Method for setting root file system of computer and computer program product

By loading and verifying the compressed file signature on the external storage device in the RAM work area of ​​the computer and expanding the compressed file when the verification is successful, the problem of not being able to ensure the overall authenticity of the root file system in the prior art is solved, and effective verification of the root file system and ensuring its authenticity is achieved.

CN120215815APending Publication Date: 2025-06-27SEIKO EPSON CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411916254.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-12-24
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When verifying the authenticity of the computer root file system, the prior art has the problem that the overall authenticity of the root file system cannot be guaranteed, because the file used for the system startup has been started before the signature verification of the compressed file.

Method used

By reading the compressed file and electronic signature of the compressed root file system partition from the external storage device, and loading and verifying the signature in the RAM work area of ​​the computer, when the verification is successful, the compressed file is expanded into the external storage device to set the root file system.

Benefits of technology

Ensures the overall authenticity of the root file system and shortens the verification time. When verification fails, it can be started using the real root file system stored in the ROM.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120215815A_ABST
    Figure CN120215815A_ABST
Patent Text Reader

Abstract

The invention discloses a method for setting a root file system of a computer and a computer program product, which can ensure the whole real property of the root file system. The method comprises the following steps: (a) reading a compressed file obtained by compressing the whole partition of a root file system and an electronic signature of the compressed file from an external storage device, and loading the compressed file and the electronic signature to a working area of an RAM of a computer; (b) verifying the electronic signature of the compressed file loaded in the working area; and (c) if the verification is successful, setting the root file system by expanding the compressed file in the external storage device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a method for setting a root file system of a computer and a computer program. Background Art

[0002] A root file system is a file system that stores a root directory and is a file system at the apex of all other file systems mounted at system startup. The root file system includes a plurality of startup files used when the computer starts up. The root file system is written to the ROM of the computer, but for partial version upgrades, it is sometimes desired to update it to a new root file system using an external storage device such as an SD card.

[0003] In recent years, in order to improve security, it has been required to verify that the firmware has not been tampered with. In order to perform a secure startup of a computer, it is necessary to verify the authenticity of the files included in the root file system. However, since the root file system on the SD card includes a plurality of files, if the signatures of these files are verified one by one, it will take time.

[0004] In Patent Document 1, a method for verifying the authenticity of a plurality of files is disclosed. In this method, the system startup memory in the information processing device is divided into a partition 1 that stores files to be verified and a partition 2 that stores files other than those to be verified. Then, a plurality of files are compressed to create a compressed file, and its authentication data is generated, and both are stored in partition 1. When using the compressed file, the compressed data is verified for signature using the authentication data, and if the authentication is successful, the plurality of files are expanded to partition 2.

[0005] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2021-177593

[0006] However, in the above prior art, before the signature verification of the compressed file, the system startup files existing in the root file system have already been started, so there is a problem that the authenticity of the entire root file system cannot be guaranteed. Therefore, a technique capable of guaranteeing the authenticity of the entire root file system is desired. Summary of the Invention

[0007] According to a first aspect of the present disclosure, there is provided a method for setting a root file system of a computer. The method includes the following steps: (a) reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device and loading them into a working area of the RAM of the computer; (b) verifying the electronic signature of the compressed file loaded into the working area; and (c) in the case where the verification is successful, setting the root file system by expanding the compressed file in the external storage device.

[0008] According to a second aspect of the present disclosure, there is provided a computer program for performing a process of setting a root file system of a computer. The computer program causes the computer to perform the following processes: (a) a process of reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device and loading them into a working area of the RAM of the computer; (b) a process of verifying the electronic signature of the compressed file loaded into the working area; and (c) a process of setting the root file system by expanding the compressed file in the external storage device in the case where the verification is successful. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 is a block diagram of a robot system in an embodiment.

[0010] Figure 2 is an explanatory diagram of a startup process of a controller in the first embodiment.

[0011] Figure 3 is a flowchart showing the steps of the startup process of the controller in the first embodiment.

