Information processing device, control method, and program

By using the authentication process based on security keys in the BIOS processing of the information processing device, combining trust lists and chain lock information storage, restricting the use of protocols related to illegal startup programs, the defense problem of third-party attacks under security guidance is solved, and higher system security is achieved.

CN120012093APending Publication Date: 2025-05-16LENOVO (SINGAPORE) PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411608663.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-14
Filing Date
2024-11-12
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing information processing devices are difficult to effectively defend against third-party attacks under secure guidance, especially tampering with or monitoring tampering programs.

Method used

By authenticating the process based on the pre-determined security key in the BIOS processing, the legitimacy of the initiator is confirmed, and the trusted initiator source and execution status are recorded in the trust list and chain lock information store, and the protocols related to the use of illegal initiator are restricted.

Benefits of technology

Under security guidance, improve the defense capabilities against third-party attacks, reduce the risk of tampering or monitoring of subsequent programs by tampered programs, and enhance the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012093A_ABST
    Figure CN120012093A_ABST
Patent Text Reader

Abstract

The invention relates to an information processing apparatus, a control method, and a program, which improve defense against attacks from a third party under secure boot. The information processing device is provided with: an authentication processing unit which, during BIOS processing, confirms the validity of a startup program for starting an OS on the basis of a security key; a trustworthiness list storage unit that stores a trustworthiness list that is a list of trustworthiness sources of the startup program; a link information storage unit that stores link information indicating whether or not an illegal startup program has been executed; a boot-up processing unit that, in a secure boot-up process for executing the boot-up program whose validity has been confirmed by the authentication processing unit, changes the chain information if the boot-up program acquired from a provision source not included in the trustworthiness list has been executed; and a restriction processing unit that restricts the use of a security-related protocol when the link information is changed to information indicating that an illegal startup program has been executed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing device, a control method, and a program. Background Art

[0002] In recent years, in information processing devices such as personal computers, a secure boot function has been installed in the BIOS (Basic Input Output System), which prevents a third party from tampering with or monitoring the pre-boot environment before the OS (Operating System) is started, and makes it impossible for programs that are not signed by a key (secure boot key) registered in the system to run (for example, refer to Patent Document 1).

[0003] Patent document 1: Japanese Patent Application Publication No. 2017-146694.

[0004] In addition, in existing information processing devices, information exchange between drivers, management of system information, BIOS settings, etc. are performed through a universal interface defined by the UEFI (Unified Extensible Firmware Interface) specification, such as a protocol. However, this universal interface is a program existing in the memory, so it may be rewritten by a third-party program.

[0005] In addition, in programs signed by a secure boot key, vulnerabilities that bypass secure boot are sometimes found, and they may be tampered with by a third party even under the protection of secure boot. Therefore, in existing information processing devices, under secure boot, for example, if a program tampered with by a third party is executed, it is possible to tamper with or monitor the program executed later. Summary of the invention

[0006] The present invention has been made to solve the above-mentioned problems, and an object of the present invention is to provide an information processing device, a control method, and a program that can improve the defense against attacks from third parties under secure boot.

[0007] In order to solve the above-mentioned problem, one method of the present invention is an information processing device, comprising: an authentication processing unit, which confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; a trust list storage unit, which stores a list of trusted sources of the above-mentioned startup program, namely a trust list; a chain information storage unit, which stores chain information of whether an illegal above-mentioned startup program that may be tampered with has been executed; a startup processing unit, which, during a secure boot process of executing the above-mentioned startup program whose legitimacy is confirmed by the above-mentioned authentication processing unit, changes the above-mentioned chain information stored in the above-mentioned chain information storage unit to information indicating that the above-mentioned illegal startup program has been executed when the above-mentioned startup program obtained from a source not included in the above-mentioned trust list stored in the above-mentioned trust list storage unit is executed; and a restriction processing unit, which restricts the use of a predetermined security-related protocol when the above-mentioned chain information stored in the above-mentioned chain information storage unit is information indicating that an illegal startup program has been executed.

[0008] In addition, one method of the present invention can also be configured as follows: in the above-mentioned information processing device, the above-mentioned trust list includes a firmware volume or a network boot, the above-mentioned firmware volume uses a BIOS memory storing the above-mentioned BIOS program as a providing source, and the above-mentioned network boot uses a pre-set server device as a providing source.

