Information processing apparatus, control method, and program
The information processing apparatus addresses vulnerabilities in Secure Boot by authenticating startup programs, tracking unauthorized executions, and restricting security protocols, thereby bolstering defense against third-party attacks.
Patent Information
- Application Number
- JP2023193416
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-26
- Estimated Expiration
- 2043-11-14
AI Technical Summary
Conventional information processing apparatuses face vulnerabilities in Secure Boot, where third-party tampering can occur even with Secure Boot protection, and the general-purpose interface used for information exchange can be rewritten, compromising security.
An information processing apparatus equipped with an authentication processing unit to verify startup programs, a trust list storage unit to store reliable sources, and a chain information storage unit to track unauthorized program execution. When an unauthorized program is detected, the apparatus restricts the use of security-related protocols.
The solution significantly enhances defense against third-party attacks in Secure Boot by ensuring only trusted programs are executed and restricting potentially threatening protocols, thereby maintaining system integrity.
Smart Images

Figure 2025080332000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, a control method, and a program.
Background Art
[0002] In recent years, in information processing apparatuses such as personal computers, in the BIOS (Basic Input Output System), a secure boot function has been implemented so that a program not signed with a key (secure boot key) registered in the system cannot be tampered with or monitored in the pre-boot environment before the OS (Operating System) starts (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, in conventional information processing apparatuses, information exchange between drivers, system information management, BIOS settings, etc. are performed by a general-purpose interface in which a protocol or the like is defined according to the UEFI (Unified Extensible Firmware Interface) specification. However, since this general-purpose interface is a program existing in memory, it may be rewritten by a third-party program. In addition, among the programs signed with the Secure Boot key, there may be vulnerabilities that bypass Secure Boot, and there is a possibility that a third party may tamper with them even under the protection of Secure Boot. Therefore, in conventional information processing apparatuses, in Secure Boot, for example, when a program tampered with by a third party is executed, the programs executed thereafter may be tampered with or monitored.
[0005] The present invention has been made to solve the above problems, and an object thereof is to provide an information processing apparatus, a control method, and a program capable of improving the defense against attacks from third parties in Secure Boot.
Means for Solving the Problems
[0006] To solve the above problems, one aspect of the present invention is an authentication processing unit that, in the processing of BIOS (Basic Input Output System), confirms the legitimacy of a startup program for starting an OS (Operating System) based on a predetermined security key, a trust list storage unit that stores a trust list that is a list of reliable sources of the startup program, a chain information storage unit that stores chain information indicating whether an illegal startup program that may have been tampered with has been executed, and in a secure boot process of executing the startup program whose legitimacy has been confirmed by the authentication processing unit, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, a startup processing unit that changes the chain information stored in the chain information storage unit to information indicating that the illegal startup program has been executed, and a restriction processing unit that restricts the use of a protocol related to security set in advance when the chain information stored in the chain information storage unit is information indicating that an illegal startup program has been executed. The information processing apparatus includes these components.
[0007] Also, in one aspect of the present invention, in the above information processing apparatus, the trust list may include a firmware volume provided by a BIOS memory in which the BIOS program is stored, or a network boot provided by a preset server device as a provider.
[0008] Also, in one aspect of the present invention, in the above information processing apparatus, a usage restriction list storage unit that stores a list of the protocols to be restricted in usage is provided, and when the chain information is information indicating that an unauthorized startup program has been executed, the restriction processing unit may restrict the usage of the protocols included in the list of the protocols stored in the usage restriction list storage unit.
[0009] Also, in one aspect of the present invention, in the above information processing apparatus, the list of the protocols to be restricted in usage may include a protocol related to network connection or a protocol related to TPM (Trusted Platform Module).
[0010] Also, one aspect of the present invention is a control method for an information processing apparatus including: an authentication processing unit that, in the processing of BIOS (Basic Input Output System), confirms the validity of a startup program for starting an OS (Operating System) based on a predetermined security key; a trust list storage unit that stores a trust list which is a list of sources of the reliable startup programs; and a chain information storage unit that stores chain information indicating whether an illegal startup program that may have been tampered with has been executed. In the secure boot process in which the startup processing unit causes the startup program whose validity has been confirmed by the authentication processing unit to be executed, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, a startup processing step of changing the chain information stored in the chain information storage unit to information indicating that the illegal startup program has been executed; and a restriction processing step in which the restriction processing unit restricts the use of a protocol related to security set in advance when the chain information stored in the chain information storage unit is information indicating that an illegal startup program has been executed.