[0012] Figure 4 is a flowchart showing the steps of the startup process of the controller in the first embodiment.

[0013] Figure 5 is an explanatory diagram of a startup process of a controller in the second embodiment.

[0014] Figure 6 is a flowchart showing the steps of the startup process of the controller in the second embodiment.

[0015] Figure 7 is an explanatory diagram of a startup process of a controller in the third embodiment.

[0016] Figure 8 is a flowchart showing the steps of the startup process of the controller in the third embodiment.

[0017] Figure 9 is an explanatory diagram of a startup process of a controller in the fourth embodiment.

[0018] Figure 10 is a flowchart showing the steps of the startup process of the controller in the fourth embodiment.

[0019] DESCRIPTION OF REFERENCE NUMERALS

[0020] 100: Controller; 110: CPU; 120: ROM; 121: First boot loader area; 122: Second boot loader area; 123: First ROM area; 124: Second ROM area; 130: RAM; 131: Kernel area; 132: Working area; 133: RAM disk; 140: External memory card; 200: Information processing device; 300: Robot body; 400: Robot system. Detailed implementation

[0021] A. First implementation

[0022] Figure 1 It is a block diagram showing the structure of the robot system 400 in one implementation. The robot system 400 includes a controller 100, an information processing device 200, and a robot body 300. The controller 100 is a computer called a "robot controller". The controller 100 and the information processing device 200 function as a control system for controlling the robot body 300. For example, the controller 100 functions as a lower-level control device, and the information processing device 200 functions as a higher-level control device. Alternatively, the information processing device 200 may be omitted, and the robot body 300 may be controlled only by the controller 100. As the information processing device 200, for example, a personal computer can be used.

[0023] The controller 100 has a CPU 110 as a processor, a RAM 120, a ROM 130, and an external memory card 140. The ROM 130 is constituted by a flash ROM, for example. The external memory card 140 is an SD card, for example, and is inserted into the memory card slot of the controller 100. The memory card slot may also be connected to the controller 100 via a USB interface. A compressed file CFa including the entire root file system is stored in the external memory card 140.

[0024] The present disclosure is not limited to the controller 100 for robots, and can also be applied to other types of computers. In addition, as the external storage device for storing the compressed file CFa, other types of external storage devices other than the SD card can also be used.

[0025] Figure 2 It is an explanatory diagram of the startup process of the controller 100 in the first implementation. Figure 3 and Figure 4 is a flowchart showing the order of the startup process. In Figure 2 are marked with Figure 3 and Figure 4 Part of the step numbers. Hereinafter, the processing related to the setting of the root file system will be described with reference to Figures 2 to 4 The description of other processes such as the initialization of the hardware is omitted.

[0026] The ROM 120 has a first boot loader area 121, a second boot loader area 122, a first ROM area 123, and a second ROM area 124. A main boot loader is stored in the first boot loader area 121. An IPL (Initial Program Loader) as a slave loader is stored in the second boot loader area 122. For example, U-boot is used as the IPL. Multiple programs including an expansion program DPM for file expansion and electronic signature authentication are stored in the first ROM area 123. A boot file SF1 and a root file system used when starting the controller 100 are stored in the second ROM area 124. The boot file SF1 includes an OS kernel.

[0027] In the following description, the first ROM area 123 is referred to as the "ROM area 1", and the second ROM area 124 is referred to as the "ROM area 2". In this embodiment, Linux (registered trademark) is used as the OS (Operating System). However, the content of the present disclosure can also be applied to other OSs other than Linux (registered trademark).

[0028] The RAM 130 has a kernel area 131 and a working area 132. In the first embodiment, a part of the area of the RAM 130 is used as a RAM disk 133.

[0029] A compressed file CFa including the entire root file system is stored in the external memory card 140. The compressed file CFa is stored in a normal file system that is not the root file system. This normal file system is, for example, FAT32. In this embodiment, since the compressed file CFa is compressed in zip format, it is named FAT32.zip in Figure 2 . An electronic signature DSa is added to the compressed file CFa. The compressed file CFa includes: a compressed file CFb obtained by compressing the entire partition of the root file system; and a boot file SF2 for starting the system with the external memory card 140 as the root file system.

