Information processing device, information processing system, program, and information processing method
By employing an intermediate certification authority to manage device signatures with multiple public keys, the challenges of delayed verification and increased costs in code signing are addressed, facilitating efficient and secure user application installation.
Patent Information
- Application Number
- JP2023222164
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-10
AI Technical Summary
In the process of installing user applications on devices, the device vendor's involvement in generating signatures for code signing complicates development schedules and increases costs due to delayed defect discovery and the inability to perform easy operation verification.
A second user, acting as an intermediate certification authority, manages signatures using a key storage unit, key management unit, signature verification unit, and user application unit to verify and install user applications with multiple public keys provided by a first user acting as a root certification authority.
This approach allows for flexible and timely signature management, reducing development and quality costs by enabling operation verification at desired times and minimizing the risk of signature leakage.
Smart Images

Figure 2025104409000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing apparatus, an information processing system, a program, and an information processing method.
Background Art
[0002] When installing a program on a device, signature technology has been conventionally used to verify the validity of the program. Signature technology is a technology that applies public key cryptography. Public key cryptography is a cryptographic technology characterized by using a public key pair in which an asymmetric private key and a public key are paired.
[0003] When the message sender has the public key and the message receiver has the private key, the message encrypted by the sender with the public key can be decrypted only by the receiver with the private key, so it is used for message confidentiality.
[0004] Conversely, when the message receiver has the public key and the message sender has the private key, the signature data generated from the message by the sender with the private key can be verified by the receiver with the public key, so it is used to guarantee the validity of the message and the signature data.
[0005] The above public key cryptography can be applied to program installation on a device. For example, a program signed with a device vendor private key held only by the device vendor is input to the device, and its signature is verified with the device vendor public key pre-embedded in the device, and only the qualified ones are permitted to be installed on the device. A mechanism can be configured.
[0006] This is called code signing, and generally, when the device vendor itself distributes firmware update data or the like to a device purchased and owned by a user, it can be used to guarantee the integrity to ensure that the data has not been tampered with by a third party.
[0007] There are cases where, by using this mechanism, a gateway device provided by a device vendor is signed and verified to permit the installation of a user application, which is a program created by an organization different from the device vendor.
Prior Art Documents
Patent Documents
[0008]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0009] When code signing is used to install a user application on a device, the device vendor itself needs to generate the signature for the user application. Therefore, when a software vendor developing a user application verifies the operation of the user application during its development, the software vendor cannot confirm the operation on a real device until it sends the user application to the device vendor and obtains the signed user application from the device vendor.
[0010]
[0011] In the development of a program that requires a tight schedule, it is difficult to incorporate frequent signature generation into the process, and the schedule is difficult to arrange because it depends on the response of the device vendor. In addition, since easy operation verification cannot be performed, there is a possibility that the discovery of defects will be delayed and the setback will be large. Furthermore, development in debug mode may not be equivalent to operation in the product version. As a result, there has been a problem of increased development and quality costs.
[0012] Therefore, one or more aspects of the present disclosure aim to enable a second user to manage signatures within the scope assumed by a first user having a function as a root certification authority.
Means for Solving the Problem
[0013] An information processing apparatus according to one aspect of the present disclosure is an information processing apparatus used by a second user to whom a function as an intermediate certification authority is given from a first user having a function as a root certification authority, and includes a key storage unit that stores at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority; a key management unit that selects at least two public keys necessary for verifying a signature block of a user application developed by the second user from among the plurality of public keys; a signature verification unit that verifies the signature block using the at least two public keys; and a user application unit that installs the user application when the verification of the signature block is successful.
[0014] An information processing system according to one aspect of the present disclosure is an information processing system used by a second user to whom a function as an intermediate certification authority is given from a first user having a function as a root certification authority, and includes a key management unit that selects at least two secret keys from among a plurality of secret keys included in a plurality of public key pairs generated with the authority of the root certification authority; a signature block generation unit that generates a signature block from a user application using the at least two secret keys; a signature verification unit that verifies the signature block using at least two public keys corresponding to the at least two secret keys; and a user application unit that installs the user application when the verification of the signature block is successful.