[0011] Also, one aspect of the present invention is in the processing of the BIOS (Basic Input Output System). An authentication processing unit that verifies the validity of a startup program for starting the OS (Operating System) based on a predetermined security key, a trust list storage unit that stores a trust list which is a list of reliable sources of the startup program, and a chain information storage unit that stores chain information indicating whether an unauthorized startup program that may have been tampered with has been executed. In the secure boot process of causing a computer of an information processing apparatus provided with these to execute the startup program whose validity has been verified by the authentication processing unit, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, a startup processing step of changing the chain information stored in the chain information storage unit to information indicating that the unauthorized startup program has been executed, and a restriction processing step of restricting the use of a protocol related to security set in advance when the chain information stored in the chain information storage unit is information indicating that an unauthorized startup program has been executed. It is a program for causing these steps to be executed.
Effects of the Invention
[0012] According to the above aspect of the present invention, in secure boot, it is possible to improve the defense against attacks from third parties.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Mode for Carrying Out the Invention
[0014] Hereinafter, an information processing apparatus and a control method according to an embodiment of the present invention will be described with reference to the drawings.
[0015] FIG. 1 is a diagram showing an example of the main hardware configuration of the notebook PC 1 according to this embodiment. In this embodiment, the notebook PC 1 will be described as an example of the information processing apparatus.
[0016] As shown in FIG. 1, the notebook PC 1 includes a CPU 11, a main memory 12, a video subsystem 13, a display unit 14, a chipset 21, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, a USB connector 26, an embedded controller 31, an input unit 32, and a power circuit 33.
[0017] In this embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. The main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).
[0018] The CPU (Central Processing Unit) 11 executes various arithmetic processes under program control and controls the entire notebook PC 1. The main memory 12 is a writable memory that is used as a loading area for the execution program of the CPU 11 or as a working area for writing the processing data of the execution program. The main memory 12 is composed of, for example, a plurality of DRAM (Dynamic Random Access Memory) chips. This execution program includes BIOS (Basic Input Output System), OS, various drivers for operating peripheral devices in hardware, various services / utilities, application programs, and the like.
[0019] The video subsystem 13 is a subsystem for realizing functions related to image display and includes a video controller. This video controller processes the drawing commands from the CPU 11, writes the processed drawing information to the video memory, reads the drawing information from the video memory, and outputs it as drawing data (display data) to the display unit 14.
[0020] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13.
[0021] The chipset 21 is provided with controllers such as USB (Universal Serial Bus), Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and a plurality of devices are connected. In FIG. 1, as an example of devices, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, and a USB connector 26 are connected to the chipset 21.
[0022] The BIOS memory 22 is composed of an electrically rewritable non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read Only Memory) or a flash ROM. The BIOS memory 22 stores the BIOS and system firmware for controlling the embedded controller 31 and the like.
[0023] The SSD (Solid State Drive) 23 (an example of a non-volatile storage device) stores the OS, various drivers, various services / utilities, application programs, and various data. The audio system 24 records, plays back, and outputs audio data.
[0024] The WLAN (Wireless Local Area Network) card 25 connects to the network via a wireless (radio) LAN and performs data communication. The USB connector 26 is a connector for connecting peripheral devices using USB.
[0025] The embedded controller 31 (an example of a sub-control unit) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. Further, the embedded controller 31 has a power management function for controlling the power circuit 33. Note that the embedded controller 31 is composed of a CPU, ROM, RAM, etc. (not shown) and includes a plurality of channels of A / D input terminals, D / A output terminals, timers, and digital input / output terminals. For example, the input unit 32 and the power circuit 33 are connected to the embedded controller 31 via these input / output terminals, and the embedded controller 31 controls the operations thereof.
