Information processing apparatus, firmware updating system and program
The described firmware update system addresses the challenges of secure and easy firmware updates across devices of the same model by using unique key pairs to decrypt encrypted firmware, thereby enhancing security and usability.
Patent Information
- Application Number
- JP2024161629
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-09-19
- Publication Date
- 2025-06-02
AI Technical Summary
Conventional firmware update systems for printers face challenges in securely updating firmware across different devices of the same model while allowing for individual settings, and they struggle with the practicality of encrypting firmware with device-unique secret keys for public distribution.
An information processing apparatus and firmware update system that generate a pair of unique secret and public keys, allowing the decryption of encrypted firmware using a common key, which is encrypted with the unique public key, thereby enabling secure and easy firmware updates across devices of the same model.
This solution enhances security performance by ensuring that only authorized devices can decrypt and update their firmware, while also facilitating easy use of firmware updates without compromising security.
Smart Images

Figure 2025084061000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing apparatus, a firmware update system, and a program.
Background Art
[0002] In order to prevent malicious persons from tampering with the FW (FirmWare) for updating a printer, conventionally, a common key was prepared for each printer model, and the FW was encrypted with the common key (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the conventional technology, since a common key is prepared for each printer model, it has been difficult to perform individual settings of FW between different devices when they are of the same printer model.
[0005] On the other hand, since the FW for updating is to be made public to the printer user, it is not practical to post the updated FW encrypted with the device-unique secret key on the public server.
[0006] Therefore, one or more aspects of the present disclosure aim to enhance security performance while enabling easy use of the FW for updating an information processing apparatus.
Means for Solving the Problems
[0007] An information processing apparatus according to one aspect of the present disclosure is an information processing apparatus capable of acquiring the first encrypted firmware from a storage device that stores the first encrypted firmware obtained by encrypting firmware with a common key via an information communication apparatus, the information processing apparatus including: a first communication unit that communicates with the information communication apparatus; a first key generation unit that generates a pair of a first unique secret key and a first unique public key, which is a pair of a secret key and a public key; a key processing unit that receives, via the first communication unit, a second encrypted firmware including an encrypted common key obtained by encrypting the common key using the first unique public key and the first encrypted firmware, decrypts the encrypted common key using the first unique secret key to obtain the common key, and decrypts the first encrypted firmware using the common key to obtain the firmware; and a firmware update unit that updates the firmware of the information processing apparatus using the firmware.
[0008] A firmware update system according to the first aspect of the present disclosure is a firmware update system including the above-described information processing apparatus, wherein the information processing apparatus further includes a key management unit that sends the first unique public key to the information communication apparatus via the first communication unit, the information communication apparatus includes: a second communication unit that communicates with the information processing apparatus and the storage device; a key acquisition unit that acquires the first unique public key from the information processing apparatus via the second communication unit; a firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit; and a first encryption unit that generates the encrypted common key by encrypting the common key using the first unique public key and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware, and the storage device includes: a third communication unit that communicates with the information communication apparatus; and a firmware management unit that sends the first encrypted firmware to the information communication apparatus via the third communication unit.
[0009] A firmware update system according to a second aspect of the present disclosure includes the information processing apparatus, and in a firmware update system including a plurality of information processing apparatuses configured in the same manner as the information processing apparatus, the information communication apparatus includes a second communication unit that communicates with the plurality of information processing apparatuses and the storage device, a key acquisition unit that acquires the first unique public key from each of the plurality of information processing apparatuses via the second communication unit, a firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit, a temporary storage unit that temporarily stores the first encrypted firmware, a first encryption unit that generates the encrypted common key for each of the plurality of information processing apparatuses by encrypting the common key using the first unique public key of each of the plurality of information processing apparatuses, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing apparatuses, a firmware update management unit that sends the second encrypted firmware to each of the plurality of information processing apparatuses, and after sending the corresponding second encrypted firmware to all of the plurality of information processing apparatuses, deletes the first encrypted firmware from the temporary storage unit, and the storage device includes a third communication unit that communicates with the information communication apparatus, and a firmware management unit that sends the first encrypted firmware to the information communication apparatus via the third communication unit.
[0010] The firmware update system according to the third aspect of the present disclosure includes the above information processing apparatus, and in the firmware update system including a plurality of information processing apparatuses configured in the same manner as the information processing apparatus, the information communication apparatus includes: a second communication unit that communicates with the plurality of information processing apparatuses and the storage device; a key acquisition unit that acquires the first unique public key from each of the plurality of information processing apparatuses via the second communication unit; a second key generation unit that generates a pair of a second unique private key and a second unique public key, which is a pair of a private key and a public key; a firmware acquisition unit that sends the second unique public key to the storage device via the second communication unit and acquires third encrypted firmware obtained by encrypting the first encrypted firmware with the second unique public key; a decryption unit that decrypts the third encrypted firmware using the second unique private key to acquire the first encrypted firmware; a temporary storage unit that temporarily stores the first encrypted firmware; a first encryption unit that generates an encrypted common key for each of the plurality of information processing apparatuses by encrypting the common key using the first unique public key of each of the plurality of information processing apparatuses, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing apparatuses; a firmware update management unit that sends the second encrypted firmware to each of the plurality of information processing apparatuses, and after sending the corresponding second encrypted firmware to all of the plurality of information processing apparatuses, deletes the first encrypted firmware from the temporary storage unit. The storage device includes: a third communication unit that communicates with the information communication apparatus; a second encryption unit that encrypts the first encrypted firmware using the second unique public key acquired via the third communication unit to generate the third encrypted firmware; and a firmware management unit that sends the third encrypted firmware to the information communication apparatus via the third communication unit.
[0011] A program according to one aspect of the present disclosure causes a computer to function as an information processing device that acquires first encrypted firmware obtained by encrypting firmware with a common key from a storage device storing the first encrypted firmware via an information communication device, the program causing the computer to function as a first key generation unit that generates a pair of a first unique secret key and a first unique public key, which is a pair of a secret key and a public key, and a first communication unit that communicates with the information communication device to receive second encrypted firmware including an encrypted common key obtained by encrypting the common key using the first unique public key and the first encrypted firmware, and further causing the computer to function as a key processing unit that decrypts the encrypted common key using the first unique secret key to obtain the common key, and decrypts the first encrypted firmware using the common key to obtain the firmware.
Advantages of the Invention
[0012] According to one or more aspects of the present disclosure, it is possible to easily use FW for updating an information processing device while enhancing security performance.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Embodiments for Carrying Out the Invention
[0014] Embodiment 1. FIG. 1 is a block diagram schematically showing the configuration of an FW (FirmWare) update system 100 according to Embodiment 1. The FW update system 100 includes a server 110 as a storage device, a PC (Personal Computer) 130 as an information communication device, and a printer 150 as an information processing device. The server 110 and the PC 130 are connected to a first network 101, for example, the Internet, and the PC 130 and the printer 150 are connected to a second network 102, for example, a LAN (Local Area Network). Note that the PC 130 is connected to the first network 101 via a relay device 103 such as a router.
[0015] The FW update system 100 includes a PC 130, a server 110 that stores a first encrypted FW obtained by encrypting the FW with a common key, and a printer 150 that acquires the first encrypted FW via the PC 130. In the FW update system 100, the PC 130 acquires the FW from the server 110, and the printer 150 acquires the FW from the PC 130. Then, the printer 150 updates its own FW using the acquired FW.
