Image processing device, backup holding method, and program
The image processing device addresses storage capacity constraints by automatically switching backup firmware based on device status, ensuring effective storage usage and appropriate processing when firmware tampering is detected.
Patent Information
- Application Number
- JP2023192743
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-23
AI Technical Summary
Conventional image processing apparatuses face challenges in storing duplicate firmware due to storage capacity constraints, which can lead to inadequate processing when firmware tampering is detected, especially in low-cost devices or when storage devices are added or removed.
An image processing device with a first memory unit for staging multiple firmwares and a second memory unit for storing a selected firmware as a backup, equipped with a tampering detection unit, recovery processing unit, and selection unit that automatically switches the backup firmware based on device status to optimize storage usage.
This solution enables effective use of storage area while ensuring appropriate processing when firmware is tampered with, even in devices with limited storage capacity, by automatically managing backup firmware based on device status.
Smart Images

Figure 2025079890000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an image processing apparatus, a backup holding method, and a program.
Background Art
[0002] In an image processing apparatus such as an MFP (Multifunction Peripheral), there is known one that detects whether firmware has been tampered with at startup (for example, Patent Documents 1 and 2). These conventional image processing apparatuses store backup data of the firmware separately from the startup firmware. When detecting firmware tampering at startup of the firmware, the image processing apparatus restores the firmware from the backup data and starts up using the restored firmware.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, when storing all the firmware installed in the image processing apparatus in duplicate for startup and backup, it is necessary to mount a storage device with sufficient storage capacity in the image processing apparatus, which is a factor in cost increase. Therefore, an image processing apparatus such as a low-cost image processing apparatus that does not have sufficient storage capacity to store all the firmware in duplicate cannot apply the above-described conventional technology and cannot execute appropriate processing when the firmware is tampered with.
[0005] In addition, storage devices such as hard disk drives (HDDs) and solid state drives (SSDs) installed in image processing devices may be added as options to the image processing device or removed from the image processing device. In particular, if a storage device is removed when all firmware in the image processing device is duplicated and stored, there is a possibility that sufficient storage capacity for storing the firmware duplicated cannot be secured.
[0006] Furthermore, a firmware update may increase the amount of firmware data, which may result in a case where an image processing device is unable to secure sufficient storage capacity to store duplicated firmware even though the image processing device had duplicated firmware stored therein before the firmware update.
[0007] On the other hand, instead of storing the firmware in duplicate, a method of acquiring the firmware from outside via a network and updating it is conceivable. However, depending on the user environment in which the image processing device is installed, acquiring firmware from outside via a network may not be permitted. In such a state, if firmware tampering is detected, the image processing device cannot acquire and update the firmware from outside, and therefore cannot restore the firmware.
[0008] The present invention has been made to solve the above-mentioned problems in the prior art. That is, an object of the present invention is to provide an image processing device, a backup storage method, and a program that can automatically switch firmware to be stored as a backup depending on the device status, thereby enabling effective use of storage area while also enabling appropriate processing when firmware is tampered with. [Means for solving the problem]
[0009] In order to achieve the above-mentioned object, the invention of claim 1 is an image processing device comprising: a first memory unit that stores multiple firmwares that are started in stages; a second memory unit that stores a firmware selected from the multiple firmwares as a backup; a tampering detection unit that detects tampering with each of the multiple firmwares stored in the first memory unit; a recovery processing unit that recovers the tampered firmware using the firmware stored in the second memory unit when tampering with the firmware is detected by the tampering detection unit; and a selection unit that selects firmware to be stored as a backup in the second memory unit depending on the device status.
[0010] The invention according to claim 2 is the image processing device of claim 1, characterized in that the second storage unit stores the firmware selected by the selection unit in a non-rewritable storage area.
[0011] The invention of claim 3 is characterized in that, in the image processing device of claim 1, the selection unit selects firmware to be stored as a backup in the second memory unit from among the multiple firmware based on the memory capacity of the second memory unit.
[0012] The invention of claim 4 is characterized in that, in the image processing device of claim 1, the selection unit selects firmware to be stored as a backup in the second memory unit from among the multiple firmwares based on a change in the data amount of the multiple firmwares.
[0013] The invention of claim 5 is characterized in that, in the image processing device of claim 1, it further comprises an acquisition unit that acquires the multiple firmware from an external device via a network, and a setting unit that sets the acquisition of firmware by the acquisition unit to prohibited or permitted, and the selection unit selects firmware to be stored as a backup in the second memory unit based on the setting by the setting unit.
[0014] The invention of claim 6 is characterized in that, in the image processing device of claim 5, when the setting unit prohibits the acquisition unit from acquiring firmware, the selection unit selects firmware that can notify that firmware tampering has been detected as firmware to be stored as a backup in the second memory unit.
[0015] The invention of claim 7 is characterized in that, in the image processing device of claim 5, when the setting unit permits the acquisition unit to acquire firmware, the selection unit selects firmware required for the acquisition unit to acquire and update firmware from the external device as firmware to be stored as a backup in the second memory unit.
[0016] The invention of claim 8 is characterized in that, in the image processing device of claim 3, the selection unit selects all of the multiple firmware when the second memory unit is capable of storing all of the multiple firmware.
[0017] The invention of claim 9 is characterized in that, in the image processing device of claim 1, it further includes an update unit that updates the multiple firmware stored in the first memory unit, and the selection unit selects firmware to be stored as a backup in the second memory unit when the update unit updates the firmware, and changes the firmware to be stored in the second memory unit.
[0018] The invention of claim 10 is characterized in that, in the image processing device of claim 1, the selection unit determines whether the device state has changed at startup, and if the device state has changed, selects firmware to be stored as a backup in the second memory unit, and changes the firmware to be stored in the second memory unit.
[0019] The invention according to claim 11 is an image processing apparatus comprising: a first storage unit that stores a plurality of firmware programs to be started up step by step; a second storage unit that stores, as a backup, the firmware program selected from among the plurality of firmware programs; a forgery detection unit that detects forgery of each of the plurality of firmware programs stored in the first storage unit; and a restoration processing unit that restores the forged firmware program using the firmware program stored in the second storage unit when forgery of the firmware program is detected by the forgery detection unit. A backup retention method for controlling the firmware program retained as a backup in the second storage unit, the method comprising: a selection step of selecting, according to the apparatus state, the firmware program to be stored as a backup in the second storage unit from among the plurality of firmware programs; and a change step of changing the firmware program retained as a backup in the second storage unit according to the selection result of the selection step.
[0020] The invention according to claim 12 is a program executed in an image processing apparatus comprising: a first storage unit that stores a plurality of firmware programs to be started up step by step; a second storage unit that stores, as a backup, the firmware program selected from among the plurality of firmware programs; a forgery detection unit that detects forgery of each of the plurality of firmware programs stored in the first storage unit; and a restoration processing unit that restores the forged firmware program using the firmware program stored in the second storage unit when forgery of the firmware program is detected by the forgery detection unit. The program causes the image processing apparatus to execute: a selection step of selecting, according to the apparatus state, the firmware program to be stored as a backup in the second storage unit from among the plurality of firmware programs; and a change step of changing the firmware program retained as a backup in the second storage unit according to the selection result of the selection step.
Advantages of the Invention
[0021] According to the present invention, the firmware to be stored as a backup is automatically switched depending on the device status. Therefore, it is possible to back up firmware according to the device status of the image processing device, and it is possible to effectively use the storage area while taking appropriate action when the firmware is tampered with. [Brief description of the drawings]
[0022] [Figure 1] FIG. 1 is a diagram illustrating an example of a conceptual configuration of a network system including an image processing apparatus. [Diagram 2] FIG. 2 is a block diagram showing an example of a hardware configuration of the image processing device. [Diagram 3] 4 is a block diagram showing a functional configuration of a control unit; FIG. [Figure 4] 13 is a flowchart showing an example of a processing procedure performed by the security chip. [Diagram 5] 10 is a flowchart showing an example of a processing procedure performed by a setting unit of a basic operation control unit. [Figure 6] 11 is a flowchart illustrating an example of a main process performed by a firmware update unit. [Figure 7] 10 is a flowchart illustrating an example of a detailed procedure of a firmware update process. [Figure 8] 13 is a flowchart illustrating an example of a detailed procedure for determining whether or not a backup is held. [Figure 9] 13 is a flowchart illustrating an example of a detailed processing procedure of a backup change process. [Figure 10] 1A to 1C are conceptual diagrams showing examples of firmware backup storage modes. [Figure 11] 10 is a flowchart showing a processing procedure in which a firmware update unit acquires firmware from a server device. [Figure 12] 11 is a flowchart illustrating an example of a processing procedure performed by a boot processing unit when a legitimate OS firmware cannot be booted. [Figure 13]FIG. 13 is a diagram showing an example of a notification screen displayed on a display unit. [Figure 14] FIG. 11 is a block diagram showing the functional configuration of a control unit in a second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0023] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the drawings. In the following embodiments, elements common to each other are designated by the same reference numerals, and duplicated descriptions thereof will be omitted.
