory storing the first boot program and a second boot program for a verification program, the startup method including: at startup, the first CPU executes the boot program stored in the first non-volatile memory, wherein the first CPU determines whether to set a verification method indicating encryption in the first non-volatile memory as a setting for verifying program tampering, in a case where the verification method is not set, the first CPU executes the first boot program, and writes the setting of the verification method into the first non-volatile memory, when the setting of the verification method is written into the first non-volatile memory, the first CPU restarts the information processing apparatus, and in a case where the verification method is set, the first CPU executes the second boot program according to the setting, and when the processing performed by the second boot program ends normally, the second CPU starts the information processing apparatus.

[0010] Other features of the present disclosure will become clear from the following description of exemplary embodiments with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The drawings incorporated in the specification and constituting a part of the specification illustrate embodiments of the present invention and, together with the description, are used to explain the principles of the present invention.

[0012] Figure 1 is a block diagram for describing the hardware configuration of an MFP according to an embodiment of the present invention.

[0013] Figure 2 is a block diagram for describing software modules included in the MFP according to the present embodiment.

[0014] Figures 3A to 3CThis is a diagram for describing the startup sequence in the MFP according to this embodiment.

[0015] Figure 4A This is a configuration diagram of the flash memory regarding the sub-bootloader 217 and its signature, BIOS, reset vector, and its signature in the MFP according to this embodiment.

[0016] Figure 4B This is a configuration diagram in which the sub-bootloader 218 and its hash value are added to Figure 4A the configuration.

[0017] Figure 5 This is a flowchart for describing the startup sequence process to be executed by the CPU 111 of the MFP according to this embodiment.

[0018] Figure 6A This is for describing the process in the case where the sub-bootloader 217 is executed in Figure 5 step S512.

[0019] Figure 6B This is for describing the process in the case where the sub-bootloader 218 is executed in Figure 5 step S516.

[0020] Figure 7 This is a flowchart for describing the startup sequence of the MFP by the CPU 101 according to this embodiment. Detailed Description of the Invention

[0021] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be understood that the following embodiments are not intended to limit the claims of the present invention, and not all combinations of aspects described in the following embodiments are necessary means for solving the problems according to the present invention. Additionally, multiple features can be arbitrarily combined.

[0022] Note that, by way of example, an MFP (digital MFP / multi-functional peripheral device) is described as the information processing apparatus according to this embodiment. However, the application scope is not limited to the MFP, and the apparatus only needs to be an information processing apparatus. In the following embodiments, a method for performing the tampering detection setting process and the tampering detection process in the startup sequence in an isolated manner will be described.

[0023] Figure 1 This is a block diagram for describing the hardware configuration of the MFP 100 according to an embodiment of the present invention.

[0024] The controller 110 includes hardware modules for controlling the MFP 100. In the present embodiment, it will be assumed that the controller 110 is configured as a semiconductor chip for description. The clock generator 103 generates a clock signal and supplies the clock signal (external clock) at a frequency matching the modules of the MFP 100. In the present embodiment, the clock generator 103 supplies the clock signal 105 to the PLL (Phase Locked Loop) 123 in the controller 110. Note that the frequency of the clock signal 105 can be changed by the clock control signal 107.

[0025] The clock controller 121 controls the PLL 123 with the internal clock control signal 108. Thereby, the PLL 123 multiplies the frequency of the clock signal 105 and supplies the clock signal with the multiplied frequency to the modules of the controller 110. The clock controller 121 performs control such that, when the controller 110 is started or operated, by changing the setting of the PLL 123 regarding multiplication, the PLL 123 supplies the clock signal (internal clock signal) with the optimal frequency to the modules. In addition, the clock controller 121 can stop supplying the clock signal to the module by performing gating on the clock signal.

[0026] The reset generator 104 is a semiconductor chip that resets or releases the reset of the modules of the MFP 100 by generating and outputting a reset signal 106. Although Figure 1 it is illustrated that the reset signal 106 is only supplied to the controller 110, the reset signal is also supplied to modules such as the flash memory 145, the LED 147, the scanner 141, and the printer 142.

[0027] When the power supplied to the MFP 100 is turned on, the reset signal 106 is maintained in the reset state for a fixed time (for example, until the supplied power voltage stabilizes), and then the reset of the controller 110 is released by bringing the reset signal 106 into the release state. The state in which the reset signal 106 is determined is the reset state, and the state in which the reset signal 106 is negated is the release state of the reset signal 106. When the reset of the controller 110 is released, the reset controller 122 performs reset control on the modules in the controller 110. This reset control refers to the control of bringing each module into the reset state or the reset release state when the controller 110 is started or operated.

[0028] The CPU 101 performs overall control of the entire MFP 100 by executing the software program of the MFP 100. The RAM 102 is a volatile random access memory used for storing programs and temporary data when the CPU 101 controls the MFP 100. The HDD 144 is a hard disk drive and stores some applications and various types of data. The HDD 144 stores the Java (registered trademark) program 214 to be executed by the CPU 101 ( Figure 2 ). Note that the Java program 214 will be described later (similarly applicable to the BIOS 210, etc. hereinafter). The flash memory 145 stores fixed parameters of the MFP 100, etc. In addition, the flash memory 145 stores the BIOS 210 to be executed by the CPU 101 ( Figure 2 ). Furthermore, the flash memory 145 stores the loader 211, the kernel program 212, and the native program 213 to be executed by the CPU 101 (all as Figure 2 shown). Note that the HDD 144 and the flash memory 145 may be the same storage module.

