Information processing system, information processing apparatus, and information processing method

The information processing apparatus locks BIOS settings during shipment and uses USB Type-C authentication to securely unlock and update, addressing security risks in conventional systems by preventing unauthorized changes.

JP2025108118AActive Publication Date: 2025-07-23レノボ アイルランド インターナシヨナル リミテッド
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024001810
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-10
Publication Date
2025-07-23
Estimated Expiration
2044-01-10

AI Technical Summary

Technical Problem

Conventional information processing apparatuses face security risks as BIOS settings can be changed by third parties between shipment and arrival at the user, compromising OS and software integrity.

Method used

An information processing apparatus is shipped with a locked state, prohibiting OS startup, and uses a sub-control unit powered independently to unlock via a USB Type-C interface upon mutual authentication with a host device using public-key cryptography.

Benefits of technology

Enhances security by preventing unauthorized BIOS changes and ensuring secure BIOS settings and updates, reducing the risk of OS and software alterations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108118000001_ABST
    Figure 2025108118000001_ABST
Patent Text Reader

Abstract

To improve security.SOLUTION: An information processing system comprises: an information processing apparatus that holds a public key out of a private key and the public key of a public encryption scheme assigned to the apparatus, and is shipped in a locked state in which activation by an OS (Operating System) is prohibited; and a host apparatus that can be connected to the information processing apparatus via a USB (Universal Serial Bus) Type C interface. The information processing apparatus includes: a main control unit that executes processing based on the OS and a BIOS (Basic Input Output System); and a sub-control unit that is capable of operating if power is not supplied to the main control unit, the sub-control unit releasing the locked state if the mutual authenticity of the information processing apparatus and the host apparatus is confirmed based on the private key and the public key using the USB Type C.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing apparatus, and an information processing method.

Background Art

[0002] In an information processing apparatus such as a personal computer (PC), various settings can be changed by the BIOS (Basic Input Output System). Further, in such an information processing apparatus, in order to improve security, a BIOS password is set to enable BIOS settings (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in a conventional information processing apparatus, when a user purchases an information processing apparatus such as a new PC, the user individually performs BIOS settings. Therefore, in a conventional information processing apparatus, since the BIOS setup menu is not locked between shipment and arrival at the user, there is a possibility that the BIOS settings may be changed by a third party, or the OS (Operating System) and other software functions may be changed.

[0005] The present invention has been made to solve the above problems, and an object thereof is to provide an information processing system, an information processing apparatus, and an information processing method capable of improving security.

Means for Solving the Problems

[0006] To solve the above problems, one aspect of the present invention provides an information processing apparatus that holds the public key among the secret key and the public key of the public-key cryptography assigned corresponding to the apparatus, and is shipped in a locked state in which startup by the OS (Operating System) is prohibited, and an upper-level apparatus connectable to the information processing apparatus via a USB (Universal Serial Bus) Type-C interface. The information processing apparatus includes a main control unit that executes processing based on the OS and the BIOS (Basic Input Output System), and a sub-control unit operable in a state where power is not supplied to the main control unit. The sub-control unit uses the USB Type-C to release the locked state when the mutual authenticity between the information processing apparatus and the upper-level apparatus based on the secret key and the public key is confirmed. The information processing system includes the sub-control unit.

[0007] Also, in one aspect of the present invention, in the above information processing system, when the mutual authenticity between the information processing apparatus and the upper-level apparatus is confirmed, the sub-control unit further permits the setting process and the update process of the BIOS. The upper-level apparatus may execute the setting process and the update process of the BIOS for the information processing apparatus via the sub-control unit using the USB Type-C.

[0008] Also, in one aspect of the present invention, in the above information processing system, in the mutual authentication process for verifying the mutual validity between the information processing device and the host device, the sub-control unit encrypts information including a random number with the public key to obtain first encrypted information, and transmits the first encrypted information and a first hash value, which is a hash value of the information including the random number, to the host device using the USB Type-C. The host device generates a second hash value, which is a hash value of the information obtained by decrypting the received first encrypted information with the private key, and determines that the information processing device is valid when the received first hash value and the second hash value match. When the host device determines that the information processing device is valid, the host device generates a digital signature based on predetermined information with the private key, and transmits the digital signature to the sub-control unit using the USB Type-C. The sub-control unit may verify the validity of the host device based on the received digital signature and the public key.

[0009] Also, in one aspect of the present invention, in the above information processing system, the host device generates the digital signature by encrypting a third hash value, which is a hash value of the predetermined information, with the private key, and the sub-control unit may determine that the host device is valid when the third hash value and a fourth hash value, which is the received digital signature decrypted with the public key, match.

[0010] Also, in one aspect of the present invention, in the above information processing system, the host device and the sub-control unit may execute the mutual authentication process using the CC signal line of the USB Type-C.

[0011] Also, in one aspect of the present invention, in the above information processing system, the mutual validity between the information processing device and the host device may be verified based on the private key stored in a USB device connected to the host device and the public key held by the information processing device.

[0012] Also, in one aspect of the present invention, in the above information processing system, the legitimacy of the information processing apparatus and the upper-level apparatus may be confirmed based on the private key stored in the server apparatus connected to the upper-level apparatus via a network and the public key held by the information processing apparatus.

