Information processing system, information processing apparatus, and information processing method

By using USB Type-C interface and key authentication technology in the information processing device, the security problem that BIOS settings are not locked during delivery is solved, and secure BIOS settings and operating system legality control are realized.

CN120296720APending Publication Date: 2025-07-11LENOVO (SINGAPORE) PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411878980.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-10
Filing Date
2024-12-19
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the information processing device, the BIOS settings are not locked from factory to delivery to the user, and there is a security risk that a third party will change the BIOS settings or operating system and software functions.

Method used

The information processing system is adopted, and the information processing device and the upper device are connected through the USB Type-C interface. The legality authentication of the secret key and the public key is used to unlock the lock state, and the BIOS setting and update processing is performed after the legality is confirmed.

Benefits of technology

It improves the security of the information processing device, reduces the possibility of BIOS settings and operating system changes, and ensures legal operations of legal users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296720A_ABST
    Figure CN120296720A_ABST
Patent Text Reader

Abstract

The invention relates to an information processing system, an information processing apparatus, and an information processing method. The safety is improved. An information processing system is provided with: an information processing device that holds a public key among a secret key of a public password allocated corresponding to the device and the public key, and that leaves a factory in a locked state in which activation by an OS is prohibited; and a host device connectable to the information processing device via a USBType-C interface, the information processing device being provided with: a main control unit that executes processing based on the OS and BIOS; and a sub-control unit that is capable of operating in a state in which power is not supplied to the main control unit, and that releases the locked state when mutual legality between the information processing apparatus and the higher-level apparatus is confirmed on the basis of the secret key and the public key using the USB Type-C.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing apparatus, and an information processing method. Background Art

[0002] In an information processing apparatus such as a personal computer (PC), various setting changes can be made through the BIOS (Basic Input Output System). Further, in such an information processing apparatus, in order to enhance security, a password for the BIOS is set so that BIOS settings can be made (for example, refer to Patent Document 1).

[0003] Patent Document 1: Japanese Patent Application Laid-Open No. 2010-152721

[0004] However, in a conventional information processing apparatus, when a user purchases a new PC or other information processing apparatus, the user individually makes BIOS settings. Therefore, in a conventional information processing apparatus, during the period from factory shipment to delivery to the user, the BIOS setup menu is not locked, so there is a possibility that a third party changes the BIOS settings or changes the OS (Operating System) and other software functions. Summary of the Invention

[0005] The present invention has been made to solve the above problems, and an object thereof is to provide an information processing system, an information processing apparatus, and an information processing method that can enhance security.

[0006] To solve the above problems, one aspect of the present invention is an information processing system including: an information processing apparatus that holds the public key among a secret key and a public key that are distributed corresponding to the apparatus, and is shipped in a locked state in which startup based on the OS (Operating System) is prohibited; and a host apparatus that can be connected to the information processing apparatus through an interface of USB (Universal Serial Bus) Type-C. The information processing apparatus includes: a main control unit that executes processing based on the OS and the BIOS (Basic Input Output System); and a sub-control unit that can operate in a state where power is not supplied to the main control unit. When the mutual legality of the information processing apparatus and the host apparatus is confirmed based on the secret key and the public key using the USB Type-C, the locked state is released.

[0007] In addition, in one aspect of the present invention, in the above information processing system, the sub-control unit may further permit the BIOS setting process and the BIOS update process when the mutual legality between the information processing device and the host device is confirmed. The host device uses the USB Type-C to execute the BIOS setting process and the BIOS update process on the information processing device via the sub-control unit.

[0008] In addition, in one aspect of the present invention, in the above information processing system, in the mutual authentication process of confirming the mutual legality between the information processing device and the host device, the sub-control unit may use the USB Type-C to send the first ciphertext information obtained by encrypting the information including the random number with the public key and the hash value of the information including the random number, that is, the first hash value, to the host device. The host device generates the hash value of the information obtained by decrypting the received first ciphertext information with the secret key, that is, the second hash value. When the received first hash value is consistent with the second hash value, it is determined that the information processing device is legal. When the host device determines that the information processing device is legal, it generates a digital signature based on the specified information with the secret key and sends the digital signature to the sub-control unit using the USB Type-C. The sub-control unit confirms the legality of the host device based on the received digital signature and the public key.

[0009] In addition, in one aspect of the present invention, in the above information processing system, the host device may encrypt the hash value of the specified information, that is, the third hash value, with the secret key to generate the digital signature. When the third hash value is consistent with the fourth hash value obtained by decrypting the received digital signature with the public key, the sub-control unit determines that the host device is legal.

[0010] In addition, in one aspect of the present invention, in the above information processing system, the host device and the sub-control unit may use the CC signal line of the USB Type-C to execute the mutual authentication process.

[0011] In addition, in one aspect of the present invention, in the above information processing system, the mutual legality between the information processing device and the host device may be confirmed based on the secret key stored in the USB device connected to the host device and the public key held by the information processing device.

[0012] In addition, in one aspect of the present invention, in the above-described information processing system, it is also possible to confirm the mutual legality between the information processing device and the upper-level device based on the secret key stored in the server device connected to the upper-level device via the network and the public key held by the information processing device.

[0013] In addition, one aspect of the present invention is an information processing device, which includes: an information processing device that holds the public key among the secret key and the public key of the public password allocated corresponding to the device, and is shipped in a locked state in which startup based on the OS (Operating System) is prohibited; and an upper-level device that can be connected to the information processing device through the interface of USB (Universal Serial Bus) Type-C. The information processing device of the information processing system includes: a main control unit that executes processing based on the above OS and BIOS (Basic Input Output System); and a sub-control unit that can operate in a state where power is not supplied to the main control unit. When the mutual legality between the information processing device and the upper-level device is confirmed based on the secret key and the public key using the USB Type-C, the locked state is released.