[0015] A program according to an aspect of the present disclosure is a program that causes a computer to function as an information processing apparatus used by a second user provided with a function as an intermediate certification authority from a first user having a function as a root certification authority, wherein the computer is caused to function as a key storage unit that stores at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority, a key management unit that selects at least two public keys necessary for verifying a signature block of a user application developed by the second user from among the plurality of public keys, a signature verification unit that verifies the signature block using the at least two public keys, and a user application unit that installs the user application when the verification of the signature block is successful.
[0016] An information processing method according to an aspect of the present disclosure is an information processing method performed by an information processing apparatus used by a second user provided with a function as an intermediate certification authority from a first user having a function as a root certification authority, wherein at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority are stored, at least two public keys necessary for verifying a signature block of a user application developed by the second user are selected from among the plurality of public keys, the signature block is verified using the at least two public keys, and the user application is installed when the verification of the signature block is successful.
Effect of the Invention
[0017] According to one or more aspects of the present disclosure, within the range assumed by the first user having a function as a root certification authority, the second user can manage signatures.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Embodiments for Carrying Out the Invention
[0019] Embodiment 1. FIG. 1 is a block diagram schematically showing the configuration of an information processing system 100 according to Embodiment 1. In the information processing system 100, the software vendor 101 has concluded a contract with the device vendor 102 and is granted the function of an intermediate certification authority from the device vendor 102. An intermediate certification authority is a certification authority located between a root certification authority that is the basis of guarantee and the owner of a public key in a public key certificate mechanism for guaranteeing the owner of the public key. The intermediate certification authority can sign the public key under the guarantee of the root certification authority.
[0020] In Embodiment 1, the device vendor 102 is the first user having the function of a root certification authority, and the software vendor 101 becomes the second user granted the function of an intermediate certification authority from the device vendor 102. As shown in FIG. 1, the information processing apparatus 110 is a device used by the software vendor 101.
[0021] The software vendor 101 develops a user application at the request of the device vendor 102 and performs signature verification of the user application on the information processing apparatus 110 connected to a network 103 such as a public network or a private network.
[0022] Conventionally, the software vendor 101 has sent the user application to the device vendor 102 via the network 103, the device vendor 102 has signed the user application, and then sent it back to the software vendor 101.
[0023] On the other hand, in this embodiment, the device vendor 102 generates a plurality of public key pairs, which are a pair of a private key and a public key corresponding to the private key, with the authority of the root certification authority. Then, the device vendor 102 signs the public key pairs with the device vendor private key that the device vendor 102 has, and sends the signed plurality of public key pairs to the software vendor 101.
[0024] The software vendor 101 stores the signed plurality of public key pairs in the information processing device 110 that functions as a gateway device for developing user applications, and acquires the plurality of public key pairs by performing verification with the device vendor public key given in advance from the device vendor 102.
[0025] As a result, the software vendor 101 can sign and verify the user application by itself without sending the user application to the device vendor 102 using the network 103, and install it in the information processing device 110.
[0026] Note that when releasing the user application, the software vendor 101 installs in the information processing device 110 the user application signed with the device vendor private key held by the device vendor 102.
[0027] Figure 2 is a block diagram schematically showing the configuration of the information processing device 110 in Embodiment 1. The information processing device 110 includes a key storage unit 111, a key management unit 112, a user interface unit (hereinafter referred to as UI unit) 113, a signature block generation unit 114, a signature verification unit 115, and a user application unit 116.
[0028] The key storage unit 111 stores at least a plurality of public keys among a plurality of public key pairs provided by the device vendor 102. Here, the key storage unit 111 stores a plurality of public key pairs provided by the device vendor 102. The plurality of public key pairs provided by the device vendor 102 are each signed by the device vendor private key possessed by the device vendor 102. The expiration date of the signature is extremely short, and as shown in FIG. 3, it is assumed that each expiration period is designed to overlap with the expiration periods before and after.
[0029] Specifically, as shown in FIG. 3, at any time other than the head period T01 including the earliest time of the expiration period and the tail period T02 including the latest time of the expiration period, it is assumed that the signatures of two or more public key pairs are always within the expiration period, so that the expiration periods overlap. In addition, as shown in FIG. 3, among all the expiration periods of the signatures of the plurality of public key pairs, the period excluding the head period T01 and the tail period T02 is defined as the expiration period T11 of the signature block.