[0013] Also, one aspect of the present invention is an information processing apparatus that includes an upper-level apparatus connectable to the information processing apparatus via a USB Type-C interface, the information processing apparatus being shipped in a locked state in which the public key of the public-key cryptography assigned to the apparatus is held and the startup by the OS (Operating System) is prohibited, the information processing apparatus including a main control unit that executes processing based on the OS and BIOS (Basic Input Output System), and a sub-control unit that can operate in a state where power is not supplied to the main control unit, the sub-control unit releasing the locked state when the mutual legitimacy of the information processing apparatus and the upper-level apparatus based on the private key and the public key is confirmed using the USB Type-C.

[0014] In addition, one aspect of the present invention is an information processing method for an information processing system including an information processing device having a main control unit that executes processing based on an OS (Operating System) and a BIOS (Basic Input Output System), and a sub-control unit that can operate in a state where power is not supplied to the main control unit, and a host device that can be connected to the information processing device through a USB (Universal Serial Bus) Type-C interface. The information processing method includes: the information processing device holding the public key among the private key and the public key of the public key cryptography assigned corresponding to the device, and being shipped in a locked state in which startup by the OS is prohibited; the information processing device being connected to the host device through the USB Type-C interface; and the sub-control unit releasing the locked state when the mutual authenticity between the information processing device and the host device based on the private key and the public key is confirmed using the USB Type-C.

Effect of the Invention

[0015] According to the above aspect of the present invention, security can be improved.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Mode for Carrying Out the Invention

[0017] Hereinafter, an information processing system, an information processing apparatus, and an information processing method according to an embodiment of the present invention will be described with reference to the drawings.

[0018] FIG. 1 is a configuration diagram showing an example of the information processing system 100 according to the present embodiment. As shown in FIG. 1, the information processing system 100 includes a notebook PC 1, an authentication device 2, a USB (Universal Serial Bus) device 3, and a management server 4.

[0019] The notebook PC 1 and the authentication device 2 are connected by a USB Type-C (USB-C) interface. Also, the authentication device 2 and the management server 4 are connected via a network NW1. In the present embodiment, the notebook PC 1 will be described as an example of the information processing apparatus.

[0020] The notebook PC 1 holds the public key among the secret key and the public key of the public key cryptography assigned to the device, and is shipped in a locked state in which the startup by the OS is prohibited. The detailed configuration of the notebook PC 1 will be described later with reference to FIG. 2.

[0021] The authentication device 2 (an example of a higher-level device) is a device connectable to the notebook PC 1 by a USB Type-C interface, and executes an unlocking process of the lock state of the notebook PC 1, a BIOS setting process, and a BIOS program update process. The authentication device 2 is, for example, a notebook PC, a desktop PC, or the like. Also, the authentication device 2 can be connected to a USB device or the management server 4 that holds a secret key in order to execute mutual authentication processing with the notebook PC 1.

[0022] The USB device 3 is a device that can be connected to the authentication device 2 via a USB interface (e.g., USB Type A). The USB device 3 holds a private key corresponding to the notebook PC 1 and is used for unlocking the shipped notebook PC 1, setting the BIOS, and updating the BIOS program.

[0023] The management server 4 is, for example, a server device managed by the manufacturer (manufacturing maker) of the notebook PC 1 and can be connected to the authentication device 2 via the network NW1. The management server 4 holds the private key and public key corresponding to each notebook PC 1. Similar to the USB device 3, the management server 4 is used for unlocking the shipped notebook PC 1, setting the BIOS, and updating the BIOS program.

[0024] Next, with reference to FIG. 2, the main hardware configuration of the notebook PC 1 will be described. FIG. 2 is a diagram showing an example of the main hardware configuration of the notebook PC 1 according to the present embodiment.

[0025] As shown in FIG. 2, the notebook PC 1 includes a CPU 11, a main memory 12, a video subsystem 13, a display unit 14, a chipset 21, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, a USB connector 26, an embedded controller 31, an input unit 32, a power circuit 33, and a PD controller 34.

[0026] In the present embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. The main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).

[0027] The CPU (Central Processing Unit) 11 executes various arithmetic processes under program control and controls the entire notebook PC 1. The main memory 12 is a writable memory that is used as a loading area for the execution program of the CPU 11 or as a working area for writing the processing data of the execution program. The main memory 12 is composed of, for example, a plurality of DRAM (Dynamic Random Access Memory) chips. This execution program includes BIOS, OS, various drivers for operating peripheral devices in hardware, various services / utilities, application programs, and the like.

[0028] Also, the main memory 12 is an example of a system memory for storing programs and data, and is mounted on the notebook PC 1 by a DIMM on which a plurality of DRAMs are mounted.

[0029] The video subsystem 13 is a subsystem for realizing functions related to image display, and includes a video controller. This video controller processes the drawing commands from the CPU 11, writes the processed drawing information to the video memory, reads the drawing information from the video memory, and outputs it as drawing data (display data) to the display unit 14.

[0030] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13.

[0031] The chipset 21 is provided with controllers such as a USB, Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and a plurality of devices are connected. In FIG. 2, as an example of devices, a BIOS memory 22, an SSD 23, an audio system 24, a WLAN card 25, and a USB connector 26 are connected to the chipset 21.

