Information processing system and method, program product, and normality assurance system
By introducing a processor into the information processing system, using first and second confirmation information to verify the normality of the startup program, and granting communication after mutual confirmation between multiple systems, the network security vulnerability caused by the rewriting of the IoT device startup program is solved, and the normality guarantee of the startup program and the reliability of communication are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FUJIFILM BUSINESS INNOVATION CORP
- Filing Date
- 2025-05-12
- Publication Date
- 2026-05-08
AI Technical Summary
In information processing systems, especially when the startup program of IoT devices is improperly rewritten, it may become a cybersecurity vulnerability, and existing technologies cannot effectively guarantee the normality of the startup program.
By introducing a processor into the information processing system, the normality of the startup program is confirmed using first and second confirmation information, ensuring mutual confirmation with other pre-registered systems. External devices are only permitted to communicate when multiple systems consistently confirm that the system is normal. The monitoring system can be implemented through a cloud server or edge server.
It provides a guarantee of the normality of the startup program, improves the reliability of communication, prevents communication to the outside of the local area network when the startup program is not guaranteed to be normal, and enhances network security.
Smart Images

Figure CN121997326A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to information processing systems, information processing methods, program products, and normality guarantee systems. Background Technology
[0002] Japanese Patent Application Publication No. 2009-259160 describes a system for preventing improper program startup, which controls a program that works in conjunction with a TPM (Trusted Platform Module) security chip installed on the motherboard of a PC (Personal Computer) to ensure that only the correct program works.
[0003] Japanese Patent Application Publication No. 2020-140665 describes a procedure for ensuring the safety of a device during startup.
[0004] Japanese Patent Application Publication No. 2021-190808 describes an information processing system that combines the security management of IoT (Internet of Things) with the security management of its stored data. Summary of the Invention
[0005] If the startup program of an information processing system that can connect to the Internet, also known as an IoT device, is improperly rewritten, it could become a security vulnerability on the network. Therefore, it is desirable to ensure the proper functioning of the startup program for information processing systems connected to the network.
[0006] The purpose of this invention is to provide an information processing system, information processing method, program product, and normality guarantee system that can guarantee the normality of the startup program.
[0007] According to a first aspect of the present invention, an information processing system is provided, comprising a processor that, upon confirming that the startup program is normal with reference to first confirmation information for confirming the normality of the startup program, performs startup based on the startup program, communicates with one or more pre-registered other systems, mutually confirms the normality of the startup program with other systems with reference to second confirmation information for confirming the normality of the startup program with other systems, and permits communication with external devices when the startup program is mutually confirmed to be normal with a set number or more of other systems.
[0008] According to a second aspect of the present invention, in the information processing system involved in the first aspect, at least one of the first confirmation information and the second confirmation information is a hash value of the startup program.
[0009] According to a third aspect of the invention, in the information processing system according to the second aspect, the startup program is composed of a plurality of programs, and the hash value of the startup program is a hash value derived from each of the plurality of programs constituting the startup program.
[0010] According to a fourth aspect of the invention, in the information processing system according to the second aspect, the startup program is composed of multiple programs, and the hash value of the startup program is a hash value derived from the startup program as a whole.
[0011] According to a fifth aspect of the present invention, in the information processing system according to any one of the first to fourth aspects, in a monitoring system for verifying the matching of normal confirmation of a startup program by the processor in obtaining confirmation results of normal confirmation of the startup program from the system itself and other systems, communication with the external device is permitted if the confirmation results in the system itself are consistent with the confirmation results in other systems.
[0012] According to a sixth aspect of the invention, in the information processing system described in the fifth aspect, the monitoring system is implemented via a cloud server.
[0013] According to a seventh aspect of the invention, in the information processing system described in the fifth aspect, the monitoring system is implemented via an edge server of a local area network including the system.
[0014] According to an eighth aspect of the present invention, a program product is provided, comprising a program for causing a computer to perform processing, wherein the processing includes the following steps: upon confirming that the startup program is normal by referring to first confirmation information for confirming the normality of the startup program, performing startup based on the startup program; communicating with one or more pre-registered other systems, mutually confirming with other systems that the startup program is normal by referring to second confirmation information for confirming the normality of the startup programs of other systems; and, upon mutually confirming that the startup program is normal with a set number or more of other systems, permitting communication with an external device.