[0029] The CPU 111 executes a tamper detection software program for detecting tampering of the software program to be executed by the CPU 101, and performs some control of the MFP 100 in a manner shared with the CPU 101. The ROM 112 is a non-volatile read-only memory and stores the tamper detection software program to be executed by the CPU 111, the public key, etc. to be described later. In addition, the ROM 112 stores the boot program 209 to be executed by the CPU 111 ( Figure 2 ). Here, the ROM 112 is composed of a mask ROM, and the mask ROM is composed of a logic circuit or an OTP-ROM (one-time programmable ROM) that can be written only once during manufacturing, so that it cannot be rewritten from the external interface. The RAM 113 is a volatile random access memory and is used for storing programs, temporary data, etc. when the CPU 111 controls the MFP 100. Note that the RAM 102 and the RAM 113 may be the same module.

[0030] The power supply controller 120 is an IC (Integrated Circuit) that controls the power supply to the modules of the controller 110. The power supply controller 120 can supply predetermined power to these modules or stop the power supply when the controller 110 (MFP 100) starts or operates. The scanner interface controller 131 controls the reading of the original document by the scanner 141. The printer interface controller 132 controls the printing process performed by the printer 142, etc. The panel controller 133 controls the touch panel type console unit 143, displays various types of information, and accepts the input of instructions from the user. The HDD controller 134 controls the data read from the HDD 144 or the data written to the HDD 144. For example, the image data stored in the RAM 102 can be stored in the HDD 144 via the system bus 109. The flash memory controller 135 controls the data read from the flash memory 145 or the data written to the flash memory 145. The flash memory controller 135 reads out the program stored in the flash memory 145 via the system bus 109 and expands the program into the RAM 113. The network interface controller 136 controls the transmission / reception of data to / from other devices or servers on the network 146. The external port controller 137 is the input / output port controller of the controller 110. For example, by controlling the output port and lighting the LED 147 as needed, information about abnormalities in software or hardware can be transmitted to the outside. The image processor 138 is a processor that performs shading correction on the image data obtained by reading the original document by the scanner 141, and performs halftone processing and smoothing processing for outputting the image data to the printer 142. The system bus 109 connects the modules to each other. Control signals from the CPUs 101 and 111 and data signals between the units are transmitted and received via this system bus 109.

[0031] Figure 2 It is a block diagram for describing the software modules included in the MFP 100 according to the present embodiment. It will be described assuming that these software are executed by the CPU 101 or the CPU 111.

[0032] The communication management module 207 transmits data to external devices and receives data from external devices via the network 146 by controlling the network interface controller 136 to be connected to the network 146. The UI control module 216 receives input from the console unit 143 via the panel controller 133, processes the input according to the input, and outputs to the screen of the console unit 143.

[0033] The bootstrap program 209 is stored in the ROM 112 and is a program to be executed by the CPU 111 when the power of the MFP 100 is turned on. The bootstrap program 209 executes the startup sequence of the controller 110 as processing related to startup. It will be referred to later Figure 5FIG. 6 describes the startup sequence. The bootstrap program 209 includes a sub - bootstrap program tampering detection module 200 for detecting tampering of the sub - bootstrap programs 217 and 218. Note that all programs except the bootstrap program 209 in Figure 2 are stored in the flash memory 145.

[0034] The sub - bootstrap program 217 executes a BIOS reset vector tampering detection module 201 for detecting tampering with the BIOS 210. Alternatively, the sub - bootstrap program 217 executes a tampering detection setting module 202 and executes a tampering detection setting program for the ROM 112 to be described later.

[0035] The BIOS 210 is a program executed by the CPU 101 after the bootstrap program 209 is executed, and in addition to performing startup - related processing, it includes a loader tampering detection module 203 for detecting tampering with the loader 211. In addition, the sub - bootstrap program 218 includes a tampering detection setting module 202 for detecting tampering with the loader 211.

[0036] The loader 211 is a program to be executed by the CPU 101 after the processing of the BIOS 210 ends, and in addition to performing startup - related processing, it includes a core program tampering detection module 204 for detecting tampering with the core program 212.

[0037] The core program 212 is a program to be executed by the CPU 101 after the processing of the loader 211 ends, and in addition to performing startup - related processing, it includes a native program tampering detection module 205 for detecting tampering with the native program 213.

[0038] The reset vector 215 is a program that specifies information about the processing to be executed first when the reset of the CPU 101 is released. The addresses of the exception handler and the ISR (Interrupt Service Routine) are specified in the reset vector 215. As a result of specifying the jump target address, the handler automatically jumps to that address, and the CPU 101 can start executing the program from that address. When the reset is released, the reset handler, which is one of the exception handlers, is referred to and the program starting from the jump target address specified in the reset handler is executed. Note that depending on the CPU, a method of specifying a command may also be adopted, and the transfer to the specified address is performed by executing the command. In this embodiment, the former method will be assumed for the description.