[0032] The BIOS memory 22 is composed of an electrically rewritable non-volatile memory such as, for example, an EEPROM (Electrically Erasable Programmable Read Only Memory) or a flash ROM. The BIOS memory 22 stores the BIOS and system firmware for controlling the embedded controller 31 and the like.

[0033] The SSD (Solid State Drive) 23 (an example of a non-volatile storage device) stores the OS, various drivers, various services / utilities, application programs, and various data. The audio system 24 records, plays back, and outputs audio data.

[0034] The WLAN (Wireless Local Area Network) card 25 connects to the network via a wireless (radio) LAN and performs data communication. The USB connector 26 is a connector for connecting peripheral devices using USB. The USB connector 26 shall include, for example, a USB Type-C connector.

[0035] The embedded controller 31 (an example of a sub-control unit) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. Further, the embedded controller 31 has a power management function for controlling the power circuit 33. Note that the embedded controller 31 is composed of a CPU, ROM, RAM, etc. (not shown) and is provided with a plurality of channels of A / D input terminals, D / A output terminals, timers, and digital input / output terminals. To the embedded controller 31, for example, the input unit 32 and the power circuit 33 are connected via those input / output terminals, and the embedded controller 31 controls the operations thereof.

[0036] Note that the embedded controller 31 can operate in a state where power is not supplied to the main control unit 10, and can communicate with the authentication device 2 using a USB Type-C without going through the main control unit 10, and can access the BIOS memory 22 without going through the main control unit 10.

[0037] The input unit 32 is an input device such as a keyboard, a pointing device, a touch pad, etc.

[0038] The power supply circuit 33 includes, for example, a DC / DC converter, a charge / discharge unit, a battery unit, an AC / DC adapter, etc., and converts the DC voltage supplied from the AC / DC adapter or the battery unit into a plurality of voltages necessary to operate the notebook PC 1. Further, the power supply circuit 33 supplies power to each part of the notebook PC 1 based on the control from the embedded controller 31.

[0039] The PD (Power Delivery) controller 34 communicates with a device connected to the USB connector 26 (for example, a USB Type-C connector) and controls power supply or power reception with the device. When a device is connected to the USB connector 26, the PD controller 34 acquires or determines the detection of the connection of the device, information on the connected device (device attribute information), etc. via a CC (Configuration Channel) terminal or the like. For example, the PD controller 34 acquires or determines information regarding correspondence to the USB-PD standard, information indicating whether it corresponds to one or both of power supply and power reception when corresponding to the USB-PD standard, information regarding correspondence to data communication, information regarding correspondence to the USB BC1.2 standard, etc. based on communication via the CC terminal with the device connected to the USB connector 26.

[0040] Note that in this embodiment, the PD controller 34 enables communication between the authentication device 2 and the embedded controller 31 using the CC signal line of the USB Type-C.

[0041] Next, with reference to FIG. 3, the functional configuration of the information processing system 100 according to the present embodiment will be described. FIG. 3 is a functional block diagram showing an example of the functional configuration of the information processing system 100 according to the present embodiment. Note that in FIG. 3, only the configurations related to the present invention among the various functional configurations provided in the information processing system 100 are described.

[0042] As shown in FIG. 3, the information processing system 100 includes a notebook PC 1, an authentication device 2, a USB device 3, and a management server 4. The management server 4 includes a NW communication unit 41, a server storage unit 42, and a server control unit 43.

[0043] The NW (NetWork) communication unit 41 is, for example, a network adapter that can be connected to the network NW1 by a wired LAN or the like, and can be connected to the authentication device 2 via the network NW1.

[0044] The server storage unit 42 is a storage unit realized by, for example, a RAM, an SSD, an HDD, or the like, and stores various information used by the management server 4. The server storage unit 42 includes a registration information storage unit 421.

[0045] The registration information storage unit 421 stores the registration information of each notebook PC 1 manufactured and shipped by the manufacturer. The registration information storage unit 421 stores, for example, as shown in FIG. 4, the manufacturing number, the public key, and the private key in association with each other.

[0046] Here, the manufacturing number is an example of identification information for identifying the notebook PC 1. The public key and the private key are a key pair (public key and private key) of public key cryptography assigned to the notebook PC 1. In the present embodiment, one key pair is assigned to one notebook PO1.

[0047] In the example shown in FIG. 4, it shows that the public key "XXXXXXX1" and the private key "YYYYYYY1" are assigned to the notebook PC 1 with the manufacturing number "L000001".

[0048] Returning to the description of FIG. 3, the server control unit 43 is a functional unit realized by causing a CPU (not shown) to execute a program stored in the server storage unit 42. The server control unit 43 executes encryption processing and decryption processing for authentication during the registration process of the manufacturing number, public key, and private key stored in the registration information storage unit 421 and the authentication process between the notebook PC 1 and the authentication device 2.

[0049] The notebook PC 1 includes a main control unit 10, a BIOS memory 22, and an embedded controller 31. The BIOS memory 22 includes a BIOS program storage unit 221, a setting storage unit 222, a lock information storage unit 223, and a public key storage unit 224. Note that the BIOS memory 22 is accessible from the embedded controller 31 via an SPI bus.

[0050] The BIOS program storage unit 221 stores the BIOS program. The setting storage unit 222 stores BIOS setting information including the BIOS password. The lock information storage unit 223 stores information indicating whether the notebook PC 1 is in a locked state. At the time of shipment of the notebook PC 1, information indicating the locked state is stored in the lock information storage unit 223.