[0016] FIG. 2 is a block diagram schematically showing the configuration of the server 110 in Embodiment 1. The server 110 includes a communication unit 111, a storage unit 112, and a control unit 120.
[0017] The communication unit 111 is a third communication unit that communicates with the PC 130. For example, the communication unit 111 communicates with the PC 130 via the first network 101 and the relay device 103.
[0018] The storage unit 112 stores data and programs necessary for processing in the server 110. For example, the storage unit 112 stores a common key encrypted FW 113 obtained by encrypting the FW using a common key shared with the PC 130 as the first encrypted FW.
[0019] The control unit 120 controls the processing in the server 110. The control unit 120 includes an FW management unit 121.
[0020] The FW management unit 121 sends the common key encrypted FW 113 to the PC 130 via the communication unit 111. For example, the FW management unit 121 receives a request to obtain the FW of the printer 150 from the PC 130 via the communication unit 111. When the FW management unit 121 receives the acquisition request, it reads out the common key encrypted FW 113 from the storage unit 112. Then, the FW management unit 121 sends the common key encrypted FW 113 to the PC 130 via the communication unit 111.
[0021] The server 110 described above can be realized by a computer 10 as shown in, for example, FIG. 3. The computer 10 includes a storage 11 such as an HDD (Hard Disk Drive) and an SSD (Solid State Drive), a memory 12, a processor 13 such as a CPU (Central Processing Unit), and a communication I / F (Interface) 14 such as a NIC (Network Interface Card).
[0022] For example, the storage unit 112 can be realized by the storage 11 or the memory 12. The control unit 120 can be realized by loading a program stored in the storage 11 into the memory 12 and having the processor 13 execute the program. The communication unit 111 can be realized by the communication I / F 14.
[0023] The program may be downloaded from a recording medium (not shown) via a reader / writer (not shown) or from a network via the communication I / F 14 to the storage 11, and then loaded onto the memory 12 and executed by the processor 13. Alternatively, it may be directly loaded onto the memory 12 from a recording medium via a reader / writer or from a network via the communication I / F 14 and executed by the processor 13. In other words, the program may be provided by a computer program product such as a recording medium.
[0024] FIG. 4 is a block diagram schematically showing the configuration of the PC 130 in the first embodiment. The PC 130 includes a communication unit 131, a storage unit 133, and a control unit 140.
[0025] The communication unit 131 is a second communication unit that communicates with the printer 150 and the server 110. Specifically, the communication unit 131 communicates with the server 110 via the second network 102, the relay device 103, and the first network 101. Also, the communication unit 131 communicates with the printer 150 via the second network 102.
[0026] The storage unit 133 stores data and programs necessary for processing in the PC 130. For example, the storage unit 133 stores a common key 134. The common key 134 is a key shared with the server 110.
[0027] The control unit 140 controls the processing in the PC 130. The control unit 140 includes a key acquisition unit 141, a FW acquisition unit 142, and an encryption unit 143.
[0028] The key acquisition unit 141 acquires the device-specific public key from the printer 150 via the communication unit 131. Specifically, the key acquisition unit 141 sends a request for acquiring the device-specific public key to the printer 150 via the communication unit 131, and acquires the device-specific public key of the printer 150 as a response. The device-specific public key thus acquired is given to the encryption unit 143.
[0029] The FW acquisition unit 142 acquires the common key-encrypted FW 113 as the first encrypted FW from the server 110 via the communication unit 131. Specifically, the FW acquisition unit 142 sends a FW acquisition request to the server 110 via the communication unit 131, and as a response thereto, receives the common key encrypted FW 113. The FW acquisition unit 142 provides the common key encrypted FW 113 received from the server 110 to the encryption unit 143.
[0030] Further, the FW acquisition unit 142 receives the FW with an encrypted common key, which is generated by attaching the encrypted common key obtained by encrypting the common key 134 with the device-specific public key from the encryption unit 143 to the common key encrypted FW 113. Then, the FW acquisition unit 142 sends the FW with an encrypted common key received from the encryption unit 143 to the printer 150 via the communication unit 131 as the second encrypted FW.
[0031] The encryption unit 143 is a first encryption unit that generates an encrypted common key by encrypting the common key 134 using the device-specific public key acquired via the communication unit 131. For example, the encryption unit 143 receives the device-specific public key of the printer 150 from the key acquisition unit 141, and generates an encrypted common key by encrypting the common key 134 stored in the storage unit 133 using the device-specific public key.
[0032] Then, the encryption unit 143 generates the FW with an encrypted common key by attaching the encrypted common key to the common key encrypted FW 113. The encryption unit 143 provides the generated FW with an encrypted common key to the FW acquisition unit 142.
[0033] The PC 130 described above can also be realized by a computer 10 as shown in, for example, FIG. 3.
[0034] For example, the storage unit 133 can be realized by the storage 11 or the memory 12. The control unit 140 can be realized by loading the program stored in the storage 11 into the memory 12 and having the processor 13 execute the program. The communication unit 131 can be realized by the communication I / F 14.
[0035] FIG. 5 is a block diagram schematically showing the configuration of the printer 150 in the first embodiment. The printer 150 includes a communication unit 151, a storage unit 152, a control unit 160, and a printer main body 170 as an information processing apparatus main body.
[0036] The communication unit 151 is a first communication unit that communicates with the PC 130 via the first network 101.
[0037] The storage unit 152 stores data and programs necessary for processing in the printer 150. For example, the storage unit 152 stores a device unique secret key 153 as a first unique secret key and a device unique public key 154 as a first unique public key.
[0038] The pair of the device unique secret key 153 and the device unique public key 154 is a pair of a secret key and a public key generated by the printer 150 according to the public key cryptosystem. In the pair of the secret key and the public key generated by the public key cryptosystem, encrypted data encrypted using the public key cannot be decrypted without the secret key. Any known technique may be used as the public key cryptosystem here.
[0039] The control unit 160 controls the processing in the printer 150. The control unit 160 includes a key generation unit 161, a key management unit 162, a key processing unit 163, and an FW update unit 164.
[0040] The key generation unit 161 is a first key generation unit that generates a pair of the device unique secret key 153 and the device unique public key 154, which is a pair of a secret key and a public key of the printer 150. For example, the key generation unit 161 generates a device-specific secret key 153 and a device-specific public key 154, which are a pair of a unique secret key and a public key of the printer 150, according to a known public-key cryptosystem. Here, the key generation unit 161 may generate the device-specific secret key 153 and the device-specific public key 154 when the printer 150 is first started up. The generated device-specific secret key 153 and device-specific public key 154 are stored in the storage unit 152.
[0041] The key management unit 162 manages the device-specific secret key 153 and the device-specific public key 154 stored in the storage unit 152. For example, the key management unit 162 sends the device-specific public key to the PC 130 via the communication unit 151. Specifically, when the key management unit 162 receives a request for acquiring the device-specific public key from the PC 130 via the communication unit 151, the key management unit 162 reads out the device-specific public key 154 from the storage unit 152 and responds to the PC 130 with the device-specific public key 154 via the communication unit 151.