[0030] The compressed file CFb obtained by compressing the entire partition of the root file system is a file in the squashfs format, which is a compressed file format for Linux (registered trademark), and is named rootfs.squashfs in Figure 2 . The entire partition of the root file system has a structure compliant with EXT4, which is a file system commonly used for Linux (registered trademark).

[0031] The compressed file CFa is created by further compressing the compressed file CFb, which is obtained by compressing the entire partition of the root file system, in another compressed file format. In the following description, the compressed file CFa is also referred to as the "upper-level compressed file CFa", and the compressed file CFb is also referred to as the "lower-level compressed file CFb". The reason for performing two-stage compression is that in addition to the lower-level compressed file CFb, it also includes generating the upper-level compressed file CFa by compressing the startup file SF2 and other data used to start the system with the external memory card 140 as the root file system, and adding an electronic signature to the upper-level compressed file CFa, so that they can be verified as a whole. However, instead of performing such two-stage compression, it is also possible to use a compressed file obtained by compressing the entire partition of the root file system in one stage to execute the startup process of the present disclosure.

[0032] When the signature verification of the upper-level compressed file CFa is successful in the steps described later, the root directory is set in the external memory card 140, and the root file system is expanded from the lower-level compressed file CFb. The root file system includes various programs and data as follows.

[0033] (1) Instructions.

[0034] (2) Application programs.

[0035] (3) Setting data.

[0036] These programs and data are stored in the respective directories set below the root directory. The lower-level compressed file CFb is created by compressing the image file of the root file system expanded in the form of writing to the external memory card 140. The "image file" is data that stores the data recorded in the storage device while maintaining the file or folder structure.

[0037] Figure 3 The processing of starts when the power of the controller 100 is turned on. In step S01, the main boot loader verifies the electronic signature DS1 of the IPL. In this verification, the public key PK1 stored in the first boot loader area 121 in advance is used.

[0038] In step S02, the main boot loader determines whether the verification of the IPL is successful. If the verification of the IPL fails, the system is stopped and the processing of ends. Figure 3 On the other hand, if the verification of the IPL is successful, the process proceeds to step S03, and the IPL loads the upper-level compressed file CFa in the external memory card 140 into the working area 132 of the RAM130.

[0039] In step S04, the IPL verifies the electronic signature DS2 of ROM area 1. This verification is preferably set as the verification of the entire ROM area 1, but can also be set as the verification of the expansion program DPM stored in ROM area 1. In this verification, the public key PK2 pre-stored in the second boot loader area 122 is used.

[0040] In step S05, the IPL determines whether the verification of ROM area 1 is successful. If the verification of ROM area 1 fails, the system is stopped and the Figure 3 processing ends. On the other hand, if the verification of ROM area 1 is successful, the process proceeds to step S06, and the IPL starts the program in ROM area 1. The started program includes at least the expansion program DPM.

[0041] In step S07, the expansion program DPM of ROM area 1 verifies the electronic signature DS3 of ROM area 2. This verification is preferably set as the verification of the entire ROM area 2, but can also be set as the verification of the startup file SF1 and the root file system stored in ROM area 2. In this verification, the public key PK3 pre-stored in ROM area 1 is used.

[0042] In step S08, the expansion program DPM determines whether the verification of ROM area 2 is successful. If the verification of ROM area 2 fails, the system is stopped and the Figure 3 processing ends. On the other hand, if the verification of ROM area 2 is successful, the process proceeds to step S09, and the expansion program DPM expands the startup file SF1 for ROM startup from ROM area 2 to RAM130. This startup file SF1 includes the OS kernel. The OS kernel is expanded in the kernel area 131 of RAM130. This startup file SF1 is referred to as the "first startup file SF1". If the first startup file SF1 is expanded at this time, in the case where the verification of the upper compressed file CFa fails in the subsequent steps, the genuine first startup file SF1 pre-stored in ROM130 can be used to start the OS kernel.