[0030] Note that in FIG. 3, a case using three public key pairs is illustrated, but the present embodiment is not limited to three public key pairs used for generating the signature block. The number of public key pairs can be freely selected, such as four consecutive public key pairs or five consecutive public key pairs. The specific number of public key pairs and the method of overlapping the expiration periods are not limited to the example shown in FIG. 3. They may be adjusted according to the development period or application. For example, increasing the number of public key pairs can lengthen the expiration period T11 of the signature block. Also, not all of the plurality of public key pairs need to be signed by the same device vendor private key, and not all of the plurality of public key pairs need to have the same certificate property (such as the expiration date).
[0031] The key management unit 112 manages at least the public keys among the plurality of public key pairs given by the device vendor 102. Here, the key management unit 112 manages the plurality of public key pairs given by the device vendor 102. For example, the key management unit 112 receives a plurality of public key pairs from the device vendor 102 and the network 103 via a communication unit realized by a communication interface (not shown), and stores the plurality of public key pairs in the key storage unit 111.
[0032] The key management unit 112 manages the public key pairs stored in the key storage unit 111 in plurality. Generally, public key management in a system using a public key certificate or the like refers to checking the expiration date of the public key certificate, invalidation processing, reissue procedures, etc. In the present embodiment, the key management unit 112 may or may not have them, but has a public key selection function for generating a signature block in a method different from the conventional one.
[0033] For example, the key management unit 112 reads the keys used in the signature block generation unit 114 and the signature verification unit 115 from the key storage unit 111 and provides them to the signature block generation unit 114 and the signature verification unit 115, respectively.
[0034] Specifically, the key management unit 112 selects at least two public keys necessary for verifying the signature block of the user application from among the plurality of public keys stored in the key storage unit 111. The at least two public keys thus selected are provided to the signature verification unit 115. Also, here, the key management unit 112 also selects at least two secret keys corresponding to the at least two selected public keys, respectively. The at least two secret keys thus selected are provided to the signature block generation unit 114.
[0035] The signature generation and signature verification performed by the signature block generation unit 114 and the signature verification unit 115, respectively, are essentially the same as general signature generation and verification. In Embodiment 1, the method of constructing the signature data used is different.
[0036] Note that the signature block generation unit 114 and the signature verification unit 115 may utilize the signature generation and verification functions provided by an OS (Operating System) or OSS (Open Source Software), or they may be separate programs. Also, the signature block generation unit 114 and the signature verification unit 115 do not necessarily have to be independent institutions. Furthermore, the signature block generation unit 114 and the signature verification unit 115 may be signature generation applications developed by the device vendor 102 itself.
[0037] Specifically, the key management unit 112 manages the device vendor public key, a plurality of public key pairs passed to the software vendor 101, the expiration date of each signature of the plurality of public key pairs, the order of those expiration dates, and the way of overlapping of those expiration dates. Then, in response to a request from the software vendor 101, in other words, a request from the signature block generation unit 114 and the signature verification unit 115, it returns an appropriate public key pair.
[0038] The request from the software vendor 101 is, for example, the number of public key pairs to be used when generating a signature block or the apparent expiration period, or the minimum value of the number of valid public key pairs at any given time, etc. The method of providing this information can be to use a CUI (Character User Interface) or a GUI (Graphical User Interface), or to separately prepare a configuration file and directly specify it, etc.
[0039] In the example shown in FIG. 3, when the software vendor 101 inputs the number of public key pairs to be used as "3", the key management unit 112 performs a process of returning three public key pairs, namely, public key pair (n - 1), public key pair n, and public key pair (n + 1), such that the validity period T11 of the signature block starts from that time or a separately specified time.
[0040] Also, without specifying the number in particular, when software vendor 101 designates the specific start time and end time of the validity period T11 of the signature block, the key management unit 112 performs a process of returning a combination of public key pairs that matches it.
[0041] Although the device vendor public key, the plurality of public key pairs passed to software vendor 101, the expiration date of the signature of each of the plurality of public key pairs, the order of the expiration dates, and the way of overlapping of the expiration dates managed by key management unit 112 are not confidential information, public disclosure is not recommended.