[0042] The key processing unit 163 receives a second encrypted FW including an encrypted common key obtained by encrypting the common key using the device-specific public key via the communication unit 151, decrypts the encrypted common key using the device-specific secret key, and acquires the common key. Then, the key processing unit 163 decrypts the common key encrypted FW 113 included in the second encrypted FW using the decrypted common key to acquire the FW.
[0043] Specifically, when the key processing unit 163 receives the FW with the encrypted common key from the PC 130 via the communication unit 151, the key processing unit 163 decrypts the encrypted common key included in the FW with the encrypted common key using the device-specific secret key 153 read out from the storage unit 152 to acquire the common key. Also, the key processing unit 163 decrypts the common key encrypted FW 113 included in the FW with the encrypted common key using the common key thus acquired to acquire the FW. The FW thus acquired is provided to the FW update unit 164.
[0044] The FW update unit 164 updates the FW of the printer 150 using the FW acquired by the key processing unit 163. For example, the FW update unit 164 updates the FW by rewriting the FW stored in a storage unit (not shown) of the printer main body 170 with the FW decrypted by the key processing unit 163.
[0045] The printer main body 170 is a part that executes the process of printing an image on a medium. Here, the printer main body 170 may perform printing by an electrophotographic method, an inkjet method, a dot impact method, or the like, and there is no limitation on the method of performing printing.
[0046] A part or all of the control unit 160 of the printer 150 described above can be configured by, for example, a memory 20 and a processor 21 such as a CPU (Central Processing Unit) that executes a program stored in the memory 20, as shown in FIG. 6(A). Such a program may be provided through a network or may be provided by being recorded on a recording medium. That is, such a program may be provided as, for example, a computer program product.
[0047] Also, a part or all of the control unit 160 can be configured by, for example, a processing circuit 22 such as a single circuit, a composite circuit, a processor that operates with a program, a parallel processor that operates with a program, an ASIC (Application Specific Integrated Circuit), or an FPGA (Field Programmable Gate Array), as shown in FIG. 6(B). As described above, the control unit 160 can be realized by a processing circuit network.
[0048] Note that the storage unit 152 can be realized by a storage such as a memory. Also, the communication unit 151 can be realized by a communication I / F such as a NIC. Furthermore, the printer main body 170 can be realized by a printing mechanism that performs printing by an electrophotographic method, an inkjet method, a dot impact method, or the like.
[0049] FIG. 7 is a sequence diagram showing the operation of the FW update system 100 in the first embodiment. First, the key acquisition unit 141 of the PC 130 sends a request to acquire the device-specific public key of the printer 150 to the printer 150 via the communication unit 131 (S10).
[0050] In the printer 150 that has received such an acquisition request, the key management unit 162 responds by sending the device-specific public key 154 read from the storage unit 152 to the PC 130 via the communication unit 151 (S11).
[0051] Next, in the PC 130, the FW acquisition unit 142 sends a request to acquire the FW to the server 110 via the communication unit 131 (S12).
[0052] In the server 110 that has received such an acquisition request, the FW management unit 121 reads out the common key-encrypted FW 113 stored in the storage unit 112 and responds by sending the common key-encrypted FW 113 to the PC 130 via the communication unit 111 (S13).
[0053] In the PC 130 that has received the common key-encrypted FW 113, the encryption unit 122 encrypts the common key 134 stored in the storage unit 133 using the device-specific public key 154 received in step S11 to generate an encrypted common key (S14). Then, the encryption unit 122 attaches the encrypted common key to the common key-encrypted FW 113 acquired in step S13 to generate an FW with an attached encrypted common key.
[0054] The FW acquisition unit 142 sends the FW with the attached encrypted common key to the printer 150 via the communication unit 131 (S15).
[0055] In the printer 150 that has received the FW with the encrypted common key, the key processing unit 163 obtains the common key by decrypting the encrypted common key included in the FW with the encrypted common key using the device-specific secret key 153 read from the storage unit 152 (S16).
[0056] Also, the key processing unit 163 obtains the FW by decrypting the common key-encrypted FW 113 included in the FW with the encrypted common key using the common key thus obtained (S17).
[0057] Then, the FW update unit 164 updates the FW of the printer 150 using such FW (S18).
[0058] In the sequence described above, after the PC 130 obtains the device-specific public key 154 from the printer 150 (S10 and S11), it obtains the common key-encrypted FW 113 from the server 110 (S12 and S13). However, the first embodiment is not limited to such an example. For example, the PC 130 may obtain the device-specific public key 154 from the printer 150 (S10 and S11) after obtaining the common key-encrypted FW 113 from the server 110 (S12 and S13).
[0059] As described above, in the first embodiment, even if the FW with the encrypted common key is leaked, other devices cannot decrypt the FW with the encrypted common key, so the security performance is improved. Also, even if the device-specific secret key is leaked, other printers 150 cannot use the device-specific secret key.
[0060] Second Embodiment. FIG. 8 is a block diagram schematically showing the configuration of the FW update system 200 according to the second embodiment. The FW update system 200 includes a server 110, a PC 230, and printers 150A and 150B. The server 110 and the PC 230 are connected to the first network 101, and the PC 230 and the printers 150A and 150B are connected to the second network 102. Note that the PC 230 is connected to the first network 101 via the relay device 103.
[0061] The server 110 of the FW update system 200 according to the second embodiment is configured in the same manner as the server 110 of the FW update system 100 according to the first embodiment. Also, the FW update system 200 according to the second embodiment includes two printers 150A and 150B, and each of the two printers 150A and 150B is configured in the same manner as the printer 150 in the FW update system 100 according to the first embodiment. Note that when there is no need to particularly distinguish between the printers 150A and 150B, each of the printers 150A and 150B is referred to as the printer 150. Also, in the second embodiment, two printers 150 are provided, but the number of printers 150 may be plural.
[0062] In the FW update system 200 according to the second embodiment, the PC 230 acquires the FW from the server 110 and sends it to the plurality of printers 150A and 150B. Then, each of the plurality of printers 150A and 150B updates its own FW using the acquired FW.
[0063] FIG. 9 is a block diagram schematically showing the configuration of the PC 230 in the second embodiment. The PC 230 includes a communication unit 131, a temporary storage unit 232, a storage unit 133, and a control unit 240.
[0064] The communication unit 131 and the storage unit 133 of the PC 230 in the second embodiment are the same as those of the communication unit 131 and the storage unit 133 of the PC 130 in the first embodiment.
[0065] The temporary storage unit 232 temporarily stores data necessary for processing in the PC 230. Here, the temporary storage unit 232 temporarily stores the common key encrypted FW 113 acquired from the server 110.
[0066] The control unit 240 controls the processing on the PC 230. The control unit 240 includes a key acquisition unit 241, a FW acquisition unit 242, an encryption unit 243, and a FW update management unit 244.
[0067] The FW update management unit 244 manages the FW updates of the printers 150A and 150B connected to the second network 102 to which the PC 230 is connected. For example, the FW update management unit 244 performs device discovery via the communication unit 131 in order to detect the printers 150A and 150B for which the FW update is to be managed. The technique for performing device discovery may be, for example, a Get request by broadcast for a specific OID (Object IDentifier) using SNMP (Simple Network Management Protocol), or an inquiry by multicast such as MDNS (Multicast Domain Name System), and any known technique capable of discovering devices connected to the network may be used. Here, it is assumed that the printers 150A and 150B are detected by device discovery by the FW update management unit 244.