[0043] In Figure 4 step S10, the expansion program DPM of ROM area 1 verifies the electronic signature DSa of the upper compressed file CFa loaded into the working area 132 of RAM130 in step S303. In this verification, the public key PK3 stored in ROM area 1 is used. In Figure 2In the example, the public key PK3 is the same as the public key used for the verification of the ROM area 2, but they can also be set as different public keys. When the verification in step S10 is successful, the authenticity of the lower compressed file CFb included in the upper compressed file CFa, that is, the compressed file CFb obtained by compressing the partitions of the entire root file system, is guaranteed.

[0044] In step S11, the expansion program DPM determines whether the verification of the upper compressed file CFa is successful. When the verification of the upper compressed file CFa fails, it proceeds to step S18, designates ROM120 as the root file system, and starts the OS kernel expanded in the kernel area 131 in step S09. After the OS kernel starts, it starts the application program for the update mode included in the root file system. The "update mode" refers to a processing mode in which the upper compressed file CFa stored in the external memory card 140 is overwritten with another upper compressed file considered to be authentic. The other upper compressed file with an electronic signature is transmitted from an external device such as the information processing device 200. After step S18, in the update mode, it is preferable to perform the rewriting of the upper compressed file CFa stored in the external memory card 140.

[0045] When the verification of the upper compressed file CFa is successful, it proceeds to step S12, the expansion program DPM reads the upper compressed file CFa from the external memory card 140, and expands the startup file SF2 included in the upper compressed file CFa to the RAM130. This startup file SF2 is a file for starting the system with the external memory card 140 as the root file system. This startup file SF2 is called the "second startup file SF2". The second startup file SF2 includes the OS kernel and is overwritten by the first startup file SF1 expanded to the RAM130 in the above step S09. If the second startup file SF2 is overwritten on the first startup file SF1, the OS kernel can be started using the authentic second startup file SF2 included in the upper compressed file CFa with a successful electronic signature verification.

[0046] The first startup file SF1 and the second startup file SF2 can also be files with different functions. For example, the first startup file SF1 may have the function of the update mode and not have the function of a robot controller. On the other hand, the second startup file SF2 preferably has the function of a robot controller. In addition, it is preferable that the data volume of the first startup file SF1 is smaller than that of the second startup file SF2.

[0047] In step S13, the expansion program DPM designates ROM120 as the root file system to start the OS kernel. At this time, it is preferable to use the init= / root instruction to set the device tree for ROM startup. At this moment, since the root file system is designated as ROM120, the external memory card 140 is not used as the root file system.

[0048] In step S14, the OS kernel creates a RAM disk 133 and mounts the partition of the root file system of the external memory card 140 as a normal file system. The reason for mounting the partition of the root file system as a normal file system is that in the above step S13, ROM120 is designated as the root file system.

[0049] In step S15, the OS kernel expands the upper compressed file CFa of the external memory card 140 and stores the lower compressed file CFb in the RAM disk 133. In step S16, the OS kernel expands the lower compressed file CFb stored in the RAM disk 133 to the external memory card 140. As a result, as Figure 2 shown, the root file system is set in the external memory card 140. In step S17, the OS kernel switches the root file system from ROM120 to the external memory card 140. Specifically, the pivot_root instruction is used to switch the root file system.

[0050] When setting the root file system in step S17, the application program for the robot control mode is started. The "robot control mode" refers to the mode in which the controller 100 functions as a robot controller. The description of the subsequent processing is omitted.

[0051] As described above, in the first embodiment, when the verification of the electronic signature for the compressed file CFa in the working area 132 loaded in the RAM130 is successful, the compressed file CFa is expanded into the external memory card 140 to set the root file system, so the authenticity of the entire root file system can be ensured. In addition, in the first embodiment, different from the prior art of verifying each file, the compressed file CFa including the root file system is verified together, so the time required for verification can be shortened compared with the prior art. Furthermore, in the first embodiment, since ROM120 is set as the root file system when the verification of the compressed file CFa fails, in the case where the verification of the compressed file CFa fails, the controller can be started using the genuine root file system stored in ROM120.