[0014] In addition, one aspect of the present invention is an information processing method, which is an information processing method of an information processing system. The information processing system includes: an information processing device that includes a main control unit that executes processing based on the OS (Operating System) and BIOS (Basic Input Output System), and a sub-control unit that can operate in a state where power is not supplied to the main control unit; and an upper-level device that can be connected to the information processing device through the interface of USB (Universal Serial Bus) Type-C. The information processing method includes: a step in which the information processing device holds the public key among the secret key and the public key of the public password allocated corresponding to the device, and is shipped in a locked state in which startup based on the above OS is prohibited; a step in which the information processing device is connected to the upper-level device through the USB Type-C interface; and a step in which the sub-control unit releases the locked state when the mutual legality between the information processing device and the upper-level device is confirmed based on the secret key and the public key using the USB Type-C.

[0015] According to the above aspect of the present invention, security can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a configuration diagram showing an example of the information processing system according to this embodiment.

[0017] Figure 2 This is a block diagram showing an example of the main hardware configuration of the notebook PC according to this embodiment.

[0018] Figure 3 This is a functional block diagram showing an example of the functional configuration of the information processing system according to this embodiment.

[0019] Figure 4 This is a diagram showing an example of data in the registration information storage unit according to this embodiment.

[0020] Figure 5 This is a diagram showing an example of the unlocking process of the locked state of the information processing system according to this embodiment.

[0021] Figure 6 This is a diagram showing an example of the BIOS update process of the information processing system according to this embodiment.

[0022] Figure 7 This is a diagram showing another example of the unlocking process of the locked state of the information processing system according to this embodiment.

[0023] Description of Reference Numerals

[0024] 1... Notebook PC, 2... Authentication device, 3... USB device, 4... Management server, 10... Main control unit, 11... CPU, 12... Main memory, 13... Video subsystem, 14... Display unit, 21... Chipset, 22... BIOS memory, 23... SSD, 24... Audio system, 25... WLAN card, 26... USB connector, 31... Embedded controller (EC), 32... Input unit, 33... Power supply circuit, 34... PD controller, 41, 210... NW communication unit, 42... Server storage unit, 43... Server control unit, 100... Information processing system, 101... BIOS processing unit, 102... OS processing unit, 221... BIOS program storage unit, 222... Setting storage unit, 223... Locking information storage unit, 224... Public key storage unit, 230... Device storage unit, 231... Setting information storage unit, 232... BIOS program storage unit, 240... Device control unit, 241, 311... Authentication processing unit, 242, 313... BIOS setting unit, 312... Locking control unit, 421... Registration information storage unit, NW1... Network. Detailed Embodiment

[0025] Hereinafter, an information processing system, an information processing apparatus, and an information processing method according to an embodiment of the present invention will be described with reference to the accompanying drawings.

[0026] Figure 1 This is a configuration diagram showing an example of the information processing system 100 of the present embodiment.

[0027] As Figure 1 shown, the information processing system 100 includes a notebook PC 1, an authentication device 2, a USB (Universal Serial Bus) device 3, and a management server 4.

[0028] The notebook PC 1 and the authentication device 2 are connected through a USB Type-C interface.

[0029] In addition, the authentication device 2 and the management server 4 are connected via the network NW1.

[0030] In addition, in the present embodiment, as an example of the information processing device, the notebook PC 1 will be described.

[0031] The notebook PC 1 holds the public key among the secret key and the public key of the public password allocated corresponding to the device, and is shipped in a locked state that prohibits OS-based startup. Refer to Figure 2 the detailed configuration of the notebook PC 1 described later.

[0032] The authentication device 2 (an example of the upper device) is a device that can be connected to the notebook PC 1 through a USB Type-C interface, and performs the unlocking process of the locked state of the notebook PC 1, the BIOS setting process, and the BIOS program update process. The authentication device 2 is, for example, a notebook PC, a desktop PC, etc. In addition, the authentication device 2 can be connected to a USB device or the management server 4 that holds the secret key in order to perform mutual authentication processing with the notebook PC 1.

[0033] The USB device 3 is a device that can be connected to the authentication device 2 through a USB interface (for example, USB Type-A). The USB device 3 holds the secret key corresponding to the notebook PC 1 and is used for the unlocking process of the locked state of the shipped notebook PC 1, the BIOS setting process, and the BIOS program update process.

[0034] The management server 4 is, for example, a server device managed by the manufacturer of the notebook PC 1, and can be connected to the authentication device 2 via the network NW1. The management server 4 holds the secret key and the public key corresponding to each notebook PC 1. Similar to the USB device 3, the management server 4 is used for the unlocking process of the locked state of the shipped notebook PC 1, the BIOS setting process, and the BIOS program update process.

[0035] Next, refer toFigure 2 , the main hardware components of the notebook PC1 will be described.

[0036] Figure 2 It is a diagram showing an example of the main hardware components of the notebook PC1 of the present embodiment.

[0037] As Figure 2 shown, the notebook PC1 includes a CPU 11, a main memory 12, a video subsystem 13, a display unit 14, a chipset 21, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, a USB connector 26, an embedded controller 31, an input unit 32, a power supply circuit 33, and a PD controller 34.

[0038] In addition, in the present embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. Further, the main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).

[0039] The CPU (Central Processing Unit) 11 executes various arithmetic processes under program control and controls the entire notebook PC1.

[0040] The main memory 12 is a writable memory that is used as a read-in area for the execution program of the CPU 11 or as a work area for writing the processing data of the execution program. The main memory 12 is composed of, for example, a plurality of DRAM (Dynamic Random Access Memory) chips. The execution program includes BIOS, OS, various driver programs for hardware operations on peripheral device groups, various service / utilities, application programs, and the like.

[0041] In addition, the main memory 12 is an example of a system memory that stores programs and data, and is mounted on the notebook PC1 through a DIMM on which a plurality of DRAMs are installed.

[0042] The video subsystem 13 is a subsystem for implementing functions related to image display and includes a video controller. The video controller processes the drawing commands from the CPU 11, writes the processed drawing information into the video memory, reads out the drawing information from the video memory, and outputs it as drawing data (display data) to the display unit 14.

[0043] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13.

[0044] The chipset 21 includes controllers such as USB, Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and is connected to multiple devices. In Figure 2 as an example of a device, the BIOS memory 22, SSD 23, audio system 24, WLAN card 25, and USB connector 26 are connected to the chipset 21.

[0045] The BIOS memory 22 is composed of a non-volatile memory such as EEPROM (Electrically Erasable Programmable Read Only Memory) or flash ROM that can be electrically rewritten. The BIOS memory 22 stores system firmware for controlling the BIOS and the embedded controller 31, etc.