[0024] (First embodiment) 1 is a diagram showing an example of a conceptual configuration of a network system including an image processing device 1 according to an embodiment of the present invention. This network system includes the image processing device 1 installed in a user's office environment 5. The image processing device 1 is configured, for example, by an MFP. The image processing device 1 has multiple functions such as a scan function, a print function, and a copy function, and executes a job specified by a user.
[0025] The image processing device 1 comprises an operation panel 14, a scanner unit 18, and a printer unit 21. The operation panel 14 is a user interface when the user uses the image processing device 1. The user can perform job settings and the like by operating the operation panel 14. The scanner unit 18 operates when a scan job or a copy job is executed. The scanner unit 18 reads the image of a document set by the user and generates image data. The printer unit 21 operates when a print job or a copy job is executed. The printer unit 21 forms and outputs an image on a sheet such as printing paper based on the image data to be printed.
[0026] The image processing device 1 is connected to a local network 2 provided in an office environment 5. In addition to the image processing device 1, an information processing device 3 constituted by a personal computer (PC) or the like, and a proxy server 4 are connected to the local network 2. For example, the image processing device 1 can transmit image data generated by executing a scan job to the information processing device 3 via the local network 2. Furthermore, when the image processing device 1 receives a print job transmitted from the information processing device 3 via the local network 2, it executes the print job and forms an image on a sheet and outputs it.
[0027] The proxy server 4 connects the local network 2 to the Internet 6, which is an external network. A server device 7, which is an external device, is connected to the Internet 6. The server device 7 holds firmware 8 for the image processing device 1, and provides the latest firmware 8 to the image processing device 1 when requested by the image processing device 1. Therefore, when the image processing device 1 is permitted to access the external server device 7 via the proxy server 4, it can update its own firmware 8 by downloading the latest firmware 8 from the server device 7. The firmware 8 is a computer-readable program, and is a dedicated program for the image processing device 1.
[0028] On the other hand, if the security of the office environment 5 is strict, the image processing device 1 may be prohibited from accessing the external server device 7 via the proxy server 4. In such a case, the image processing device 1 cannot access the server device 7 to download the firmware 8. Therefore, the image processing device 1 is provided with an external device connection interface 25 for connecting an external device 9 such as a USB memory. When an external device 9 such as a USB memory is attached to the external device connection interface 25, the image processing device 1 can obtain the firmware 8 stored in the external device 9 and update the firmware 8 of its own device.
[0029] 2 is a block diagram showing an example of a hardware configuration of the image processing device 1. The image processing device 1 includes a control unit 10, an operation panel 14, a network interface 17, a scanner unit 18, a printer unit 21, a storage device 24, and an external device connection interface 25. The image processing device 1 is configured such that each of these units is connected to a bus 26, and each unit can input and output data to and from each other via the bus 26.
[0030] The control unit 10 comprehensively controls the operation of the image processing device 1. The control unit 10 includes a hardware processor 11, a memory 12, and a security chip 13. For example, the hardware processor 11, the memory 12, and the security chip 13 are mounted on one board. The hardware processor 11 reads and executes the firmware 8 stored in the memory 12. In this way, the hardware processor 11 controls the operation of each part of the image processing device 1. The memory 12 is a non-volatile storage device that stores the firmware 8. For example, the memory 12 is composed of a non-volatile random access memory (NVRAM) or the like. The memory 12 can also store data other than the firmware 8. The security chip 13 is a chip that checks whether the firmware 8 stored in the memory 12 is genuine firmware or not. The security chip 13 can detect tampering of the firmware 8.
[0031] The operation panel 14 includes a display unit 15 and an operation unit 16. The display unit 15 is configured, for example, by a color liquid crystal display, and displays various operation screens that can be operated by the user. The operation unit 16 is configured, for example, by touch panel keys arranged on the display screen of the display unit 15, and accepts operations by the user.
[0032] The network interface 17 connects the image processing device 1 to the local network 2. The image processing device 1 communicates with external devices via the network interface 17.
[0033] The scanner unit 18 includes an automatic document feeder (ADF) 19 and an image reading unit 20. The automatic document feeder 19 takes out the topmost document out of multiple documents set by the user one by one, and automatically transports it to a reading position by the image reading unit 20. The image reading unit 20 optically reads the image of the document when the document transported by the automatic document feeder 19 passes the reading position, and generates image data. The image reading unit 20 is also capable of reading the image of a document placed on a platen glass.
[0034] The printer unit 21 includes a paper feed unit 22 and an image forming unit 23. The paper feed unit 22 holds a plurality of sheets such as printing paper, and takes out the topmost sheet from the plurality of sheets one by one and transports it. The image forming unit 23 forms an image on the surface of the sheet when the sheet transported by the paper feed unit 22 passes a predetermined position.
[0035] The storage device 24 is a non-volatile storage device configured, for example, by a hard disk drive, a solid state drive, etc. The storage device 24 can store image data, job data, etc. The storage device 24 can also temporarily store firmware 8 acquired from an external device.
[0036] The external device connection interface 25 is an interface for connecting the external device 9 such as the USB memory as described above.
[0037] Fig. 3 is a block diagram showing the functional configuration of the control unit 10. As shown in Fig. 3, the memory 12 has a first storage unit 12a and a second storage unit 12b. The memory 12 stores the same firmware 8 in each of the first storage unit 12a and the second storage unit 12b. That is, the image processing device 1 can store the firmware 8 in the memory 12 in a duplicated manner.
[0038] The first storage unit 12a is a storage area for storing the boot firmware 8a executed by the hardware processor 11. The firmware 8a includes the BOOT firmware 31, the OS firmware 32, the update firmware 33, and the application firmware 34. The BOOT firmware 31 is firmware that is executed first when the image processing device 1 is started, and is firmware for starting the OS firmware 32. The OS firmware 32 is basic software of the image processing device 1, and controls the basic operation of the image processing device 1. When the OS firmware 32 is normally started by the hardware processor 11, the OS firmware 32 starts the update firmware 33 and the application firmware 34 in sequence. The update firmware 33 is software that executes the update process of the firmware 8. The application firmware 34 is software that controls the execution of a job in the image processing device 1. These multiple firmware 31, 32, 33, and 34 are started step by step in the hardware processor 11.
[0039] The second storage unit 12b is a storage area different from the first storage unit 12a, and is a storage area for storing backup firmware 8b. The firmware 8b includes the firmware for BOOT 31, the firmware for OS 32, the firmware for update 33, and the firmware for application 34, similar to the firmware 8a. However, the firmware 8b stored in the second storage unit 12b may not include all of the firmware for BOOT 31, the firmware for OS 32, the firmware for update 33, and the firmware for application 34. A write-protect setting is given to the second storage unit 12b except when the backup firmware 31, 32, 33, and 34 are rewritten. Therefore, the backup firmware 31, 32, 33, and 34 stored in the second storage unit 12b will not be tampered with during normal operation of the image processing device 1.
[0040] The security chip 13 operates immediately after the image processing device 1 is powered on, and determines whether the firmware 8a stored in the first storage unit 12a has been tampered with. The security chip 13 includes a tampering detection unit 41 and a recovery processing unit .
[0041] The tampering detection unit 41 functions when the image processing device 1 is started up. The tampering detection unit 41 sequentially checks whether or not each of the firmware for BOOT 31, the firmware for OS 32, the firmware for update 33, and the firmware for application 34 included in the firmware 8a has been tampered with.
[0042] The tampering detection unit 41 first checks whether the BOOT firmware 31 stored in the first storage unit 12a has been tampered with. For example, the tampering detection unit 41 checks whether the BOOT firmware 31 has been tampered with by signature verification or the like. Signature verification is a method of decrypting cryptographic information included in a signature with a public key and verifying whether the decrypted value matches a predetermined hash value. If the BOOT firmware 31 is genuine firmware, the decrypted value matches the predetermined hash value. On the other hand, if the BOOT firmware 31 has been tampered with, the decrypted value does not match the predetermined hash value. Therefore, if the BOOT firmware 31 has been tampered with, the tampering detection unit 41 can detect the tampering of the BOOT firmware 31.