[0068] As will be described later, the FW update management unit 244 stores the common key encrypted FW 113 acquired by the FW acquisition unit 242 in the temporary storage unit 232.
[0069] Then, as will be described later, the FW update management unit 244 sends the FW with an encrypted common key including the encrypted common key encrypted by the encryption unit 243 to each of the plurality of printers 150, and after sending the FW with the corresponding encrypted common key to all of the plurality of printers 150, deletes the common key encrypted FW from the temporary storage unit 232. Specifically, as will be described later, the FW update management unit 244 sends the FW with the encrypted common key generated by the encryption unit 243 to the printers 150A and 150B detected by device discovery via the communication unit 131. Then, when the FW update management unit 244 sends the FW with the encrypted common key to all the printers 150A and 150B detected by device discovery, it deletes the common key encrypted FW stored in the temporary storage unit 232.
[0070] The FW acquisition unit 242 acquires the common key encrypted FW 113 from the server 210 via the communication unit 131. Specifically, the FW acquisition unit 242 sends a FW acquisition request to the server 210 via the communication unit 131, and receives the common key encrypted FW 113 as a response thereto. Then, the FW acquisition unit 242 provides the common key encrypted FW 113 received from the server 210 to the FW update management unit 244.
[0071] The key acquisition unit 241 acquires the device-specific public key from each of the plurality of printers 150 via the communication unit 131. Specifically, the key acquisition unit 241 sends a device-specific public key acquisition request to each of the printers 150A and 150B detected by the FW update management unit 244 via the communication unit 131, and acquires the device-specific public key from each of the printers 150A and 150B as a response thereto. The device-specific public key thus acquired is provided to the encryption unit 243.
[0072] The encryption unit 243 generates an encrypted common key by encrypting the common key 134 stored in the storage unit 133 using the device-specific public key of each of the plurality of printers 150. Then, the encryption unit 243 is a first encryption unit that generates the FW with the encrypted common key as the second encrypted FW by attaching the generated encrypted common key to the common key encrypted FW 113 stored in the temporary storage unit 232.
[0073] Specifically, the encryption unit 243 receives the device-specific public key from the key acquisition unit 241, and generates an encrypted common key by encrypting the common key 134 stored in the storage unit 133 using the device-specific public key. Next, the encryption unit 243 generates an FW with an encrypted common key by attaching the generated encrypted common key to the common key encryption FW stored in the temporary storage unit 232. The FW with the encrypted common key thus generated is provided to the FW update management unit 244.
[0074] The PC 230 described above can also be realized by the computer 10 as shown in FIG. 3, for example. For example, the temporary storage unit 232 can be realized by the memory 12.
[0075] FIG. 10 is a sequence diagram showing the operation of the FW update system 200 in the second embodiment. First, the FW update management unit 244 of the PC 230 sends a packet for device discovery of the devices connected to the second network 102 to which the PC 230 is connected via the communication unit 131 (S20, S21).
[0076] In the printer 150A that has received such a packet, the communication unit 151 returns a response packet (S22). Similarly, in the printer 150B as well, the communication unit 151 returns a response packet (S23). As described above, the FW update management unit 244 of the PC 230 can detect the printer 150A and the printer 150B connected to the second network 102.
[0077] Next, the FW acquisition unit 242 of the PC 230 sends an FW acquisition request to the server 210 via the communication unit 131 (S24).
[0078] In the server 210 that has received such an acquisition request, the FW management unit 221 responds by sending the common key encryption FW 113 stored in the storage unit 112 to the PC 230 via the communication unit 111 (S25).
[0079] On the PC 230 that has received the common key encrypted FW 113, the FW update management unit 244 receives the common key encrypted FW 113 via the communication unit 131 and the FW acquisition unit 242, and temporarily stores the common key encrypted FW 113 in the temporary storage unit 232 (S26). Note that the temporary storage unit 232 is a functional unit realized by the volatile memory 12 (see FIG. 3) in order to reliably delete the common key encrypted FW 113 after use.
[0080] Next, the key acquisition unit 241 of the PC 230 sends a request to acquire the device-specific public key of the printer 150A to the printer 150A detected by the response packet in step S22 via the communication unit 131 (S27).
[0081] In the printer 150A that has received such an acquisition request, the key management unit 162 responds by sending the device-specific public key 154 read from the storage unit 152 to the PC 230 via the communication unit 151 (S28).
[0082] On the PC 230 that has received the response of the device-specific public key 154, the encryption unit 243 encrypts the common key 134 stored in the storage unit 133 using the device-specific public key 154 received from the printer 150A to generate an encrypted common key (S29). Then, the encryption unit 243 attaches the generated encrypted common key to the common key encrypted FW 113 stored in the temporary storage unit 232 to generate an FW with an encrypted common key.
[0083] Then, the FW update management unit 244 of the PC 230 sends the generated FW with an encrypted common key to the printer 150A via the communication unit 131 (S30).
[0084] In the printer 150A that has received the FW with an encrypted common key, the key processing unit 163 decrypts the encrypted common key included in the FW with an encrypted common key using the device-specific secret key 153 read from the storage unit 152 to acquire the common key (S31).
[0085] Also, the key processing unit 163 obtains the FW by decrypting the common key encryption FW 113 included in the FW with the common key encryption FW with the acquired common key (S32).
[0086] Then, the FW update unit 164 updates the FW of the printer 150A using such FW (S33).
[0087] Also, the key acquisition unit 241 of the PC 230 sends a request to acquire the device-specific public key of the printer 150B to the printer 150B detected by the response packet in step S23 via the communication unit 131 (S34).
[0088] In the printer 150B that has received such an acquisition request, the key management unit 162 responds by sending the device-specific public key 154 read from the storage unit 152 to the PC 230 via the communication unit 151 (S35).
[0089] In the PC 230 that has received the response of the device-specific public key 154, the encryption unit 243 encrypts the common key 134 stored in the storage unit 133 using the device-specific public key 154 received from the printer 150B to generate an encrypted common key (S36). Then, the encryption unit 243 generates the FW with the encrypted common key by attaching the generated encrypted common key to the common key encryption FW 113 stored in the temporary storage unit 232.
[0090] Then, the FW update management unit 244 of the PC 230 sends the generated FW with the encrypted common key to the printer 150B via the communication unit 131 (S37).
[0091] In the printer 150B that has received the FW with the encrypted common key, the key processing unit 163 obtains the common key by decrypting the encrypted common key included in the FW with the encrypted common key using the device-specific secret key 153 read from the storage unit 152 (S38).
[0092] Also, the key processing unit 163 obtains the FW by decrypting the common key encryption FW 113 included in the FW with the obtained common key (S39).
[0093] Then, the FW update unit 164 updates the FW of the printer 150B using such FW (S40).
[0094] When the transmission of the FW with the encrypted common key to all the printers 150 detected in the device search in steps S20 to S23 is completed, the FW update management unit 244 of the PC 230 deletes the common key encryption FW 113 stored in the temporary storage unit 232 (S41).
[0095] In the sequence described above, after the PC 230 obtains the common key encryption FW 113 from the server 110 (S24 and S25), it obtains the device-specific public key 154 from the printers 150A and 150B (S27 and S28, or S34 and S35). However, the second embodiment is not limited to such an example. For example, the PC 230 may obtain the device-specific public key 154 from the printers 150A and 150B (S27 and S28, or S34 and S35) and then obtain the common key encryption FW 113 from the server 110 (S12 and S13).