[0039] The native program 213 is a program to be executed by the CPU 101 and is composed of multiple programs that cooperate with the Java program 214 of the MFP 100 to provide functions. These multiple programs include, for example, programs for controlling the scanner interface controller 131 and the printer interface controller 132, startup programs for these controllers, and a restart program for the CPU 111. These startup programs and the restart program for the CPU 111 are called from the native program by the core program 212 and undergo startup processing. Here, the restart program for the CPU 111 is used to enable other applications to use the CPU 111 after the CPU 111 has executed the boot program and completed the BIOS reset vector tampering detection process. For example, the restart program is used as a program for monitoring interrupts of external ports in the power-saving mode. Here, the power-saving mode refers to a state in which power is safely cut off from or the clock signal is stopped for controllers and processors other than the CPU 111, the external port controller, the system bus 109, the network interface controller 136, and the console unit 143. For example, when the external port controller 137 detects an external port interrupt by receiving a signal from a sensor, the CPU 111 performs a process of returning from the power-saving mode to the normal mode. The aforementioned controllers and processors whose power has been cut off or whose clock signal has been stopped are safely transferred to the operating state. As a result of the CPU 111 monitoring interrupts, when the scale and standby power of the CPU 111 are smaller than those of the CPU 101, power-saving efficiency can be improved by cutting off power from or stopping the clock signal for the CPU 101 that processes in the normal operating state. In addition, as one of the programs, the native program 213 includes a Java program tampering detection module 206 for detecting tampering with the Java program.

[0040] The Java program 214 is a program to be executed by the CPU 101 and is a program for cooperating with the native program 213 of the MFP 100 to provide functions (for example, a program for displaying a screen in the console unit 143).

[0041] Next, with reference to Figures 3A to 3C the startup sequence of the MFP 100 will be described.

[0042] Figures 3A to 3C is a diagram for describing the startup sequence of the MFP 100 according to the present embodiment.

[0043] Figure 3A is a diagram schematically illustrating the startup sequence showing the order in which the MFP 100 starts without performing tampering detection on the program.

[0044] The CPU 111 executes the boot program 209 and releases the reset of the CPU 101. Thus, when the CPU 101 starts the BIOS 210, the BIOS 210 starts the loader 211, and the loader 211 starts the core program 212. In addition, the core program 212 starts the startup program of the native program 213. In this way, the Java program 214 is started from the startup program, and then the native program 213 and the Java program 214 cooperate and can provide the functions included in the MFP 100.

[0045] Figure 3B and Figure 3C is a schematic diagram of the startup sequence according to this embodiment. Figure 3B and Figure 3C is also a schematic diagram showing the storage locations of the respective programs, the storage locations of the digital signatures (hereinafter referred to as signatures) and the public keys, the verification method, the sub-boot program header address pointer, and the hash values.

[0046] Here, the signature is obtained by converting an authorized program (data stream) into a hash value using a predetermined hash function and encrypting the hash value with a private key corresponding to the public key. The hash value of the authorized program is calculated by decoding the encrypted hash value with the public key, converting the program to be verified for tampering into a hash value using the aforementioned hash function, and comparing the two hash values. If the two hash values are the same, it can be determined that the program to be verified has not been tampered with from the authorized program. Additionally, if the two hash values are different from each other, it can be determined that the program to be verified has been tampered with from the authorized program. In this way, the method of using the signature to check whether the program to be verified has been tampered with is hereinafter referred to as signature verification. Additionally, the fact that the program has not been tampered with is referred to as successful signature verification, and the fact that the program has been tampered with is referred to as failed signature verification. Additionally, in signature verification, the hash value of the program is encrypted, but it is also possible to determine whether there has been tampering by simply comparing the hash values of the programs without encrypting the hash values. In this way, the method of using the hash value to check whether the program to be verified has been tampered with is hereinafter referred to as hash verification.

[0047] The value of the verification method 313 is a setting value used by the CPU 111 to switch between signature verification and hash verification when the CPU 111 executes the boot program 209, and this value is stored in the ROM 112. Note that in this embodiment, a value of "0" for the verification method in the ROM 112 indicates hash verification, and a value of "1" indicates signature verification.

[0048] The sub-boot program header address pointer 314 indicates the position of the sub-boot program header address in the boot program 209. In this embodiment, which of the BIOS reset vector tampering detection module 201 and the tampering detection setting module 202 is to be operated by the CPU 111 is determined by the sub-boot program indicated by the header obtained by referring to this address pointer. Note that in this embodiment, when the sub-boot program header address pointer 314 is not set in the ROM 112, the value of the address pointer of the ROM 112 is "0". In this case, a predetermined address on the flash memory 145 is referred to. On the other hand, when the sub-boot program header address pointer 314 is set, the program is executed by referring to this address. What is to be referred to will be described later with reference to FIG. 4.

[0049] Note that in this embodiment, the method using a signature and a public key and the method using a hash value are adopted as the methods for checking whether a program has been tampered with, but other methods for checking whether tampering has occurred can also be used.

[0050] Figure 3B is a schematic diagram of the startup sequence that sequentially starts the boot program 209, the sub-boot program 217, the BIOS 210, and the reset vector 215, the loader 211, the core program 212, the native program 213, and the Java program 214 while performing tampering detection.