[0051] The public key storage unit 224 stores the public key assigned to the notebook PC 1. Note that the public key storage unit 224 may store the public key in association with the manufacturing number of the notebook PC 1.

[0052] The main control unit 10 is a functional unit realized by causing the CPU 11 to execute programs stored in the SSD 23, the BIOS memory 22, the main memory 12, etc. The main control unit 10 executes processing based on the OS and the BIOS. The main control unit 10 includes, for example, a BIOS processing unit 101 and an OS processing unit 102.

[0053] The BIOS processing unit 101 is a functional unit realized by, for example, causing the CPU 11 to execute the BIOS program stored in the BIOS memory 22, and executes processing based on the BIOS.

[0054] The OS processing unit 102 is a functional unit realized by, for example, causing the CPU 11 to execute the OS program stored in the SSD 23, and executes processing based on the OS.

[0055] The embedded controller 31 is a control unit that can operate in a state where power is not supplied to the main control unit 10. When the mutual authenticity between the notebook PC 1 and the authentication device 2 based on the private key and the public key is confirmed using the USB Type-C, the locked state of the notebook PC 1 is released. Further, when the mutual authenticity between the notebook PC 1 and the authentication device 2 is confirmed, the embedded controller 31 further permits the BIOS setting process and the BIOS update process.

[0056] The embedded controller 31 includes an authentication processing unit 311, a lock control unit 312, and a BIOS setting unit 313. The authentication processing unit 311 executes an authentication process for confirming the mutual authenticity between the embedded controller 31 (notebook PC 1) and the authentication device 2 using the CC signal line of the USB Type-C. First, the authentication processing unit 311 generates a random number (for example, a pseudo-random number using software), and encrypts the information including the generated random number (for example, a character string of the random number) by public key encryption using the public key stored in the public key storage unit 224. Further, the authentication processing unit 311 generates a hash value (first hash value) of the information including the generated random number (for example, a character string of the random number) using a hash function.

[0057] The authentication processing unit 311 transmits the encrypted information (first encrypted information) obtained by encrypting the information including the random number and the hash value (first hash value) to the authentication device 2 using the CC signal line of the USB Type-C. Note that the authentication processing unit 311 may transmit the manufacturing number of the notebook PC 1 to the authentication device 2 in advance.

[0058] In addition, the authentication processing unit 311 uses the CC signal line of the USB Type-C to confirm the validity of the authentication device 2 based on the digital signature received from the authentication device 2 and the public key. For example, the authentication processing unit 311 determines whether the hash value generated by decrypting the digital signature using the public key stored in the public key storage unit 224 matches the hash value separately generated from the message data (predetermined information), thereby confirming the validity of the authentication device 2. Here, when the validity of the notebook PC 1 (embedded controller 31) is confirmed in the authentication device 2, a digital signature is transmitted from the authentication device 2.

[0059] When the authentication processing unit 311 confirms the validity of the authentication device 2, the lock control unit 312 releases the locked state of the notebook PC 1. The lock control unit 312 changes the information indicating whether the notebook PC 1 stored in the lock information storage unit 223 is in the locked state to information indicating that it is not in the locked state, thereby releasing the locked state.

[0060] When the authentication processing unit 311 confirms the validity of the authentication device 2, the BIOS setting unit 313 permits the BIOS setting process and the BIOS update process. In the BIOS setting process, the BIOS setting unit 313 stores the BIOS setting information received from the authentication device 2 in the setting storage unit 222 to change the BIOS settings. The BIOS setting information includes, for example, the BIOS password.

[0061] In addition, in the BIOS update process, the BIOS setting unit 313 stores the BIOS program received from the authentication device 2 in the BIOS program storage unit 221 to update the BIOS. The BIOS update process includes, for example, patch processing for updating a part of the BIOS program.

[0062] The authentication device 2 includes an NW communication unit 210, a device storage unit 230, and a device control unit 240. The NW communication unit 210 is a network adapter that can be connected to the network NW1, for example, by a wired LAN, a wireless KAN, etc., and can be connected to the management server 4 via the network NW1.

[0063] The device storage unit 230 is a storage unit realized by, for example, RAM, SSD, HDD, etc., and stores various information used by the authentication device 2. The device storage unit 230 includes a setting information storage unit 231 and a BIOS program storage unit 232.

[0064] The setting information storage unit 231 stores the BIOS setting information acquired from the management server 4 or the USB device 3. The BIOS program storage unit 232 stores the BIOS update program acquired from the management server 4 or the USB device 3.

[0065] The device control unit 240 is a functional unit realized, for example, by causing a CPU (not shown) to execute the program stored in the device storage unit 230. The device control unit 240 executes various processes executed by the authentication device 2.

[0066] The device control unit 240 executes, for example, an authentication process with the notebook PC1, and controls the BIOS setting process and the BIOS update process of the notebook PC1. The device control unit 240 uses the USB Type-C to execute the BIOS setting process and the BIOS update process for the notebook PC1 via the embedded controller 31. The device control unit 240 includes an authentication processing unit 241 and a BIOS setting unit 242.