[0096] As described above, according to the second embodiment, for each of the plurality of printers 150, when downloading the FW, the traffic increases. Therefore, by encrypting the FW in the PC 230, the traffic can be reduced, and by deleting the FW from the PC 230, the security performance can be improved.
[0097] Embodiment 3. As shown in FIG. 8, the FW update system 300 according to the third embodiment includes a server 310, a PC 330, and printers 150A and 150B.
[0098] The FW update system 300 according to Embodiment 3 also includes two printers 150A and 150B, and each of the two printers 150A and 150B is configured in the same manner as the printer 150 in the FW update system 100 according to Embodiment 1. When there is no need to particularly distinguish each of the printers 150A and 150B, each of the printers 150A and 150B is referred to as the printer 150.
[0099] FIG. 11 is a block diagram schematically showing the configuration of the server 310 in Embodiment 3. The server 310 includes a communication unit 111, a storage unit 112, and a control unit 320.
[0100] The communication unit 111 and the storage unit 112 of the server 310 in Embodiment 3 are the same as the communication unit 111 and the storage unit 112 of the server 110 in Embodiment 1.
[0101] The control unit 320 controls the processing in the server 310. The control unit 320 includes an FW management unit 321 and an encryption unit 322.
[0102] The FW management unit 321 receives a request to acquire the FW of the printer 150 from the PC 330 via the communication unit 111. The FW management unit 321 extracts the PC-specific public key, which is the public key specific to the PC 330 included in the acquisition request, and gives the PC-specific public key to the encryption unit 322. In addition, the FW management unit 321 acquires the re-encrypted FW, which is the common key-encrypted FW 113 re-encrypted using the PC-specific public key, from the encryption unit 322. Then, the FW management unit 321 sends the re-encrypted FW to the PC 330 via the communication unit 111.
[0103] The encryption unit 322 is a second encryption unit that encrypts the common key-encrypted FW 113 as the first encrypted FW using the PC-specific public key acquired via the communication unit 111 to generate the re-encrypted FW as the third encrypted FW. Specifically, the encryption unit 322 receives the PC-specific public key of the PC 330 from the FW management unit 321, and uses the PC-specific public key to re-encrypt the common key encrypted FW 113 stored in the storage unit 112, thereby generating a re-encrypted FW which is the re-encrypted common key encrypted FW. Then, the encryption unit 322 provides the re-encrypted FW to the FW management unit 321.
[0104] FIG. 12 is a block diagram schematically showing the configuration of the PC 330 in the third embodiment. The PC 330 includes a communication unit 131, a temporary storage unit 332, a storage unit 333, and a control unit 340.
[0105] The communication unit 131 of the PC 330 in the third embodiment is the same as the communication unit 131 of the PC 130 in the first embodiment.
[0106] The temporary storage unit 332 temporarily stores data necessary for processing in the PC 330. Here, the temporary storage unit 332 temporarily stores the common key encrypted FW 113 acquired from the server 310 and decrypted in the PC 330.
[0107] The storage unit 333 stores data and programs necessary for processing in the PC 330. For example, the storage unit 333 stores a common key 134, a PC-specific secret key 335 as the second specific secret key, and a PC-specific public key 336 as the second specific public key.
[0108] The common key 134 stored in the storage unit 333 in the third embodiment is the same as the common key 134 stored in the storage unit 133 in the first embodiment.
[0109] The pair of the PC-specific secret key 335 and the PC-specific public key 336 is a pair of a secret key and a public key generated in the PC 330 according to the public key cryptosystem. Any known technique may be used as the public key cryptosystem here.
[0110] The control unit 340 controls the processing in the PC 330. The control unit 340 includes a key acquisition unit 241, an FW acquisition unit 342, an encryption unit 243, an FW update management unit 244, a key generation unit 345, and a decryption unit 346.
[0111] The key acquisition unit 241, the encryption unit 243, and the FW update management unit 244 of the control unit 340 in Embodiment 3 are the same as those of the control unit 240 in Embodiment 2.
[0112] The key generation unit 345 is a second key generation unit that generates a pair of a PC-specific private key and a PC-specific public key, which is a pair of the private key and the public key of the PC 330. Specifically, the key generation unit 345 generates a pair of a PC-specific private key 335 and a PC-specific public key 336, which is a pair of the unique private key and public key of the PC 330, according to a known public key cryptosystem. For example, the key generation unit 345 may generate the PC-specific private key 335 and the PC-specific public key 336 when there is an instruction from the user of the PC 330, or when an application for managing the printer 150 is started for the first time, etc. The generated PC-specific private key 335 and PC-specific public key 336 are stored in the storage unit 333.
[0113] The FW acquisition unit 342 sends the PC-specific public key 336 to the server 310 via the communication unit 131, and acquires the re-encrypted FW as the third encrypted FW obtained by encrypting the common key encrypted FW 113 with the PC-specific public key 336. Specifically, the FW acquisition unit 342 sends a FW acquisition request including the PC-specific public key 336 read from the storage unit 333 to the server 310 via the communication unit 131, and receives the re-encrypted FW as a response. Then, the FW acquisition unit 342 provides the re-encrypted FW received from the server 310 to the decryption unit 346.
[0114] The decryption unit 346 decrypts the re-encrypted FW using the PC-specific private key 335, and acquires the common key encrypted FW 113. For example, when the decryption unit 346 receives the re-encrypted FW from the FW acquisition unit 342, it decrypts the re-encrypted FW using the PC-specific secret key 335 read from the storage unit 333 to obtain the common key-encrypted FW113. Then, the decryption unit 346 provides the obtained common key-encrypted FW113 to the FW update management unit 244, and the FW update management unit 244 temporarily stores the common key-encrypted FW113 in the temporary storage unit 332.
[0115] FIG. 13 is a sequence diagram showing the operation of the FW update system 300 in the third embodiment. Here, the device search process in steps S50 to S53 in FIG. 13 is the same as the device search process in steps S20 to S23 in FIG. 10.
[0116] After the process of step S53, the FW acquisition unit 342 of the PC 330 reads out the PC-specific public key 336 stored in the storage unit 333, and sends a FW acquisition request including the PC-specific public key 336 to the server 310 via the communication unit 131 (S54).
[0117] In the server 310 that has received such an acquisition request, the encryption unit 322 encrypts the common key-encrypted FW113 stored in the storage unit 112 using the PC-specific public key 336 included in the FW acquisition request to generate a re-encrypted FW (S55).
[0118] Then, the FW management unit 321 responds by sending the re-encrypted FW to the PC 330 via the communication unit 111 (S56).
[0119] When the PC 330 that has received such a re-encrypted FW, the decryption unit 346 reads out the PC-specific secret key 335 stored in the storage unit 333, and decrypts the re-encrypted FW using the PC-specific secret key 335 to obtain the common key-encrypted FW113. The obtained common key-encrypted FW113 is provided to the FW update management unit 244.
[0120] The FW update management unit 244 of the PC 230 temporarily stores the common key encrypted FW 113 provided from the decryption unit 346 in the temporary storage unit 232 (S58). Then, the process proceeds to step S59.
[0121] The processes of steps S59 to S73 in FIG. 13 are the same as the processes of steps S27 to S41 in FIG. 10.