[0051] The boot program 209 includes a public key 300 for verifying the sub-boot program signature and the BIOS signature. The sub-boot program includes its signature 301. The BIOS 210 includes a BIOS reset vector signature 302 and a loader verification public key 303. In addition, the loader 211 includes a loader signature 304 and a core program verification public key 305. In addition, the core program 212 includes a core program signature 306 and a native program verification public key 307. In addition, the native program 213 includes a native program signature 308 and a Java program verification public key 309. In addition, the Java program 214 includes a Java program signature 310. These public keys and signatures are given to the programs before the MFP 100 is shipped.

[0052] Figure 3C is a schematic diagram of the startup sequence showing the execution flow of the tampering detection setting process for the sub-boot program according to the boot program 209. Here, its hash value 315 is added to the sub-boot program in the flash memory 145.

[0053] Figure 4A is a structural diagram of the sub-boot program 217 on the flash memory 145, its signature 301, the BIOS 210, the reset vector 215, and its signature 302.

[0054] Here, an example is shown Figure 3CThe case where the sub-bootloader header address pointer 314 in

[0055] The above BIOS reset vector tampering detection module 201, loader tampering detection module 203, core program tampering detection module 204, native program tampering detection module 205, and Java program tampering detection module 206 respectively verify whether the subsequent programs have been tampered with. Additionally, if the program has not been tampered with, the program is started. In this way, after sequentially executing the verification of whether the program has been tampered with and the startup sequence of the startup program, the MFP 100 is started.

[0056] Figure 4B is a configuration diagram of the configuration in which the sub-bootloader 218 on the flash memory 145 and its hash value are added to Figure 4A the configuration.

[0057] Here, since tampering detection settings are not performed on the sub-bootloader 218, hash value verification is used instead of signature verification. Figure 3CShows a configuration in which the sub-boot program header address pointer 314 is not set, and the boot program 209 reads "0x0005_0000". Here, the value obtained by converting the data stream from the header of the sub-boot program 218 to the end of the sub-boot program 218 into a hash value is stored in the hash value area of the sub-boot program 218. In addition, the program to be verified for tampering is converted into a hash value using the aforementioned hash function, and the two hash values are compared. The address and size of the sub-boot program 218 are stored as the header of the sub-boot program 218 in the hash calculation target range from "0x0005_0000" to "0x0005_0010". In addition, the CPU 111 executes the boot program 209, reads the address and size, and converts the data stream in the required area into a hash value. In the flash memory 145, the hash value is arranged next to the sub-boot program 218, but it can also be configured such that the address and size of the hash value are added to the header of the sub-boot program 218, and the boot program 209 reads and refers to the address and size.

[0058] Next, a method of tampering detection setting processing and tampering detection processing to be executed in the startup sequence in an isolated manner, which is a feature of the present invention, will be described with reference to Figures 5 to 7 the flowchart of.

[0059] Figure 5 is a flowchart for describing the startup sequence processing to be executed by the CPU 111 of the MFP 100 according to the present embodiment. Note that in the present embodiment, in the initial state, after operating in the following settings, the processing in the flowchart in Figure 5 is executed.

[0060] When the power of the MFP 100 is turned on, the power controller 120 controls to supply power to the units of the controller 110. When receiving power, the clock controller 121 controls so that the oscillator or resonator of the clock generator 103 generates the clock signal 105 by outputting the clock control signal 107 to the clock generator 103. In addition, the clock controller 121 controls so that the PLL 123 generates the internal clock signal of the desired controller 110 by outputting the internal clock control signal 108 to the PLL 123.

[0061] Next, the reset generator 104 releases the reset of the reset controller 122 via the reset signal 106. When releasing the reset of the reset controller 122, first the reset controller 122 releases the resets of the system bus 109, ROM 112, CPU 111, flash memory controller 135, and flash memory 145. Note that the CPU 101 is still in the reset state at this time point. Additionally, the reset vector of the CPU 111 is the address of the ROM 112. That is, when the reset of the CPU 111 is released, the CPU 111 executes the boot program 209 stored in the ROM 112. The reset vector of the CPU 101 is stored at a predetermined address (in this embodiment, "0x0000_0000") in the flash memory 145, and when the reset of the CPU 101 is released, the CPU 101 reads the reset vector. Additionally, the CPU 101 jumps to the address written in the reset vector and executes the BIOS 210 stored in the flash memory 145.

[0062] Next, steps S501 to S516 show the startup sequence to be executed by the CPU 111. That is, the following processing to be executed by the CPU 111 is performed by the Figure 2 software module shown. The feature of the startup sequence is in step S508. That is, by reading the header of the sub-boot program, the sub-boot program is switched to and executed.

[0063] When this sequence starts as a result of the release of the reset of the CPU 111, first in step S501, the CPU 111 starts up and executes the boot program 209 stored in the ROM 112. Next, the process advances to step S502, and the CPU 111 performs power control according to the boot program 209. Here, control is performed such that power is supplied only to some of the units in the controller 110 required for tampering detection or tampering detection setting. Note that in this embodiment, power is supplied to at least the following units required for tampering detection processing or tampering detection setting. These units are the clock controller 121, reset controller 122, PLL 123, power controller 120, CPU 101, flash memory 145, RAM 102, CPU 111, ROM 112, RAM 113, HDD controller 134, flash memory controller 135, and external port controller 137.