[0067] The authentication processing unit 241 controls the authentication processing with the embedded controller 31 (notebook PC 1) using the CC signal line of USB Type-C. When the authentication processing unit 241 receives, from the embedded controller 31, encrypted information obtained by encrypting information including a random number and a hash value (first hash value) via the CC signal line of USB Type-C, it transmits a request to decrypt the encrypted information to the management server 4 via the network NW1 using the private key corresponding to the notebook PC 1.

[0068] Also, the authentication processing unit 241 receives, from the management server 4 via the network NW1, information obtained by encrypting information (first encrypted information), and generates a hash value (second hash value) of the received information (information obtained by decrypting the encrypted information with the private key). The authentication processing unit 241 determines that the notebook PC 1 is legitimate when the hash value (first hash value) received from the notebook PC 1 matches the generated hash value (second hash value).

[0069] Also, when the authentication processing unit 241 determines that the notebook PC 1 is legitimate, it generates a digital signature based on predetermined information using the private key corresponding to the notebook PC 1, and transmits the digital signature to the embedded controller 31 using USB Type-C. The authentication processing unit 241 generates a digital signature by encrypting a hash value (third hash value) that is the hash value of the predetermined information with the private key.

[0070] Specifically, the authentication processing unit 241 generates a hash value (third hash value) of predetermined information (for example, random number + α, etc.), transmits the generated hash value (third hash value) to the management server 4, and requests encryption using the private key corresponding to the notebook PC 1. The authentication processing unit 241 transmits the encrypted hash value as a digital signature together with predetermined information (message data) to the embedded controller 31 (notebook PC 1) using the CC signal line of USB Type-C.

[0071] As described above, the embedded controller 31 determines that the authentication device 2 is legitimate when the hash value (third hash value) of the predetermined information (message data) generated independently and the hash value (fourth hash value) obtained by decrypting the received digital signature with the public key match.

[0072] After the authentication process is executed by the authentication processing unit 241, the BIOS setting unit 242 executes the BIOS setting process and the BIOS update process. For example, when the legitimacy of the notebook PC 1 (embedded controller 31) is confirmed by the authentication process, the BIOS setting unit 242 transmits the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31 using USB Type-C to change the BIOS setting information.

[0073] Also, for example, when the legitimacy of the notebook PC 1 (embedded controller 31) is confirmed by the authentication process, the BIOS setting unit 242 transmits the BIOS program stored in the BIOS program storage unit 232 to the embedded controller 31 using USB Type-C to execute the BIOS update.

[0074] In the above example, the case where the management server 4 decrypts the encrypted information and generates the digital signature using the private key has been described. However, instead of the management server 4, the USB device 3 may execute the same processes as the management server 4. For example, when the authentication device 2 cannot be connected to the network NW1 or the like, the information processing system 100 uses the USB device 3 to execute the lock release process, the BIOS setting process, and the BIOS update process.

[0075] Next, with reference to the drawings, the operation of the information processing system 100 according to the present embodiment will be described. FIG. 5 is a diagram showing an example of the lock release process of the information processing system 100 according to the present embodiment.

[0076] As shown in FIG. 5, the authentication device 2 first executes a login process with the management server 4 (step S101). The device control unit 240 of the authentication device 2 accesses the management server 4 by transmitting a user ID and a password to the management server 4 via the NW communication unit 210.

[0077] Next, the authentication device 2 connects to the notebook PC 1 (embedded controller (EC) 31) using USB-C (USB Type C) (step S102). The authentication device 2 connects to the embedded controller 31 via the CC signal line through the EN PD controller 34. Here, it is assumed that the main control unit 10 of the notebook PC 1 is not supplied with power from the power circuit 33, and the embedded controller 31, the BIOS memory 22, and the PD controller 34 are supplied with power.

[0078] Next, the embedded controller 31 generates a hash value of a random number and encrypts the generated random number with a public key (step S103). The authentication processing unit 311 of the embedded controller 31, for example, generates a hash value of a random number (first hash value), and encrypts the random number using the public key stored in the public key storage unit 224 to generate encrypted information.

[0079] Next, the embedded controller 31 transmits the ciphertext of the random number (encrypted information) and the hash value (first hash value) to the authentication device 2 (step S104). The authentication processing unit 311 transmits the encrypted information and the hash value (first hash value) to the authentication device 2 via the CC signal line.

[0080] Next, the authentication device 2 requests the management server 4 to decrypt the ciphertext of the random number (encrypted information) (step S105). The authentication processing unit 241 of the authentication device 2 transmits a decryption request for decrypting the encrypted information received from the embedded controller 31 to the management server 4 via the NW communication unit 210.

[0081] Next, the management server 4 decrypts the ciphertext of the random number (encrypted information) with the private key (step S106). The server control unit 43 of the management server 4 acquires the private key corresponding to the notebook PC 1 from the registration information storage unit 421, and decrypts the encrypted information received from the authentication device 2 using the private key. Here, the decrypted encrypted information corresponds to the random number described above.

[0082] Next, the management server 4 transmits the decrypted random number (decrypted text) to the authentication device 2 (step S107). The server control unit 43 transmits the decrypted random number (decrypted text) to the authentication device 2 via the NW communication unit 41.

[0083] Next, the authentication device 2 generates a hash value (second hash value) of the received random number (decrypted text) (step S108). The authentication processing unit 241 of the authentication device 2 receives the random number (decrypted text) from the management server 4 via the NW communication unit 210, and generates a hash value (second hash value) of the random number (decrypted text).