[0026] Next, with reference to FIG. 2, the functional configuration of the notebook PC 1 according to the present embodiment will be described. FIG. 2 is a functional block diagram showing an example of the functional configurations of the information processing system 100 and the notebook PC 1 according to the present embodiment. Note that FIG. 2 shows only the configurations related to the present invention among the functional configurations of the notebook PC 1.
[0027] As shown in FIG. 2, the information processing system 100 includes a notebook PC 1 and a boot server 2. The notebook PC 1 and the boot server 2 can be connected to each other via a network NW1.
[0028] The boot server 2 is, for example, a server device provided by the manufacturer of the notebook PC 1 to provide various services, and is a server device for network booting. The boot server 2 provides the notebook PC 1 with a startup program of an OS for network booting via the network NW1.
[0029] Also, as shown in FIG. 2, the notebook PC 1 includes a main control unit 10, a storage unit 40, and a NW (Network) communication unit 250.
[0030] The NW communication unit 250 is a functional unit realized by a network device such as a WLAN card 25, for example. The main control unit 10 can be connected to the network NW1 via the NW communication unit 250. Note that in the present embodiment, the NW communication unit 250 is described as being connected to the network NW1 using a wireless LAN (WiFi (registered trademark)).
[0031] The storage unit 40 is a storage unit realized by a memory such as a BIOS memory 22 or a main memory 12, for example, and stores various information used for various processes of the main control unit 10, for example. The storage unit 40 includes a trust list storage unit 41, a restriction list storage unit 42, and a chain flag storage unit 43.
[0032] The trust list storage unit 41 is a storage unit realized by, for example, the BIOS memory 22, and stores a trust list that is a list of sources of reliable startup programs. Here, the source refers to the device that is the execution source (startup source) of the startup program. For example, it is Https boot, a USB device connected to the USB connector 26, the built-in SSD 23, the firmware of the BIOS memory 22, and the like. Also, the startup program is, for example, various UEFI programs executed when starting an OS (such as Windows (registered trademark)). The trust list storage unit 41 stores a list of devices that can be trusted as the source (startup source). Here, referring to FIG. 3, a data example of the trust list storage unit 41 will be described.
[0033] FIG. 3 is a diagram showing a data example of the trust list storage unit 41 in the present embodiment. In the example shown in FIG. 3, the trust list stored in the trust list storage unit 41 includes "Firmware Volume" (firmware volume), "Https Boot", etc. as reliable UEFI Sources.
[0034] Here, "Firmware Volume" (firmware volume) indicates that the firmware of the BIOS memory 22 is the source (startup source), and "Https Boot" indicates that, for example, network boot by the boot server 2 is the source (startup source).
[0035] Returning to the description of FIG. 2, the restriction list storage unit 42 (an example of a usage restriction list storage unit) is a storage unit realized by, for example, the BIOS memory 22, and stores a list of protocols that restrict usage. Here, a protocol means a standard that defines procedures, rules, electrical rules for signals, transmission and reception procedures in communication, etc. determined for data exchange in the notebook PC 1. When the startup program (UEFI program) is executed from a provider (starting source) not in the above-described trust list, the restriction list storage unit 42 stores, as a usage restriction list, a list of protocols to be restricted (prohibited from use) in subsequent processing. The usage restriction list includes protocols that are highly likely to pose a security threat, such as protocols related to network connection and protocols related to TPM (Trusted Platform Module). Here, referring to FIG. 4, a data example of the restriction list storage unit 42 will be described.
[0036] FIG. 4 is a diagram showing a data example of the restriction list storage unit 42 in the present embodiment. In the example shown in FIG. 4, the usage restriction list stored in the restriction list storage unit 42 includes "WiFiInfoPassProtocol", "WiFiConfigProtocol", "BBBBBBBBBBProtocol", "CCCCCCCCProtocol", etc. as usage restriction protocols.
[0037] Here, "WiFiInfoPassProtocol" is a protocol for passing the SSID (Service Set Identifier) and password of a wireless LAN. Also, "WiFiConfigProtocol" is a protocol for performing connection settings for a wireless LAN.