[0043] If the BOOT firmware 31 has not been tampered with, the tampering detection unit 41 permits the hardware processor 11 to start the BOOT firmware 31. As a result, the hardware processor 11 reads the BOOT firmware 31 from the first storage unit 12a and starts it.
[0044] On the other hand, when tampering of the BOOT firmware 31 is detected, the tampering detection unit 41 causes the recovery processing unit 42 to function. The recovery processing unit 42 deletes the BOOT firmware 31 from the first storage unit 12a. After deleting the BOOT firmware 31 from the first storage unit 12a, the recovery processing unit 42 copies the BOOT firmware 31 from the second storage unit 12b to the first storage unit 12a. When the copying of the BOOT firmware 31 is completed, the recovery processing unit 42 permits the hardware processor 11 to start the BOOT firmware 31. As a result, the hardware processor 11 reads the BOOT firmware 31 from the first storage unit 12a and starts it.
[0045] When the boot process of the firmware for BOOT 31 is being performed in the hardware processor 11, the tampering detection unit 41 checks whether the firmware for OS 32 stored in the first storage unit 12a has been tampered with. This verification method is the same as the verification method of the firmware for BOOT 31.
[0046] If the firmware for the OS 32 has not been tampered with, the tamper detection unit 41 permits the hardware processor 11 to start up the firmware for the OS 32. As a result, the hardware processor 11 reads out the firmware for the OS 32 from the first storage unit 12a and starts up the firmware for the OS 32.
[0047] On the other hand, when tampering of the OS firmware 32 is detected, the tampering detection unit 41 causes the recovery processing unit 42 to function. The recovery processing unit 42 deletes the OS firmware 32 from the first storage unit 12a. After deleting the OS firmware 32 from the first storage unit 12a, the recovery processing unit 42 copies the OS firmware 32 from the second storage unit 12b to the first storage unit 12a. When the copying of the OS firmware 32 is completed, the recovery processing unit 42 permits the hardware processor 11 to start the OS firmware 32. As a result, the hardware processor 11 reads the OS firmware 32 from the first storage unit 12a and starts it.
[0048] When the boot process of the OS firmware 32 is being performed in the hardware processor 11, the tamper detection unit 41 checks whether the update firmware 33 and the application firmware 34 stored in the first storage unit 12a have been tampered with. The verification method is the same as the verification method for the BOOT firmware 31.
[0049] If the update firmware 33 has not been tampered with, the tamper detection unit 41 permits the hardware processor 11 to start the update firmware 33. As a result, the hardware processor 11 reads the update firmware 33 from the first storage unit 12a and starts it.
[0050] On the other hand, when tampering of the update firmware 33 is detected, the tampering detection unit 41 causes the recovery processing unit 42 to function. The recovery processing unit 42 deletes the update firmware 33 in the first storage unit 12a. After deleting the update firmware 33 from the first storage unit 12a, the recovery processing unit 42 copies the update firmware 33 in the second storage unit 12b to the first storage unit 12a. When copying of the update firmware 33 is completed, the recovery processing unit 42 permits the hardware processor 11 to start the update firmware 33. As a result, the hardware processor 11 reads the update firmware 33 from the first storage unit 12a and starts it.
[0051] Furthermore, if the application firmware 34 has not been tampered with, the tamper detection unit 41 permits the hardware processor 11 to start up the application firmware 34. As a result, the hardware processor 11 reads out the application firmware 34 from the first storage unit 12a and starts up the application firmware 34.
[0052] On the other hand, when tampering of the application firmware 34 is detected, the tampering detection unit 41 causes the recovery processing unit 42 to function. The recovery processing unit 42 deletes the application firmware 34 from the first storage unit 12a. After deleting the application firmware 34 from the first storage unit 12a, the recovery processing unit 42 copies the application firmware 34 from the second storage unit 12b to the first storage unit 12a. When the copying of the application firmware 34 is completed, the recovery processing unit 42 permits the hardware processor 11 to start the application firmware 34. As a result, the hardware processor 11 reads the application firmware 34 from the first storage unit 12a and starts it.
[0053] Therefore, when the security chip 13 detects tampering with the firmware 31, 32, 33, 34 in the first storage unit 12a to be booted, it can restore the firmware 31, 32, 33, 34 from the second storage unit 12b, which is used as a backup, and boot the firmware.
[0054] The hardware processor 11 functions as a startup processing unit 51, a basic operation control unit 52, a firmware update unit 53, and an application 54 by successively starting up the multiple pieces of firmware 31, 32, 33, and 34.
[0055] The boot processing unit 51 functions by the hardware processor 11 booting the BOOT firmware 31. The boot processing unit 51 performs processing for booting the OS firmware 32 in the hardware processor 11.
[0056] The basic operation control unit 52 functions when the hardware processor 11 starts the OS firmware 32. The basic operation control unit 52 controls the basic operation of the image processing device 1. The basic operation control unit 52 includes a setting unit 55.
[0057] The setting unit 55 performs various settings related to the basic operations of the image processing device 1. For example, when the image processing device 1 is brought into the office environment 5 and started up for the first time, the setting unit 55 functions and accepts various setting operations related to the basic operations by the user. The setting unit 55 then generates and stores setting information related to the basic operations based on the setting operations by the user. The basic operation control unit 52 controls the basic operations of the image processing device 1 based on the setting information. The setting information is information that can be changed by the user as appropriate.
[0058] The setting information held in the setting unit 55 includes a setting as to whether or not the image processing device 1 is permitted to access the external server device 7 via the proxy server 4. If the setting information permits access to the external server device 7, the image processing device 1 can access the server device 7 and download the firmware 8 held in the server device 7. On the other hand, if the setting information prohibits access to the external server device 7, the basic operation control unit 52 prohibits the image processing device 1 from accessing the external server device 7. Therefore, the image processing device 1 cannot download and obtain the firmware 8 from the server device 7.
[0059] The firmware update unit 53 functions by the hardware processor 11 activating the update firmware 33. The firmware update unit 53 updates the startup firmware 8a stored in the first storage unit 12a. The firmware update unit 53 also generates backup firmware 8b from the startup firmware 8a stored in the first storage unit 12a, and stores the firmware 8b in the second storage unit 12b. The process by the firmware update unit 53 will be described in detail later.
[0060] The application 54 functions by the hardware processor 11 activating the application firmware 34. The application 54 controls the operation of each part of the image processing device 1 via the basic operation control part 52. The application 54 includes a job control part 58.
[0061] The job control unit 58 displays a job setting screen on the display unit 15 of the operation panel 14 via the basic operation control unit 52. Furthermore, the job control unit 58 acquires operation information based on a user's operation on the job setting screen via the basic operation control unit 52. The job control unit 58 sets a job based on the operation information. Furthermore, the job control unit 58 controls the execution of a job in the image processing device 1 based on the operation information that instructs the start of job execution. Therefore, when the application 54 is normally started in the hardware processor 11, the image processing device 1 becomes ready to execute a job.
[0062] Next, updating and backing up the firmware 8 in the image processing device 1 will be described in detail.
[0063] For example, when access to an external server device 7 is permitted, the firmware update unit 53 periodically accesses the server device 7. When the server device 7 is accessed, the firmware update unit 53 judges whether or not the version of the firmware 8 held in the server device 7 has been updated. When the firmware 8 has been updated by a version upgrade or the like, the firmware update unit 53 downloads the latest firmware 8 from the server device 7. The downloaded firmware 8 is temporarily stored in, for example, the storage device 24. Then, the firmware update unit 53 deletes the firmware 8a stored in the first storage unit 12a at an appropriate update timing for the firmware 8, and stores the firmware 8 downloaded from the server device 7 in the first storage unit 12a. Note that the update timing for the firmware 8 may be, for example, a timing when a restart is instructed by a user.