[0015] According to a ninth aspect of the present invention, a normality guarantee system is provided, comprising: a plurality of information processing systems; and a monitoring system, wherein the plurality of information processing systems includes a processor, which, upon confirming that a startup program is normal by referring to first confirmation information for confirming the normality of a startup program, performs startup based on the startup program, communicates with one or more pre-registered other systems, mutually confirms the normality of the startup program with other systems by referring to second confirmation information for confirming the normality of the startup programs of other systems, and in the monitoring system that confirms the normality of the startup program by mutually confirming the normality of the startup program with a set number or more other systems and obtains information on the confirmation results of the normality confirmation of the startup program from the plurality of information processing systems to confirm the matching of the normality confirmation of the startup program, allows communication with an external device if the confirmation result in the monitoring system is consistent with the confirmation results in other systems.
[0016] According to a tenth aspect of the present invention, an information processing method is provided, comprising the steps of: performing a startup based on the startup program after confirming that the startup program is normal by referring to first confirmation information for confirming the normality of the startup program; communicating with one or more pre-registered other systems, mutually confirming that the startup program is normal with the other systems by referring to second confirmation information for confirming the normality of the startup program of the other systems; and permitting communication with an external device after mutually confirming that the startup program is normal with a set number or more of the other systems.
[0017] (Effect)
[0018] Based on the first and tenth aspects, the normality of the startup procedure can be guaranteed.
[0019] According to the second aspect, it is possible to confirm that the startup program is working correctly without using any information other than the startup program itself.
[0020] Based on the third aspect, it can be confirmed whether each program is functioning correctly.
[0021] According to the fourth aspect, the confirmation of starting the program can be completed with a single confirmation.
[0022] According to the fifth aspect, the reliability of the guarantee of normality can be improved compared to the case where the normality of the initiation procedure is guaranteed solely by this system.
[0023] According to the sixth aspect, compared with the case where the normality of the startup program is guaranteed only by this system without preparing hardware for monitoring the system, the reliability of the guarantee of normality can be improved.
[0024] According to the seventh aspect, it is possible to prevent communication to the outside of the local area network when the normality of the startup program is not guaranteed.
[0025] According to the eighth aspect, the normality of the startup procedure can be guaranteed.
[0026] According to the ninth aspect, the normality of the startup procedure can be guaranteed. Attached Figure Description
[0027] Figure 1 This is a diagram illustrating the system structure of a normality guarantee system according to one embodiment of the present invention;
[0028] Figure 2 This is a block diagram illustrating the hardware structure of a surveillance camera according to one embodiment of the present invention;
[0029] Figure 3 This is a block diagram illustrating the hardware structure of an edge server and a cloud server according to an embodiment of the present invention.
[0030] Figure 4 This is a diagram illustrating the data structure of a surveillance camera according to one embodiment of the present invention;
[0031] Figure 5 This is a flowchart of the confirmation result verification process;
[0032] Figure 6 This is a flowchart of the program termination process;
[0033] Figure 7 This is a flowchart of the connection confirmation process;
[0034] Figure 8 This is a flowchart of the confirmation result verification process;
[0035] Figure 9 This is a diagram used to illustrate the mutual confirmation result information of an edge server integrated in one embodiment of the present invention;
[0036] Figure 10 This is a flowchart showing the system continuing to terminate the process. Detailed Implementation
[0037] The following detailed description of the technical embodiments used to implement the present invention is provided with reference to the accompanying drawings. Figure 1 This is a diagram illustrating the system structure of a normality guarantee system according to one implementation method.
[0038] like Figure 1 As shown, the normality guarantee system of this embodiment includes: surveillance cameras 10A, 10B, and 10C that can be connected to the Internet 40; an edge server 20; and a cloud server 30.
[0039] The normality guarantee system is a system that can guarantee the normality of the startup procedures of surveillance cameras 10A, 10B, and 10C that can be connected to the Internet 40.
[0040] In addition, Figure 1 The document shows three surveillance cameras: surveillance camera 10A, surveillance camera 10B, and surveillance camera 10C. However, in the following description, unless it is necessary to distinguish between the individual cameras, they will be referred to as surveillance camera 10.