[0046] The SSD (Solid State Drive) 23 (an example of a non-volatile storage device) stores the OS, various drivers, various services / utilities, application programs, and various data.

[0047] The audio system 24 records, plays, and outputs sound data.

[0048] The WLAN (Wireless Local Area Network) card 25 is connected to the network via a wireless LAN and performs data communication.

[0049] The USB connector 26 is a connector for connecting a peripheral device group using USB. The USB connector 26 includes, for example, a USB Type-C connector.

[0050] The embedded controller 31 (an example of a sub-control unit) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. In addition, the embedded controller 31 has a power management function for controlling the power supply circuit 33. Furthermore, the embedded controller 31 is composed of a CPU, ROM, RAM, etc. (not shown), and is equipped with multi-channel A / D input terminals, D / A output terminals, timers, and digital input / output terminals. For example, an input unit 32 and a power supply circuit 33 are connected to the embedded controller 31 via these input / output terminals, and the embedded controller 31 controls their operations.

[0051] In addition, the embedded controller 31 can operate in a state where power is not supplied to the main control unit 10, can communicate with the authentication device 2 using USB Type-C without going through the main control unit 10, and can access the BIOS memory 22 without going through the main control unit 10.

[0052] The input unit 32 is, for example, an input device such as a keyboard, a pointing device, or a touchpad.

[0053] The power supply circuit 33 includes, for example, a DC / DC converter, a charge / discharge unit, a battery unit, and an AC / DC adapter, etc., and converts the DC voltage supplied from the AC / DC adapter or the battery unit into multiple voltages required for the operation of the notebook PC 1. In addition, the power supply circuit 33 supplies power to each part of the notebook PC 1 based on the control from the embedded controller 31.

[0054] The PD (Power Delivery) controller 34 communicates with the device connected to the USB connector 26 (for example, a USB Type-C connector) and performs control such as power supply or power reception with respect to the device. When a device is connected to the USB connector 26, the PD controller 34 acquires or determines the detection of the connection of the device, information on the connected device (device attribute information), etc. via CC (Configuration Channel) terminals, etc. For example, the PD controller 34 acquires or determines information corresponding to the USB-PD standard, information indicating whether it corresponds to one or both of power supply and power reception in the case of correspondence with the USB-PD standard, information corresponding to data communication, information corresponding to the USB BC1.2 standard, etc. based on the communication via the CC terminal with the device connected to the USB connector 26.

[0055] In addition, in the present embodiment, the PD controller 34 enables communication between the authentication device 2 and the embedded controller 31 using the CC signal line of USB Type-C.

[0056] Next, with reference to Figure 3 , the functional configuration of the information processing system 100 of the present embodiment will be described.

[0057] Figure 3 FIG. is a functional block diagram showing an example of the functional configuration of the information processing system 100 of the present embodiment. In addition, in Figure 3 , only the configurations related to the present invention among the various functional configurations included in the information processing system 100 are described.

[0058] As Figure 3 shown, the information processing system 100 includes a notebook PC 1, an authentication device 2, a USB device 3, and a management server 4.

[0059] The management server 4 includes a NW communication unit 41, a server storage unit 42, and a server control unit 43.

[0060] The NW (NetWork) communication unit 41 is, for example, a network adapter that can be connected to the network NW1 through a wired LAN or the like, and can be connected to the authentication device 2 via the network NW1.

[0061] The server storage unit 42 is, for example, a storage unit implemented by a RAM, an SSD, an HDD, etc., and stores various information used by the management server 4. The server storage unit 42 includes a registration information storage unit 421.

[0062] The registration information storage unit 421 stores the registration information of each notebook PC 1 manufactured and shipped by the manufacturer. The registration information storage unit 421, for example, as Figure 4 shown, stores the manufacturing number, public key, and secret key in a corresponding relationship.

[0063] Here, the manufacturing number is an example of the identification information for identifying the notebook PC 1. In addition, the public key and the secret key refer to a key pair (public key and secret key) of the public key cryptography assigned to the notebook PC 1. In the present embodiment, one key pair is assigned to one notebook PO1.

[0064] In Figure 4 the example shown, it is shown that the public key "XXXXXXX1" and the secret key "YYYYYYY1" are assigned to the notebook PC 1 with the manufacturing number "L000001".

[0065] Returning to Figure 3The server control unit 43 is a functional unit implemented by, for example, causing a CPU (not shown) to execute a program stored in the server storage unit 42. The server control unit 43 performs registration processing for the manufacturing number, public key, and secret key stored in the registration information storage unit 421, and performs encryption processing and decryption processing for authentication during the authentication process between the notebook PC 1 and the authentication device 2.

[0066] The notebook PC 1 includes a main control unit 10, a BIOS memory 22, and an embedded controller 31.

[0067] The BIOS memory 22 includes a BIOS program storage unit 221, a setting storage unit 222, a lock information storage unit 223, and a public key storage unit 224. In addition, the BIOS memory 22 can be accessed from the embedded controller 31 via the SPI bus.

[0068] The BIOS program storage unit 221 stores the BIOS program.

[0069] The setting storage unit 222 stores the setting information of the BIOS including the BIOS password.

[0070] The lock information storage unit 223 stores information indicating whether the notebook PC 1 is in a locked state. In addition, at the time of shipment of the notebook PC 1, information indicating the locked state is stored in the lock information storage unit 223.

[0071] The public key storage unit 224 stores the public key assigned to the notebook PC 1. In addition, the public key storage unit 224 may store the public key in association with the manufacturing number of the notebook PC 1.

[0072] The main control unit 10 is a functional unit implemented by causing the CPU 11 to execute programs stored in the SSD 23, the BIOS memory 22, the main memory 12, etc. The main control unit 10 performs processing based on the OS and the BIOS. The main control unit 10 includes, for example, a BIOS processing unit 101 and an OS processing unit 102.

[0073] The BIOS processing unit 101 is a functional unit implemented by causing the CPU 11 to execute the BIOS program stored in the BIOS memory 22, and performs processing based on the BIOS.

[0074] The OS processing unit 102 is a functional unit implemented by causing the CPU 11 to execute the OS program stored in the SSD 23, and performs processing based on the OS.