[0052] B. Second Embodiment

[0053] Figure 5 It is an explanatory diagram of the startup process of the controller 100 in the second embodiment, Figure 6It is a flowchart showing the steps of its startup process. Figure 5 It is for the first embodiment Figure 2 after making partial changes to Figure 6 It is for the first embodiment Figure 4 after making partial changes to Figure 3 The processing of is the same as that of the first embodiment, so the description is omitted.

[0054] The second embodiment is different from the first embodiment in the following two points, and is otherwise substantially the same as the first embodiment.

[0055] (1) The RAM disk 133 is not used.

[0056] (2) Figure 4 Steps S14 - S16 of Figure 6 are replaced with

[0057] In Figure 6 step S21 of Figure 5 the OS kernel installs the partition of the root file system of the external memory card 140 as a normal file system. In step S22, the OS kernel starts from the upper compressed file CFa of the external memory card 140 and expands the lower compressed file CFb, rootfs.squashfs, into the folder installed in step S21. As a result, as

[0058] shown, the root file system is set in the external memory card 140. The description of other processing is omitted.

[0059] C. Third Embodiment

[0060] Figure 7 It is an explanatory diagram of the startup process of the controller 100 in the third embodiment Figure 8 It is a flowchart showing the steps of the startup process of the controller 100 in the third embodiment. Figure 7 It is for the second embodiment Figure 5 after making partial changes to Figure 8 It is for the second embodiment Figure 6 after making partial changes to Figure 3 The processing of is the same as that of the first embodiment and the second embodiment, so the description is omitted.

[0061] The third embodiment is different from the second embodiment only in the following point, and is otherwise substantially the same as the second embodiment.

[0062] (1) Figure 6 Step S22 of Figure 8 is replaced by steps S31 - S32 of

[0063] In Figure 8 step S31 of Figure 7 , the OS kernel expands the upper - level compressed file CFa of the external memory card 140 and stores the lower - level compressed file CFb in the folder installed in step S21. In this process, the lower - level compressed file CFb is written to the external memory card 140. In step S32, the OS kernel expands the lower - level compressed file CFb into the folder installed in step S21. Additionally, in step S32, a process of moving the root directory storing the lower - level compressed file CFb using the pivot_root instruction and setting a new root directory for the root file system is executed. As a result, as Figure 7 shown, a root file system is set in the external memory card 140. The description of other processes is omitted.

[0064] The third embodiment also has substantially the same effects as the first and second embodiments. However, in the first and second embodiments, there is no process such as step S31 of writing the lower - level compressed file CFb to the external memory card 140. Therefore, it is sufficient that the number of writes to the external memory card 140 is small. Thus, it has the advantage of not shortening the life of the external memory card 140.

[0065] D. Fourth Embodiment

[0066] Figure 9 is an explanatory diagram of the startup process of the controller 100 in the fourth embodiment, Figure 10 and is a flowchart showing the steps of its startup process. Figure 9 is a diagram obtained by partially modifying Figure 5 of the second embodiment, Figure 8 is a diagram obtained by partially modifying Figure 6 of the second embodiment. Figure 3 The process of

[0067] is the same as that of the first and second embodiments, so the description is omitted.

[0068] (1) Figure 6 Step S22 of Figure 10 is replaced by steps S41 - S42 of

[0069] In Figure 10 step S41 of Figure 10 , the OS kernel expands the upper - level compressed file CFa of the external memory card 140 and stores the lower - level compressed file CFb in the file system of the external memory card 140. As a result, asFigure 9 As shown, the lower compressed file CFb is stored in the same file system as the upper compressed file CFa. In step S42, the OS kernel expands the lower compressed file CFb into the folder installed in step S21. Additionally, in step S42, a process of moving the root directory storing the lower compressed file CFb using the pivot_root instruction and setting a new root directory for the root file system is executed. As a result, as Figure 9 shown, the root file system is set in the external memory card 140. The description of other processes is omitted.