[0009] In addition, one method of the present invention can also be configured as follows: in the above-mentioned information processing device, there is a use restriction list storage unit, which stores a list of the above-mentioned protocols whose use is restricted, and the above-mentioned restriction processing unit restricts the use of the protocols included in the list of the above-mentioned protocols stored in the above-mentioned use restriction list storage unit when the above-mentioned chain information is information indicating that an illegal startup program has been executed.

[0010] In one aspect of the present invention, in the information processing device, the list of protocols for which the use is restricted may include a protocol related to network connection or a protocol related to a TPM (Trusted Platform Module).

[0011] In addition, one embodiment of the present invention is a control method, which is a control method for an information processing device, wherein the information processing device comprises: an authentication processing unit, which confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; a trust list storage unit, which stores a list of trustworthy sources of the startup program, i.e., a trust list; and a chain information storage unit, which stores chain information of whether an illegal startup program that may be tampered with has been executed, wherein the control method comprises: a startup processing step, wherein the startup processing unit, in executing a secure boot process of the startup program whose legitimacy is confirmed by the authentication processing unit, changes the chain information stored in the chain information storage unit to information indicating that the illegal startup program has been executed when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed; and a restriction processing step, wherein the restriction processing unit restricts the use of a predetermined security-related protocol when the chain information stored in the chain information storage unit is information indicating that an illegal startup program has been executed.

[0012] In addition, one aspect of the present invention is a program for causing a computer of an information processing device to execute a startup processing step and a restriction processing step, wherein the information processing device comprises: an authentication processing unit, which confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; a trust list storage unit, which stores a list of trustworthy sources of the startup program, i.e., a trust list; and a chain information storage unit, which stores chain information indicating whether an illegal startup program that may be tampered with has been executed, wherein in the startup processing step, in a secure boot process for executing the startup program whose legitimacy is confirmed by the authentication processing unit, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, the chain information stored in the chain information storage unit is changed to information indicating that the illegal startup program has been executed, and in the restriction processing step, when the chain information stored in the chain information storage unit is information indicating that the illegal startup program has been executed, use of a predetermined security-related protocol is restricted.

[0013] According to the above-described aspects of the present invention, it is possible to improve the defense against attacks from a third party under secure boot. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1This is a diagram showing an example of the main hardware configuration of the notebook PC according to the present embodiment.

[0015] Figure 2 This is a functional block diagram showing an example of the functional configuration of the information processing system and the notebook PC according to the present embodiment.

[0016] Figure 3 It is a diagram showing a data example of the trust list storage unit in this embodiment.

[0017] Figure 4 2 is a diagram showing a data example of the restriction list storage unit in the present embodiment.

[0018] Figure 5 This is a flowchart showing an example of the startup process of the notebook PC according to the present embodiment.

[0019] Figure 6 This is a flowchart showing an example of the protocol processing of the notebook PC according to the present embodiment.

[0020] Figure 7 This is a diagram for explaining an example of an attack by a third party in a notebook PC according to the related art.

[0021] Figure 8 This is the first diagram for explaining the effect of the notebook PC according to the present embodiment against attacks by a third party.

[0022] Fig. 9 This is a diagram for explaining another example of an attack by a third party in a notebook PC according to the related art.

[0023] Fig.10 The second diagram is a diagram for explaining the effect of the notebook PC according to the present embodiment against attacks by a third party.

[0024] Description of Reference Numerals

[0025] 1...notebook PC; 2...boot server; 10...main control unit; 11...CPU; 12...main memory; 13...video subsystem; 14...display unit; 21...chip set; 22...BIOS memory; 23...SSD; 24...audio system; 25...WLAN card; 26...USB connector; 31...embedded controller (EC); 32...input unit; 33...power circuit; 40...storage unit; 41...trust list storage unit; 42...restriction list storage unit; 43...chain flag storage unit; 100...information processing system; 110...BIOS processing unit; 111...authentication processing unit; 112...startup processing unit; 113...restriction processing unit; 120...OS processing unit; 250...NW communication unit; NW1...network. DETAILED DESCRIPTION

[0026] Hereinafter, an information processing device and a control method according to an embodiment of the present invention will be described with reference to the drawings.

[0027] Figure 1 1 is a diagram showing an example of a main hardware configuration of a notebook PC 1 according to the present embodiment. In the present embodiment, the notebook PC 1 is described as an example of an information processing device.

[0028] like Figure 1 As shown, the notebook PC 1 includes a CPU 11 , a main memory 12 , a video subsystem 13 , a display unit 14 , a chipset 21 , a BIOS memory 22 , an SSD 23 , an audio system 24 , a WLAN card 25 , a USB connector 26 , an embedded controller 31 , an input unit 32 and a power circuit 33 .