[0064] Next, the process proceeds to step S503, and the CPU 111 performs the following clock control according to the boot program 209. After the controller 110 finishes starting up, the operating frequencies of the units in the controller 110 differ according to the specifications of the MFP 100. The clock controller 121 uses the clock control signal 107 to instruct the clock generator 103 to supply the desired clock signal 105. Note that when changing the frequency of the clock signal 105, it is necessary to wait for a fixed time until the crystal resonator or crystal oscillator stabilizes. In addition, the clock controller 121 uses the internal clock control signal 108 to set the frequency of the internal clock signal to be supplied to the required units in the controller 110 with respect to the PLL 123 to the desired frequency. In this way, the processing in the CPU 111, the system bus 109, and the flash memory controller 135 is performed.

[0065] Note that in order to change the frequency of the internal clock signal, the clock controller 121 performs the following processing. That is, the clock controller 121 gates the clock signal from the PLL 123 once and switches to the external clock signal bypassing the PLL 123. Then, after the internal clock signal generated by the PLL 123 stabilizes, control is performed so as to supply the desired internal clock signal to the unit. Here, the control for switching the internal clock signal also stops supplying the clock signal to the CPU 111, so the control is performed by providing a hardware sequencer inside the clock controller 121.

[0066] The clock controller 121 makes settings such that the frequencies of the clock signals to be supplied to the CPU 101, the flash memory 145, the RAM 102, the CPU 111, the ROM 112, the RAM 113, the system bus 109, the HDD controller 134, and the flash memory controller 135 are the desired frequencies. Note that here, the frequency of the clock signal to be supplied can be changed according to the unit to be supplied.

[0067] Next, the process proceeds to step S504, and the CPU 111 releases the reset according to the bootstrap program 209. That is, the CPU 111 releases the reset of the units required for the tampering detection process or the tampering detection setting. Specifically, the resets of the RAM 113, the system bus 109, and the HDD controller 134 are released. Next, the process proceeds to step S505, and the CPU 111 reads the tampering detection setting value set in the ROM 112 according to the bootstrap program 209. Then, the process proceeds to step S506, and the CPU 111 confirms the verification method according to the tampering detection setting value. Here, if the verification method is the signature verification method, the process proceeds to step S507, and if the verification method is the hash verification method, the process proceeds to step S508. In the present embodiment, it is assumed that the signature verification method is set during the tampering detection process, and the hash verification method is set during the tampering detection setting process. Note that in the case where no value is written in the verification method 313 ( Figure 3C ) in the ROM 112, the hash verification method is set.

[0068] When the signature verification method is adopted, in step S507, the CPU 111 reads the public key from the ROM 112, stores the public key in the RAM 113, and the process proceeds to step S508. In step S508, the CPU 111 reads the value of the head pointer of the sub-boot program. Next, the process proceeds to step S509, and the CPU 111 determines whether the value of the head pointer of the sub-boot program is the head of the sub-boot program 217 or the head of the sub-boot program 218. Here, if it is determined that it is the head of the sub-boot program 217, the process proceeds to step S510, and if not, that is, if it is determined that it is the head of the sub-boot program 218, the process proceeds to step S514. Note that in the present embodiment, in the case where the initial value of the head address pointer of the sub-boot program in the ROM 112 is not written with any value (for example, all are "0"), the CPU 111 performs the same process as reading the address of the sub-boot program 218 ( Figure 4B in 0x0005_0000).

[0069] In step S509, when it is determined that it is the head of the sub-boot program 217, the CPU 111 causes the process to proceed to step S510. In step S510, if the address, size, and signature address of the sub-boot program 217 are written, the CPU 111 also reads the signature according to the head pointer of the sub-boot program 217. In Figure 4BIn the embodiment, the address (0x0004_0000) is set. The CPU 111 calculates the hash value of the sub-boot program 217 based on the read address and size. In addition, the encrypted signature is decoded into a hash value using the public key read in step S507. Then, the signature verification of the sub-boot program 217 is performed by comparing these two hash values. Then, the process proceeds to step S511. If the hash values match, the CPU 111 determines that the sub-boot program 217 has not been tampered with and advances the process to step S512. On the other hand, if these hash values do not match, it is determined that the sub-boot program 217 has been tampered with, and the process advances to step S513.

[0070] In step S512, the CPU 111 loads the sub-boot program 217 into the RAM 113 and executes the sub-boot program 217. That is, the BIOS reset vector tampering detection process is performed. The processing content here will be described later with reference to the flowchart in Figure 6A In step S513, since the sub-boot program 217 has been tampered with, the CPU 111 blinks the LED 147 for error notification and ends the process.