[0070] The fourth embodiment also has substantially the same effects as the above-described third embodiment.

[0071] Other aspects

[0072] The present disclosure is not limited to the above-described embodiments, and can be implemented in various ways without departing from its gist. For example, the present disclosure can also be implemented by the following aspects. To solve part or all of the problems of the present disclosure, or to achieve part or all of the effects of the present disclosure, the technical features in the above-described embodiments corresponding to the technical features in each of the following aspects can be appropriately replaced and combined. Additionally, if the technical feature is not described as an essential feature in this specification, it can be appropriately deleted.

[0073] (1) According to the first aspect of the present disclosure, a method for setting the root file system of a computer is provided. The method includes the following steps: (a) a step of reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device and loading them into a working area of the RAM of the computer; (b) a step of verifying the electronic signature of the compressed file loaded into the working area; and (c) a step of setting the root file system by expanding the compressed file in the external storage device when the verification is successful.

[0074] According to this method, it is possible to perform signature verification on the entire root file system to ensure authenticity.

[0075] (2) The above method may also include a step (d): when the verification is unsuccessful, setting the ROM of the computer as the root file system.

[0076] According to this method, when the verification of the compressed file fails, it is possible to use the genuine root file system stored in the ROM.

[0077] (3) In the above method, it may also be that the process (a) includes: reading a first startup file including the OS kernel from the ROM and expanding it in the kernel area of the RAM.

[0078] According to this method, in the case where the verification of the compressed file fails, the OS kernel can be started using the first startup file stored in the ROM.

[0079] (4) In the above method, it may also be that the compressed file is compressed to include a second startup file, the second startup file includes the OS kernel, and the process (c) includes: reading the compressed file from the external storage device, expanding the second startup file, and overwriting the first startup file in the kernel area.

[0080] According to this method, in the case where the verification of the compressed file is successful, the OS kernel can be started using the second startup file included in the compressed file.

[0081] (5) According to the second aspect of the present disclosure, there is provided a computer program for executing a process of setting the root file system of a computer. This computer program causes the computer to execute the following processes: (a) reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device and loading them into the working area of the RAM of the computer; (b) verifying the electronic signature of the compressed file loaded into the working area; and (c) in the case where the verification is successful, setting the root file system by expanding the compressed file in the external storage device.

[0082] The present disclosure can also be implemented in various ways other than the above. For example, it can be implemented by a computer program for implementing the functions of a controller, a non-transitory storage medium (non-transitory storage medium) recording the computer program, and the like.

Claims

1. A method for setting a root file system of a computer, characterized in that: Including the following processes: (a) reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device, and loading the compressed file into a working area of ​​the RAM of the computer; (b) performing verification of the electronic signature on the compressed file loaded into the working area; as well as (c) When the verification is successful, the root file system is set by expanding the compressed file in the external storage device.

2. The method according to claim 1, characterized in that Also includes: (d) If the verification fails, a step of setting the ROM of the computer to the root file system.

3. The method according to claim 2, characterized in that The step (a) includes the step of reading a first startup file including an OS kernel from the ROM and developing the first startup file in a kernel area of ​​the RAM.

4. The method according to claim 3, characterized in that The compressed file is compressed to include a second startup file, wherein the second startup file includes the OS kernel. The step (c) includes the steps of reading the compressed file from the external storage device, expanding the second boot file, and overwriting the first boot file in the kernel area.

5. A computer program product, characterized in that A computer program for executing a process of setting a root file system of a computer is included, wherein the computer program causes the computer to execute the following process: (a) reading a compressed file obtained by compressing the entire partition of the root file system and an electronic signature of the compressed file from an external storage device, and loading the compressed file into a working area of ​​the RAM of the computer; (b) performing verification of the electronic signature on the compressed file loaded into the working area; as well as (c) When the verification is successful, the root file system is set by expanding the compressed file in the external storage device.

Citation Information

Patent Citations

  • Information processing apparatus, information processing method, and program

    JP2021177593A