[0029] In the present embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. The main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).

[0030] The CPU (Central Processing Unit) 11 executes various calculation processes under program control and controls the entire notebook PC 1 .

[0031] The main memory 12 is a writable memory used as a read area for the execution program of the CPU 11 or as a work area for writing processing data of the execution program. The main memory 12 is composed of, for example, a plurality of DRAM (Dynamic Random Access Memory) chips. The execution program includes BIOS (Basic Input Output System), OS, various drivers for hardware operations of peripheral devices, various services / utilities, applications, etc.

[0032] The video subsystem 13 is a subsystem for realizing functions related to image display, and includes a video controller that processes rendering commands from the CPU 11, writes the processed rendering information into the video memory, and reads the rendering information from the video memory and outputs it to the display unit 14 as rendering data (display data).

[0033] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13 .

[0034] Chipset 21 has controllers such as USB (Universal Serial Bus), Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and connects multiple devices. Figure 1 In the embodiment, as examples of devices, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, and a USB connector 26 are connected to the chipset 21.

[0035] The BIOS memory 22 is composed of an electrically rewritable nonvolatile memory such as an EEPROM (Electrically Erasable Programmable Read Only Memory) or a flash ROM, and stores BIOS and system firmware for controlling the embedded controller 31 and the like.

[0036] The SSD (Solid State Drive) 23 (an example of a nonvolatile storage device) stores the OS, various drivers, various services / utilities, application programs, and various data.

[0037] The audio system 24 records, reproduces, and outputs audio data.

[0038] The WLAN (Wireless Local Area Network) card 25 is connected to a network via a wireless LAN to perform data communication.

[0039] The USB connector 26 is a connector for connecting peripheral devices using USB.

[0040] The embedded controller 31 (an example of a sub-controller) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. In addition, the embedded controller 31 has a power management function for controlling the power supply circuit 33. In addition, the embedded controller 31 is composed of a CPU, ROM, RAM, etc., which are not shown in the figure, and has a plurality of channel A / D input terminals, D / A output terminals, timers, and digital input and output terminals. The embedded controller 31 is connected to, for example, an input unit 32 and a power supply circuit 33 via these input and output terminals, and the embedded controller 31 controls these actions.

[0041] Next, refer to Figure 2 The functional structure of the notebook PC 1 according to the present embodiment will be described.

[0042] Figure 2 1 is a functional block diagram showing an example of the functional configuration of the information processing system 100 and the notebook PC 1 according to the present embodiment. Figure 2 In the present invention, only the functional configuration of the notebook PC 1 that is relevant to the present invention is described.

[0043] like Figure 2 As shown, the information processing system 100 includes a notebook PC 1 and a notification server 2. The notebook PC 1 and the notification server 2 are connectable to each other via a network NW1.

[0044] The boot server 2 is, for example, a server device that provides various services for the manufacturer of the notebook PC 1 and is a server device for network booting. The boot server 2 provides the notebook PC 1 with a startup program of an OS for network booting via the network NW1.

[0045] In addition, if Figure 2 As shown, the notebook PC 1 includes a main control unit 10 , a storage unit 40 , and a NW (Network) communication unit 250 .

[0046] The NW communication unit 250 is a functional unit implemented by a network device such as the WLAN card 25. The main control unit 10 can connect to the network NW1 via the NW communication unit 250. In this embodiment, the NW communication unit 250 is described as connecting to the network NW1 using a wireless LAN (WiFi (registered trademark)).

[0047] The storage unit 40 is implemented by a memory such as the BIOS memory 22 or the main memory 12, and stores various information used in various processes of the main control unit 10. The storage unit 40 includes a trust list storage unit 41, a restriction list storage unit 42, and a chain flag storage unit 43.

[0048] The trust list storage unit 41 is, for example, a storage unit implemented by the BIOS memory 22, and stores a list of trusted sources of boot programs, namely a trust list. Here, the so-called source is a device that is the execution source (boot source) of the boot program, such as Https boot, a USB device connected to the USB connector 26, a built-in SSD23, the firmware of the BIOS memory 22, etc. In addition, the so-called boot program is, for example, various UEFI programs executed when starting an OS (Windows (registered trademark) etc.). The trust list storage unit 41 stores a list of devices that are trusted as sources (boot sources).

[0049] Here, refer to Figure 3 , a data example of the trust list storage unit 41 is explained.

[0050] Figure 3 2 is a diagram showing a data example of the trust list storage unit 41 in the present embodiment.