[0075] The embedded controller 31 is a control unit that can operate without supplying power to the main control unit 10. When using USB Type-C and confirming the mutual legality of the notebook PC 1 and the authentication device 2 based on the secret key and the public key, the locked state of the notebook PC 1 is released. In addition, when the mutual legality of the notebook PC 1 and the authentication device 2 is confirmed, the embedded controller 31 further permits the BIOS setting process and the BIOS update process.

[0076] The embedded controller 31 includes an authentication processing unit 311, a lock control unit 312, and a BIOS setting unit 313.

[0077] The authentication processing unit 311 executes an authentication process of using the CC signal line of USB Type-C to confirm the mutual legality between the embedded controller 31 (notebook PC 1) and the authentication device 2. The authentication processing unit 311 first generates a random number (for example, a pseudo-random number using software), and uses the public key stored in the public key storage unit 224 to encrypt the information (for example, the string of the random number) including the generated random number through public key cryptography. In addition, the authentication processing unit 311 generates a hash value (first hash value) of the information (for example, the string of the random number) including the generated random number using a hash function.

[0078] The authentication processing unit 311 uses the CC signal line of USB Type-C to send the encrypted information (first encrypted information) obtained by encrypting the information including the random number and the hash value (first hash value) to the authentication device 2. In addition, the authentication processing unit 311 may also send the manufacturing number of the notebook PC 1 to the authentication device 2 in advance.

[0079] In addition, the authentication processing unit 311 confirms the legality of the authentication device 2 based on the digital signature and the public key received from the authentication device 2 using the CC signal line of USB Type-C. The authentication processing unit 311 confirms the legality of the authentication device 2, for example, by determining whether the hash value generated by decrypting the digital signature using the public key stored in the public key storage unit 224 is consistent with the hash value generated according to the message data (prescribed information).

[0080] In addition, here in the authentication device 2, when the legality of the notebook PC 1 (embedded controller 31) is confirmed, a digital signature is sent from the authentication device 2.

[0081] When the authentication control unit 312 confirms the legitimacy of the authentication device 2 through the authentication processing unit 311, it releases the locked state of the notebook PC 1. The locking control unit 312 changes the information indicating whether the notebook PC 1 is in the locked state stored in the lock information storage unit 223 to information indicating that it is not in the locked state, and releases the locked state.

[0082] When the BIOS setting unit 313 confirms the legitimacy of the authentication device 2 through the authentication processing unit 311, it permits the BIOS setting process and the BIOS update process. In the BIOS setting process, the BIOS setting unit 313 stores the BIOS setting information received from the authentication device 2 in the setting storage unit 222 and changes the BIOS settings. In addition, the BIOS setting information includes a BIOS password, etc.

[0083] In addition, in the BIOS update process, the BIOS setting unit 313 stores the BIOS program received from the authentication device 2 in the BIOS program storage unit 221 and updates the BIOS. In addition, the BIOS update process also includes a patch process for updating a part of the BIOS program.

[0084] The authentication device 2 includes an NW communication unit 210, a device storage unit 230, and a device control unit 240.

[0085] The NW communication unit 210 is, for example, a network adapter that can be connected to the network NW1 through a wired LAN, a wireless KAN, etc., and can be connected to the management server 4 via the network NW1.

[0086] The device storage unit 230 is, for example, a storage unit implemented by a RAM, an SSD, an HDD, etc., and stores various information used by the authentication device 2. The device storage unit 230 includes a setting information storage unit 231 and a BIOS program storage unit 232.

[0087] The setting information storage unit 231 stores the BIOS setting information obtained from the management server 4 or the USB device 3.

[0088] The BIOS program storage unit 232 stores the BIOS update program obtained from the management server 4 or the USB device 3.

[0089] The device control unit 240 is, for example, a functional unit implemented by causing a CPU (not shown) to execute a program stored in the device storage unit 230. The device control unit 240 executes various processes performed by the authentication device 2.

[0090] The device control unit 240 performs, for example, authentication processing with the notebook PC 1, and controls the setting processing of the BIOS of the notebook PC 1 and the update processing of the BIOS. The device control unit 240 uses USB Type-C to perform the setting processing of the BIOS and the update processing of the BIOS on the notebook PC 1 via the embedded controller 31.

[0091] The device control unit 240 includes an authentication processing unit 241 and a BIOS setting unit 242.

[0092] The authentication processing unit 241 uses the CC signal line of USB Type-C to control the authentication processing with the embedded controller 31 (notebook PC 1). If the authentication processing unit 241 uses the CC signal line of USB Type-C and receives the encrypted information and the hash value (first hash value) obtained by encrypting the information including the random number from the embedded controller 31, it sends a delegation to decrypt the encrypted information using the secret key corresponding to the notebook PC 1 to the management server 4 via the network NW1.

[0093] In addition, the authentication processing unit 241 receives the information of the encrypted information (first encrypted information) from the management server 4 via the network NW1, and generates the hash value (second hash value) of the received information (the information obtained by decrypting the encrypted information with the secret key). The authentication processing unit 241 determines that the notebook PC 1 is legitimate when the hash value (first hash value) received from the notebook PC 1 is consistent with the generated hash value (second hash value).

[0094] In addition, when the authentication processing unit 241 determines that the notebook PC 1 is legitimate, it generates a digital signature based on the specified information using the secret key corresponding to the notebook PC 1, and sends the digital signature to the embedded controller 31 using USB Type-C. The authentication processing unit 241 encrypts the hash value of the specified information, that is, the hash value (third hash value), with the secret key to generate a digital signature.

[0095] Specifically, the authentication processing unit 241 generates the hash value (third hash value) of the specified information (for example, random number + α, etc.), and sends the generated hash value (third hash value) to the management server 4, delegating the encryption based on the secret key corresponding to the notebook PC 1. The authentication processing unit 241 uses the encrypted hash value as a digital signature, and sends it to the embedded controller 31 (notebook PC 1) together with the specified information (message data) using the CC signal line of USB Type-C.

[0096] As described above, when the hash value (third hash value) of the predetermined information (telegraphic data) generated independently matches the hash value (fourth hash value) obtained by decrypting the received digital signature using the public key, the embedded controller 31 determines that the authentication device 2 is legitimate.