[0064] In addition, the firmware update unit 53 monitors whether or not an external device 9 such as a USB memory is attached to the external device connection interface 25. When the attachment of the external device 9 is detected, the firmware update unit 53 judges whether or not the firmware 8 is stored in the external device 9. As a result, if the firmware 8 is stored in the external device 9, the firmware update unit 53 performs version determination. If the version of the firmware 8 stored in the external device 9 is newer than the version of the firmware 8a stored in the first storage unit 12a, the firmware update unit 53 reads the firmware 8 of the external device 9 and temporarily stores it in the storage device 24. Thereafter, the firmware update unit 53 deletes the firmware 8a stored in the first storage unit 12a at an appropriate firmware 8 update timing, and stores the firmware 8 acquired from the external device 9 in the first storage unit 12a.
[0065] On the other hand, if access to the external server device 7 is prohibited, the firmware update unit 53 does not access the external server device 7. In this case, the firmware update unit 53 obtains the latest firmware 8 from the external device 9 attached to the external device connection interface 25, and updates the firmware 8a in the first storage unit 12a.
[0066] The firmware update unit 53 includes a state detection unit 56 and a selection unit 57. The state detection unit 56 and the selection unit 57 function when saving the backup firmware 8b in the second storage unit 12b.
[0067] The status detection unit 56 detects the device status of the image processing device 1. The status detection unit 56 detects the storage capacity of the second storage unit 12b as the device status. The status detection unit 56 also detects the device status based on the setting information held by the setting unit 55. For example, the status detection unit 56 detects, as the device status, whether access to the external server device 7 is permitted or prohibited in the setting information.
[0068] The selection unit 57 selects firmware to be stored as a backup in the second storage unit 12b according to the device state detected by the state detection unit 56. That is, the selection unit 57 selects firmware to be stored as a backup from among the BOOT firmware 31, the OS firmware 32, the update firmware 33, and the application firmware 34. Then, based on the selection result by the selection unit 57, the firmware update unit 53 generates backup firmware 8b from the startup firmware 8a stored in the first storage unit 12a, and stores the firmware 8b in the second storage unit 12b.
[0069] Therefore, the image processing device 1 of this embodiment switches the firmware 8b stored as a backup in the second storage unit 12b depending on the device status. For example, when the memory 12 is added as an option to the image processing device 1, the storage capacity of the memory 12 increases. Conversely, when the memory 12 added as an option is removed from the image processing device 1, the storage capacity of the memory 12 decreases. Therefore, the device status of the image processing device 1 changes due to the addition or removal of the memory 12. In this case, the selection unit 57 judges whether or not a storage area required for storing the backup firmware 8b can be secured as the second storage unit 12b based on the storage capacity of the memory 12. Based on the judgment result, the selection unit 57 selects firmware to be stored as a backup in the second storage unit 12b from among the multiple firmware 31, 32, 33, and 34.
[0070] Furthermore, the amount of data in the firmware 8 may increase as a result of the firmware 8 being updated through version upgrades or the like. In this case, the amount of data in the first storage unit 12a in the memory 12 increases, which inevitably reduces the available storage area in the second storage unit 12b. This changes the device state of the image processing device 1. The selection unit 57 selects firmware to be stored in the second storage unit 12b as a backup from among the multiple firmwares 31, 32, 33, and 34, based on the amount of data in the firmware 8 and the available storage area in the second storage unit 12b.
[0071] Furthermore, from the viewpoint of prioritizing security, the setting in the image processing device 1 that permitted access to the external server device 7 may be changed to prohibit access to the external server device 7. In this case, the device state of the image processing device 1 also changes. Therefore, the selection unit 57 selects firmware to be stored in the second storage unit 12b as a backup from among the multiple firmware 31, 32, 33, 34, depending on the setting of permission or prohibition of access to the server device 7.
[0072] When the storage capacity of the second storage unit 12b is capable of storing all of the plurality of firmware 31, 32, 33, 34, the selection unit 57 selects all of the firmware 31, 32, 33, 34 as backup targets. In this case, the firmware update unit 53 reads all of the plurality of firmware 31, 32, 33, 34 stored in the first storage unit 12a and copies them to the second storage unit 12b. As a result, all of the plurality of firmware 31, 32, 33, 34 stored in the first storage unit 12a are stored in the second storage unit 12b as backups. When the firmware update unit 53 stores the firmware 31, 32, 33, 34 in the second storage unit 12b, it sets a write-protect setting for the second storage unit 12b. As a result, the firmware update unit 53 prevents the firmware 31, 32, 33, 34 stored in the second storage unit 12b from being illegally tampered with.
[0073] By storing all the firmware 31, 32, 33, 34 as backups in the second storage unit 12b, the image processing device 1 can restore the four firmware 31, 32, 33, 34 from the backups. Therefore, even if any of the four firmware 31, 32, 33, 34 is tampered with, the image processing device 1 can normally start up with the genuine firmware 31, 32, 33, 34. In other words, the image processing device 1 can normally start up the start-up processing unit 51, the basic operation control unit 52, the firmware update unit 53, and the application 54.
[0074] On the other hand, the storage capacity of the second storage unit 12b may not be sufficient to store all of the firmware 31, 32, 33, and 34. In this case, the selection unit 57 judges whether the firmware 31, 32, and 33 can be stored in the second storage unit 12b, except for the application firmware 34. That is, the selection unit 57 judges whether the BOOT firmware 31, the OS firmware 32, and the update firmware 33, which are necessary to acquire the firmware 8 from the server device 7, can be stored in the second storage unit 12b. As a result, if the firmware 31, 32, and 33 can be stored in the second storage unit 12b, the selection unit 57 selects the BOOT firmware 31, the OS firmware 32, and the update firmware 33 as backup targets. In this case, the firmware update unit 53 reads out the BOOT firmware 31, the OS firmware 32, and the update firmware 33 stored in the first storage unit 12a, and copies them to the second storage unit 12b. As a result, the BOOT firmware 31, the OS firmware 32, and the update firmware 33 stored in the first storage unit 12a are stored in the second storage unit 12b as backups. After storing the firmware 31, 32, and 33 in the second storage unit 12b, the firmware update unit 53 sets a write-protect setting for the second storage unit 12b. As a result, the firmware update unit 53 prevents the three firmware 31, 32, and 33 stored in the second storage unit 12b from being tampered with illegally.
[0075] By storing the three firmware 31, 32, and 33 as backups in the second storage unit 12b, the image processing device 1 can restore the three firmware 31, 32, and 33 from the backups. Therefore, even if any of the three firmware 31, 32, and 33 is tampered with, the image processing device 1 can normally start up with the genuine firmware 31, 32, and 33. In other words, the image processing device 1 can normally start up the start-up processing unit 51, the basic operation control unit 52, and the firmware update unit 53.
[0076] However, if the application firmware 34 in the first storage unit 12a is tampered with, the recovery processing unit 42 cannot recover the application firmware 34 using the firmware 8b in the second storage unit 12b. In this case, the recovery processing unit 42 instructs the firmware update unit 53 to download the genuine application firmware 34 from the server device 7. Based on the instruction from the recovery processing unit 42, the firmware update unit 53 accesses the server device 7 and downloads the genuine application firmware 34. Then, the firmware update unit 53 saves the application firmware 34 downloaded from the server device 7 in the first storage unit 12a. As a result, the application firmware 34 is recovered to a normal state that has not been tampered with.
[0077] However, if the setting information prohibits access to the server device 7, the firmware update unit 53 cannot download the genuine application firmware 34 from the server device 7. In other words, even if the application firmware 34 in the first storage unit 12a has been tampered with, the image processing device 1 cannot immediately restore the application firmware 34 to a normal state. Therefore, if access to the server device 7 is prohibited, it is pointless to store the three firmware 31, 32, and 33 as backups in the second storage unit 12b in order to download and restore the firmware 8 from the server device 7.
[0078] Therefore, when the image processing apparatus 1 cannot store all of the plurality of firmware 31, 32, 33, 34 in the second storage unit 12b and access to the server apparatus 7 is prohibited, only the minimum amount of firmware is saved as a backup. In this case, the selection unit 57 selects only the BOOT firmware 31 out of the plurality of firmware 31, 32, 33, 34 as the backup target. Then, the firmware update unit 53 reads only the BOOT firmware 31 from the first storage unit 12a and stores it in the second storage unit 12b. Thereby, it is possible to prevent the storage area of the memory 12 from being occupied by the unnecessary backup firmware 8b. As a result, the image processing apparatus 1 can effectively utilize the storage capacity of the memory 12 and store more data other than the firmware 8 in the memory 12.