[0041] Surveillance camera 10 is an IoT device that can connect to the Internet 40. Surveillance camera 10 connects to the Internet 40 via edge server 20 (described later). Surveillance camera 10 has a photographic function and sends the image data acquired through photography to cloud server 30 (described later). Surveillance camera 10 is an example of an information processing system in the technology of this invention.
[0042] Edge server 20 is connected to the Internet 40 and local area network 45. Edge server 20 functions as a repeater for connecting devices connected to local area network 45 to the Internet 40. Edge server 20 is an example of a monitoring system according to the technology of this invention.
[0043] The cloud server 30 is a server used to manage image data and other data received from the surveillance camera 10 via the Internet 40.
[0044] Next, the hardware structure of the surveillance camera 10 in this embodiment will be described. Figure 2 This is a block diagram showing the hardware structure of the surveillance camera 10.
[0045] like Figure 2 As shown, the surveillance camera 10 includes a control unit 11, a communication interface (abbreviated as communication IF) 12, a user interface device (abbreviated as UI device) 13, and a camera 14. These structural elements are interconnected via a control bus 15.
[0046] The control unit 11 includes a processor 11a, a memory 11b, and a storage unit 11c. The processor 11a executes predetermined processes based on a program read from the storage unit 11c and expanded in the memory 11b. The storage unit 11c is composed of, for example, a ROM, HDD, or SSD. Various programs and data are stored in the storage unit 11c.
[0047] Furthermore, in this embodiment, the processor 11a reads and executes the program stored in the storage unit 11c, but this is not a limitation. The program may also be provided in the form of being recorded on a computer-readable recording medium as described above. Alternatively, the program may be obtained from an external device via a communication line.
[0048] The communication IF12 transmits and receives data with external devices. The UI device 13 is, for example, a touch panel and / or a button, a device used by the user to input information.
[0049] Next, the hardware structure of the edge server 20 in this embodiment will be described. Figure 3 This is a block diagram representing the hardware structure of edge server 20. Furthermore, Figure 2 The block diagram is the same as that showing the hardware structure of the cloud server 30 described later.
[0050] like Figure 3 As shown, the edge server 20 includes a control unit 21, a communication interface 22, and a user interface (UI) device 23. These structural elements are interconnected via a control bus 24.
[0051] The control unit 21 includes a processor 21a, a memory 21b, and a storage unit 21c. The processor 21a executes predetermined processes based on a control program read from the storage unit 21c and expanded in the memory 21b. The storage unit 21c is composed of, for example, ROM, HDD, or SSD. Various programs and data are stored in the storage unit 21c.
[0052] Furthermore, this embodiment describes the case where the processor 21a reads and executes the program stored in the storage unit 21c, but it is not limited to this. The program may also be provided in the form of being recorded on a computer-readable recording medium as described above. Alternatively, the program may be obtained from an external device via a communication line.
[0053] The communication IF22 transmits and receives data with external devices. The UI device 23 is, for example, a mouse and / or keyboard, a device used by the user to input information.
[0054] Next, the hardware structure of the cloud server 30 in this embodiment will be described. For example... Figure 3 As shown, the cloud server 30 includes a control unit 31, a communication interface 32, and a user interface (UI) device 33. These structural elements are interconnected via a control bus 34.
[0055] These structural elements are common to edge server 20, so detailed descriptions are omitted.
[0056] If the startup program of the surveillance camera 10, which can connect to the Internet 40, is improperly rewritten, it could become a security vulnerability in the network. Therefore, it is desirable to ensure the proper functioning of the startup program of the surveillance camera 10, which can connect to the Internet 40.
[0057] To fulfill this requirement, the control unit 11 of the surveillance camera 10 in this embodiment confirms that the startup program is normal by referring to the first confirmation information used to confirm the normality of the startup program, starts the program based on the startup program, communicates with one or more pre-registered other devices, mutually confirms the normality of the startup program with other devices by referring to the second confirmation information used to confirm the normality of the startup program with other devices, and permits communication with external devices such as the cloud server 30 when the startup program is mutually confirmed to be normal with a set number or more of other devices.