[0051] exist Figure 3 In the example shown, the trust list stored in the trust list storage unit 41 includes “FirmwareVolume” (firmware volume), “Https Boot”, etc. as trusted UEFI Sources.

[0052] Here, “Firmware Volume” indicates that the firmware of the BIOS memory 22 is a supply source (boot source), and “Https Boot” indicates that, for example, network booting by the boot server 2 is a supply source (boot source).

[0053] Return to Figure 2As described above, the restriction list storage unit 42 (an example of a usage restriction list storage unit) is, for example, a storage unit implemented by the BIOS memory 22, and stores a list of protocols that are restricted in use. Here, the so-called protocol refers to a standard such as procedures, regulations, electrical rules of signals, and procedures for sending and receiving in communications that are prescribed for exchanging data in the notebook PC 1. When the boot program (UEFI program) is executed from a source (boot source) that does not exist in the above-mentioned trust list, the restriction list storage unit 42 stores a list of protocols that will be restricted in use (prohibited in use) as a usage restriction list in subsequent processing. The usage restriction list includes, for example, protocols related to network connection, protocols related to TPM (Trusted Platform Module), and other protocols that are likely to pose a security threat.

[0054] Here, refer to Figure 4 , a data example of the restriction list storage unit 42 is described.

[0055] Figure 4 2 is a diagram showing a data example of the restriction list storage unit 42 in the present embodiment.

[0056] exist Figure 4 In the illustrated example, the use restriction list stored in the restriction list storage unit 42 includes “WiFiInfoPassProtocol”, “WiFiConfigProtocol”, “BBBBBBBBBBProtocol”, “CCCCCCCCProtocol”, and the like as use restriction protocols.

[0057] Here, "WiFiInfoPassProtocol" is a protocol for handing over the SSID (Service Set Identifier) ​​and password of the wireless LAN, and "WiFiConfigProtocol" is a protocol for performing connection settings of the wireless LAN.

[0058] Return to Figure 2 As described above, the chain lock flag storage unit 43 (an example of the chain lock information storage unit) is a storage unit implemented by, for example, the system area of ​​the main memory 12, and stores a boot chain lock flag (chain lock information) indicating whether an illegal boot program that may be tampered with is executed. In the boot chain lock flag, for example, when the illegal boot program is not executed, information indicating a trusted state (for example, "0") is stored, and when the illegal boot program is executed, information indicating a distrusted state (for example, "1") is stored.

[0059] The main control unit 10 is a functional unit realized by causing the CPU 11 and the chipset 21 to execute programs stored in the BIOS memory 22 and the SSD 23 , and executes various processes based on the BIOS and the OS.

[0060] The main control unit 10 includes a BIOS processing unit 110 and an OS processing unit 120 .

[0061] The BIOS processing unit 110 executes various processes based on the BIOS (BIOS processes). The BIOS processing unit 110 includes an authentication processing unit 111 , a startup processing unit 112 , and a restriction processing unit 113 .

[0062] The authentication processing unit 111 verifies the legitimacy of the boot program (e.g., UEFI program) for booting the OS based on a predetermined security key in the BIOS process (BIOS process). The authentication processing unit 111 verifies the legitimacy of the boot program (e.g., UEFI program) by verifying the signature (signature) based on the security key (e.g., secure boot key). The authentication processing unit 111 performs authentication processing for secure booting described later.

[0063] The boot processing unit 112 executes various processes for booting up the notebook PC 1 (OS) in the BIOS process (BIOS process). The boot processing unit 112 executes a secure boot process for executing the boot program whose legitimacy has been verified by the authentication processing unit 111.

[0064] Furthermore, when a boot program obtained from a source not included in the trust list stored in the trust list storage unit 41 is executed during the secure boot process, the boot processing unit 112 changes the boot chain flag stored in the chain flag storage unit 43 to information indicating that an illegal boot program has been executed.

[0065] The boot processing unit 112 obtains the Device PathClass from the Device Path of the boot program (UEFI program), and confirms the source of the boot program (UEFI program) based on the Device Path Class. The boot processing unit 112 determines whether the confirmed source of supply is included in the trust list stored in the trust list storage unit 41. In the case where the confirmed source of supply is not included in the trust list stored in the trust list storage unit 41, the boot processing unit 112 changes the boot chain lock flag stored in the chain lock flag storage unit 43 from a trusted state (e.g., "0") to an untrusted state (e.g., "1").