[0071] In addition, in step S514, the CPU 111 obtains the address and size of the sub-boot program 218 based on the header pointer of the sub-boot program 218. In addition, if the storage address where the hash value is written is available, the hash value is also read. In the embodiment shown in Figure 4B the header of the sub-boot program 218 is set to the address (0x0005_0000). In addition, the CPU 111 calculates the hash value of the sub-boot program 218 based on the read address and size. This hash value is compared with the stored hash value of the sub-boot program 218. Then, in step S515, if these hash values match, it is determined that the sub-boot program 218 has not been tampered with, and the process advances to step S516. Otherwise, the process advances to step S513 and the LED 147 blinks. In step S516, the CPU 111 loads the sub-boot program 218 into the RAM 113 and executes the sub-boot program 218. That is, the tampering detection setting process is to be executed. The processing content here will be described later with reference to the flowchart in Figure 6B In the embodiment shown in

[0072] Note that in the determination of the verification method in step S506, it is determined not to perform the signature verification method. That is, in the case of the hash verification of the initial value, the header pointer of the sub-boot program 218 can be read, and then the process can advance to step S514. Similarly, if in step S507, the value of the public key is the initial value, the header pointer of the sub-boot program 218 can be read, and the process can advance to step S514.

[0073] Next, reference will be made toFigure 6A The flowchart of Figure 5 describes the execution method of the BIOS reset vector tampering detection process when executing the sub-boot program 217 in step S512 of

[0074] Figure 6A It is used to describe the process in Figure 5 when executing the sub-boot program 217 in step S512 of

[0075] In step S601, the CPU 111 reads the head pointer of the BIOS reset vector. In Figure 4B the illustrated embodiment, this head pointer is set to 0x0000_8000. In this embodiment, the head pointer of the BIOS reset vector is specified in the sub-boot program 217. It can be constructed as follows: such that this head pointer is included in the head of the sub-boot program 217 and this head pointer is read from the head.

[0076] Next, the process advances to step S602, and the CPU 111 performs a signature verification on the BIOS and the reset vector. Here, the CPU 111 serves as the BIOS reset vector tampering detection module 201 included in the sub-boot program 217, and reads the BIOS 210 and the reset vector 215 from the flash memory 145 into the RAM 113 via the system bus 109. In this embodiment, as Figure 4B shown, the data in the fixed area (hash calculation target range) from the fixed address 0x0000_0000 to the fixed address 0x0001_FFFF is read. In addition, the BIOS reset vector tampering detection module 201 verifies the BIOS reset vector signature 302 using the public key 300 for verifying the signature of the BIOS 210. Note that in this embodiment, the BIOS and the reset vector are verified centrally, but they can also be verified separately. In addition, the addresses and sizes of the reset vector and the BIOS may not be fixed. In this case, as described above, the head addresses and sizes of the reset vector and the BIOS are stored in the hash calculation target range and read out.

[0077] Next, the process advances to step S603, and the CPU 111 determines whether the signature verification of the BIOS reset vector is successful. As a result of the signature verification, if it is determined that the BIOS and the reset vector have not been tampered with (the hash value matches the signature value), the CPU 111 determines that the signature verification is successful, and the process advances to step S604. On the other hand, if it is determined that the BIOS or the reset vector has been tampered with (the hash value does not match the signature value), the CPU 111 determines that the signature verification has failed, and the process advances to the error handling in step S605. That is, even when the reset vector has been tampered with, the tampering can be detected, and the process advances to the error handling in step S605. In step S604, the CPU 111 releases the resets of the CPU 101, the flash memory 145, and the RAM 102 by controlling the reset controller 122, and ends the processing of the sub-boot program 217. Then, the startup sequence transfers to step S701, which will be described later. That is, the CPU 101 executes the BIOS 210 and starts up. On the other hand, if the process advances to step S605, the CPU 111 serves as the BIOS reset vector tampering detection module 201, turns on the LED 147 by controlling the external port controller 137 to give a notification of the signature verification failure, and ends the processing of the boot program.

[0078] Next, the processing for executing the sub-boot program 218 in step S516 will be described with reference to the flowchart in Figure 6B . Figure 5 The processing of the sub-boot program 218 in step S516 will be described with reference to the flowchart in

[0079] Figure 6B is a flowchart for describing the processing of the sub-boot program 218 executed in step S516 of Figure 5 .

[0080] First, in step S610, the CPU 111 writes the tampering detection setting to a predetermined address in the flash memory 145. The content of this setting is the aforementioned verification method, public key, and the head pointer of the sub-boot program, and these have values in the sub-boot program 218. Next, the process advances to step S611, and the CPU 111 determines whether the content written in step S610 can be read correctly. Here, if the content can be read correctly, the process advances to step S612; otherwise, the process transfers to step S613. In step S612, the CPU 111 restarts the system and ends the processing of the sub-boot program 218. In this embodiment, a watchdog timer (not shown) is started and the reset controller 122 is reset after a fixed time has elapsed. The method of reset is not limited to this. In step S613, in order to give a notification of the failure of the tampering detection setting in step S611, the CPU 111 turns on the LED 147 by controlling the external port controller 137, and ends the processing of the sub-boot program 218.

[0081] As a result of executing the above sequence, the CPU 111 can execute the tampering detection process and the tampering detection setting process in an isolated manner.

[0082] Figure 7 It is a flowchart for describing the startup sequence of the MFP 100 by the CPU 101 according to the present embodiment. Note that the method for determining whether the programs (loader 211, core program 212, native program 213, Java program 214) have been tampered with in the following processes is only an example, and other methods may also be executed as long as the method is for detecting program tampering. Note that the processes shown in this flowchart can be implemented by the CPU 101 executing the programs expanded in the RAM 102.