[0122] As described above, according to the third embodiment, even when the PC 330 downloads the FW from the server 310, since the unique public key encryption method of the PC 330 is used, the security performance can be improved.
[0123] Embodiment 4. As shown in FIG. 1, the FW update system 400 according to the fourth embodiment includes a server 110, a PC 130, and a printer 450. The server 110 and the PC 130 of the FW update system 400 according to the fourth embodiment are the same as the server 110 and the PC 130 of the FW update system 100 according to the first embodiment.
[0124] FIG. 14 is a block diagram schematically showing the configuration of the printer 450 in the fourth embodiment. The printer 450 includes a communication unit 151, a storage unit 452, a control unit 460, and a printer main body 170.
[0125] The communication unit 151 and the printer main body 170 of the printer 450 in the fourth embodiment are the same as the communication unit 151 and the printer main body 170 of the printer 150 in the first embodiment.
[0126] The storage unit 452 stores data and programs necessary for processing in the printer 450. For example, the storage unit 452 stores the device - specific secret key 153, the device - specific public key 154, and the log information 455.
[0127] The device-specific secret key 153 and the device-specific public key 154 of the storage unit 452 in the fourth embodiment are the same as the device-specific secret key 153 and the device-specific public key 154 of the storage unit 152 in the first embodiment.
[0128] The log information 455 is information indicating a log related to the update of the FW. In the fourth embodiment, the log information 455 is information indicating the update result of the FW.
[0129] FIG. 15 is a schematic diagram showing a first example of the log information 455. As shown in FIG. 15, the log information 455 is information in a table format having a number sequence 455a, an update end time sequence 455b, and a result sequence 455c.
[0130] The number sequence 455a stores numbers as log identification information for identifying the log. The update end time sequence 455b stores the time when the update of the FW was normally completed. Here, the year, month, day, and time when the update of the FW was completed are stored. The result sequence 455c stores information indicating the update result of the FW. Here, whether the update was normally completed or abnormally terminated is stored. If the update was abnormally terminated, it means that the update of the FW failed.
[0131] Returning to FIG. 14, the control unit 460 controls the processing in the printer 450. The control unit 460 includes a key generation unit 161, a key management unit 162, a key processing unit 163, an FW update unit 164, and a log acquisition unit 465.
[0132] The key generation unit 161, the key management unit 162, the key processing unit 163, and the FW update unit 164 of the control unit 460 in the fourth embodiment are the same as the key generation unit 161, the key management unit 162, the key processing unit 163, and the FW update unit 164 of the control unit 160 in the first embodiment.
[0133] The log acquisition unit 465 acquires log information indicating a log related to the update of the FW and stores the log information in the storage unit 452. Here, the log acquisition unit 465 monitors the processing in the FW update unit 164 and stores the FW update result in the FW update unit 164 as log information 455 in the storage unit 452. The FW update result indicates whether the FW update was successful or failed.
[0134] FIG. 16 is a sequence diagram showing the operation of the FW update system 400 in the fourth embodiment. Here, the processing of steps S80 to S88 in FIG. 16 is the same as the processing of steps S10 to S18 in FIG. 7.
[0135] After the processing of step S88, the log acquisition unit 465 stores the FW update result in the FW update unit 164 as log information 455 in the storage unit 452 (S89).
[0136] As described above, according to the fourth embodiment, since the printer 450 stores the log related to the FW update, the user of the printer 450 can grasp the FW update status by checking the log.
[0137] Embodiment 5. As shown in FIG. 1, the FW update system 500 according to the fifth embodiment includes a server 110, a PC 130, and a printer 550. The server 110 and the PC 130 of the FW update system 500 according to the fifth embodiment are the same as the server 110 and the PC 130 of the FW update system 100 according to the first embodiment.
[0138] FIG. 17 is a block diagram schematically showing the configuration of the printer 550 in the fifth embodiment. The printer 550 in the fifth embodiment includes a communication unit 151, a storage unit 552, a control unit 560, a printer main body 170, an input I / F (Interface) 580, and a USB connector 590.
[0139] The communication unit 151 and the printer main body 170 of the printer 550 in Embodiment 5 are the same as those of the printer 150 in Embodiment 1.
[0140] The input I / F 580 receives various inputs from the user of the printer 550. In Embodiment 5, it is assumed that the user who performs the FW update inputs the user name to the input I / F 580 before performing the FW update.
[0141] The USB connector 590 is a connection I / F according to USB. In Embodiment 5, it is assumed that the printer 550 can acquire the FW via a USB memory or a USB cable through the USB connector 590. Note that for the acquisition of the FW through the USB connector 590, a known method may be used and is not particularly limited.
[0142] The storage unit 552 stores data and programs necessary for processing in the printer 550. For example, the storage unit 552 stores the device-specific secret key 153, the device-specific public key 154, and the log information 555.
[0143] The device-specific secret key 153 and the device-specific public key 154 of the storage unit 552 in Embodiment 5 are the same as those of the storage unit 152 in Embodiment 1.
[0144] The log information 555 is information indicating the log related to the FW update in the printer 550. In Embodiment 5, the log information 555 is information indicating the content and result of the FW update process. Here, in addition to the update result indicating whether the FW update was successful or failed, the log information 555 indicates at least one of the user identification information for identifying the user who instructed the FW update and the cause in the case where the FW update failed.
[0145] FIG. 18 is a schematic diagram showing a second example of the log information 555. As shown in FIG. 18, the log information 555 is information in a table format having a number column 555a, an update end time column 555b, a via column 555c, a user name column 555d, a result column 555e, and a result detail column 555f.
[0146] The number column 555a stores a number as log identification information for identifying the log. The update end time column 555b stores the time when the FW update was normally completed. Here, the year, month, day, and time when the FW update was completed are stored.
[0147] The via column 555c stores information indicating the acquisition source of the FW. Specifically, when "network" is described in the via column 555c, as described above, it is assumed that the FW was acquired from the PC 130 via the first network 101 by the communication unit 151. When "USB memory" is described in the via column 555c, it is assumed that the FW was acquired from the USB memory via the USB connector 590. Also, when "USB" is described in the via column 555c, it is assumed that the FW was acquired from another device (not shown) via the USB cable via the USB connector 590.
[0148] The user name column 555d stores a user name as user identification information for identifying the user who updates the FW. As described above, the user who updates the FW inputs the user name to the input I / F 580 before updating the FW, and the input user name is stored in the user name column 555d.
[0149] The result column 555e stores information indicating the FW update result. Here, whether the update was normally completed or abnormally terminated is stored.
[0150] The result detail column 555f stores information indicating the cause of abnormal termination when the FW update result is abnormally terminated. For example, if "decryption error" is stored in the result details column 555f, it indicates that the FW could not be decrypted in the printer 550. If "communication error" is stored in the result details column 555f, it indicates that the FW could not be acquired in the communication unit 151 of the printer 550. Note that if "none" is stored in the result details column 555f, it indicates that the FW update has been completed normally.
[0151] Returning to FIG. 17, the control unit 560 controls the processing in the printer 550. The control unit 560 includes a key generation unit 161, a key management unit 162, a key processing unit 163, an FW update unit 164, and a log acquisition unit 565.
[0152] The key generation unit 161, the key management unit 162, the key processing unit 163, and the FW update unit 164 of the control unit 560 in Embodiment 5 are the same as those of the key generation unit 161, the key management unit 162, the key processing unit 163, and the FW update unit 164 of the control unit 160 in Embodiment 1.