[0084] Next, the authentication processing unit 241 of the authentication device 2 determines whether or not the generated hash value (second hash value) matches the hash value (first hash value) received from the embedded controller 31 (step S109). When the hash value (second hash value) matches the hash value (first hash value) (step S109: YES), the authentication processing unit 241 proceeds to step S110. Also, when the hash value (second hash value) does not match the hash value (first hash value) (step S109: NO), the authentication processing unit 241 proceeds to step S111 and aborts the authentication process.

[0085] In step S110, the authentication processing unit 241 of the authentication device 2 requests the management server 4 to generate a digital signature. The authentication processing unit 241 generates a hash value (third hash value) of predetermined information (for example, random number + α), and transmits the hash value (third hash value) to the management server 4 via the NW communication unit 210.

[0086] Next, the management server 4 generates a digital signature using the private key corresponding to the notebook PC 1 (step S112). The server control unit 43 receives the hash value (third hash value) from the authentication device 2 via the NW communication unit 41, and acquires the private key corresponding to the notebook PC 1 from the registration information storage unit 421. The server control unit 43 encrypts the received hash value (third hash value) with the private key to generate a digital signature.

[0087] Next, the server control unit 43 of the management server 4 transmits the generated digital signature to the authentication device 2 via the NW communication unit 41 (step S113).

[0088] Next, the authentication processing unit 241 of the authentication device 2 transmits the digital signature together with predetermined information (for example, random number + α) to the embedded controller 31 using the CC signal line (step S114).

[0089] Next, the authentication processing unit 311 of the embedded controller 31 verifies the validity of the digital signature with the public key (step S115). The authentication processing unit 311 decrypts the received digital signature with the public key stored in the public key storage unit 224 to generate a hash value (fourth hash value). Also, the authentication processing unit 311 verifies the validity of the digital signature based on whether the hash value (third hash value) of the predetermined information (for example, random number + α) matches the hash value (fourth hash value).

[0090] Next, the authentication processing unit 311 of the embedded controller 31 determines whether the validity of the digital signature has been verified (step S116). When the validity of the digital signature has been verified (the hash value (third hash value) and the hash value (fourth hash value) match) (step S116: YES), the authentication processing unit 311 proceeds to step S117. Also, when the validity of the digital signature has not been verified (the hash value (third hash value) and the hash value (fourth hash value) do not match) (step S116: NO), the authentication processing unit 311 proceeds to step S118 and aborts the authentication processing.

[0091] In step S117, the embedded controller 31 releases the locked state. The lock control unit 312 of the embedded controller 31 changes the information indicating whether the notebook PC 1 stored in the lock information storage unit 223 is in the locked state to information indicating that it is not in the locked state, thereby releasing the locked state. Also, the BIOS setting unit 313 of the embedded controller 31 permits the BIOS setting process and the BIOS update process.

[0092] Next, the authentication device 2 transmits the BIOS setting information to the embedded controller 31 (step S119). The BIOS setting unit 242 of the authentication device 2 transmits the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31 using the CC signal line.

[0093] Next, the embedded controller 31 executes the BIOS setting process (step S120). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS setting information in the setting storage unit 222 and changes the BIOS settings.

[0094] Next, with reference to FIG. 6, the BIOS update process of the information processing system 100 according to the present embodiment will be described. FIG. 6 is a diagram showing an example of the BIOS update process of the information processing system 100 according to the present embodiment.

[0095] In FIG. 6, the processes from step S201 to step S216 are the same as the processes from step S101 to step S116 shown in FIG. 5 described above, and thus the description thereof is omitted here.

[0096] In step S216, when the authentication processing unit 311 confirms the validity of the digital signature (the hash value (the third hash value) and the hash value (the fourth hash value) match) (step S216: YES), the process proceeds to step S217. Also, when the authentication processing unit 311 fails to confirm the validity of the digital signature (the hash value (the third hash value) and the hash value (the fourth hash value) do not match) (step S216: NO), the process proceeds to step S218 and the authentication process is aborted.

[0097] In step S217, the embedded controller 31 permits BIOS changes. The BIOS setting unit 313 of the embedded controller 31 permits the setting process and the update process of the BIOS.

[0098] Next, the authentication device 2 transmits the BIOS update program to the embedded controller 31 (step S219). The BIOS setting unit 242 of the authentication device 2 uses the CC signal line to transmit the BIOS program stored in the BIOS program storage unit 232 to the embedded controller 31 as the BIOS update program.

[0099] Next, the embedded controller 31 executes the update process of the BIOS program (step S220). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS update program in the BIOS program storage unit 221 to update the BIOS program.

[0100] Next, the authentication device 2 transmits the BIOS setting information to the embedded controller 31 (step S221). The BIOS setting unit 242 of the authentication device 2 uses the CC signal line to transmit the BIOS setting information stored in the setting information storage unit 231 to the embedded controller 31.

[0101] Next, the embedded controller 31 executes BIOS setting processing (step S1222). The BIOS setting unit 313 of the embedded controller 31 stores the received BIOS setting information in the setting storage unit 222 to change the BIOS settings.