[0038] Returning again to the description of FIG. 2, the chain flag storage unit 43 (an example of a chain information storage unit) is a storage unit realized by, for example, the system area of the main memory 12, and stores a boot chain flag (chain information) indicating whether an unauthorized startup program that may have been tampered with has been executed. In the boot chain flag, for example, information indicating a trusted state (e.g., "0") is stored when an unauthorized startup program has not been executed, and information indicating a distrusted state (e.g., "1") is stored when an unauthorized startup program has been executed.
[0039] The main control unit 10 is a functional unit realized by causing the CPU 11 and the chipset 21 to execute programs stored in the BIOS memory 22 and the SSD 23, and executes various processes based on the BIOS and the OS. The main control unit 10 includes a BIOS processing unit 110 and an OS processing unit 120.
[0040] The BIOS processing unit 110 executes various processes (BIOS processes) based on the BIOS. The BIOS processing unit 110 includes an authentication processing unit 111, a startup processing unit 112, and a restriction processing unit 113.
[0041] The authentication processing unit 111 confirms the validity of a startup program (e.g., a UEFI program) for starting the OS based on a predetermined security key in the BIOS process (BIOS process). The authentication processing unit 111 confirms the validity of the startup program (e.g., a UEFI program) by confirming the signature by the security key (e.g., a secure boot key). The authentication processing unit 111 executes an authentication process for secure boot, which will be described later.
[0042] The startup processing unit 112 executes various processes for starting the notebook PC 1 (OS) in the BIOS process (BIOS process). The startup processing unit 112 executes a secure boot process for executing the startup program whose validity has been confirmed by the authentication processing unit 111.
[0043] Further, in the secure boot process, when the startup processing unit 112 executes a startup program obtained from a provider not included in the trust list stored in the trust list storage unit 41, the startup processing unit 112 changes the boot chain flag stored in the chain flag storage unit 43 to information indicating that an unauthorized startup program has been executed.
[0044] The startup processing unit 112, for example, obtains the Device Path Class from the Device Path of the startup program (UEFI program), and based on the Device Path Class, confirms the provider of the startup program (UEFI program). The startup processing unit 112 determines whether the confirmed provider is included in the trust list stored in the trust list storage unit 41. When the confirmed provider is not included in the trust list stored in the trust list storage unit 41, the startup processing unit 112 changes the boot chain flag stored in the chain flag storage unit 43 from a trusted state (for example, "0") to a distrusted state (for example, "1").
[0045] When the boot chain flag stored in the chain flag storage unit 43 is information indicating that an unauthorized startup program has been executed (for example, the distrusted state "1"), the restriction processing unit 113 restricts the use of a preset security-related protocol. For example, when the boot chain flag is information indicating that an unauthorized startup program has been executed (for example, the distrusted state "1"), the restriction processing unit 113 restricts the use of the protocols included in the protocol list stored in the restriction list storage unit 42. For example, the restriction processing unit 113 prohibits the use of the protocols included in the usage restriction list shown in FIG. 3.
[0046] The OS processing unit 120 is a functional unit that takes over the processing after the BIOS processing unit 110 starts up the OS. The OS processing unit 120 executes various processes based on the OS.
[0047] Next, with reference to the drawings, the operation of the notebook PC 1 according to this embodiment will be described. First, referring to FIG. 5, the startup process of the notebook PC 1 according to the present embodiment will be described. FIG. 5 is a flowchart showing an example of the startup process of the notebook PC 1 according to the present embodiment.
[0048] As shown in FIG. 5, when the startup of the notebook PC 1 is started, the BIOS processing unit 110 of the notebook PC 1 starts the POST (Power On Self Test) process and sets the trust state "0" to the boot chain flag (step S101). The BIOS processing unit 110 stores the trust state "0" in the boot chain flag of the chain flag storage unit 43.
[0049] Next, the startup processing unit 112 of the BIOS processing unit 110 determines whether the boot source (supply source) is included in the trust list (step S102). The startup processing unit 112 confirms the source of the boot program (startup program) by the Device Path Class, and determines whether the confirmed source is included in the trust list stored in the trust list storage unit 41. When the boot source (supply source) is included in the trust list (step S102: YES), the startup processing unit 112 advances the process to step S104. Also, when the boot source (supply source) is not included in the trust list (step S102: NO), the startup processing unit 112 determines that an unauthorized boot program has been executed and advances the process to step S103.