[0153] The log acquisition unit 565 acquires the log related to the FW update and stores the log in the storage unit 452 as log information 455. Here, the log acquisition unit 465 monitors the processing in the communication unit 151, the processing in the key processing unit 163, the processing in the FW update unit 164, the content input to the input I / F 580, and the processing in the USB connector 590, and stores the content and the update result of the FW update process in the storage unit 552 as log information 555.
[0154] FIG. 19 is a sequence diagram showing the operation of the FW update system 500 in Embodiment 5. Here, the processing of steps S90 to S95 in FIG. 19 is the same as the processing of steps S10 to S15 in FIG. 7. Note that the log acquisition unit 565 stores the user name input to the input I / F 580 in the log information 555 before the FW update.
[0155] In the printer 550 that has received the FW with an encrypted common key, the log acquisition unit 565 stores the acquisition path of the FW with an encrypted common key in the log information 555 (S96). Here, "network" is stored as the acquisition path.
[0156] Also, if the communication unit 151 does not receive the FW with an encrypted common key even after a predetermined period has elapsed since receiving the request for acquiring the device-specific public key of the printer 550 in step S90, the update of the FW ends abnormally due to a communication error. Then, when the update of the FW ends abnormally due to a communication error, the log acquisition unit 565 stores in the log information 555 the fact that the update of the FW has ended abnormally due to the communication error (S97). Here, the description continues assuming that the update of the FW has not ended abnormally due to a communication error.
[0157] Next, the key processing unit 163 acquires the common key by decrypting the encrypted common key included in the acquired FW with an encrypted common key using the device-specific secret key 153 read from the storage unit 152 (S98).
[0158] Also, the key processing unit 163 acquires the FW by decrypting the common key-encrypted FW 113 included in the FW with an encrypted common key using the common key acquired in this way (S99).
[0159] Also, if the encrypted common key cannot be decrypted in step S98, or if the common key-encrypted FW 113 cannot be decrypted in step S99, the update of the FW ends abnormally due to a decryption error. Then, when the update of the FW ends abnormally due to a decryption error, the log acquisition unit 565 stores in the log information 555 the fact that the update of the FW has ended abnormally due to the decryption error (S100). Here, the description continues assuming that the update of the FW has not ended abnormally due to a decryption error.
[0160] Next, the FW update unit 164 updates the FW of the printer 550 using the acquired FW (S101).
[0161] Then, the log acquisition unit 565 stores the FW update result in the FW update unit 164 in the log information 555 (S102).
[0162] As described above, according to the fifth embodiment, since the printer 450 stores the log related to the FW update, the user of the printer 550 can grasp the FW update status by checking the log.
[0163] Hereinafter, the various aspects of this embodiment will be summarized and described as an appendix. (Appendix 1) An information processing apparatus capable of acquiring the first encrypted firmware encrypted with a common key from a storage device storing the first encrypted firmware via an information communication apparatus, a first communication unit that communicates with the information communication apparatus, a first key generation unit that generates a pair of a first unique secret key and a first unique public key, which is a pair of a secret key and a public key, receives second encrypted firmware including an encrypted common key obtained by encrypting the common key using the first unique public key and the first encrypted firmware via the first communication unit, decrypts the encrypted common key using the first unique secret key to obtain the common key, and decrypts the first encrypted firmware using the common key to obtain the firmware, and a key processing unit, a firmware update unit that updates the firmware of the information processing apparatus using the firmware, characterized in that it comprises an information processing apparatus. (Appendix 2) further comprising a log acquisition unit that acquires log information indicating a log related to the update of the firmware characterized in that the information processing apparatus according to Appendix 1. (Appendix 3) the log information at least indicates an update result indicating whether the update of the firmware was successful or failed characterized in that the information processing apparatus according to Appendix 2. (Appendix 4) The log information indicates at least one of user identification information for identifying a user who instructed the update of the firmware and a cause in the case where the update of the firmware fails. The information processing apparatus according to appended note 2 or 3, characterized by the above. (Appended note 5) The log information indicates an acquisition path of the second encrypted firmware. The information processing apparatus according to any one of appended notes 2 to 4, characterized by the above. (Appended note 6) In a firmware update system including the information processing apparatus according to any one of appended notes 1 to 5, the information processing apparatus further includes a key management unit that sends the first unique public key to the information communication apparatus via the first communication unit, the information communication apparatus includes a second communication unit that communicates with the information processing apparatus and the storage device, a key acquisition unit that acquires the first unique public key from the information processing apparatus via the second communication unit, a firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit, a first encryption unit that generates the encrypted common key by encrypting the common key using the first unique public key, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware, the storage device includes a third communication unit that communicates with the information communication apparatus, and a firmware management unit that sends the first encrypted firmware to the information communication apparatus via the third communication unit. A firmware update system characterized by the above. (Appended note 7) In a firmware update system including the information processing apparatus according to any one of appended notes 1 to 5 and including a plurality of information processing apparatuses configured in the same manner as the information processing apparatus, the information communication apparatus includes a second communication unit that communicates with the plurality of information processing apparatuses and the storage device, A key acquisition unit that acquires the first unique public key from each of the plurality of information processing devices via the second communication unit; A firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit; A temporary storage unit that temporarily stores the first encrypted firmware; A first encryption unit that generates the encrypted common key for each of the plurality of information processing devices by encrypting the common key using the first unique public key of each of the plurality of information processing devices, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing devices; A firmware update management unit that sends the second encrypted firmware to each of the plurality of information processing devices, and after sending the corresponding second encrypted firmware to all of the plurality of information processing devices, deletes the first encrypted firmware from the temporary storage unit, and The storage device A third communication unit that communicates with the information communication device; A firmware management unit that sends the first encrypted firmware to the information communication device via the third communication unit, A firmware update system characterized by that. (Supplementary Note 8) In a firmware update system including the information processing device according to any one of Supplementary Notes 1 to 5 and including a plurality of information processing devices configured in the same manner as the information processing device, The information communication device A second communication unit that communicates with the plurality of information processing devices and the storage device; A key acquisition unit that acquires the first unique public key from each of the plurality of information processing devices via the second communication unit; A second key generation unit that generates a pair of a second unique secret key and a second unique public key, which is a pair of a secret key and a public key; A firmware acquisition unit that sends the second public key to the storage device via the second communication unit and acquires third encrypted firmware obtained by encrypting the first encrypted firmware with the second public key; A decryption unit that decrypts the third encrypted firmware using the second private key and acquires the first encrypted firmware; A temporary storage unit that temporarily stores the first encrypted firmware; A first encryption unit that encrypts the common key using the first public key of each of the plurality of information processing devices, generates the encrypted common key for each of the plurality of information processing devices, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing devices; A firmware update management unit that sends the second encrypted firmware to each of the plurality of information processing devices, and after sending the corresponding second encrypted firmware to all of the plurality of information processing devices, deletes the first encrypted firmware from the temporary storage unit; The storage device A third communication unit that communicates with the information communication device; A second encryption unit that encrypts the first encrypted firmware using the second public key acquired via the third communication unit to generate the third encrypted firmware; A firmware management unit that sends the third encrypted firmware to the information communication device via the third communication unit; A firmware update system characterized by the above. (Supplementary Note 9) A program that causes a computer to function as an information processing device that acquires the first encrypted firmware from a storage device that stores the first encrypted firmware obtained by encrypting firmware with a common key via an information communication device, The computer A first key generation unit that generates a pair of a first private key and a first public key, which is a pair of a private key and a public key, and Causing a key processing unit to function as follows: receiving, via a first communication unit that communicates with the information communication device, a second encrypted firmware including an encrypted common key obtained by encrypting the common key using the first public key and the first encrypted firmware; decrypting the encrypted common key using the first private key to obtain the common key; and decrypting the first encrypted firmware using the common key to obtain the firmware. A program characterized by the above. (Appendix 10) Further causing the computer to function as a firmware update unit that updates the firmware of the information processing device using the firmware. The program according to Appendix 9, characterized by the above. (Appendix 11) A firmware update method for updating the firmware of an information processing device using a first encrypted firmware obtained by encrypting the firmware with a common key, the method comprising: generating a pair of a first private key and a first public key, which is a pair of a private key and a public key; receiving a second encrypted firmware including an encrypted common key obtained by encrypting the common key using the first public key and the first encrypted firmware; decrypting the encrypted common key using the first private key to obtain the common key; decrypting the first encrypted firmware using the common key to obtain the firmware; and updating the firmware of the information processing device using the firmware. A firmware update method characterized by the above.