[0058] Here, at least one of the first confirmation information and the second confirmation information may also be set as the hash value of the startup program. Here, "hash value" means other data generated from the original data (here, the startup program) using a specific algorithm.
[0059] In this case, when the startup program consists of multiple programs, the hash value of the startup program can be set to a hash value derived from each of the multiple programs that make up the startup program, or it can be set to a hash value derived from the startup program as a whole.
[0060] Alternatively, the control unit 11 may be configured to allow communication with external devices such as the cloud server 30 when the confirmation results in the control unit are consistent with the confirmation results in other devices, in a monitoring system that obtains confirmation results of the normal confirmation of the startup program from the control unit and other devices.
[0061] In this case, the monitoring system can be implemented through a cloud server 30 or through an edge server 20 that includes the local area network 45 of this device. In this embodiment, as an example, the edge server 20 is used as the monitoring system.
[0062] The processing in the surveillance camera 10 of this embodiment will be described in detail below. Figure 4 This is a diagram used to illustrate the data structure of the surveillance camera 10. Furthermore, in Figure 4 As an example, the data structure of surveillance camera 10A is shown, but the data structure is basically the same in surveillance cameras 10B and 10C.
[0063] The storage unit 11c of the surveillance camera 10 stores first confirmation information and second confirmation information in advance during the factory shipment stage.
[0064] The first confirmation message is used to confirm that the device's startup procedure is normal. For example... Figure 4As shown, in this embodiment, as an example, the startup procedure of the surveillance camera 10 consists of four programs: program A, program B, program C, and program D. The first confirmation information is a hash value derived from each of the four programs.
[0065] The second confirmation information is used to confirm that the startup procedures of other devices are normal. Regarding surveillance camera 10, other surveillance cameras 10 that will be combined with each other in the normality assurance system are known at the factory stage. In this embodiment, as an example, surveillance cameras 10A, 10B, and 10C are combined with each other. The second confirmation information is a hash value derived from the individual identifiers of other devices and the startup procedures of the other devices as a whole.
[0066] For example, such as Figure 4 As shown, in surveillance camera 10A, as the second confirmation information, the individual identifier of surveillance camera 10B, the hash value exported from the startup program of surveillance camera 10B, the individual identifier of surveillance camera 10C, and the hash value exported from the startup program of surveillance camera 10C are stored.
[0067] After the monitoring camera 10 is installed in the normality guarantee system, when the monitoring camera 10 is started, the control unit 11 of the monitoring camera 10 refers to the first confirmation information used to confirm the normality of the startup procedure and confirms that the startup procedure of the device is normal.
[0068] Specifically, such as Figure 5 As shown in the flowchart, in step ST01, the control unit 11 executes the startup procedure.
[0069] Next, in step ST02, the control unit 11 executes a monitoring program to verify the normality of the startup program, etc.
[0070] Next, based on the monitoring program, the control unit 11 determines, in steps ST03 to ST05, whether the hash value of the program executed at startup is consistent with the first confirmation information for each of the programs included in the startup program.
[0071] In step ST04, if it is determined that the hash value of the program is inconsistent with the first confirmation information, the control unit 11 transfers to... Figure 6 The program termination flow is shown below.
[0072] In the program termination process, in step ST11, the control unit 11 forcibly terminates the program that is determined to be inconsistent with the first confirmation information.
[0073] Next, in step ST12, the control unit 11 issues an alarm indicating an abnormal startup procedure and terminates the startup of the device. Regarding the alarm notification, either an LED-based indicator or a sound-based notification can be used.
[0074] Back Figure 5 In steps ST03 to ST05, if it is determined that the hash values of all programs match the first confirmation information, the startup of the monitoring camera 10 is completed by executing all programs included in the startup procedure. Then, the control unit 11 proceeds to the connection confirmation process described later.
[0075] Next, the control unit 11 communicates with other pre-registered devices, refers to the second confirmation information used to confirm the normality of the startup program of other devices, and mutually confirms with other devices that the startup program is normal. If the startup program is mutually confirmed to be normal with more than a set number of other devices, communication with external devices such as the cloud server 30 is permitted.