[0042] Note that although the secret key is not necessarily restricted, it is desirable that it is not stored in information processing apparatus 110 and the signature block is passed to software vendor 101 by separate means. However, in this case, since the generation of the signature block needs to be performed outside information processing apparatus 110, there is a trade-off between the security due to not storing the secret key in information processing apparatus 110 and the convenience in development.
[0043] If the secret key of the public key pair is leaked to a third party during the development period, the security of the method disclosed in this embodiment is not guaranteed. Alternatively, during development, the secret key exists in key storage unit 111, and signature block generation unit 114 exists in information processing apparatus 110, but at the time of shipment of the user application, measures such as deleting the secret key may be taken. Note that outside the development period, even if the secret key is passed to a third party, no signature can be made (accurately, the validity period of the public key for verifying the signature has expired), so there is no actual harm.
[0044] As described above, in Embodiment 1, the key management unit 112 selects at least two secret keys and at least two public keys so that two or more predetermined numbers of secret keys and the public keys corresponding to the secret keys are valid at all times within the assumed validity period, in other words, so that two or more predetermined numbers of public key pairs are valid. Then, the signature block generation unit 114 generates a signature block using the predetermined number of private keys. Here, secret sharing technology is used to generate the signature block. Also, the signature verification unit 115 can perform verification by decrypting the signature block using the predetermined number of public keys.
[0045] Note that when the information processing apparatus 110 does not manage the private keys, the key management unit 112 selects at least two public keys so that two or more predetermined numbers of public keys are valid at all times within the assumed valid period. Even in this case, since the signature block is generated by secret sharing technology using the predetermined number of private keys corresponding to the predetermined number of public keys, the signature verification unit 115 can perform verification by decrypting the signature block using the predetermined number of public keys.
[0046] The UI unit 113 is an interface that accepts input of user applications and necessary information described later.
[0047] The signature block generation unit 114 generates a signature block for the user application. For example, the signature block generation unit 114 generates a signature block for the user application using at least two private keys selected by the key management unit 112, and attaches the generated signature block to the user application.
[0048] Note that when the private key exists outside the information processing apparatus 110, the signature block generation unit 114 is unnecessary. In such a case, the user application with the attached signature block may be input to the information processing apparatus 110 via the UI unit 113 or a communication unit (not shown). For example, the software vendor 101 may have a signature device outside the information processing apparatus 110, store the private key therein, and generate a signature block for the user application.
[0049] The signature verification unit 115 verifies the signature block of the user application with the attached signature block using at least two public keys selected by the key management unit 112. When the verification of the signature block is successful, the signature verification unit 115 provides the user application for which the verification of the signature block has succeeded to the user application unit 116.
[0050] The user application unit 116 installs the user application corresponding to the signature and makes it available only when the signature verification performed by the signature verification unit 115 is successful. Since the behavior of the user application after installation is irrelevant to the signature mechanism, it is not particularly described in this embodiment.
[0051] Next, in Embodiment 1, the operation of generating a signature block will be described with reference to FIG. 3. Signature generation and signature verification are essentially the same function.
[0052] The original data, here the hash is applied to the user application to obtain a short digest, which is generally the signature block encrypted with the private key. At the time of verification, the hash is also applied to the user application to obtain a short digest, and it is checked whether the digest matches the data obtained by decrypting the signature block with the public key. If they match, it can be guaranteed that the user application and the signature block have not been tampered with, that is, the signature block was correctly generated with the private key.
[0053] In this embodiment, the above-mentioned signature block, that is, the encrypted digest, is not used as the signature block as it is. Specifically, it is as follows.
[0054] First, the key management unit 112 selects three public keys with consecutive expiration dates from the key storage unit 111. Next, the signature block generation unit 114 generates a ciphertext by encrypting the digest obtained from the user application with the secret key corresponding to each public key. Then, the signature block generation unit 114 generates one signature block for the obtained ciphertext using a secret sharing technique.
[0055] The secret sharing technique is a mechanism that generates n pieces (where n is an integer of two or more) from a certain secret information s (here, the ciphertext), and guarantees that the original s cannot be restored unless m or more pieces, which are integers of n or less, are available.