Explanation of Signs
[0164] 100, 200, 300, 400, 500 FW update system, 110, 310 server, 111 communication unit, 112 memory unit, 120, 320 control unit, 121, 321 FW management unit, 322 encryption unit, 130, 230, 330 PC, 131 communication unit, 332 temporary memory unit, 133, 333 memory unit, 140, 240, 340 control unit, 141, 241 key acquisition unit, 142, 242, 342 FW acquisition unit, 345 key generation unit, 346 decryption unit, 143, 243 encryption unit, 244 FW update management unit, 150, 450, 550 printer, 151 communication unit, 152, 452 memory unit, 160, 460, 560 control unit, 161 key generation unit, 162 key management unit, 163 key processing unit, 164 FW update unit, 465, 565 log acquisition unit, 170 printer body, 580 input I / F, 590 USB connector.
Claims
1. An information processing device capable of acquiring first encrypted firmware, the first encrypted firmware being obtained by encrypting firmware with a common key, from a storage device storing the first encrypted firmware via an information communication device, a first communication unit that communicates with the information communication device; a first key generation unit configured to generate a pair of a first unique private key and a first unique public key, which are a pair of a private key and a public key; a key processing unit that receives, via the first communication unit, an encrypted common key obtained by encrypting the common key using the first unique public key and second encrypted firmware including the first encrypted firmware, decrypts the encrypted common key using the first unique private key to obtain the common key, and decrypts the first encrypted firmware using the common key to obtain the firmware; a firmware update unit that updates the firmware of the information processing device using the firmware. An information processing device comprising:
2. Further comprising a log acquisition unit that acquires log information indicating a log related to the firmware update.
2. The information processing apparatus according to claim 1,
3. The log information at least indicates an update result indicating whether the firmware update was successful or failed.
3. The information processing apparatus according to claim 2,
4. The log information further indicates at least one of user identification information for identifying a user who instructed the firmware update and a cause of failure in the firmware update.
4. The information processing apparatus according to claim 3,
5. The log information indicates a route through which the second encrypted firmware was obtained.
3. The information processing apparatus according to claim 2,
6. A firmware update system comprising the information processing device according to any one of claims 1 to 5, the information processing device further includes a key management unit that transmits the first unique public key to the information communication device via the first communication unit; The information communication device includes: A second communication unit that communicates with the information processing device and the storage device; a key acquisition unit that acquires the first unique public key from the information processing device via the second communication unit; a firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit; a first encryption unit that generates the encrypted common key by encrypting the common key using the first unique public key, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware; The storage device includes: A third communication unit that communicates with the information communication device; a firmware management unit that transmits the first encrypted firmware to the information communication device via the third communication unit. A firmware update system comprising:
7. A firmware update system including the information processing device according to any one of claims 1 to 5 and including a plurality of information processing devices configured similarly to the information processing device, The information communication device includes: A second communication unit that communicates with the plurality of information processing devices and the storage device; a key acquisition unit that acquires the first unique public key from each of the plurality of information processing devices via the second communication unit; a firmware acquisition unit that acquires the first encrypted firmware from the storage device via the second communication unit; a temporary storage unit that temporarily stores the first encrypted firmware; a first encryption unit that encrypts the common key using the first unique public key of each of the plurality of information processing devices to generate the encrypted common key for each of the plurality of information processing devices, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing devices; a firmware update management unit that transmits the second encrypted firmware to each of the plurality of information processing devices, and deletes the first encrypted firmware from the temporary storage unit after transmitting the corresponding second encrypted firmware to all of the plurality of information processing devices; The storage device includes: A third communication unit that communicates with the information communication device; a firmware management unit that transmits the first encrypted firmware to the information communication device via the third communication unit. A firmware update system comprising:
8. A firmware update system including the information processing device according to any one of claims 1 to 5 and including a plurality of information processing devices configured similarly to the information processing device, The information communication device includes: A second communication unit that communicates with the plurality of information processing devices and the storage device; a key acquisition unit that acquires the first unique public key from each of the plurality of information processing devices via the second communication unit; a second key generation unit configured to generate a pair of a second unique private key and a second unique public key, which is a pair of a private key and a public key; a firmware acquisition unit that transmits the second unique public key to the storage device via the second communication unit and acquires third encrypted firmware obtained by encrypting the first encrypted firmware with the second unique public key; a decryption unit that decrypts the third encrypted firmware by using the second unique private key to obtain the first encrypted firmware; a temporary storage unit that temporarily stores the first encrypted firmware; a first encryption unit that generates the encrypted common key for each of the plurality of information processing devices by encrypting the common key using the first unique public key of each of the plurality of information processing devices, and generates the second encrypted firmware including the encrypted common key and the first encrypted firmware for each of the plurality of information processing devices; a firmware update management unit that transmits the second encrypted firmware to each of the plurality of information processing devices, and deletes the first encrypted firmware from the temporary storage unit after transmitting the corresponding second encrypted firmware to all of the plurality of information processing devices; The storage device includes: A third communication unit that communicates with the information communication device; a second encryption unit that encrypts the first encrypted firmware using the second unique public key acquired via the third communication unit to generate the third encrypted firmware; a firmware management unit that transmits the third encrypted firmware to the information communication device via the third communication unit. A firmware update system comprising:
9. A program that causes a computer to function as an information processing device that acquires, via an information communication device, first encrypted firmware obtained by encrypting firmware with a common key from a storage device that stores the first encrypted firmware, the first encrypted firmware comprising: The computer, a first key generation unit that generates a pair of a private key and a public key, the pair being a first unique private key and a first unique public key; and receiving, via a first communication unit that communicates with the information communication device, an encrypted common key obtained by encrypting the common key using the first unique public key and second encrypted firmware including the first encrypted firmware, decrypting the encrypted common key using the first unique private key to obtain the common key, and decrypting the first encrypted firmware using the common key to obtain the firmware; A program characterized by.
Citation Information
Patent Citations
Information processing system, update method, information device, and program
JP2017173893A