[0102] In the examples shown in FIGS. 5 and 6 described above, an example using the management server 4 has been described. However, in an environment where the authentication device 2 cannot be connected to the network NW1, the USB device 3 may be used instead of the management server 4. Here, with reference to FIG. 7, an example of the lock state release process when using the USB device 3 will be described.

[0103] FIG. 7 is a diagram showing another example of the lock state release process of the information processing system 100 according to the present embodiment.

[0104] In FIG. 7, the processes from step S301 to step S303 are the same as the processes from step S102 to step S104 shown in FIG. 5 described above, and thus the description thereof is omitted here.

[0105] In step S304, the authentication device 2 requests the USB device 3 to decrypt the ciphertext (encrypted information) of the random number. The authentication processing unit 241 of the authentication device 2 transmits a decryption request for requesting decryption of the encrypted information received from the embedded controller 31 to the USB device 3.

[0106] Next, the USB device 3 decrypts the ciphertext (encrypted information) of the random number with the private key (step S305). The USB device 3 decrypts the encrypted information received from the authentication device 2 using the private key corresponding to the notebook PC1. Here, the decrypted encrypted information corresponds to the random number described above.

[0107] Next, the USB device 3 transmits the decrypted random number (decrypted text) to the authentication device 2 (step S306).

[0108] Subsequently, the processes of step S307 and step S308 are the same as the processes of step S108 and step S109 shown in FIG. 5 described above, so the description thereof is omitted here.

[0109] Note that in step S308, when the hash value (second hash value) and the hash value (first hash value) match (step S308: YES), the authentication processing unit 241 of the authentication device 2 proceeds with the process to step S309. Also, when the hash value (second hash value) and the hash value (first hash value) do not match (step S308: NO), the authentication processing unit 241 proceeds with the process to step S310 and aborts the authentication process.

[0110] In step S309, the authentication processing unit 241 of the authentication device 2 requests the USB device 3 to generate a digital signature. The authentication processing unit 241 generates a hash value (third hash value) of predetermined information (for example, random number + α), and transmits the hash value (third hash value) to the USB device 3.

[0111] Next, the USB device 3 generates a digital signature with the private key corresponding to the notebook PC 1 (step S311). The USB device 3 encrypts the received hash value (third hash value) with the private key to generate a digital signature.

[0112] Next, the USB device 3 transmits the generated digital signature to the authentication device 2 (step S312).

[0113] Subsequently, the processes from step S313 to step S319 are the same as the processes from step S114 to step S120 shown in FIG. 5 described above, so the description thereof is omitted here.

[0114] Note that in the example shown in FIG. 7 described above, an example of performing the lock state release process using the USB device 3 has been described. However, for the BIOS update process shown in FIG. 6 described above, similarly, it may be performed using the USB device 3.

[0115] As described above, the information processing system 100 according to the present embodiment includes a notebook PC 1 (information processing device) and an authentication device 2 (upper device). The notebook PC 1 holds a public key out of the secret key and the public key of the public key cryptography assigned corresponding to the device, and is shipped in a locked state in which the startup by the OS is prohibited. The authentication device 2 can be connected to the notebook PC 1 through a USB Type-C interface. The notebook PC 1 includes a main control unit 10 and an embedded controller 31 (sub-control unit). The main control unit 10 executes processes based on the OS and the BIOS. The embedded controller 31 is a sub-control unit that can operate in a state where power is not supplied to the main control unit 10, and uses USB Type-C to unlock the locked state when the mutual authenticity between the notebook PC 1 and the authentication device 2 based on the secret key and the public key is confirmed.

[0116] Thereby, when the mutual authenticity between the notebook PC 1 and the authentication device 2 is confirmed, the information processing system 100 according to the present embodiment unlocks the locked state, so that the security can be improved. The information processing system 100 according to the present embodiment can reduce the possibility that, for example, the BIOS settings are changed by a third party or the OS and other software functions are changed.

[0117] In addition, in the information processing system 100 according to the present embodiment, since the embedded controller 31 (sub-control unit) that can operate in a state where power is not supplied to the main control unit 10 uses USB Type-C to unlock the locked state, the locked state can be unlocked in a state where power is not supplied to the main control unit 10. Therefore, the information processing system 100 according to the present embodiment can further improve the security in unlocking the locked state.

[0118] Also, in this embodiment, when the mutual authenticity between the notebook PC 1 and the authentication device 2 is confirmed, the embedded controller 31 further permits the BIOS setting process and the BIOS update process. The authentication device 2 uses the USB Type-C to execute the BIOS setting process and the BIOS update process on the notebook PC 1 via the embedded controller 31.

[0119] Thereby, the information processing system 100 according to this embodiment can perform the BIOS setting process and the BIOS update process in a state where power is not supplied to the main control unit 10. Therefore, the information processing system 100 according to this embodiment can further improve security in the BIOS setting process and the BIOS update process.

[0120] Also, in this embodiment, in the mutual authentication process for confirming the mutual authenticity between the notebook PC 1 and the authentication device 2, the embedded controller 31 transmits, via the USB Type-C, encrypted information obtained by encrypting information including a random number with a public key and a first hash value which is a hash value of the information including the random number to the authentication device 2. The authentication device 2 generates a second hash value which is a hash value of the information obtained by decrypting the received encrypted information with a private key, and determines that the notebook PC 1 is legitimate when the received first hash value and the second hash value match. When the authentication device 2 determines that the notebook PC 1 is legitimate, it generates a digital signature based on predetermined information with the private key, and transmits the digital signature to the embedded controller 31 via the USB Type-C. The embedded controller 31 confirms the authenticity of the authentication device 2 based on the received digital signature and the public key.