[0079] Here, when the startup processing unit 51 cannot normally start the OS firmware 32 in the hardware processor 11, the startup processing unit 51 executes a process of displaying a notification screen indicating that the firmware 8 has been tampered with on the display unit 15 of the operation panel 14. That is, the BOOT firmware 31 includes a module that displays such a notification screen when the OS firmware 32 cannot be normally started. Therefore, when the basic operation control unit 52 does not function normally after the startup processing unit 51 functions in the hardware processor 11 at the time of starting the image processing apparatus 1, the notification screen by the startup processing unit 51 is displayed on the display unit 15. With this notification screen, the user can grasp that the firmware 8 has been tampered with and the image processing apparatus 1 cannot be normally started. Therefore, the user can take appropriate measures such as immediately making a service call.
[0080] Next, the operation in the image processing apparatus 1 will be described. FIG. 4 is a flowchart showing an example of a processing procedure by the security chip 13. The processing procedure shown in FIG. 4 starts when the power to the image processing apparatus 1 is turned on.
[0081] When the image processing device 1 is powered on, the security chip 13 activates the tampering detection unit 41. The tampering detection unit 41 detects whether the BOOT firmware 31 stored in the first storage unit 12a has been tampered with (step S10). When the tampering detection unit 41 detects that the BOOT firmware 31 has been tampered with (YES in step S11), the security chip 13 activates the recovery processing unit 42. The recovery processing unit 42 reads out the BOOT firmware 31 from the second storage unit 12b (step S12). The recovery processing unit 42 overwrites the BOOT firmware 31 from the first storage unit 12a with the BOOT firmware 31 read out from the second storage unit 12b (step S13). As a result, the BOOT firmware 31 from the first storage unit 12a is replaced with a genuine firmware that has not been tampered with. If no tampering of the BOOT firmware 31 is detected (NO in step S11), the processes of steps S12 and S13 are not performed. After that, the security chip 13 causes the hardware processor 11 to start the BOOT firmware 31 (step S14). As a result, the BOOT firmware 31 in the first storage unit 12a is started in the hardware processor 11, and the start-up processing unit 51 starts to function.
[0082] The security chip 13 activates the tampering detection unit 41 again. The tampering detection unit 41 detects whether the OS firmware 32 stored in the first storage unit 12a has been tampered with (step S15). As a result, when the tampering of the OS firmware 32 is detected (YES in step S16), the security chip 13 activates the recovery processing unit 42. The recovery processing unit 42 reads the OS firmware 32 from the second storage unit 12b (step S17). The recovery processing unit 42 then overwrites the OS firmware 32 in the first storage unit 12a with the OS firmware 32 read from the second storage unit 12b (step S18). As a result, the OS firmware 32 in the first storage unit 12a is replaced with genuine firmware that has not been tampered with. If no tampering of the OS firmware 32 is detected (NO in step S16), the processes of steps S17 and S18 are not performed. After that, the security chip 13 causes the hardware processor 11 to start the OS firmware 32 (step S19). As a result, the OS firmware 32 in the first storage unit 12a is started in the hardware processor 11, and the basic operation control unit 52 starts to function.
[0083] The security chip 13 activates the tampering detection unit 41 again. The tampering detection unit 41 detects whether the update firmware 33 stored in the first storage unit 12a has been tampered with (step S20). As a result, when the tampering of the update firmware 33 is detected (YES in step S21), the security chip 13 activates the recovery processing unit 42. The recovery processing unit 42 reads the update firmware 33 from the second storage unit 12b (step S22). The recovery processing unit 42 overwrites the update firmware 33 in the first storage unit 12a with the update firmware 33 read from the second storage unit 12b (step S23). As a result, the update firmware 33 in the first storage unit 12a is replaced with a genuine firmware that has not been tampered with. Note that, when the tampering of the update firmware 33 is not detected (NO in step S21), the processes of steps S22 and S23 are not performed. Thereafter, the security chip 13 causes the hardware processor 11 to start the update firmware 33 (step S24). As a result, the update firmware 33 in the first storage unit 12a is started in the hardware processor 11, and the firmware update unit 53 starts functioning.
[0084] The security chip 13 activates the tampering detection unit 41 again. The tampering detection unit 41 detects whether the application firmware 34 stored in the first storage unit 12a has been tampered with (step S25). As a result, when the tampering of the application firmware 34 is detected (YES in step S26), the security chip 13 activates the recovery processing unit 42. The recovery processing unit 42 reads the application firmware 34 from the second storage unit 12b (step S27). The recovery processing unit 42 then overwrites the application firmware 34 in the first storage unit 12a with the application firmware 34 read from the second storage unit 12b (step S28). As a result, the application firmware 34 in the first storage unit 12a is replaced with a genuine firmware that has not been tampered with. If no tampering of the application firmware 34 is detected (NO in step S26), the processes of steps S27 and S28 are not performed. After that, the security chip 13 causes the hardware processor 11 to start the application firmware 34 (step S29). As a result, the application firmware 34 in the first storage unit 12a is started in the hardware processor 11, and the application 54 functions.
[0085] 5 is a flowchart showing an example of a processing procedure performed by the setting unit 55 of the basic operation control unit 52. This processing is started, for example, when the basic operation control unit 52 is functioning in the hardware processor 11 and no setting information is saved. This processing is also started when the user changes the setting information while the basic operation control unit 52 is functioning.
[0086] When the setting unit 55 starts this process, it accepts a setting operation by the user (step S30). Then, the setting unit 55 judges whether or not the user has permitted a remote update in which the firmware 8 is downloaded from the server device 7 and updated (step S31). If the remote update is permitted (YES in step S31), the setting unit 55 performs a setting to permit access to the server device 7 to obtain the firmware 8 (step S32). On the other hand, if the remote update is not permitted (NO in step S31), the setting unit 55 performs a setting to prohibit obtaining the firmware 8 from the server device 7 (step S33). After that, the setting unit 55 saves the contents of the setting in step S32 or S33 as setting information (step S34).
[0087] Next, FIG. 6 to FIG. 9 are flowcharts showing an example of a processing procedure performed by the firmware update unit 53. This processing is periodically executed by the firmware update unit 53. When the firmware update unit 53 starts this processing, it reads out the setting information stored by the setting unit 55 (step S40). The firmware update unit 53 judges whether or not it is permitted to acquire the firmware 8 from the server device 7 based on the setting information (step S41). If it is permitted to acquire the firmware 8 from the server device 7 (YES in step S41), the firmware update unit 53 accesses the server device 7. Then, the firmware update unit 53 checks whether or not the firmware 8 held in the server device 7 has been updated (step S42). If the firmware 8 of the server device 7 has been updated (YES in step S43), the firmware update unit 53 downloads the firmware 8 from the server device 7 (step S44). Note that if it is prohibited to acquire the firmware 8 from the server device 7 (NO in step S41), the processing of steps S42 to S44 is not performed. Moreover, if the firmware 8 of the server device 7 has not been updated (NO in step S43), the process of step S44 is not performed.
[0088] The firmware update unit 53 judges whether or not an external device 9 such as a USB memory is attached to the external device connection interface 25 (step S45). If the external device 9 is attached (YES in step S45), the firmware update unit 53 reads and acquires the firmware 8 stored in the external device 9 (step S46). The firmware update unit 53 acquires the firmware 8 from the external device 9 if the version of the firmware 8 stored in the external device 9 is newer than the version of the firmware 8a stored in the first storage unit 12a. Note that if the external device 9 is not attached to the external device connection interface 25 (NO in step S45), the process of step S46 is not performed.
[0089] The firmware update unit 53 determines whether the firmware 8 has been acquired from the server device 7 or the external device 9 (step S47). If the firmware 8 has been acquired (YES in step S47), the firmware update unit 53 executes firmware update processing (step S48). Note that if the firmware 8 has not been acquired (NO in step S47), the processing in step S48 is not performed.
[0090] Next, the firmware update unit 53 executes a backup change process (step S49). Through this backup change process, the firmware 8b stored as a backup in the second storage unit 12b may be changed.
[0091] 7 is a flowchart showing an example of a detailed processing procedure of the firmware update process (step S48). When the firmware update unit 53 starts this process, it deletes all of the firmware 31, 32, 33, and 34 stored in the first storage unit 12a (step S50). After deleting all of the firmware 31, 32, 33, and 34, the firmware update unit 53 stores the firmware 8 acquired from the server device 7 or the external device 9 in the first storage unit 12a (step S51). As a result, the first storage unit 12a stores the latest versions of the BOOT firmware 31, the OS firmware 32, the update firmware 33, and the application firmware 34.