[0056] For example, assume that the straight line y = ax + b is the secret information s. That is, s = (a, b). There are theoretically an infinite number of points on the straight line, and if only one point (x, y) = (x1, y1) is used, s cannot be restored because there are an infinite number of straight lines passing through one point. However, when the second point (x, y) = (x2, y2) is determined, since there is only one straight line passing through two points, s can be calculated. This can also be uniquely determined even if the third point and the fourth point on the straight line are added. In this case, that is, when the secret sharing method is a straight line, the original secret information can be restored if two or more pieces of point information are available, and the information about the secret information obtained from a smaller number, that is, one piece of point information, is zero.
[0057] Using the concept of this secret sharing technique, the signature block generation unit 114 generates a signature block such that signature verification fails unless two or more of the three signature data are available. In other words, at the time of signature verification, when a digest is obtained from the user application and the signature block is decrypted using two or more public keys within the valid period, the same data as the digest is obtained. Any method within the scope guaranteed by the secret sharing technique may be used, and the specific method is not limited in this disclosure.
[0058] For example, the signature block generation unit 114 may divide the digest obtained from the application program into two halves, and encrypt each of the divided parts with the secret key corresponding to each public key. In the example of FIG. 3, the encrypted text (signature data) obtained by encrypting the first half of the digest with the secret keys of the public key pairs (n-1) and (n+1) may be generated, and the encrypted text (signature data) obtained by encrypting the second half of the digest with the secret key of the public key pair n may be generated. In this case, the signature verification unit 115 can generate one digest by combining the parts decrypted with two valid public keys, so verification can be performed.
[0059] Also, the signature block generation unit 114 can divide the digest into three data by secret sharing technology, and use three types of secret keys to encrypt and combine them to form the signature block.
[0060] If three public key pairs with overlapping expiration periods are selected one after another, there will be exactly two public key pairs within the expiration period at a certain time, so the above situation is always guaranteed.
[0061] In FIG. 3, even if the time elapses from time t1 between the expiration period of the public key pair (n-1) and the expiration period of the public key pair n, and changes to time t2 between the expiration period of the public key pair n and the expiration period of the public key pair (n+1), there are exactly two valid encrypted texts. Overall, the sum of all the expiration periods from the public key pair (n-1) to the public key pair (n+1) is the expiration period T11 of the signature block.
[0062] Note that the beginning and the end can be realized by performing special processing such as generating additional public key pairs.
[0063] The information processing apparatus 110 described above can be realized by a computer such as the PC 10 shown in FIG. 4, for example. PC10 includes a storage 11 such as an HDD (Hard Disk Drive) and an SSD (Solid State Drive), a memory 12, a processor 13 such as a CPU (Central Processing Unit), a communication I / F (InterFace) 14 such as a NIC (Network Interface Card), and an input I / F 15 such as a keyboard and a mouse.
[0064] For example, the key storage unit 111 can be realized by the storage 11 or the memory 12. The key management unit 112, the signature block generation unit 114, the signature verification unit 115, and the user application unit 116 can be realized by the processor 13. Specifically, it can be realized by the processor 13 loading the program stored in the storage 11 into the memory 12 and executing the program.
[0065] The UI unit 113 can be realized by the communication I / F 14 or the input I / F 15.
[0066] The above program may be downloaded from a recording medium (not shown) via a reader / writer (not shown) or from a network via the communication I / F 14 to the storage 11, and then loaded onto the memory 12 and executed by the processor 13. Alternatively, it may be directly loaded onto the memory 12 from a recording medium via a reader / writer or from a network via the communication I / F 14 and executed by the processor 13. In other words, the program may be provided by a program product such as a recording medium.
[0067] Figure 5 is a flowchart showing an example of the operation of selecting a public key pair in the key management unit 112. Here, it is assumed that an input is made from the software vendor 101, the user, or a configuration file.
[0068] Specifically, a private key used for signature generation and a public key used for signature verification are selected. Since the public key used for signature verification must correspond to the private key used for signature generation, the same public key pair must be used when selecting the private key and the public key.
[0069] In this example, it is assumed that the start time and end time of the validity period of the signature block, or the start time of the validity period of the signature block and the number of private keys used for signature block generation, are input. For development, a convenient input method can be selected. However, the same public key pair must be used when selecting the private key and when selecting the public key. If the above prerequisites are met, in the selection algorithm, it doesn't matter whether the selection target is a private key or a public key. Therefore, in the description of FIG. 5, it is simply referred to as a key.