[0050] In step S103, the startup processing unit 112 sets the untrusted state "1" to the boot chain flag. That is, the startup processing unit 112 stores the untrusted state "1" in the boot chain flag of the chain flag storage unit 43. After the process of step S103, the process advances to step S104.
[0051] In step S104, the startup processing unit 112 executes the boot program by Secure Boot. The startup processing unit 112 uses the authentication processing unit 111 to confirm the validity of the boot program and executes the process of the boot program whose validity has been confirmed.
[0052] Next, the startup processing unit 112 determines whether the boot process has been completed (step S105). That is, the startup processing unit 112 determines whether there is a boot program to be executed next. When the boot process is completed (there is no boot program to be executed next) (step S105: YES), the startup processing unit 112 transfers the process to the OS processing unit 120. Also, when the boot process is not completed (there is a boot program to be executed next) (step S105: YES), the startup processing unit 112 returns the process to step S102 and executes the process for the boot program to be executed next.
[0053] Next, with reference to FIG. 6, the protocol restriction process of the notebook PC 1 will be described. FIG. 6 is a flowchart showing an example of the protocol process of the notebook PC according to the present embodiment. Here, the protocol process is, for example, protocol processes such as InstallProtocol, LocalteProtocol, and HandleProtocol of the UEFI specification.
[0054] As shown in FIG. 6, the restriction processing unit 113 of the BIOS processing unit 110 determines whether the boot chain flag is in the untrusted state "1" (step S201). The restriction processing unit 113 determines whether the boot chain flag in the boot chain flag storage unit 43 is in the untrusted state "1". When the boot chain flag is in the untrusted state "1" (step S201: YES), the restriction processing unit 113 advances the process to step S203. Also, when the boot chain flag is not in the untrusted state "1" (in the trusted state "0") (step S201: NO), the restriction processing unit 113 advances the process to step S202.
[0055] In step S202, the BIOS processing unit 110 executes a protocol process. The BIOS processing unit 110 executes protocol processes such as InstallProtocol, LocalteProtocol, and HandleProtocol, for example. After the processing in step S202, the BIOS processing unit 110 advances the processing to the next processing.
[0056] Also, in step S203, the restriction processing unit 113 determines whether the protocol is included in the usage restriction list. The restriction processing unit 113 checks the usage restriction list stored in the restriction list storage unit 42 and determines whether the process is included in the usage restriction list. When the process is included in the usage restriction list (step S203: YES), the restriction processing unit 113 advances the processing to step S204. Also, when the process is not included in the usage restriction list (step S203: NO), the restriction processing unit 113 returns the processing to step S204.
[0057] In step S204, the restriction processing unit 113 returns an error result and does not execute the protocol process. After the processing in step S204, the restriction processing unit 113 advances the processing to the next processing.
[0058] Next, with reference to FIGS. 7 to 10, an attack example and the effects of the notebook PC 1 according to the present embodiment will be described. FIG. 7 is a diagram for explaining an example of a third-party attack in a conventional notebook PC.
[0059] In the attack example shown in FIG. 7, an example is shown in which an attacker AT1, who is a malicious third party, tries to steal connection information by implanting malware and forging a protocol before the execution of the Wifi Configuration App.
[0060] The attacker AT1 uses a USB to execute a boot program ATP1 that incorporates malware called "Attack.efi" and forges "WiFiConfigProtocol".
[0061] In the conventional notebook PC shown in Figure 7, when the BIOS subsequently executes the boot program BP1 called “WifiConfigurationApp.efi”, the attacker AT1 can steal wireless LAN connection information using the tampered “WiFiConfigProtocol”.
[0062] 8 is a first diagram for explaining the effect of the notebook PC 1 according to this embodiment against an attack by a third party. Here, a case where an attacker AT1 launches an attack similar to that in FIG. 7 against the notebook PC 1 according to this embodiment will be explained.
[0063] As shown in FIG. 8, in the notebook PC 1 according to this embodiment, when a boot program ATP1 called “Attack.efi” is executed from USB, for example, as shown in FIG. 3, the USB is not included in the trust list as a trusted source, so the boot processing unit 112 changes the boot chain flag to the untrusted state “1.”