[0097] The BIOS setting unit 242 performs BIOS setting processing and BIOS update processing after the authentication processing unit 241 performs authentication processing. For example, when the legitimacy of the notebook PC 1 (embedded controller 31) is confirmed through the authentication processing, the BIOS setting unit 242 uses the USB Type-C to send the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31 to change the BIOS setting information.

[0098] When the legitimacy of the notebook PC 1 (embedded controller 31 ) is confirmed through authentication processing, the BIOS setting unit 242 transmits the BIOS program stored in the BIOS program storage unit 232 to the embedded controller 31 using USB Type-C to execute BIOS update.

[0099] In the above example, the management server 4 uses a secret key to decrypt the cryptographic information and generate a digital signature, but the USB device 3 may be substituted for the management server 4 to perform the same processing as the management server 4. For example, when the authentication device 2 cannot be connected to the network NW1, the information processing system 100 uses the USB device 3 to perform a lock state release process, a BIOS setting process, and a BIOS update process.

[0100] Next, the operation of the information processing system 100 according to the present embodiment will be described with reference to the drawings.

[0101] Figure 5 This is a diagram showing an example of a lock state release process of the information processing system 100 according to the present embodiment.

[0102] like Figure 5 As shown, the authentication device 2 first performs a login process with the management server 4 (step S101 ). The device control unit 240 of the authentication device 2 transmits a user ID and a password to the management server 4 via the NW communication unit 210 , thereby enabling access to the management server 4 .

[0103] Next, the authentication device 2 uses USB-C (USB Type-C) to connect to the notebook PC 1 (embedded controller (EC) 31) (step S102). The authentication device 2 is connected to the embedded controller 31 via the PD controller 34 using the CC signal line. Here, it is assumed that power is supplied to the embedded controller 31, the BIOS memory 22, and the PD controller 34 in a state where the main control unit 10 of the notebook PC 1 does not supply power from the power supply circuit 33.

[0104] Next, the embedded controller 31 generates a hash value of a random number and encrypts the generated random number using a public key (step S103). The authentication processing unit 311 of the embedded controller 31, for example, generates a hash value of a random number (first hash value), and encrypts the random number using the public key stored in the public key storage unit 224 to generate encrypted information.

[0105] Next, the embedded controller 31 sends the ciphertext of the random number (encrypted information) and the hash value (first hash value) to the authentication device 2 (step S104). The authentication processing unit 311 uses the CC signal line to send the encrypted information and the hash value (first hash value) to the authentication device 2.

[0106] Next, the authentication device 2 entrusts the management server 4 to decrypt the ciphertext of the random number (encrypted information) (step S105). The authentication processing unit 241 of the authentication device 2 sends a decryption request to the management server 4 via the NW communication unit 210 to decrypt the encrypted information received from the embedded controller 31.

[0107] Next, the management server 4 decrypts the ciphertext of the random number (encrypted information) using the secret key (step S106). The server control unit 43 of the management server 4 obtains the secret key corresponding to the notebook PC 1 from the registration information storage unit 421 and uses the secret key to decrypt the encrypted information received from the authentication device 2. Here, the decrypted encrypted information corresponds to the above-mentioned random number.

[0108] Next, the management server 4 sends the decrypted random number (decrypted text) to the authentication device 2 (step S107). The server control unit 43 sends the decrypted random number (decrypted text) to the authentication device 2 via the NW communication unit 41.

[0109] Next, the authentication device 2 generates a hash value (second hash value) of the received random number (decrypted text) (step S108). The authentication processing unit 241 receives the random number (decrypted text) from the management server 4 via the NW communication unit 210 and generates a hash value (second hash value) of the random number (decrypted text).

[0110] Next, the authentication processing unit 241 of the authentication device 2 determines whether the generated hash value (second hash value) is the same as the hash value (first hash value) received from the embedded controller 31 (step S109). When the hash value (second hash value) is the same as the hash value (first hash value) (step S109: Yes), the authentication processing unit 241 advances the process to step S110. On the other hand, when the hash value (second hash value) is not the same as the hash value (first hash value) (step S109: No), the authentication processing unit 241 advances the process to step S111 and aborts the authentication process.

[0111] In step S110, the authentication processing unit 241 of the authentication device 2 requests the management server 4 to generate a digital signature. The authentication processing unit 241 generates a hash value (third hash value) of prescribed information (e.g., random number + α) and transmits the hash value (third hash value) to the management server 4 via the NW communication unit 210.

[0112] Next, the management server 4 generates a digital signature using the secret key corresponding to the notebook PC 1 (step S112). The server control unit 43 receives the hash value (third hash value) from the authentication device 2 via the NW communication unit 41 and acquires the secret key corresponding to the notebook PC 1 from the registration information storage unit 421. The server control unit 43 encrypts the received hash value (third hash value) using the secret key to generate a digital signature.

[0113] Next, the server control unit 43 of the management server 4 transmits the generated digital signature to the authentication device 2 via the NW communication unit 41 (step S113).

[0114] Next, the authentication processing unit 241 of the authentication device 2 uses the CC signal line to transmit the digital signature together with prescribed information (e.g., random number + α) to the embedded controller 31 (step S114).

[0115] Next, the authentication processing unit 311 of the embedded controller 31 verifies the legality of the digital signature using the public key (step S115). The authentication processing unit 311 decrypts the received digital signature using the public key stored in the public key storage unit 224 to generate a hash value (fourth hash value). In addition, the authentication processing unit 311 verifies the legality of the digital signature based on whether the hash value (third hash value) of the prescribed information (e.g., random number + α) is the same as the hash value (fourth hash value).

[0116] Next, the authentication processing unit 311 of the embedded controller 31 determines whether the legality of the digital signature has been confirmed (step S116). When the authentication processing unit 311 has confirmed the legality of the digital signature (the hash value (third hash value) is the same as the hash value (fourth hash value)) (step S116: Yes), the process proceeds to step S117. In addition, when the authentication processing unit 311 has not confirmed the legality of the digital signature (the hash value (third hash value) is different from the hash value (fourth hash value)) (step S116: No), the process proceeds to step S118 and the authentication processing is aborted.