[0083] First, in step S701, the CPU 101 is configured to read the reset vector 215 when the reset is released. In the present embodiment, the reset vector 215 is designed to be stored in the flash memory 145, so the CPU 101 reads the reset vector 215 through the system bus 109. Then, the CPU 101 jumps to the start address of the BIOS 210 written to the reset vector 215, reads the BIOS 210 from the flash memory 145, and executes the BIOS 210. When starting the BIOS 210, various types of initialization processes are executed, and the loader tampering detection module 203 included in the BIOS 210 reads the loader 211, the core program verification public key 305, and the loader signature 304 from the flash memory 145 into the RAM 102. The initialization sequence here includes, for example, the initialization of the HDD controller 134 for allowing access to the HDD 144.

[0084] Next, the process proceeds to step S702. The CPU 101 serves as the loader tampering detection module 203, uses the loader verification public key 303 to verify the loader signature 304, and determines whether the signature verification is successful. Here, if it is determined that the signature verification fails, the process proceeds to step S710. The loader tampering detection module 203 initializes the panel controller 133, displays an error message in the console unit 143, and ends the process. On the other hand, if it is determined that the signature verification is successful, the process proceeds to step S703. The loader tampering detection module 203 ends the process, and the BIOS 210 starts the loader 211 read into the RAM 102.

[0085] In this way, in step S703, the CPU 101 starts the loader 211 and performs various types of initialization processing. The initialization here includes, for example, the initialization of the panel controller 133 and the display of a startup screen on the console unit 143. Additionally, the core program tampering detection module 204 included in the loader 211 reads the core program 212, the core program verification public key 305, and the core program signature 306 from the flash memory 145 into the RAM 102.

[0086] Next, the process advances to step S704, where the CPU 101 acts as the core program tampering detection module 204, uses the core program verification public key 305 to verify the core program signature 306, and determines whether the signature verification is successful. Here, if it is determined that the verification of the core program signature fails, the process advances to step S710, and the core program tampering detection module 204 displays an error message in the console unit 143 and ends the process. On the other hand, if it is determined that the verification of the core program signature 306 is successful, the process advances to step S705, the core program tampering detection module 204 ends the process, and the loader 211 starts the core program 212 read into the RAM 102.

[0087] In this way, when the CPU 101 starts the core program 212 in step S705, various types of initialization processing are performed. The initialization here includes, for example, the initialization of the network interface controller 136 for enabling communication of the network 146. Next, the native program tampering detection module 205 included in the core program 212 reads the verification public key 307 and the native program signature 308 for verifying the native program 213 from the flash memory 145 into the RAM 102.

[0088] Then, the process advances to step S706, where the CPU 101 acts as the native program tampering detection module 205, uses the verification public key 307 to verify the native program signature 308, and determines whether the verification of the native program signature 308 is successful. If it is determined that the verification of the native program signature 308 fails, the process advances to step S710, and the native program tampering detection module 205 displays an error message on the console unit 143 and ends the process. On the other hand, if it is determined that the verification of the native program signature 308 is successful, the process advances to step S707, and the native program tampering detection module 205 ends the process and starts the native program 213.

[0089] In step S707, the CPU 101 starts the Java program tampering detection module 206 that performs tampering detection processing according to the local program 213, and reads the Java program 214 and the Java program signature 310 from the HDD 144 into the RAM 102. In addition, the CPU 101 executes a startup program for starting the scanner 141 and the printer 142. Further, the local program 213 changes the address of the program startup module of the CPU 111 from the ROM 112 to the RAM 113, writes the restart program into the RAM 113, resets the CPU 111, and then restarts the CPU 111 by releasing the reset. As a result of the restart, the CPU 111 can execute a program for monitoring an interruption of an external port in the case of the above power saving mode.

[0090] Next, the process proceeds to step S708. The CPU 101 serves as the Java program tampering detection module 206, uses the Java program verification public key 309 written into the RAM 102 in step S705 to verify the Java program signature 310, and determines whether the verification of the Java program signature is successful. Here, if it is determined that the verification of the Java program signature 310 fails, the process proceeds to step S710, and the Java program tampering detection module 206 displays an error message on the console unit 143 and ends the process. On the other hand, if it is determined that the verification of the Java program signature 310 is successful, the Java program tampering detection module 206 ends the process, causes the process to proceed to step S709, and starts the Java program 214.

[0091] Note that the process in step S710 causes an error message to be displayed on the console unit 143. Alternatively, the LED 147 can be caused to blink by controlling the external port controller 137. In addition, the display of the error message on the console unit 143 and the blinking of the LED 147 can be performed simultaneously.

[0092] Note that in the present embodiment, it is assumed that all public keys are different and described, but some public keys can be the same. In addition, the storage location of programs other than the bootstrap program is not limited, and they can also be in other storage media. In addition, the storage location of the program can be different from the foregoing location, and for example, a configuration can be adopted in which the loader 211 is stored in the flash memory 145 or the ROM 112.

[0093] As described above, according to the present embodiment, it is necessary to execute the tampering detection setting process in the case where the tampering detection setting is not set, and as a result, the security level can be improved.