[0070] Here, it is assumed that the key management unit 112 manages the finally selected keys in list form. Let the list for managing keys be key_list = [].
[0071] First, the key management unit 112 determines whether the start time of the validity period of the signature block has been input (S10). If there is no input, the key management unit 112 ends the process with an error. If there is an input, the process proceeds to step S11. In step S11, the key management unit 112 sets the time t = the specified time.
[0072] Next, the key management unit 112 determines whether the end time of the validity period of the signature block has been input (S12). If there is no input, the process proceeds to step S20. If there is an input, the process proceeds to step S13.
[0073] In step S13, the key management unit 112 sets the input end time as t_end.
[0074] Next, the key management unit 112 determines whether the time t is less than or equal to t_end (S14). If t is less than or equal to t_end (Yes in S14), the process proceeds to step S15. If t exceeds t_end (No in S14), the process ends normally.
[0075] In step S15, the key management unit 112 selects a key that is before time t and has the latest start time of the validity period among the unselected keys, and sets the selected key as key. Next, the key management unit 112 updates the time t to the end time of the validity period of key (S16).
[0076] Then, the key management unit 112 adds key to the end of key_list (S17). Then, the process returns to step S14. Note that in step S14, if the time t exceeds t_end (No in S14), the key management unit 112 outputs key_list there and ends normally.
[0077] In step S12, in step S20 where the transition is made because there is no input of the end time of the validity period, the key management unit 112 determines whether the number of secret keys has been input. If the number of secret keys has not been input, the key management unit 112 ends the process with an error. If the number of secret keys has been input, the key management unit 112 sets that number as n and proceeds with the process to step S21.
[0078] In step S21, the key management unit 112 determines whether n is greater than 0. If n is greater than 0 (Yes in S21), the process proceeds to step S22. If n is less than or equal to 0 (No in S21), the key management unit 112 ends the process with an error.
[0079] In step S22, the key management unit 112 selects a key that is before time t and has the latest start time of the validity period, and sets the selected key as key. Next, the key management unit 112 updates the time t to the end time of the validity period of key (S23).
[0080] Then, the key management unit 112 adds the key to the end of the key_list, updates n to n - 1, and returns the process to step S21.
[0081] Note that the operations shown in FIG. 5 are merely examples, and depending on the overlap mechanism, another selection algorithm may be used.
[0082] As described above, according to the first embodiment, since the device vendor 102 is configured to provide the software vendor 101 with a public key pair valid for a certain period and to provide the function as an intermediate certification authority, it is possible to avoid a situation where the operation verification of the user application cannot be performed without the signature given by the device vendor 102. For this reason, an increase in development costs can be suppressed. In addition, since the software vendor 101 can perform operation verification at a desired timing, an increase in quality costs due to a delay in discovering defects can be suppressed.
[0083] In addition, by issuing and combining short-lived public key pairs, signatures can be generated flexibly at a convenient timing and with a convenient validity period for the software vendor 101. For example, even when the software vendor 101 outsources part of the development or verification of the user application to a subcontractor, the development can proceed without increasing the dialogue cost due to communication with the device vendor 102 regarding signatures.
[0084] In addition, compared to simply using short-lived public key pairs, by combining multiple public key pairs and making signature verification impossible unless a specified number or more of public keys are available, the risk of leakage is reduced.
[0085] As described above, software vendor 101 can arbitrarily determine the number of public key pairs used for signature block generation and can apparently extend the expiration date. This does not extend beyond the lifespan initially prepared by device vendor 102, but rather is an operation within the expiration date prepared by device vendor 102. Therefore, it is possible to prevent an unintended release at a time determined solely by software vendor 101.
[0086] In this embodiment, it is also possible to consider software vendor 101 as an ordinary user after the device is commercially available. In that case, after the ordinary user purchases the product and purchases a license from device vendor 102 or the like to draw a public key pair into information processing device 110, the same processing as in this embodiment becomes possible.
[0087] Embodiment 2. In Embodiment 1, information processing device 110 that installs a user application for which signature verification has passed was shown. In Embodiment 2, a functional block that performs the same signature verification every time a user application is started is added.