[0066] When the boot chain lock flag stored in the chain lock flag storage unit 43 is information indicating that an illegal startup program has been executed (for example, untrusted state "1"), the restriction processing unit 113 restricts the use of the pre-set security-related protocols. When the boot chain lock flag is information indicating that an illegal startup program has been executed (for example, untrusted state "1"), the restriction processing unit 113 restricts the use of the protocols included in the list of protocols stored in the restriction list storage unit 42. The restriction processing unit 113 prohibits, for example, Figure 3 The usage restrictions list shown here covers the usage of the protocols.

[0067] The OS processing unit 120 is a functional unit that takes over the process after the OS startup process by the BIOS processing unit 110. The OS processing unit 120 executes various processes based on the OS.

[0068] Next, the operation of the notebook PC 1 according to the present embodiment will be described with reference to the drawings.

[0069] First, refer to Figure 5 , the startup process of the notebook PC 1 according to the present embodiment will be described.

[0070] Figure 5 This is a flowchart showing an example of the startup process of the notebook PC 1 according to the present embodiment.

[0071] like Figure 5 As shown, when the BIOS processing unit 110 of the notebook PC 1 starts booting the notebook PC 1, it starts POST (Power On Self Test) processing and sets the trust state "0" to the boot chain flag (step S101). The BIOS processing unit 110 sets the trust state "0" to the boot chain flag of the chain flag storage unit 43.

[0072] Next, the boot processing unit 112 of the BIOS processing unit 110 determines whether the boot source (supply source) is included in the trust list (step S102). The boot processing unit 112 confirms the supply source of the boot program (boot program) through the Device Path Class, and determines whether the confirmed supply source is included in the trust list stored in the trust list storage unit 41. When the boot source (supply source) is included in the trust list (step S102: Yes), the boot processing unit 112 advances the processing to step S104. In addition, when the boot source (supply source) is not included in the trust list (step S102: No), the boot processing unit 112 determines that an illegal boot program has been executed, and advances the processing to step S103.

[0073] In step S103, the boot processing unit 112 sets the untrusted state "1" to the boot chain flag. That is, the boot processing unit 112 stores the untrusted state "1" in the boot chain flag of the chain flag storage unit 43. After the processing of step S103, the processing proceeds to step S104.

[0074] In step S104, the boot processing unit 112 executes the boot program by secure booting. The boot processing unit 112 verifies the legitimacy of the boot program using the authentication processing unit 111, and executes the processing of the boot program whose legitimacy has been verified.

[0075] Next, the startup processing unit 112 determines whether the boot process is completed (step S105). That is, the startup processing unit 112 determines whether there is a boot program to be executed next. When the boot process is completed (there is no boot program to be executed next) (step S105: Yes), the startup processing unit 112 takes over the processing from the OS processing unit 120. On the other hand, when the boot process is not completed (there is a boot program to be executed next) (step S105: No), the startup processing unit 112 returns the processing to step S102 and executes the processing for the boot program to be executed next.

[0076] Next, refer to Figure 6 , the protocol restriction processing of the notebook PC 1 is described.

[0077] Figure 6 1 is a flowchart showing an example of the protocol processing of the notebook PC of this embodiment. In addition, the protocol processing here is, for example, the protocol processing such as InstallProtocol, LocaleProtocol and HandleProtocol of the UEFI standard.

[0078] like Figure 6 As shown, the restriction processing unit 113 of the BIOS processing unit 110 determines whether the boot chain lock flag is in the untrusted state "1" (step S201). The restriction processing unit 113 determines whether the boot chain lock flag of the chain lock flag storage unit 43 is in the untrusted state "1". When the boot chain lock flag is in the untrusted state "1" (step S201: Yes), the restriction processing unit 113 causes the processing to proceed to step S203. In addition, when the boot chain lock flag is not in the untrusted state "1" (is in the trusted state "0") (step S201: No), the restriction processing unit 113 causes the processing to proceed to step S202.

[0079] In step S202, the BIOS processing unit 110 executes a protocol process. For example, the BIOS processing unit 110 executes protocol processes such as InstallProtocol, LocaleProtocol, and HandleProtocol. After the process of step S202, the BIOS processing unit 110 advances the process to the next process.

[0080] In addition, in step S203, the restriction processing unit 113 determines whether the protocol is included in the use restriction list. The restriction processing unit 113 checks the use restriction list stored in the restriction list storage unit 42 and determines whether the process is included in the use restriction list. If the process is included in the use restriction list (step S203: Yes), the restriction processing unit 113 advances the processing to step S204. If the process is not included in the use restriction list (step S203: No), the restriction processing unit 113 returns the processing to step S202.