[0117] In step S117, the embedded controller 31 releases the locked state. The lock control unit 312 of the embedded controller 31 changes the information indicating whether the notebook PC 1 is in the locked state stored in the lock information storage unit 223 to information indicating that it is not in the locked state, and releases the locked state. In addition, the BIOS setting unit 313 of the embedded controller 31 permits the BIOS setting process and the BIOS update process.

[0118] Next, the authentication device 2 sends the BIOS setting information to the embedded controller 31 (step S119). The BIOS setting unit 242 of the authentication device 2 uses the CC signal line to send the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31.

[0119] Next, the embedded controller 31 performs the BIOS setting process (step S120). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS setting information in the setting storage unit 222 and changes the BIOS settings.

[0120] Next, refer to Figure 6 , and the BIOS update process of the information processing system 100 of the present embodiment will be described.

[0121] Figure 6 is a diagram showing an example of the BIOS update process of the information processing system 100 of the present embodiment.

[0122] In Figure 6 , the processing from step S201 to step S216 is the same as the processing from step S101 to step S116 shown above, so the description thereof is omitted here. Figure 5 shown.

[0123] In step S216, when the authentication processing unit 311 confirms the legality of the digital signature (the hash value (the third hash value) is the same as the hash value (the fourth hash value)) (step S216: Yes), the process proceeds to step S217. On the other hand, when the authentication processing unit 311 does not confirm the legality of the digital signature (the hash value (the third hash value) is different from the hash value (the fourth hash value)) (step S216: No), the process proceeds to step S218 and the authentication process is aborted.

[0124] In step S217, the embedded controller 31 permits the BIOS change. The BIOS setting unit 313 of the embedded controller 31 permits the setting process of the BIOS and the update process of the BIOS.

[0125] Next, the authentication device 2 sends the BIOS update program to the embedded controller 31 (step S219). The BIOS setting unit 242 of the authentication device 2 uses the CC signal line to send the BIOS program stored in the BIOS program storage unit 232 to the embedded controller 31 as the BIOS update program.

[0126] Next, the embedded controller 31 executes the update process of the BIOS program (step S220). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS update program in the BIOS program storage unit 221 and updates the BIOS program.

[0127] Next, the authentication device 2 sends the BIOS setting information to the embedded controller 31 (step S221). The BIOS setting unit 242 of the authentication device 2 uses the CC signal line to send the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31.

[0128] Next, the embedded controller 31 executes the BIOS setting process (step S1222). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS setting information in the setting storage unit 222 and changes the settings of the BIOS.

[0129] In addition, in the examples shown in Figure 5 and Figure 6 above, an example of using the management server 4 is described. However, in an environment where the authentication device 2 cannot be connected to the network NW1, the USB device 3 can be used instead of the management server 4.

[0130] Here, with reference to Figure 7 , an example of the unlocking process in the case of using the USB device 3 will be described.

[0131] Figure 7This is a diagram showing another example of the lock state release process of the information processing system 100 according to the present embodiment.

[0132] exist Figure 7 The processing from step S301 to step S303 is the same as that described above. Figure 5 The processes from step S102 to step S104 shown are the same, so their description is omitted here.

[0133] In step S304, the authentication device 2 requests the USB device 3 to decrypt the ciphertext (encrypted information) of the random number. The authentication processing unit 241 of the authentication device 2 sends a decryption request to the USB device 3 requesting the USB device 3 to decrypt the encrypted information received from the embedded controller 31 .

[0134] Next, the USB device 3 decrypts the ciphertext (encrypted information) of the random number using the secret key (step S305). The USB device 3 decrypts the encrypted information received from the authentication device 2 using the secret key corresponding to the notebook PC 1. Here, the decrypted encrypted information corresponds to the random number described above.

[0135] Next, the USB device 3 transmits the decrypted random number (decrypted text) to the authentication apparatus 2 (step S306).

[0136] Next, since the processing of step S307 and step S308 is the same as the above Figure 5 The processing of step S108 and step S109 shown is the same, so their description is omitted here.

[0137] In step S308, if the hash value (second hash value) and the hash value (first hash value) are consistent (step S308: Yes), the authentication processing unit 241 advances the process to step S309. In addition, if the hash value (second hash value) and the hash value (first hash value) are inconsistent (step S308: No), the authentication processing unit 241 advances the process to step S310 and terminates the authentication process.

[0138] In step S309, the authentication processing unit 241 of the authentication apparatus 2 requests the USB device 3 to generate a digital signature. The authentication processing unit 241 generates a hash value (third hash value) of predetermined information (for example, random number+α) and sends the hash value (third hash value) to the USB device 3.

[0139] Next, the USB device 3 generates a digital signature using the secret key corresponding to the notebook PC 1 (step S311). The USB device 3 encrypts the received hash value (third hash value) using the secret key to generate a digital signature.

[0140] Next, the USB device 3 sends the generated digital signature to the authentication apparatus 2 (step S312).

[0141] Next, since the processing from step S313 to step S319 is the same as the above Figure 5 The processes from step S114 to step S120 shown are the same, so their description is omitted here.

[0142] In addition, in the above Figure 7 In the example shown, an example of releasing the locked state using the USB device 3 is described, but Figure 6 The BIOS update process shown can also be performed using the USB device 3 in the same manner.

[0143] As described above, the information processing system 100 of the present embodiment includes a notebook PC 1 (information processing device) and an authentication device 2 (host device). The notebook PC 1 maintains a secret key of a public password and a public key of a public key assigned to the device, and is shipped from the factory in a locked state in which OS-based startup is prohibited. The authentication device 2 can be connected to the notebook PC 1 through a USB Type-C interface. The notebook PC 1 includes a main control unit 10 and an embedded controller 31 (sub-control unit). The main control unit 10 performs processing based on the OS and BIOS. The embedded controller 31 is a sub-control unit that can operate without supplying power to the main control unit 10. When the mutual legitimacy of the notebook PC 1 and the authentication device 2 is confirmed based on the secret key and the public key using USB Type-C, the locked state is released.

[0144] Thus, the information processing system 100 of this embodiment can improve security by releasing the locked state when the mutual legitimacy of the notebook PC 1 and the authentication device 2 is confirmed. The information processing system 100 of this embodiment can reduce the possibility of a third party changing the BIOS settings or changing the OS and other software functions.