[0088] As shown in FIG. 1, information processing system 200 according to Embodiment 2 includes information processing device 210.
[0089] FIG. 6 is a block diagram schematically showing the configuration of information processing device 210 in Embodiment 2. Information processing device 210 includes a key storage unit 111, a key management unit 112, a UI unit 113, a signature block generation unit 214, a signature verification unit 215, a user application unit 216, a signature block storage unit 217, and a startup confirmation unit 218.
[0090] The key storage unit 111, key management unit 112, UI unit 113, and signature block generation unit 114 of information processing device 210 in Embodiment 2 are the same as those of the key storage unit 111, key management unit 112, UI unit 113, and signature block generation unit 114 of information processing device 110 in Embodiment 1.
[0091] The signature verification unit 215 performs the following processes in addition to the same processes as the signature verification unit 115 in the first embodiment. In the same process as in the first embodiment, when the verification of the signature block is successful, the signature verification unit 215 provides the user application for which the verification of the signature block has been successful to the user application unit 216, and stores the signature block in the signature block storage unit 217 in association with the user application for which the verification has been successful.
[0092] The signature block storage unit 217 stores the signature block.
[0093] The startup confirmation unit 218 monitors the operation of the user application unit 216 and checks whether a startup instruction for the user application has been given to the user application unit 216. When a startup instruction for the user application is given, the startup confirmation unit 218 notifies the signature verification unit 215 of the user application that has received the startup instruction. For the startup instruction, it may be input to the UI unit 113.
[0094] Upon receiving the notification from the startup confirmation unit 218, the signature verification unit 215 reads out the signature block corresponding to the application that has received the startup instruction from the signature block storage unit 217 and verifies the signature block. Then, when the verification of the signature block is successful, the signature verification unit 215 notifies the user application unit 216 of the user application for which the verification of the signature block has been successful.
[0095] Similar to the first embodiment, the user application unit 216 installs the user application corresponding to the signature block only when the signature verification performed by the signature verification unit 215 passes. Also, the user application unit 216 starts the user application corresponding to the signature block only when the signature verification performed by the signature verification unit 215 passes.
[0096] The signature block storage unit 217 described above can also be implemented by the storage 11 or the memory 12. Also, the startup confirmation unit 218 can also be implemented by the processor 13. Specifically, it can be implemented by the processor 13 loading the program stored in the storage 11 into the memory 12 and executing the program.
[0097] In the second embodiment, the case of performing signature verification when the user application is started has been described. However, in view of the processing load and time cost related to signature verification, it can be applied to perform at the time of power-on, at the timing designated by the end user using the information processing apparatus 210, at a fixed cycle such as a health check, or at a combined timing thereof. In that case, it is necessary to add a timer function or add a function to accept the designation of the end user in the UI unit 113.
[0098] As described above, according to the second embodiment, since it has the function of performing signature verification at an arbitrary timing even after shipment, it is possible to avoid skipping the signature given by the device vendor 102 at the time of official release.
[0099] Also, during the operation verification on the actual machine, it is not necessary to reissue the signature every time the expiration date of the public key expires. It is possible to flexibly adjust the apparent expiration period of the public key and perform the seamless switching of each expiration period at the same time, which can reduce the development effort.
[0100] Note that the information processing apparatuses 110 and 210 described above show an example configured by, for example, one computer, but the first and second embodiments are not limited to such an example. For example, the function of generating the signature blocks of the information processing apparatuses 110 and 210 and the function of verifying the signature blocks of the information processing apparatuses 110 and 210 may be executed on different computers. In this case, it is desirable that the computer that performs the function of generating signatures stores the private key of the public key pair in the storage unit, and the computer that performs the function of verifying signatures stores the public key of the public key pair in the storage unit. In other words, the functions executed by the information processing apparatuses 110 and 210 may be executed in an information processing system including a plurality of computers.
[0101] In this case, the information processing system becomes a system used by the software vendor 101 provided with the function as an intermediate certification authority from the equipment vendor 102 having the function as a root certification authority. And the information processing system includes a key management unit that selects at least two private keys from a plurality of private keys included in a plurality of public key pairs generated with the authority of the root certification authority, a signature block generation unit that generates a signature block from the user application using the at least two private keys, a signature verification unit that verifies the signature block using at least two public keys corresponding to the at least two private keys, and a user application unit that installs the user application when the verification of the signature block is successful.