[0076] Specifically, such as Figure 7 As shown in the flowchart of the connection confirmation process, the control unit 11, based on the monitoring program, performs mutual confirmation with all the monitoring cameras 10 included in the second confirmation information in steps ST21 to ST27. The control unit 11 stores the mutual confirmation results as mutual confirmation result information in the storage unit 11c.
[0077] For example, such as Figure 4 As shown, surveillance camera 10A stores information from surveillance camera 10B (OK (consistent)) and surveillance camera 10C (NG (inconsistent)) as second confirmation information. Therefore, surveillance camera 10A performs mutual confirmation with surveillance camera 10B and with surveillance camera 10C.
[0078] Regarding mutual confirmation, for each of the other surveillance cameras 10, in step ST22, the control unit 11 exchanges the inherent identifier and the hash value of the startup procedure with the target surveillance camera 10.
[0079] Next, in step ST23, the control unit 11 determines whether the exchanged information is consistent with the second confirmation information.
[0080] In step ST23, if it is determined that the exchanged information is inconsistent with the second confirmation information, the control unit 11 cuts off the mutual communication with the target surveillance camera 10 in step ST26.
[0081] Next, in step ST27, after storing the confirmation result in the storage unit 11c, the control unit 11 moves to the beginning of the connection confirmation process.
[0082] In addition, in step ST23, if it is determined that the exchanged information is consistent with the second confirmation information, the control unit 11 stores the confirmation result in the storage unit 11c in step ST24.
[0083] After mutual confirmation with all surveillance cameras 10 (ST25), the control unit 11 determines in step ST28 whether the number of normal surveillance cameras 10 is above the set number.
[0084] In this embodiment, three surveillance cameras 10 are installed in the normality guarantee system. Furthermore, each surveillance camera 10 performs mutual verification with the other two surveillance cameras 10. Therefore, the maximum number is set to 2, which is set to "1" here. Alternatively, the set number can be any value, such as all the surveillance cameras 10 performing mutual verification.
[0085] In step ST28, if the number of surveillance cameras 10 that are determined to be normal is not greater than the set number, the control unit 11 moves to the beginning of the connection confirmation process.
[0086] In step ST28, if the number of surveillance cameras 10 determined to be normal exceeds a set number, the control unit 11 switches to... Figure 8 The confirmation result verification process is shown below.
[0087] Next, the control unit 11 obtains information from the confirmation results of the normal confirmation of the respective startup programs from the device and other devices to confirm the matching of the normal confirmation of the startup program in the edge server 20. If the confirmation result in the device is consistent with the confirmation result in the other devices, communication with external devices such as the cloud server 30 is permitted.
[0088] Specifically, such as Figure 8 As shown in the flowchart of the confirmation result verification process, the control unit 11 of the surveillance camera 10 sends the inherent identifier of the device and the mutual confirmation result information to the edge server 20 in step ST31 based on the monitoring program.
[0089] This is performed on all surveillance cameras 10A, 10B, and 10C included in the normality guarantee system. Therefore, as Figure 9 As shown, the edge server 20 contains all the unique identifiers and mutual confirmation result information of surveillance cameras 10A, 10B, and 10C.
[0090] In addition, the storage unit 21c of the edge server 20 contains a list of all the inherent identifiers of the surveillance cameras 10A, 10B and 10C included in the normality guarantee system.
[0091] Next, the control unit 21 of the edge server 20 performs the following processing on each surveillance camera 10 based on the control program. First, in step SS01, the control unit 21 determines whether the unique identifier received from the surveillance camera 10 is included in the list.
[0092] In step SS01, if it is determined that the unique identifier received from the surveillance camera 10 is not included in the list, the control unit 21 transfers to... Figure 10 The system shown continues to terminate the process.
[0093] During the system's continued termination process, in step SS11, the control unit 21 disconnects the connection with all surveillance cameras 10.
[0094] Next, in step SS12, the control unit 21 issues an alarm indicating that the normality guarantee system is malfunctioning, and terminates the process. Regarding the alarm notification, either an LED-based indicator or a sound-based notification can be used.
[0095] Back Figure 8 In step SS01, when it is determined that the inherent identifier received from the surveillance camera 10 is included in the list, the control unit 21 determines in step SS02 whether the mutual confirmation result information received from the surveillance camera 10 matches the mutual confirmation result information received from the device.