[0094] Other embodiments

[0095] Embodiments of the present invention can also be implemented by a computer of a system or apparatus that reads and executes computer-executable instructions (e.g., one or more programs) recorded on a storage medium (which may also be more fully referred to as a "non-transitory computer-readable storage medium") to perform the functions of one or more of the above-described embodiments, and / or includes one or more circuits (e.g., an application specific integrated circuit (ASIC)) for performing the functions of one or more of the above-described embodiments. Moreover, embodiments of the present invention can be implemented by a method of, for example, reading and executing the computer-executable instructions from the storage medium by the computer of the system or apparatus to perform the functions of one or more of the above-described embodiments, and / or controlling the one or more circuits to perform the functions of one or more of the above-described embodiments. The computer may include one or more processors (e.g., a central processing unit (CPU), a microprocessing unit (MPU)), and may include a network of separate computers or separate processors to read and execute the computer-executable instructions. The computer-executable instructions may be provided to the computer, for example, from a network or the storage medium. The storage medium may include, for example, a hard disk, a random access memory (RAM), a read-only memory (ROM), a storage portion of a distributed computing system, an optical disc (such as a compact disc (CD), a digital versatile disc (DVD), or a Blu-ray disc (BD) TM ), a flash device, and a memory card, among others.

[0096] Other embodiments

[0097] Embodiments of the present invention can also be implemented by the following method, i.e., by providing software (a program) that performs the functions of the above-described embodiments to a system or apparatus via a network or various storage media, and the method of the computer or the central processing unit (CPU), the microprocessing unit (MPU) of the system or apparatus reads and executes the program.

[0098] Although the exemplary embodiments have been described, it should be understood that the present disclosure is not limited to the disclosed exemplary embodiments. The scope of the appended claims should be given the broadest interpretation to cover all such variations and equivalent structures and functions.

Claims

1. An information processing apparatus, the information processing apparatus comprising: A first CPU; A second CPU; A first non-volatile memory that stores a boot program to be executed by the first CPU at startup; And A second non-volatile memory that stores the first boot program and a second boot program for verifying the program, wherein the first CPU determines whether to set a verification method indicating encryption in the first non-volatile memory as a setting for verifying program tampering. In the case where the verification method is not set, the first CPU executes the first boot program and writes the setting of the verification method into the second non-volatile memory, and in the case where the verification method is set, the first CPU executes the second boot program according to the setting, and when the processing of the second boot program ends normally, the second CPU starts the information processing apparatus.

2. The information processing apparatus according to claim 1, wherein, The setting for verifying program tampering includes a verification method, a public key for verifying the second boot program, and a setting of the header pointer of the second boot program.

3. The information processing apparatus according to claim 1 or 2, wherein In the case where the verification method is not set, the first CPU uses a hash value to verify the first boot program, and executes the first boot program in the case of successful verification.

4. The information processing apparatus according to claim 2, wherein, In the case where the verification method is set, the first CPU uses the public key included in the setting for verifying program tampering to verify the second boot program, and executes the second boot program in the case of successful verification.

5. The information processing apparatus according to claim 1, wherein, The second boot program performs a signature verification on the BIOS to be executed by the second CPU, and in the case of successful signature verification, the reset of the second CPU is released, and the second CPU starts the information processing apparatus.

6. The information processing apparatus according to claim 1, wherein, The initial value of the setting for verifying program tampering indicates a verification method using a hash value.

7. The information processing apparatus according to claim 2, wherein, In the case where the set value of the public key is the initial value, the first CPU determines that the verification method indicating encryption is not set as the setting for verifying program tampering.

8. The information processing apparatus according to claim 1, wherein, After writing the setting of the verification method into the second non-volatile memory by executing the first boot program, the first CPU restarts the information processing apparatus.

9. The information processing apparatus according to claim 1, wherein, The first non-volatile memory is an OTP-ROM.

10. The information processing apparatus according to claim 1, wherein, The second non-volatile memory is a flash memory.

11. A method for starting an information processing device, the information processing device comprising: The first CPU, the second CPU, the first non-volatile memory that stores the boot program to be executed by the first CPU, and the second non-volatile memory that stores the first boot program and the second boot program for verifying the program, the startup method comprising: The first CPU executes the boot program stored in the first non-volatile memory at startup, wherein the first CPU determines whether to set a verification method indicating encryption in the first non-volatile memory as a setting for verifying program tampering, in the case where the verification method is not set, the first CPU executes the first boot program and writes the setting of the verification method into the first non-volatile memory, in the case where the setting of the verification method is written into the first non-volatile memory, the first CPU restarts the information processing apparatus, in the case where the verification method is set, the first CPU executes the second boot program according to the setting, and When the processing performed by the second boot program ends normally, the second CPU starts the information processing apparatus.

12. The startup method according to claim 11, wherein, When the verification method has not been set, the first CPU verifies the first boot program using a hash value, and when the verification is successful, executes the first boot program.

13. The startup method according to claim 11, wherein, When the verification method has been set, the first CPU verifies the second boot program using the public key included in the setting for verifying program tampering, and when the verification is successful, executes the second boot program.

Citation Information

Patent Citations

  • Information processor and tampering verification method

    WO2009013825A1

  • Integrity verification device, integrity verification system, integrity verification method and integrity verification program

    JP2019133220A

  • Data processing apparatus and control method for a data processing apparatus

    US20070016763A1