[0064] Next, when the boot program BP1 called "WifiConfigurationApp.efi" is executed by the BIOS, the restriction processing unit 113 prohibits the use of "WiFiConfigProtocol" because "WiFiConfigProtocol" is included in the usage restriction list, for example, as shown in Fig. 4. Therefore, in the notebook PC 1 according to this embodiment, the attacker AT1 cannot steal the connection information of the wireless LAN.
[0065] FIG. 9 is a diagram for explaining another example of a third party's attack on a notebook PC according to the prior art. The example of an attack shown in Figure 9 shows an example in which a malicious third party, an attacker AT1, attempts to steal a password by running a boot program ATP2 called “EFIApp(Ver1)”, an old version in which a password leakage bug has been found, and using “WiFiInfoPassProtocol”.
[0066] Attacker AT1 can steal the Wi-Fi password by using USB to execute the boot program ATP2 of the old version "EFIApp (Ver1)" and causing "WiFiInfoPassProtocol" to be executed.
[0067] In contrast, FIG. 10 is a second diagram for explaining the effect of the notebook PC1 according to the present embodiment against a third-party attack. Here, a case where the attacker AT1 performs the same attack as in FIG. 9 described above on the notebook PC1 according to the present embodiment will be described.
[0068] As shown in FIG. 10, in the notebook PC1 according to the present embodiment, when the boot program ATP2 of "EFIApp (Ver1)" is executed from USB, for example, as shown in FIG. 3, since the USB is not in the trust list as a reliable source, the startup processing unit 112 changes the boot chain flag to the untrusted state "1".
[0069] Next, since the restriction processing unit 113 includes "WiFiInfoPassProtocol" in the usage restriction list as shown in FIG. 4, for example, the use of "WiFiInfoPassProtocol" is prohibited. Therefore, in the notebook PC1 according to the present embodiment, the attacker AT1 cannot steal the Wi-Fi password.
[0070] As described above, the notebook PC 1 (information processing apparatus) according to the present embodiment includes an authentication processing unit 111, a trust list storage unit 41, a chain flag storage unit 43 (chain information storage unit), a startup processing unit 112, and a restriction processing unit 113. The authentication processing unit 111 confirms the validity of a boot program (startup program) for starting the OS based on a predetermined security key in the BIOS process. The trust list storage unit 41 stores a trust list that is a list of sources of trustworthy boot programs. The chain flag storage unit 43 stores chain information (e.g., a boot chain flag) indicating whether an unauthorized boot program that may have been tampered with has been executed. In the secure boot process of causing the startup processing unit 112 to execute the boot program whose validity has been confirmed by the authentication processing unit 111, when a boot program obtained from a source not included in the trust list stored in the trust list storage unit 41 is executed, the startup processing unit 112 changes the boot chain flag stored in the chain flag storage unit 43 to information (untrusted state "1") indicating that an unauthorized boot program has been executed. When the boot chain flag stored in the chain flag storage unit 43 is information indicating that an unauthorized boot program has been executed, the restriction processing unit 113 restricts the use of a protocol related to security set in advance.
[0071] Thereby, the notebook PC 1 (information processing apparatus) according to the present embodiment can reduce the possibility that a program executed thereafter is tampered with or monitored even when, for example, a program tampered with by a third party is executed in secure boot (see FIGS. 8 and 10 described above). Therefore, the notebook PC 1 according to the present embodiment can improve the defense against attacks from third parties in secure boot.
[0072] Further, in the present embodiment, the trust list includes a firmware volume ("Firmware Volume") having the BIOS memory 22 in which the BIOS program is stored as a source, or a network boot ("Https Boot") having a preset server device as a source.
[0073] As a result, the notebook PC 1 according to the present embodiment lists a firmware volume (“Firmware Volume”) that can be safely booted or a network boot (“Https Boot”), and determines that it is in a state where an unauthorized boot program is executed (untrusted state “1”) by execution other than these (for example, booting from a USB). Therefore, it is possible to easily detect the execution of an unauthorized boot program that may have been tampered with.