[0092] After updating the firmware 8a in the first storage unit 12a, the firmware update unit 53 cancels the write protection setting in the second storage unit 12b (step S53). After canceling the write protection setting, the firmware update unit 53 deletes all firmware 8b stored in the second storage unit 12b (step S53). After that, the firmware update unit 53 activates the state detection unit 56 and the selection unit 57 to execute a backup holding determination (step S54).
[0093] 8 is a flowchart showing an example of a detailed process procedure of the backup holding determination (step S54). The firmware update unit 53 first activates the status detection unit 56 to detect the device status of the image processing device 1 (step S70). The status detection unit 56 then detects the capacity of the second storage unit 12b that can store the backup firmware 8b (step S71). Next, the status detection unit 56 detects the size (data amount) of each firmware 31, 32, 33, 34 stored in the first storage unit 12a (step S72).
[0094] Next, the firmware update unit 53 activates the selection unit 57. The selection unit 57 determines whether or not all of the multiple firmware 31, 32, 33, and 34 stored in the first storage unit 12a can be held in the second storage unit 12b (step S73). If all of the firmware 31, 32, 33, and 34 can be held as backups (YES in step S73), the selection unit 57 determines all of the firmware 31, 32, 33, and 34 as targets to be held as backups (step S74).
[0095] If all the firmware 31, 32, 33, and 34 cannot be held as backups (NO in step S73), the selection unit 57 makes the following judgment. That is, the selection unit 57 judges whether the firmware 31, 32, and 33 other than the application firmware 34 can be held in the second storage unit 12b (step S75). If the three firmware 31, 32, and 33 can be held (YES in step S75), the firmware update unit 53 activates the status detection unit 56. The status detection unit 56 reads out the setting information (step S76) and judges whether access to the server device 7 is permitted (step S77). If access to the server device 7 is permitted (YES in step S77), the selection unit 57 determines the three firmware 31, 32, and 33 as targets to be held as backups (step S78).
[0096] If the second storage unit 12b does not have a capacity required to store the three firmware 31, 32, and 33 (NO in step S75), the selection unit 57 determines only the BOOT firmware 31 as the backup to be stored (step S79). If access to the server device 7 is prohibited (NO in step S77), the selection unit 57 determines only the BOOT firmware 31 as the backup to be stored (step S79). By such backup storage determination (step S54), the contents of the firmware 8b to be stored as a backup in the second storage unit 12b are determined. That is, the firmware update unit 53 selects the firmware 8b to be stored as a backup in the second storage unit 12b according to the device state.
[0097] Returning to the flowchart of Fig. 7, the firmware update unit 53 judges whether or not all of the firmware 31, 32, 33, 34 have been determined as backup retention targets by the backup retention judgment (step S54) (step S55). If all of the firmware 31, 32, 33, 34 are retention targets (YES in step S55), the firmware update unit 53 reads out all of the firmware 31, 32, 33, 34 stored in the first storage unit 12a. Then, the firmware update unit 53 stores all of the firmware 31, 32, 33, 34 in the second storage unit 12b as backups (step S56).
[0098] If all of the firmware 31, 32, 33, and 34 are not to be held (NO in step S55), the firmware update unit 53 performs the following judgment. That is, the firmware update unit 53 judges whether the three firmware 31, 32, and 33 other than the application firmware 34 are to be held (step S57). If the three firmware 31, 32, and 33 are to be held (YES in step S57), the firmware update unit 53 reads the three firmware 31, 32, and 33 from the first storage unit 12a. Then, the firmware update unit 53 stores the three firmware 31, 32, 33, and 34 in the second storage unit 12b as a backup (step S58).
[0099] If the three firmware 31, 32, and 33 are not to be held (NO in step S57), the firmware update unit 53 determines that only the BOOT firmware 31 is to be held. In this case, the firmware update unit 53 reads the BOOT firmware 31 from the first storage unit 12a. Then, the firmware update unit 53 stores the BOOT firmware 31 in the second storage unit 12b as a backup (step S59).
[0100] Thereafter, the firmware update unit 53 sets a write-prohibited setting in the second storage unit 12b (step S60). This ends the firmware update process (step S48).
[0101] 9 is a flowchart showing an example of a detailed processing procedure of the backup change process (step S49). When the firmware update unit 53 starts this process, it executes a backup holding determination (step S80). The detailed processing procedure of this backup holding determination (step S80) is the same as that shown in the flowchart in FIG. 8. In other words, the firmware update unit 53 determines the firmware 8b to be held as a backup in accordance with the device state.
[0102] When the firmware update unit 53 determines the backup storage target by the backup storage determination (step S80), it determines whether the backup storage target has been changed (step S81). If the backup storage target has not been changed (NO in step S81), the process by the firmware update unit 53 ends. In this case, the firmware update unit 53 does not change the firmware 8b stored as a backup in the second storage unit 12b.
[0103] On the other hand, if the backup storage target is changed (YES in step S81), the firmware update unit 53 changes the firmware 8b stored as a backup in the second storage unit 12b. In this case, the firmware update unit 53 cancels the write protection setting of the second storage unit 12b (step S82). Next, the firmware update unit 53 deletes all firmware 8b stored in the second storage unit 12b (step S83).
[0104] Next, the firmware update unit 53 judges whether or not all of the firmware 31, 32, 33, and 34 have been determined as backup retention targets by the backup retention judgment (step S80) (step S84). If all of the firmware 31, 32, 33, and 34 are retention targets (YES in step S84), the firmware update unit 53 reads out all of the firmware 31, 32, 33, and 34 stored in the first storage unit 12a. Then, the firmware update unit 53 stores all of the firmware 31, 32, 33, and 34 in the second storage unit 12b as backups (step S85).
[0105] If all of the firmware 31, 32, 33, and 34 are not to be held (NO in step S84), the firmware update unit 53 performs the following judgment. That is, the firmware update unit 53 judges whether the three firmware 31, 32, and 33 other than the application firmware 34 are to be held (step S86). If the three firmware 31, 32, and 33 are to be held (YES in step S86), the firmware update unit 53 reads the three firmware 31, 32, and 33 from the first storage unit 12a. Then, the firmware update unit 53 stores the three firmware 31, 32, 33, and 34 in the second storage unit 12b as a backup (step S87).
[0106] If the three firmware 31, 32, and 33 are not to be held (NO in step S86), the firmware update unit 53 determines that only the BOOT firmware 31 is to be held. In this case, the firmware update unit 53 reads the BOOT firmware 31 from the first storage unit 12a. Then, the firmware update unit 53 stores the BOOT firmware 31 in the second storage unit 12b as a backup (step S88).
[0107] After that, the firmware update unit 53 sets a write-prohibited setting in the second storage unit 12b (step S89). This ends the backup change process (step S49).
[0108] By performing the above-mentioned processing in the image processing device 1, the firmware 8b stored as a backup in the second storage unit 12b is switched depending on the device state of the image processing device 1. For example, if the storage capacity of the second storage unit 12b changes when the image processing device 1 is started up due to the addition or removal of an option, the firmware 8b stored as a backup changes depending on the storage capacity. Also, if the startup firmware 31, 32, 33, and 34 stored in the first storage unit 12a is updated and the amount of data of the firmware 8 changes, the firmware 8b stored as a backup changes depending on the change in the amount of data.
[0109] FIG. 10 is a conceptual diagram showing some examples of the storage manner of the backup of the firmware 8. FIG. 10(a) shows a manner in which all the firmware 31, 32, 33, 34 are stored as backups in the second storage unit 12b. When the storage capacity of the second storage unit 12b is sufficient to store all the firmware 31, 32, 33, 34, the firmware update unit 53 stores the firmware 8 as backups in the storage manner shown in FIG. 10(a). That is, the firmware update unit 53 stores all the firmware 31, 32, 33, 34 stored in the first storage unit 12a for startup in the second storage unit 12b as backups. This allows the image processing device 1 to store the backup of the firmware 8 in a completely duplicated state. Therefore, even if tampering is detected in any of the firmware 31, 32, 33, 34, the image processing device 1 can restore the regular firmware using the firmware 31, 32, 33, 34 stored as backups.