[0096] In step SS02, if it is determined that the mutual confirmation result information received from the surveillance camera 10 does not match the mutual confirmation result information received from other devices, the control unit 21 transfers to the aforementioned... Figure 10 The system shown continues to terminate the process.
[0097] In step SS02, if it is determined that the mutual confirmation result information received from the monitoring camera 10 matches the mutual confirmation result information received from other devices, the control unit 21 sends a communication permission to the monitoring camera 10 with the external device in step SS03.
[0098] When the control unit 11 of the surveillance camera 10 receives a communication permission from the edge server 20, it begins communication with external devices such as the cloud server 30 in step ST32.
[0099] [Variation Example]
[0100] The information processing system according to one embodiment of the present invention has been described above, but the technology of the present invention is not limited to the above embodiment and can be appropriately modified.
[0101] For example, in the above embodiment, the surveillance camera 10 was used as an example of an information processing system, but the information processing system can be any IoT device that can be connected to the Internet 40, such as a human sensor.
[0102] In the above embodiments, processor refers to processor in a broad sense, including general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and special-purpose processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic devices, etc.).
[0103] Furthermore, the actions of the processor in the above embodiments are not performed by a single processor, but can also be accomplished collaboratively by multiple processors located in physically separate positions. Additionally, the order of the processor's actions is not limited to the order described in the above embodiments and can be appropriately modified.
[0104] Furthermore, in the technology of this invention, the system includes both a system composed of multiple devices and a system composed of a single device.
[0105] In addition, the technology of this invention can also be applied to programs and program products.
[0106] [Postscript] (((1)))
[0108] An information processing system, wherein,
[0109] Equipped with a processor
[0110] The processor
[0111] If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup process is performed based on that startup program.
[0112] It communicates with one or more pre-registered other systems, referring to second confirmation information used to verify the normality of the startup procedures of other systems, and mutually confirms with other systems that the startup procedures are normal.
[0113] Communication with external devices is permitted only after the startup process has been mutually verified with a set number or more other systems. (((2)))
[0115] According to the information processing system described in ((1)), wherein,
[0116] At least one of the first confirmation information and the second confirmation information is the hash value of the startup program. (((3)))
[0118] According to the information processing system described in ((2)), wherein,
[0119] The startup program consists of multiple programs.
[0120] The startup program's hash value is derived from the hash values of each of the multiple programs that make up the startup program. (((4)))
[0122] According to the information processing system described in ((2)), wherein,
[0123] The startup program consists of multiple programs.
[0124] The startup program's hash value is derived from the hash value of the startup program as a whole. (((5)))
[0126] The information processing system according to any one of ((1))) to ((4))) wherein,
[0127] The processor
[0128] In a monitoring system that verifies the matching of normal startup confirmations by obtaining confirmation results from this system and other systems, communication with the external device is permitted if the confirmation results in this system are consistent with the confirmation results in other systems. (((6)))
[0130] According to the information processing system described in ((5)), wherein,
[0131] The monitoring system is implemented through a cloud server. (((7)))
[0133] According to the information processing system described in ((5)), wherein,
[0134] The monitoring system is implemented through an edge server on a local area network that includes the system itself. (((8)))
[0136] A program that causes a computer to perform a process, wherein the process has the following steps:
[0137] If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup program is launched.
[0138] Communicating with one or more pre-registered other systems, referring to second confirmation information used to verify the normality of the startup procedures of other systems, and mutually confirming with other systems that the startup procedures are normal; and
[0139] Communication with external devices is permitted only after the startup process has been mutually verified with a set number or more other systems. ((9)))
[0141] A normality guarantee system, which has:
[0142] Multiple information processing systems; and
[0143] Monitoring system
[0144] The aforementioned multiple information processing systems are equipped with processors.
[0145] The processor
[0146] If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup process is performed based on that startup program.
[0147] It communicates with one or more pre-registered other systems, referring to second confirmation information used to verify the normality of the startup procedures of other systems, and mutually confirms with other systems that the startup procedures are normal.