[0074] In addition, the notebook PC 1 according to the present embodiment includes a restriction list storage unit 42 (usage restriction list storage unit) that stores a list of protocols to be restricted. When the boot chain flag is information indicating that an unauthorized boot program has been executed (untrusted state “1”), the restriction processing unit 113 restricts the use of the protocols included in the list of protocols stored in the restriction list storage unit 42.
[0075] As a result, the notebook PC 1 according to the present embodiment can appropriately restrict protocols that may pose a security threat by a simple method of a list of protocols to be restricted (usage restriction list). Therefore, the notebook PC 1 according to the present embodiment can further improve the defense against attacks from third parties in secure boot.
[0076] In addition, in the present embodiment, the list of protocols to be restricted includes protocols related to network connection (for example, “WiFiConfigProtocol”, etc.) or protocols related to TPM.
[0077] As a result, the notebook PC 1 according to the present embodiment can appropriately restrict protocols that are likely to pose a security threat. Therefore, the notebook PC 1 according to the present embodiment can further improve the defense against attacks from third parties in secure boot.
[0078] Also, the control method according to the present embodiment is a control method for the notebook PC 1 including the above-described authentication processing unit 111 and the chain flag storage unit 43, and includes a startup processing step and a restriction processing step. The authentication processing unit 111 confirms the validity of the boot program for starting the OS based on a predetermined security key in the BIOS process. The chain flag storage unit 43 stores a trust list storage unit 41 that stores a list of sources of reliable boot programs, and a boot chain flag indicating whether an unauthorized boot program that may have been tampered with has been executed. In the startup processing step, when the startup processing unit 112 causes a boot program obtained from a source not included in the trust list stored in the trust list storage unit 41 to be executed in the secure boot process, the chain flag storage unit 43 changes the boot chain flag stored therein to information indicating that an unauthorized boot program has been executed. In the restriction processing step, when the boot chain flag stored in the chain flag storage unit 43 is information indicating that an unauthorized startup program has been executed, the restriction processing unit 113 restricts the use of a protocol related to security set in advance.
[0079] Thereby, the control method according to the present embodiment has the same effect as the notebook PC 1 described above, and can improve the defense against attacks from third parties in secure boot.
[0080] Note that the present invention is not limited to the above-described embodiment, and can be changed without departing from the spirit of the present invention. For example, in the above-described embodiment, an example in which the information processing device is the notebook PC 1 has been described, but the present invention is not limited thereto, and for example, other information processing devices such as a tablet terminal device and a desktop PC may be used.
[0081] Also, in the above-described embodiment, the source of the trust list is not limited to an example shown in FIG. 3, and may include sources of other devices. Also, in the above-described embodiment, the protocol of the usage restriction list is not limited to the example shown in FIG. 4, and may include other protocols.
[0082] Each component included in the above-described notebook PC1 has a computer system inside. Then, a program for realizing the functions of each component included in the above-described notebook PC1 is recorded on a computer-readable recording medium, and the program recorded on this recording medium is read into the computer system and executed to perform the processing in each component included in the above-described notebook PC1. Here, "reading and executing the program recorded on the recording medium by the computer system" includes installing the program in the computer system. The "computer system" referred to here is assumed to include hardware such as an OS and peripheral devices. Also, the "computer system" may include a plurality of computer devices connected via a network including communication lines such as the Internet, WAN, LAN, and dedicated lines. The "computer-readable recording medium" refers to a portable medium such as a flexible disk, magneto-optical disk, ROM, CD-ROM, or a storage device such as a hard disk built into the computer system. In this way, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM.
[0083] In addition, the recording medium includes an internal or external recording medium that can be accessed from a distribution server for distributing the program. Note that the program may be divided into multiple parts and combined in each component of the notebook PC 1 after being downloaded at different timings, or the distribution servers that distribute each of the divided programs may be different. Further, the "computer-readable recording medium" includes those that hold a program for a certain period of time, such as a volatile memory (RAM) inside a computer system that becomes a server or a client when the program is transmitted via a network. Also, the above program may be for realizing a part of the functions described above. Furthermore, it may be a so-called difference file (difference program) that can realize the above functions in combination with a program already recorded in the computer system.