[0110] Fig. 10(b) shows a state in which the three firmware 31, 32, and 33 are stored as backups in the second storage unit 12b. When the storage capacity of the second storage unit 12b is not sufficient to store all of the multiple firmware 31, 32, 33, and 34, the firmware update unit 53 may store the firmware 8 as a backup in the storage manner shown in Fig. 10(b). That is, the firmware update unit 53 stores the three firmware 31, 32, and 33, excluding the application firmware 34, in the second storage unit 12b as backups.
[0111] In this case, if tampering is detected in any of the three pieces of firmware 31, 32, and 33 that are held as backups, the image processing device 1 can restore the original firmware using the firmware 31, 32, and 33 that are held as backups.
[0112] However, if the application firmware 34 in the first storage unit 12a is tampered with, the image processing apparatus 1 cannot restore the application firmware 34 from the backup in the second storage unit 12b. Therefore, the image processing apparatus 1 activates the firmware update unit 53 to obtain and restore the application firmware 34 from the server apparatus 7.
[0113] FIG. 11 is a flowchart showing a processing procedure in which the firmware update unit 53 obtains the firmware 34 from the server apparatus 7. The firmware update unit 53 determines whether the application 54 has been normally started in the hardware processor 11 (step S90). For example, when an instruction to download the normal application firmware 34 is received from the recovery processing unit 42, the firmware update unit 53 determines that the application 54 has not been normally started. If the application 54 has not been normally started (NO in step S90), the firmware update unit 53 accesses the server apparatus 7 and downloads the normal application firmware 34 from the server apparatus 7 (step S91). Subsequently, the firmware update unit 53 overwrites and stores the normal application firmware 34 in the first storage unit 12a (step S92). As a result, the application firmware 34 in the first storage unit 12a is updated to the normal firmware that has not been tampered with. Thereafter, the firmware update unit 53 requests the basic operation control unit 52 to restart the application firmware 34 (step S93). As a result, the basic operation control unit 52 reads out and starts the application firmware 34 from the first storage unit 12a. As a result, the application 54 is normally started in the hardware processor 11. Then, the image processing apparatus 1 becomes capable of executing a job. Therefore, even in the storage mode as shown in FIG. 10(b), the image processing apparatus 1 can restore the firmware 8.
[0114] Fig. 10(c) shows a mode in which only the BOOT firmware 31 is stored as a backup in the second storage unit 12b. When the storage capacity of the second storage unit 12b is insufficient or when access to the server device 7 is prohibited, the firmware update unit 53 stores the firmware 8 as a backup in the storage mode shown in Fig. 10(c). That is, the firmware update unit 53 stores only the BOOT firmware 31 as a backup in the second storage unit 12b.
[0115] In this case, if tampering with the BOOT firmware 31 stored as a backup is detected, the image processing device 1 can restore the authentic BOOT firmware 31 using the BOOT firmware 31 stored as a backup.
[0116] However, if the firmware 32, 33, 34 other than the BOOT firmware 31 in the first storage unit 12a is tampered with, the image processing device 1 cannot restore the firmware 32, 33, 34 from the backup in the second storage unit 12b. In this case, the startup processing unit 51 cannot normally start the basic operation control unit 52. Therefore, the startup processing unit 51 executes a process of displaying a notification screen indicating that the firmware 8 has been tampered with.
[0117] 12 is a flowchart showing an example of a processing procedure performed by the boot processing unit 51 when the genuine OS firmware 32 cannot be booted. When the boot processing unit 51 starts this processing, it judges whether the basic operation control unit 52 has been booted normally (step S100). If the basic operation control unit 52 has not been booted normally (NO in step S100), the boot processing unit 51 generates a notification screen indicating that the firmware 8 has been tampered with, and displays it on the display unit 15 (step S101).
[0118] Fig. 13 is a diagram showing an example of a notification screen displayed on the display unit 15. As shown in Fig. 13, the notification screen displays a window 60 including a message indicating that the firmware 8 has been tampered with. The window 60 also includes a message indicating that it is necessary to call a service technician and update the firmware 8. Therefore, the user can recognize the need to immediately call a service technician by checking the display contents of the notification screen. Therefore, when the firmware 8 of the image processing device 1 has been tampered with, the user can quickly take appropriate measures.
[0119] As described above, the image processing device 1 of this embodiment is configured to select firmware 8 to be stored as a backup in the second storage unit 12b depending on the device state. Therefore, when the storage capacity of the second storage unit 12b is relatively large, the image processing device 1 can store all of the multiple firmware 31, 32, 33, and 34 in the second storage unit 12b as backups. Also, when the storage capacity of the second storage unit 12b is relatively small, the image processing device 1 can store firmware selected from the multiple firmware 31, 32, 33, and 34 in the second storage unit 12b as backups.
[0120] In particular, the image processing device 1 may be permitted to access the external server device 7 even if the storage capacity of the second storage unit 12b is relatively small. In this case, the image processing device 1 stores the firmware 31, 32, and 33 required to download the firmware 8 from the server device 7 as backups in the second storage unit 12b. In this case, when the image processing device 1 detects tampering of the firmware 31, 32, and 33 in which the backups are stored, the image processing device 1 restores the startup firmware 31, 32, and 33 from the backup. In addition, when the image processing device 1 detects tampering of the firmware 34 in which the backups are not stored, the image processing device 1 obtains the regular firmware 34 from the server device 7 and restores the startup firmware 34. Therefore, even if the storage capacity of the second storage unit 12b is relatively small, the image processing device 1 can properly restore all the firmware 31, 32, 33, and 34 and start up to a state in which a job can be executed.
[0121] On the other hand, the device state of the image processing device 1 may be such that the firmware 31, 32, and 33 required for downloading the firmware 8 from the server device 7 cannot be stored as a backup in the second storage unit 12b. Also, the device state of the image processing device 1 may be such that access to an external server device 7 different from the office environment 5 is prohibited. In such a case, the image processing device 1 stores only the firmware 31 that can notify the user that the firmware 8 has been tampered with in the second storage unit 12b as a backup. Therefore, when the firmware 8 is tampered with, the image processing device 1 can appropriately notify the user that the firmware 8 has been tampered with.
[0122] Therefore, the image processing device 1 can automatically switch the firmware 8 stored as a backup depending on the device status, thereby making effective use of the storage area of the memory 12. Furthermore, when the firmware 8 is tampered with, the image processing device 1 can use the firmware 8 stored as a backup to perform appropriate processing depending on the backup holding status.
[0123] Second embodiment Next, a second embodiment of the present invention will be described. FIG. 14 is a block diagram showing the functional configuration of the control unit 10 in the second embodiment. As in the first embodiment, the security chip 13 includes a tampering detection unit 41. When the image processing device 1 is powered on, the tampering detection unit 41 detects whether the BOOT firmware 31 has been tampered with. That is, the security chip 13 of this embodiment detects only whether the BOOT firmware 31, which is started first in the image processing device 1, has been tampered with. When the tampering detection unit 41 detects that the BOOT firmware 31 has not been tampered with, it causes the hardware processor 11 to start the BOOT firmware 31. This causes the start-up processing unit 51 to function in the hardware processor 11.
[0124] The boot processing unit 51 includes a tampering detection unit 71. This tampering detection unit 71 detects whether the OS firmware 32 to be booted after the BOOT firmware 31 has been tampered with. When the tampering detection unit 71 detects that the OS firmware 32 has not been tampered with, it causes the hardware processor 11 to boot the OS firmware 32 in the first storage unit 12a. On the other hand, when the tampering detection unit 71 detects that the OS firmware 32 has been tampered with, it deletes the OS firmware 32 for booting from the first storage unit 12a. Then, the tampering detection unit 71 stores the OS firmware 32 stored as a backup in the second storage unit 12b in the first storage unit 12a. That is, the tampering detection unit 71 detects tampering of the OS firmware 32 and performs recovery processing.
[0125] When the OS firmware 32 is started by the hardware processor 11, the basic operation control unit 52 functions. The basic operation control unit 52 includes a tamper detection unit 72. The tamper detection unit 72 detects whether or not each of the update firmware 33 and the application firmware 34, which are started after the OS firmware 32, has been tampered with. When the tamper detection unit 72 detects that the update firmware 33 has not been tampered with, it causes the hardware processor 11 to start the update firmware 33 in the first storage unit 12a. This causes the firmware update unit 53 to function in the hardware processor 11. Furthermore, when the tamper detection unit 72 detects that the application firmware 34 has not been tampered with, it causes the hardware processor 11 to start the application firmware 34 in the first storage unit 12a. This causes the application 54 to function in the hardware processor 11.