[0081] In step S204, the restriction processing unit 113 replies (returns) an error result and does not execute the protocol process. After the process of step S204, the restriction processing unit 113 advances the process to the next process.

[0082] Next, refer to Figure 7 to Figure 10 , an attack example and the effect of the notebook PC 1 of this embodiment are described.

[0083] Figure 7 This is a diagram for explaining an example of an attack by a third party in a notebook PC according to the related art.

[0084] exist Figure 7 The attack example shown shows an example of a situation in which an intruder AT1, who is a malicious third party, installs malware before executing the Wifi Configuration App, tampers with the protocol, and steals the connection information.

[0085] The intruder AT1 uses a USB to execute the boot program ATP1 loaded with malware called "Attack.efi" and tamper with "WiFiConfigProtocol".

[0086] exist Figure 7 In the conventional notebook PC shown, if a boot program BP1 called "WifiConfigurationApp.efi" is subsequently executed by the BIOS, the intruder AT1 can steal the wireless LAN connection information through the tampered "WiFiConfigProtocol".

[0087] In contrast, Figure 81 is a first diagram for explaining the effect of the notebook PC 1 of the present embodiment on the attack of a third party. Here, the intruder AT1 performs the above-mentioned attack on the notebook PC 1 of the present embodiment. Figure 7 The same attack scenario is described below.

[0088] like Figure 8 As shown, in the notebook PC 1 of this embodiment, when the boot program ATP1 such as "Attack.efi" is executed from the USB, for example, Figure 3 As shown, the USB is not in the trusted list as a trusted supply source, so the boot processing unit 112 changes the boot chain flag to the untrusted state "1".

[0089] Next, if the boot program BP1 such as "WifiConfigurationApp.efi" is executed through BIOS, then "WiFiConfigProtocol" is, for example, Figure 4 As shown in the figure, the restriction processing unit 113 prohibits the use of "WiFiConfigProtocol". Therefore, in the notebook PC 1 of the present embodiment, the intruder AT1 cannot steal the connection information of the wireless LAN.

[0090] in addition, Fig. 9 This is a diagram for explaining another example of an attack by a third party in a notebook PC according to the related art.

[0091] exist Fig. 9 The attack example shown shows an example of a situation where an intruder AT1, who is a malicious third party, executes a boot program ATP2, which is an old version of "EFIApp (Ver1)" in which a bug that leaks a password is found, and steals the password using "WiFiInfoPassProtocol".

[0092] The intruder AT1 uses a USB to execute an old version of the boot program ATP2 called "EFIApp (Ver1)" and can steal the password of the wireless LAN by executing "WiFiInfoPassProtocol".

[0093] In contrast, Fig.10 1 is a second diagram illustrating the effect of the notebook PC 1 of the present embodiment on the attack by a third party. Fig. 9 The same attack scenario is described below.

[0094] like Fig.10As shown, in the notebook PC 1 of this embodiment, when the boot program ATP2 such as "EFIApp (Ver1)" is executed from the USB, for example, Figure 3 As shown, the USB is not in the trusted list as a trusted supply source, so the boot processing unit 112 changes the boot chain flag to the untrusted state "1".

[0095] Next, "WiFiInfoPassProtocol" is for example Figure 4 As shown in the figure, the restriction processing unit 113 prohibits the use of "WiFiInfoPassProtocol". Therefore, in the notebook PC 1 of this embodiment, the intruder AT1 cannot steal the password of the wireless LAN.

[0096] As described above, the notebook PC 1 (information processing device) of this embodiment includes an authentication processing unit 111, a trust list storage unit 41, a chain lock flag storage unit 43 (chain lock information storage unit), a startup processing unit 112, and a restriction processing unit 113. The authentication processing unit 111 verifies the legitimacy of the boot program (boot program) for booting the OS based on a predetermined security key during the BIOS process. The trust list storage unit 41 stores a trust list, which is a list of trustworthy boot program supply sources. The chain lock flag storage unit 43 stores chain lock information (for example, a boot chain lock flag) indicating whether an illegal boot program that may be tampered with is executed. When the startup processing unit 112 executes the secure boot process of the boot program whose legitimacy is verified by the authentication processing unit 111, if a boot program obtained from a supply source not included in the trust list stored in the trust list storage unit 41 is executed, the boot chain lock flag stored in the chain lock flag storage unit 43 is changed to information indicating that an illegal boot program is executed (untrusted state "1"). When the boot chain flag stored in the chain flag storage unit 43 is information indicating that an illegal boot program has been executed, the restriction processing unit 113 restricts the use of a preset security-related protocol.