[0102] These plurality of computers may be connected by a network so that data can be transmitted and received, or may not be connected to the network and data exchange may be performed via a recording medium.
Explanation of Signs
[0103] 100, 200 Information processing system, 101 Software vendor, 102 Equipment vendor, 110, 210 Information processing apparatus, 111 Key storage unit, 112 Key management unit, 113 UI unit, 114 Signature block generation unit, 115, 215 Signature verification unit, 116, 216 User application unit, 217 Signature block storage unit, 218 Startup confirmation unit.
Claims
1. An information processing apparatus used by a second user given the function of an intermediate certification authority from a first user having the function of a root certification authority, a key storage unit that stores at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority; a key management unit that selects at least two public keys necessary for verifying a signature block of a user application developed by the second user from among the plurality of public keys; a signature verification unit that verifies the signature block using the at least two public keys; and a user application unit that installs the user application when the verification of the signature block is successful. An information processing apparatus characterized by the above.
2. The key storage unit also stores a plurality of private keys that make up the plurality of public key pairs, the key management unit also selects at least two private keys each corresponding to the at least two public keys, and further includes a signature block generation unit that generates the signature block from the user application using the at least two private keys. The information processing apparatus according to claim 1, characterized by the above.
3. The key management unit selects the at least two public keys so that two or more predetermined numbers of public keys are valid at all times within a supposed valid period, and the signature block can be verified by decrypting it using the predetermined number of public keys. The information processing apparatus according to claim 1, characterized by the above.
4. The signature block is generated by a secret sharing technique using a predetermined private key corresponding to the predetermined number of public keys. The information processing apparatus according to claim 3, characterized by the above.
5. The key management unit selects the at least two public keys and the at least two private keys so that two or more predetermined numbers of pairs of public keys and private keys are valid at all times within a supposed valid period, the signature block is generated using the predetermined number of private keys, and can be verified by decrypting it using the predetermined number of public keys. The information processing apparatus according to claim 1, characterized by the above.
6. The signature block is generated by a secret sharing technique using the predetermined private key. The information processing apparatus according to claim 5, characterized in that...
7. A signature block storage unit that stores the signature block when the verification of the signature block is successful, and A startup confirmation unit that confirms an instruction to start the installed application, and further includes: When the instruction is confirmed, the signature verification unit verifies the signature block stored in the signature block storage unit using the at least two public keys, When the verification of the signature block is successful, the user application unit starts the installed application The information processing apparatus according to any one of claims 1 to 6, characterized in that...
8. An information processing system used by a second user provided with a function as an intermediate certification authority from a first user having a function as a root certification authority, A key management unit that selects at least two secret keys from a plurality of secret keys included in a plurality of public key pairs generated with the authority of the root certification authority, A signature block generation unit that generates a signature block from a user application using the at least two secret keys, A signature verification unit that verifies the signature block using at least two public keys corresponding to the at least two secret keys, and A user application unit that installs the user application when the verification of the signature block is successful, and includes: An information processing system characterized in that...
9. A program that causes a computer to function as an information processing apparatus used by a second user provided with a function as an intermediate certification authority from a first user having a function as a root certification authority, The computer is caused to A key storage unit that stores at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority, A key management unit that selects at least two public keys necessary for verifying a signature block of a user application developed by the second user from among the plurality of public keys, A signature verification unit that verifies the signature block using the at least two public keys, and When the verification of the signature block is successful, the user application unit that installs the user application, and causes it to function as follows A program characterized in that...
10. An information processing method performed by an information processing apparatus used by a second user provided with a function as an intermediate certification authority from a first user having a function as a root certification authority, stores at least a plurality of public keys among a plurality of public key pairs generated with the authority of the root certification authority, selects at least two public keys necessary for verifying a signature block of a user application developed by the second user from among the plurality of public keys, verifies the signature block using the at least two public keys, and installs the user application when the verification of the signature block is successful. An information processing method characterized by the above.
Citation Information
Patent Citations
Process for producing angling rods
JP1978002288A