[0126] In response to this, when the tampering detection unit 72 detects tampering of the update firmware 33, it deletes the update firmware 33 for startup from the first storage unit 12a. Then, the tampering detection unit 72 stores the update firmware 33 stored as a backup in the second storage unit 12b in the first storage unit 12a. As a result, the tampered update firmware 33 is rewritten to the regular update firmware 33 that has not been tampered with. Furthermore, when the tampering detection unit 72 detects tampering of the application firmware 34, it deletes the application firmware 34 for startup from the first storage unit 12a. Then, the tampering detection unit 72 stores the application firmware 34 stored as a backup in the second storage unit 12b in the first storage unit 12a. As a result, the tampered application firmware 34 is rewritten to the regular application firmware 34 that has not been tampered with. That is, the tamper detection unit 72 detects tampering of the update firmware 33 and the application firmware 34 and performs recovery processing.
[0127] In this manner, the image processing device 1 of this embodiment is configured so that each of the multiple firmware 31, 32, 33, 34 that are sequentially started in stages in the hardware processor 11 performs tamper detection and recovery processing on the firmware that is to be started next. The other configuration of the image processing device 1 is the same as that of the first embodiment. Therefore, the image processing device 1 of this embodiment achieves the same effects as those of the first embodiment.
[0128] (Modification) The preferred embodiments of the present invention have been described above. However, the present invention is not limited to the contents described in the above embodiments. In other words, various modifications can be applied to the present invention.
[0129] For example, in the above embodiment, an example has been described in which the update firmware 33 is started by the hardware processor 11 when the image processing device 1 is started. However, the firmware update unit 53 may be started when firmware tampering is detected and it becomes necessary to download genuine firmware from the server device 7 and update the firmware in the first storage unit 12a.
[0130] In the above embodiment, an example has been described in which the firmware 31, 32, 33, and 34 are prevented from being tampered with by providing a write-protection setting to the second storage unit 12b after the firmware 31, 32, 33, and 34 are stored in the second storage unit 12b. However, there is a possibility that the write-protection setting of the second storage unit 12b may be illegally released. In that case, not only the firmware 31, 32, 33, and 34 in the first storage unit 12a but also the firmware 31, 32, 33, and 34 in the second storage unit 12b may be tampered with. Therefore, when the image processing device 1 reads out the backup firmware 31, 32, 33, and 34 from the second storage unit 12b, it may be possible to perform tampering detection for each firmware 31, 32, 33, and 34. Furthermore, the timing for detecting tampering of the backup firmware 31, 32, 33, 34 is not limited to the timing for reading the firmware 31, 32, 33, 34 from the second storage unit 12b. For example, after the backup firmware 31, 32, 33, 34 is copied to the first storage unit 12a, the tampering detection may be performed when the firmware is read from the first storage unit 12a.
[0131] In the above embodiment, the firmware 8 is stored in the memory 12 of the control unit 10. However, the storage device in which the firmware 8 is stored is not limited to the memory 12. For example, the firmware 8 may be stored in the storage device 24.
[0132] In the above embodiment, the startup firmware 8a and the backup firmware 8b are stored in the same memory 12. However, the startup firmware 8a and the backup firmware 8b may be stored in different storage devices.
[0133] In the above embodiment, the firmware 8 implemented in the image processing device 1 includes four pieces of firmware: the BOOT firmware 31, the OS firmware 32, the update firmware 33, and the application firmware 34. However, the firmware 8 implemented in the image processing device 1 may include firmware other than the above.
[0134] In the above embodiment, an example has been described in which the device status of the image processing device 1 is determined based on the storage capacity of the second storage unit 12b and the setting of permission or prohibition of access to the server device 7. However, this is not limited to this, and the image processing device 1 may determine device status other than the storage capacity of the second storage unit 12b and the setting of access to the server device 7, and select firmware 8 to be saved as a backup.
[0135] Also, the firmware 8 described in the above embodiment is exemplified as being pre-stored in the image processing device 1. However, the firmware 8, which is a dedicated program for the image processing device 1, is not necessarily limited to being pre-stored in the image processing device 1. [Explanation of symbols]
[0136] 1 Image processing device 8,8a,8b Firmware (program) 10 Control section 11 Hardware Processor 12. Memory 12a 1st memory section 12b 2nd memory section 13. Security Chip 31 BOOT firmware 32 OS Firmware 33 Firmware Update 34 Application Firmware 41 Tampering detection unit 42 Recovery Processing Section 51 Startup Processing Section 52 Basic operation control section 53 Firmware update section 54 Applications 55 Setting section 56 Status detection unit 57 Selection section 58 Job Control Section
Claims
1. a first storage unit that stores a plurality of firmware programs that are activated in stages; a second storage unit that stores firmware selected from the plurality of firmware as a backup; a tampering detection unit that detects tampering of each of the plurality of firmware stored in the first storage unit; a recovery processing unit that recovers the tampered firmware by using the firmware stored in the second storage unit when the tampering detection unit detects tampering of the firmware; a selection unit that selects firmware to be stored as a backup in the second storage unit according to a device state; An image processing device comprising:
2. 2 . The image processing apparatus according to claim 1 , wherein the second storage unit stores the firmware selected by the selection unit in a non-rewritable storage area.
3. 2 . The image processing apparatus according to claim 1 , wherein the selection unit selects firmware to be stored as a backup in the second storage unit from among the plurality of firmware based on a storage capacity of the second storage unit.
4. 2 . The image processing apparatus according to claim 1 , wherein the selection unit selects firmware to be stored as a backup in the second storage unit from among the plurality of firmware based on a change in data amount of the plurality of firmware.
5. an acquisition unit that acquires the plurality of firmware from an external device via a network; a setting unit that sets the acquisition unit to prohibit or permit acquisition of firmware; Further comprising: The image processing apparatus according to claim 1 , wherein the selection unit selects firmware to be stored as a backup in the second storage unit based on a setting made by the setting unit.
6. The image processing device according to claim 5, characterized in that when the setting unit prohibits the acquisition unit from acquiring firmware, the selection unit selects firmware that can notify that firmware tampering has been detected as firmware to be stored as a backup in the second memory unit.
7. The image processing device according to claim 5, characterized in that, when the setting unit permits the acquisition unit to acquire firmware, the selection unit selects firmware necessary for the acquisition unit to acquire and update firmware from the external device as firmware to be stored as a backup in the second memory unit.
8. The image processing apparatus according to claim 3 , wherein the selection unit selects all of the plurality of firmware when the second storage unit is capable of storing all of the plurality of firmware.
9. an update unit that updates the plurality of firmware versions stored in the first storage unit; Further comprising: The image processing apparatus according to claim 1 , wherein the selection unit selects firmware to be stored as a backup in the second storage unit when the update unit updates the firmware, and changes the firmware to be stored in the second storage unit.
10. The image processing device according to claim 1, characterized in that the selection unit determines whether the device state has changed at startup, and if the device state has changed, selects firmware to be stored as a backup in the second memory unit, and changes the firmware to be stored in the second memory unit.
11. a first storage unit that stores a plurality of firmware programs that are activated in stages; a second storage unit that stores firmware selected from the plurality of firmware as a backup; a tampering detection unit that detects tampering of each of the plurality of firmware stored in the first storage unit; a recovery processing unit that recovers the tampered firmware by using the firmware stored in the second storage unit when the tampering detection unit detects tampering of the firmware; A backup storage method for controlling firmware stored as a backup in the second storage unit in an image processing device comprising: a selection step of selecting firmware to be stored as a backup in the second storage unit from among the plurality of firmware depending on a device state; a changing step of changing firmware stored as a backup in the second storage unit in accordance with a result of the selection step; A backup holding method comprising:
12. a first storage unit that stores a plurality of firmware programs that are activated in stages; a second storage unit that stores firmware selected from the plurality of firmware as a backup; a tampering detection unit that detects tampering of each of the plurality of firmware stored in the first storage unit; a recovery processing unit that recovers the tampered firmware by using the firmware stored in the second storage unit when the tampering detection unit detects tampering of the firmware; A program executed in an image processing device comprising: a selection step of selecting firmware to be stored as a backup in the second storage unit from among the plurality of firmware depending on a device state; a changing step of changing firmware stored as a backup in the second storage unit in accordance with a result of the selection step; A program characterized by executing the above.
Citation Information
Patent Citations
Image formation device, control method and program of the same
JP2020082441A
Information processing apparatus and method for starting the same
JP2023064046A