[0145] In addition, the embedded controller 31 (sub-controller) of the information processing system 100 of the present embodiment, which can operate without power being supplied to the main control unit 10, uses USB Type-C to release the locked state, so the locked state can be released without power being supplied to the main control unit 10. Therefore, the information processing system 100 of the present embodiment can further improve security when releasing the locked state.

[0146] In addition, in the present embodiment, when the embedded controller 31 has confirmed the mutual legality between the notebook PC 1 and the authentication device 2, it further permits the BIOS setting process and the BIOS update process. The authentication device 2 uses USB Type-C to perform the BIOS setting process and the BIOS update process on the notebook PC 1 via the embedded controller 31.

[0147] Thereby, the information processing system 100 of the present embodiment can perform the BIOS setting process and the BIOS update process in a state where power is not supplied to the main control unit 10. Thereby, the information processing system 100 of the present embodiment can further enhance security in the BIOS setting process and the BIOS update process.

[0148] In addition, in the present embodiment, in the mutual authentication process for confirming the mutual legality between the notebook PC 1 and the authentication device 2, the embedded controller 31 uses USB Type-C to send password information obtained by encrypting information including a random number with a public key and a hash value of the information including the random number, that is, a first hash value, to the authentication device 2. The authentication device 2 generates a hash value of the information obtained by decrypting the received password information with a secret key, that is, a second hash value, and determines that the notebook PC 1 is legal when the received first hash value and the second hash value match. When the authentication device 2 determines that the notebook PC 1 is legal, it generates a digital signature based on specified information with the secret key and sends the digital signature to the embedded controller 31 using USB Type-C. The embedded controller 31 confirms the legality of the authentication device 2 based on the received digital signature and the public key.

[0149] Thereby, the information processing system 100 of the present embodiment can perform the mutual authentication process for confirming the mutual legality between the notebook PC 1 and the authentication device 2 using a random number, by a simple method, and securely.

[0150] In addition, in the present embodiment, the authentication device 2 generates a digital signature by encrypting the hash value of specified information, that is, a third hash value, with a secret key. The embedded controller 31 determines that the authentication device 2 is legal when the third hash value matches a fourth hash value obtained by decrypting the received digital signature with a public key.

[0151] Thereby, the information processing system 100 of the present embodiment can confirm the legality of the authentication device 2 by a simple method and securely.

[0152] In addition, in the present embodiment, the authentication device 2 and the embedded controller 31 use the CC signal line of USB Type-C to perform the mutual authentication process.

[0153] Thus, the information processing system 100 according to the present embodiment can simply improve security by using the CC signal line of USB Type-C with an existing interface.

[0154] In addition, in the present embodiment, the mutual legitimacy between the notebook PC 1 and the authentication device 2 is confirmed based on the secret key stored in the USB device 3 connected to the authentication device 2 and the public key held by the notebook PC 1.

[0155] Thus, the information processing system 100 according to the present embodiment can use the USB device 3 to simply and securely confirm the mutual legitimacy between the notebook PC 1 and the authentication device 2.

[0156] In addition, in the present embodiment, the mutual legitimacy between the notebook PC 1 and the authentication device 2 is confirmed based on the secret key stored in the management server 4 (server device) connected to the authentication device 2 via the network and the public key held by the notebook PC 1.

[0157] Thus, the information processing system 100 according to the present embodiment can use the management server 4 (server device) to simply and securely confirm the mutual legitimacy between the notebook PC 1 and the authentication device 2.

[0158] In addition, the notebook PC 1 (information processing device) according to the present embodiment is the notebook PC 1 of the information processing system 100 including the notebook PC 1 and the authentication device 2 that can be connected to the notebook PC 1 through the USB Type-C interface, and includes a main control unit 10 and an embedded controller 31. In addition, the notebook PC 1 holds the public key among the secret key and the public key of the public password allocated corresponding to the device, and is shipped in a locked state that prohibits booting based on the OS. The main control unit 10 executes processing based on the OS and the BIOS. The embedded controller 31 is a sub-control unit that can operate in a state where power is not supplied to the main control unit 10. When the mutual legitimacy between the notebook PC 1 and the authentication device 2 is confirmed based on the secret key and the public key using USB Type-C, the locked state is released.

[0159] Thus, the notebook PC 1 (information processing device) according to the present embodiment can achieve the same effect as the above-described information processing system 100 and improve security.

[0160] In addition, the information processing method of the present embodiment is an information processing method of an information processing system 100 including a notebook PC 1 and an authentication device 2 that can be connected to the notebook PC 1 through a USB Type-C interface, and includes a factory shipment step, a connection step, and a release step. The notebook PC 1 includes a main control unit 10 that executes processing based on an OS and a BIOS, and an embedded controller 31 that can operate in a state where power is not supplied to the main control unit 10. In the factory shipment step, the notebook PC 1 ships in a locked state that prohibits OS-based startup while holding the public key among the secret key and the public key assigned corresponding to the device. In the connection step, the notebook PC 1 is connected to the authentication device 2 through the USB Type-C interface. In the release step, when the mutual legitimacy of the notebook PC 1 and the authentication device 2 is confirmed based on the secret key and the public key using USB Type-C, the embedded controller 31 releases the locked state.

[0161] Thus, the information processing method of the present embodiment can achieve the same effect as the above-described information processing system 100, improving security.

[0162] In addition, the present invention is not limited to the above-described embodiments, and can be modified without departing from the gist of the present invention.

[0163] For example, in the above-described embodiment, an example in which a secret key is used for the USB device 3 or the management server 4 to perform encryption processing or decryption processing has been described, but it is not limited thereto. The authentication device 2 may also obtain the secret key from the USB device 3 or the management server 4, and the authentication device 2 may perform encryption processing or decryption processing. Additionally, the authentication device 2 may include a secret key storage unit that stores the secret key.

[0164] In addition, in the above-described embodiment, an example in which the information processing device is a notebook PC 1 has been described, but it is not limited thereto. For example, it may also be other information processing devices such as a tablet terminal device or a desktop PC.