[0148] In a monitoring system that verifies the normality of startup procedures by mutually confirming the startup procedures with a set number or more other systems and obtaining confirmation results from the multiple information processing systems to verify the matching of startup procedure normality confirmations, communication with external devices is permitted if the confirmation results in this system are consistent with the confirmation results in other systems.
[0149] The effects of the appendix-based structure are described below.
[0150] According to the information processing system (((1))), the normality of the startup program can be guaranteed.
[0151] According to the information processing system of ((2)), the normal operation of the startup program can be confirmed without using information other than the startup program.
[0152] According to the information processing system of ((3)), it is possible to confirm whether each program is normal.
[0153] According to the information processing system ((4)), the confirmation of the startup program can be completed with a single confirmation.
[0154] According to the information processing system of ((5)), the reliability of the guarantee of normality can be improved compared with the case where the normality of the initiation procedure is guaranteed only by this system.
[0155] According to the information processing system ((6)), compared with the case where the normality of the startup program is guaranteed only by the system without the hardware to be monitored, the reliability of the guarantee of normality can be improved.
[0156] According to the information processing system (((7))), it is possible to prevent communication to the outside of the local area network when the normality of the startup program is not guaranteed.
[0157] According to the procedure (((8))), the normality of the startup procedure can be guaranteed.
[0158] According to the normality guarantee system of ((9)), the normality of the initiation procedure can be guaranteed.
Claims
1. An information processing system, characterized in that, Equipped with a processor The processor If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup process is performed based on that startup program. It communicates with one or more pre-registered other systems, referring to second confirmation information used to verify the normality of the startup procedures of other systems, and mutually confirms with other systems that the startup procedures are normal. Communication with external devices is permitted only after the startup process has been mutually verified with a set number or more other systems.
2. The information processing system according to claim 1, wherein, At least one of the first confirmation information and the second confirmation information is the hash value of the startup program.
3. The information processing system according to claim 2, wherein, The startup program consists of multiple programs. The startup program's hash value is derived from the hash values of each of the multiple programs that make up the startup program.
4. The information processing system according to claim 2, wherein, The startup program consists of multiple programs. The startup program's hash value is derived from the hash value of the startup program as a whole.
5. The information processing system according to any one of claims 1 to 4, wherein, The processor In a monitoring system that verifies the matching of normal startup confirmations by obtaining confirmation results from this system and other systems, communication with the external device is permitted if the confirmation results in this system are consistent with the confirmation results in other systems.
6. The information processing system according to claim 5, wherein, The monitoring system is implemented through a cloud server.
7. The information processing system according to claim 5, wherein, The monitoring system is implemented through an edge server on a local area network that includes the system itself.
8. A program product comprising a program that causes a computer to perform processing, characterized in that, The process comprises the following steps: If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup program is launched. It communicates with one or more pre-registered other systems, and mutually confirms with other systems that the startup program is normal by referring to the second confirmation information used to confirm the normality of the startup program of other systems; as well as Communication with external devices is permitted only after the startup process has been mutually verified with a set number or more other systems.
9. A normality guarantee system, characterized in that, have: Multiple information processing systems; and Monitoring system The aforementioned multiple information processing systems are equipped with processors. The processor If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup process is performed based on that startup program. It communicates with one or more pre-registered other systems, referring to second confirmation information used to verify the normality of the startup procedures of other systems, and mutually confirms with other systems that the startup procedures are normal. In a monitoring system that verifies the normality of startup procedures by mutually confirming the startup procedures with a set number or more other systems and obtaining confirmation results from the multiple information processing systems to verify the matching of startup procedure normality confirmations, communication with external devices is permitted if the confirmation results in this system are consistent with the confirmation results in other systems.
10. An information processing method, characterized in that, It has the following steps: If the startup program is confirmed to be functioning correctly by referring to the first confirmation information used to verify its functionality, then the startup program is launched. It communicates with one or more pre-registered other systems, and mutually confirms with other systems that the startup program is normal by referring to the second confirmation information used to confirm the normality of the startup program of other systems; as well as Communication with external devices is permitted only after the startup process has been mutually verified with a set number or more other systems.
Citation Information
Patent Citations
System and method for preventing unauthorized program start
JP2009259160A
Program, device and activation method
JP2020140665A
Information processing system, information processing method, IoT device, information processing device and control program therefor
JP2021190808A