[0097] Thus, the notebook PC 1 (information processing device) of this embodiment can reduce the possibility of tampering or monitoring of the program executed thereafter (see the above-mentioned Figure 8 as well as Fig.10 ). Therefore, the notebook PC 1 of this embodiment can improve the defense against attacks from third parties under secure boot.

[0098] In the present embodiment, the trust list includes a firmware volume (“Firmware Volume”) using the BIOS memory 22 storing the BIOS program as a providing source, or a network boot (“Https Boot”) using a preset server device as a providing source.

[0099] Thus, the notebook PC 1 of this embodiment lists the firmware volume ("Firmware Volume") or network boot ("Https Boot") that can be securely booted, and through execution other than this (for example, booting from a USB, etc.), it is determined to be a state in which an illegal boot program is executed (untrusted state "1"), so that the execution of an illegal boot program that may have been tampered with can be easily detected.

[0100] In addition, the notebook PC 1 of this embodiment has a restriction list storage unit 42 (usage restriction list storage unit) storing a list of protocols that are restricted in use. When the boot chain lock flag is information indicating that an illegal boot program has been executed (untrusted state "1"), the restriction processing unit 113 restricts the use of the protocols included in the list of protocols stored in the restriction list storage unit 42.

[0101] Thus, the notebook PC 1 of this embodiment can appropriately restrict protocols that may threaten security by a simple method such as a list of restricted protocols (usage restriction list). Therefore, the notebook PC 1 of this embodiment can further improve the defense against attacks from third parties in secure boot.

[0102] In addition, in the present embodiment, the list of protocols to be restricted in use includes protocols related to network connection (for example, "WiFiConfigProtocol" or the like) or protocols related to TPM.

[0103] Thus, the notebook PC 1 of this embodiment can appropriately restrict protocols that are likely to threaten security. Therefore, the notebook PC 1 of this embodiment can further improve the defense against attacks from third parties in a secure boot.

[0104] In addition, the control method of the present embodiment is a control method of a notebook PC 1 having the above-mentioned authentication processing unit 111 and the chain lock flag storage unit 43, and includes a startup processing step and a restriction processing step. The authentication processing unit 111 confirms the legitimacy of the boot program for booting the OS based on a predetermined security key in the BIOS processing. The trust list storage unit 41 stores a list of trustworthy boot program supply sources, that is, a trust list. The chain lock flag storage unit 43 stores a boot chain lock flag indicating whether an illegal boot program that may be tampered with is executed. In the startup processing step, the startup processing unit 112 changes the boot chain lock flag stored in the chain lock flag storage unit 43 to information indicating that an illegal boot program is executed in the case where a boot program obtained from a supply source not included in the trust list stored in the trust list storage unit 41 is executed in the secure boot process. In the restriction processing step, when the boot chain lock flag stored in the chain lock flag storage unit 43 is information indicating that an illegal boot program is executed, the restriction processing unit 113 restricts the use of a pre-set security-related protocol.

[0105] Therefore, the control method of this embodiment has the same effect as that of the above-mentioned notebook PC 1, and can improve the defense against attacks from third parties under secure boot.

[0106] In addition, the present invention is not limited to the above-mentioned embodiment, and can be modified within the scope not departing from the gist of the present invention.

[0107] For example, in the above-described embodiment, an example in which the information processing device is the notebook PC 1 is described, but the present invention is not limited thereto, and other information processing devices such as a tablet terminal device and a desktop PC may be used.

[0108] In addition, in the above-mentioned embodiment, the source of the trust list is not limited to Figure 3 The example shown is one that may also include other device sources.

[0109] In addition, in the above-mentioned embodiment, the protocol for using the restriction list is not limited to Figure 4 This is just one example; other protocols may also be included.

[0110] In addition, each structure of the notebook PC 1 has a computer system inside. In addition, a program for realizing the functions of each structure of the notebook PC 1 can be recorded in a computer-readable recording medium, and the processing in each structure of the notebook PC 1 can be performed by making the computer system read the program recorded in the recording medium and execute it. Here, the so-called "making the computer system read the program recorded in the recording medium and execute it" includes installing a program in the computer system. The so-called "computer system" here includes hardware such as OS and peripheral devices.

[0111] In addition, the "computer system" may also include a plurality of computer devices connected via a network including a communication line such as the Internet, WAN, LAN, or a dedicated line. In addition, the so-called "computer-readable recording medium" refers to a portable medium such as a floppy disk, a magneto-optical disk, a ROM, a CD-ROM, or a recording device such as a hard disk built into the computer system. In this way, the recording medium storing the program may be a non-temporary recording medium such as a CD-ROM.