[0084] Also, part or all of the functions described above may be realized as an integrated circuit such as an LSI (Large Scale Integration). Each of the functions described above may be made into a processor individually, or part or all of them may be integrated and made into a processor. Also, the method of integrating into a circuit is not limited to LSI and may be realized by a dedicated circuit or a general-purpose processor. Also, when a technology for integrating into a circuit that replaces LSI appears due to the progress of semiconductor technology, an integrated circuit using such technology may be used.
Explanation of Signs
[0085] 1 Notebook PC 2 Boot server 10 Main control unit 11 CPU 12 Main memory 13 Video subsystem 14 Display unit 21 Chipset 22 BIOS memory 23 SSD 24 Audio system 25 WLAN card 26 USB connector 31 Embedded Controller (EC) 32 Input section 33 Power supply circuit 40 Memory section 41 Trust list memory section 42 Restriction list memory section 43 Chain flag memory section 100 Information processing system 110 BIOS processing section 111 Authentication processing section 112 Startup processing section 113 Restriction processing section 120 OS processing section 250 NW communication section NW1 Network
Claims
1. In the processing of the BIOS (Basic Input Output System), an authentication processing unit that verifies the legitimacy of a startup program for starting the OS (Operating System) based on a predetermined security key; A trust list storage unit that stores a trust list which is a list of sources providing the reliable startup program; A chain information storage unit that stores chain information indicating whether an illegal startup program that may have been tampered with has been executed; In the secure boot process of executing the startup program whose legitimacy has been verified by the authentication processing unit, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, the startup processing unit that changes the chain information stored in the chain information storage unit to information indicating that the illegal startup program has been executed; A restriction processing unit that restricts the use of a protocol related to security set in advance when the chain information stored in the chain information storage unit is information indicating that an illegal startup program has been executed An information processing apparatus comprising the same.
2. The trust list includes a firmware volume having the BIOS memory in which the BIOS program is stored as a source, or a network boot having a preset server device as a source The information processing apparatus according to claim 1.
3. Comprising a use restriction list storage unit that stores a list of the protocols to be restricted in use, When the chain information indicates that an illegal startup program has been executed, the restriction processing unit restricts the use of the protocols included in the list of protocols stored in the use restriction list storage unit The information processing apparatus according to claim 1 or claim 2.
4. The list of the protocols to be restricted in use includes a protocol related to network connection or a protocol related to TPM (Trusted Platform Module) The information processing apparatus according to claim 3.
5. In the processing of the BIOS (Basic Input Output System), based on a predetermined security key, an authentication processing unit that verifies the validity of a startup program for starting the OS (Operating System), a trust list storage unit that stores a trust list which is a list of reliable sources of the startup program, and a chain information storage unit that stores chain information indicating whether an unauthorized startup program that may have been tampered with has been executed. A control method for an information processing apparatus comprising: In a secure boot process in which a startup processing unit causes the startup program whose validity has been verified by the authentication processing unit to be executed, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, a startup processing step of changing the chain information stored in the chain information storage unit to information indicating that the unauthorized startup program has been executed; A restriction processing step in which a restriction processing unit restricts the use of a protocol related to security set in advance when the chain information stored in the chain information storage unit is information indicating that an unauthorized startup program has been executed; A control method including the above.
6. In the computer of an information processing apparatus including an authentication processing unit that verifies the validity of a startup program for starting the OS (Operating System) based on a predetermined security key in the processing of the BIOS (Basic Input Output System), a trust list storage unit that stores a trust list which is a list of reliable sources of the startup program, and a chain information storage unit that stores chain information indicating whether an unauthorized startup program that may have been tampered with has been executed, In a secure boot process in which the startup program whose validity has been verified by the authentication processing unit is executed, when the startup program obtained from a source not included in the trust list stored in the trust list storage unit is executed, a startup processing step of changing the chain information stored in the chain information storage unit to information indicating that the unauthorized startup program has been executed; When the chain information stored in the chain information storage unit is information indicating that an unauthorized startup program has been executed, a restriction processing step for restricting the use of a preset security-related protocol, and A program for causing the execution.
Citation Information
Patent Citations
Authentication method, authentication program, and information processor
JP2017146694A