[0165] In addition, in the above-described embodiment, an example in which a random number is used to perform an authentication process for mutually confirming the legitimacy between the authentication device 2 and the notebook PC 1 (embedded controller 31) has been described, but it is not limited thereto. An authentication process using other methods may also be performed.

[0166] For example, in the above-described embodiment, an example in which a digital signature is used for the process of confirming the legitimacy of the authentication device 2 has been described, but it is not limited thereto. A process using a random number similar to the process of confirming the legitimacy of the notebook PC 1 may also be performed.

[0167] In addition, each component included in the above-described information processing system 100 may have a computer system therein. Further, by recording a program for implementing the functions of each component included in the above-described information processing system 100 on a computer-readable recording medium, and causing the computer system to read and execute the program recorded on the recording medium, the processing in each component included in the above-described notebook PC 1 is performed. Here, "causing the computer system to read and execute the program recorded on the recording medium" includes installing the program in the computer system. The "computer system" mentioned here includes hardware such as an OS and peripheral devices.

[0168] In addition, the "computer system" may also include a plurality of computer devices connected via a network including communication lines such as the Internet, WAN, LAN, and dedicated lines. Further, the "computer-readable recording medium" refers to removable media such as floppy disks, optical disks, ROMs, and CD-ROMs, and storage devices such as hard disks built in the computer system. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM.

[0169] In addition, the recording medium may also include a recording medium provided inside or outside and accessible from a distribution server for distributing the program. Further, the program may be divided into a plurality of parts, and may be configured to be merged in each component included in the information processing system 100 after being downloaded at different timings, and the distribution servers for distributing the divided programs may be different.

[0170] Also, the "computer-readable recording medium" also includes a recording medium that holds the program for a certain period of time, such as a volatile memory (RAM) inside a computer system that becomes a server or a client when a program is transmitted via a network. In addition, the above program may be a program for implementing a part of the above functions. Further, it may be a program that can implement the above functions by combining with a program already recorded in the computer system, that is, a so-called differential file (differential program).

[0171] In addition, a part or all of the above functions may be implemented as an integrated circuit such as an LSI (Large Scale Integration). Each of the above functions may be independently processorized, or a part or all of them may be integrated and processorized. In addition, the method of integrating into an integrated circuit is not limited to LSI, and may be implemented by a dedicated circuit or a general-purpose processor. Further, in the case where an integrated circuit technology replacing LSI appears due to the development of semiconductor technology, an integrated circuit based on that technology may be used.

Claims

1. An information processing system, wherein, Comprising: An information processing device that holds the public key among the secret key and the public key of the public key allocated corresponding to the device, and is shipped in a locked state with OS-based startup prohibited; and A host device that can be connected to the information processing device through a USB Type-C interface, The information processing device comprises: A main control unit that executes processing based on the above OS and BIOS; and A sub-control unit that is a sub-control unit that can operate in a state where power is not supplied to the main control unit. When the mutual legality of the information processing device and the host device is confirmed based on the secret key and the public key using the USB Type-C, the locked state is released.

2. The information processing system according to claim 1, wherein When the sub-control unit confirms the mutual legality of the information processing device and the host device, the sub-control unit further permits the BIOS setting process and the BIOS update process, The host device uses the USB Type-C to execute the BIOS setting process and the BIOS update process on the information processing device via the sub-control unit.

3. The information processing system according to claim 1 or claim 2, wherein In the mutual authentication process of confirming the mutual legality of the information processing device and the host device, The sub-control unit uses the USB Type-C to send the password information obtained by encrypting the information containing the random number with the public key and the hash value of the information containing the random number, that is, the first hash value, to the host device, The host device generates the hash value of the information obtained by decrypting the received password information with the secret key, that is, the second hash value. When the received first hash value is the same as the second hash value, it is determined that the information processing device is legal, When the host device determines that the information processing device is legal, the host device generates a digital signature based on the specified information using the secret key and sends the digital signature to the sub-control unit using the USB Type-C, The sub-control unit confirms the legality of the host device based on the received digital signature and the public key.

4. The information processing system according to claim 3, wherein The host device encrypts the hash value of the specified information, that is, the third hash value, with the secret key to generate the digital signature, The sub-control unit determines that the host device is legal when the third hash value is the same as the fourth hash value obtained by decrypting the received digital signature with the public key.

5. The information processing system according to claim 3, wherein The host device and the sub-control unit execute the mutual authentication process using the CC signal line of the USB Type-C.

6. The information processing system according to claim 1 or claim 2, wherein Based on the above secret key stored in the USB device connected to the above upper device and the above public key held by the above information processing device, the mutual legality between the above information processing device and the above upper device is confirmed.

7. The information processing system according to claim 1 or claim 2, wherein Based on the above secret key stored in the server device connected to the above upper device via the network and the above public key held by the above information processing device, the mutual legality between the above information processing device and the above upper device is confirmed.

8. An information processing device includes: an information processing device that holds the public key among the secret key and the public key of a public key cryptography distributed corresponding to the device, and is shipped in a locked state in which OS-based startup is prohibited; And an upper device, an information processing device of an information processing system capable of being connected to the information processing device through an interface of USB Type-C, wherein Comprising: A main control unit that executes processing based on the above OS and BIOS; And A sub-control unit that is a sub-control unit capable of operating in a state where power is not supplied to the main control unit, and when the mutual legality between the information processing device and the upper device is confirmed based on the above secret key and the above public key using the above USB Type-C, the above locked state is released.

9. An information processing method, which is an information processing method of an information processing system. The information processing system includes: an information processing device having a main control unit that executes processing based on an OS and a BIOS, and a sub-control unit that can operate in a state where power is not supplied to the main control unit; and an upper device that can be connected to the information processing device through a USB Type-C interface. Among them, Including: A step in which the above information processing device holds the above public key among the secret key and the public key of the public password allocated corresponding to the device, and is shipped from the factory in a locked state in which startup based on the above OS is prohibited; A step in which the above information processing device is connected to the above upper device through the interface of the above USB Type-C; and A step in which the above sub-control unit releases the above locked state when the mutual legality between the information processing device and the above upper device is confirmed based on the above secret key and the above public key using the above USB Type-C.

Citation Information

Patent Citations

  • Information processor and start-up program of the information processor

    JP2010152721A