[0112] In addition, the recording medium also includes an internal or external recording medium that can be accessed from a distribution server in order to distribute the program. In addition, the program can also be divided into multiple parts, and the structure formed by combining the various structures possessed by the notebook PC1 after being downloaded at different times, and the distribution server for distributing each of the divided programs is different. Moreover, the so-called "computer-readable recording medium" also includes a structure that keeps the program for a certain period of time, such as a server in the case of sending a program via a network, and a volatile memory (RAM) inside a computer system that becomes a client. In addition, the above-mentioned program can also be a structure for realizing a part of the above-mentioned functions. Furthermore, it can also be a so-called differential file (differential program) that can realize the above-mentioned functions by combining them with the programs already recorded in the computer system.

[0113] In addition, part or all of the above functions may be implemented as an integrated circuit such as LSI (Large Scale Integration). Each of the above functions may be processed independently, or part or all of them may be integrated for processing. In addition, the method of integrated circuitization is not limited to LSI, and may also be implemented with a dedicated circuit or a general-purpose processor. In addition, when an integrated circuit technology that replaces LSI emerges with the advancement of semiconductor technology, an integrated circuit based on the technology may also be used.

Claims

1. An information processing device comprising: An authentication processing unit that confirms the legitimacy of a boot program for booting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; A trust list storage unit storing a trust list which is a list of trustworthy sources of providing the startup program; A chain information storage unit for storing chain information indicating whether the illegal boot program that may be tampered with has been executed; a boot processing unit that, in executing the secure boot processing of the boot program whose legitimacy is confirmed by the authentication processing unit, changes the chain information stored by the chain information storage unit to information indicating that the illegal boot program is executed, when the boot program obtained from a providing source not included in the trust list stored by the trust list storage unit is executed; as well as The restriction processing unit restricts use of a preset security-related protocol when the linkage information stored in the linkage information storage unit is information indicating that an illegal boot program has been executed.

2. The information processing device according to claim 1, wherein: The trust list includes a firmware volume or a network boot, wherein the firmware volume uses a BIOS memory storing the BIOS program as a supply source, and the network boot uses a preset server device as a supply source.

3. The information processing device according to claim 1 or 2, wherein: A usage restriction list storage unit is provided, wherein the usage restriction list storage unit stores a list of the protocols whose usage is restricted, The restriction processing unit restricts the use of the protocols included in the list of protocols stored in the use restriction list storage unit when the link information is information indicating that an illegal boot program has been executed.

4. The information processing device according to claim 3, wherein: The list of the protocols for which the use is restricted includes protocols related to network connection or protocols related to TPM (Trusted Platform Module).

5. A control method is a control method of an information processing device, the information processing device comprising: an authentication processing unit, which confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; a trust list storage unit, which stores a list of trustworthy sources of the startup program, i.e., a trust list; and a chain information storage unit, storing chain information indicating whether the illegal boot program that may be tampered with is executed, wherein: The control method comprises: A startup processing step, in which the startup processing unit, when executing the secure boot processing of the startup program whose legitimacy is confirmed by the authentication processing unit, changes the chain information stored in the chain information storage unit to information indicating that the illegal startup program is executed, if the startup program obtained from a providing source not included in the trust list stored by the trust list storage unit is executed; and In the restriction processing step, the restriction processing unit restricts the use of a preset security-related protocol when the linkage information stored in the linkage information storage unit is information indicating that an illegal boot program has been executed.

6. A program for causing a computer of an information processing device to execute a startup processing step and a restriction processing step, the information processing device comprising: an authentication processing unit, which confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key during BIOS (Basic Input Output System) processing; a trust list storage unit, which stores a list of trustworthy sources of the startup program, i.e., a trust list; and a chain information storage unit, which stores chain information indicating whether an illegal startup program that may have been tampered with has been executed, wherein: In the startup processing step, in the secure boot processing of the startup program whose legitimacy is confirmed by the authentication processing unit, in the case where the startup program obtained from a source not included in the trust list stored by the trust list storage unit is executed, the chain information stored in the chain information storage unit is changed to information indicating that the illegal startup program is executed, In the restriction processing step, when the linkage information stored in the linkage information storage unit is information indicating that an illegal boot program has been executed, use of a preset security-related protocol is restricted.

Citation Information

Patent Citations

  • Authentication method, authentication program, and information processor

    JP2017146694A