[0121] Thereby, the information processing system 100 according to this embodiment can execute a mutual authentication process for confirming the mutual authenticity between the notebook PC 1 and the authentication device 2 simply and securely using a random number.

[0122] Also, in the present embodiment, the authentication device 2 generates a digital signature by encrypting a third hash value, which is a hash value of predetermined information, with a private key. The embedded controller 31 determines that the authentication device 2 is legitimate when the third hash value matches a fourth hash value obtained by decrypting the received digital signature with a public key.

[0123] Thereby, the information processing system 100 according to the present embodiment can confirm the legitimacy of the authentication device 2 simply and securely.

[0124] Also, in the present embodiment, the authentication device 2 and the embedded controller 31 execute mutual authentication processing using the CC signal line of the USB Type-C.

[0125] Thereby, the information processing system 100 according to the present embodiment can easily improve security by using the CC signal line of the USB Type-C and utilizing an existing interface.

[0126] Also, in the present embodiment, the mutual legitimacy between the notebook PC 1 and the authentication device 2 is confirmed based on the private key stored in the USB device 3 connected to the authentication device 2 and the public key held by the notebook PC 1.

[0127] Thereby, the information processing system 100 according to the present embodiment can confirm the mutual legitimacy between the notebook PC 1 and the authentication device 2 simply and securely using the USB device 3.

[0128] Also, in the present embodiment, the mutual legitimacy between the notebook PC 1 and the authentication device 2 is confirmed based on the private key stored in the management server 4 (server device) connected to the authentication device 2 via a network and the public key held by the notebook PC 1.

[0129] As a result, the information processing system 100 according to the present embodiment can confirm the mutual legitimacy between the notebook PC 1 and the authentication device 2 simply and securely using the management server 4 (server device).

[0130] In addition, the notebook PC 1 (information processing device) according to the present embodiment is the notebook PC 1 of the information processing system 100 including the notebook PC 1 and the authentication device 2 connectable to the notebook PC 1 through a USB Type-C interface, and includes a main control unit 10 and an embedded controller 31. The notebook PC 1 holds the public key among the secret key and the public key of the public key cryptography assigned to the device, and is shipped in a locked state in which the startup by the OS is prohibited. The main control unit 10 executes processing based on the OS and BIOS. The embedded controller 31 is a sub-control unit that can operate in a state where power is not supplied to the main control unit 10, and unlocks the locked state when the mutual legitimacy between the notebook PC 1 and the authentication device 2 based on the secret key and the public key is confirmed using the USB Type-C. As a result, the notebook PC 1 (information processing device) according to the present embodiment has the same effect as the information processing system 100 described above, and can improve security.

[0131] Also, the information processing method according to the present embodiment is an information processing method of an information processing system 100 including a notebook PC 1 and an authentication device 2 connectable to the notebook PC 1 through a USB Type-C interface, and includes a shipping step, a connection step, and a release step. The notebook PC 1 includes a main control unit 10 that executes processing based on an OS and a BIOS, and an embedded controller 31 that can operate in a state where power is not supplied to the main control unit 10. In the shipping step, the notebook PC 1 holds a public key among the private key and the public key assigned corresponding to the device, and is shipped in a locked state in which startup by the OS is prohibited. In the connection step, the notebook PC 1 is connected to the authentication device 2 through a USB Type-C interface. In the release step, when the embedded controller 31 uses USB Type-C to confirm the mutual validity between the notebook PC 1 and the authentication device 2 based on the private key and the public key, the locked state is released. Thereby, the information processing method according to the present embodiment has the same effect as the information processing system 100 described above, and can improve security.

[0132] Note that the present invention is not limited to the above-described embodiment, and can be modified without departing from the spirit of the present invention. For example, in the above embodiment, an example in which the USB device 3 or the management server 4 executes encryption processing or decryption processing using the private key has been described, but the present invention is not limited to this. The authentication device 2 may obtain the private key from the USB device 3 or the management server 4, and the authentication device 2 may execute encryption processing or decryption processing. Further, the authentication device 2 may include a private key storage unit that stores the private key.

[0133] Also, in the above embodiment, an example in which the information processing device is the notebook PC 1 has been described, but the present invention is not limited to this. For example, other information processing devices such as a tablet terminal device and a desktop PC may be used.

[0134] Also, in the above-described embodiment, an example in which an authentication process for mutually verifying the legitimacy between the authentication device 2 and the notebook PC 1 (embedded controller 31) is executed using random numbers has been described. However, the present invention is not limited to this, and an authentication process using other methods may be executed.

[0135] For example, in the above-described embodiment, an example in which a process for verifying the legitimacy of the authentication device 2 is described using a digital signature. However, the present invention is not limited to this, and a process using a random number similar to the process for verifying the legitimacy of the notebook PC 1 may be performed.

[0136] Each component included in the information processing system 100 described above has a computer system inside. Then, a program for realizing the functions of each component included in the information processing system 100 described above is recorded on a computer-readable recording medium, and the program recorded on this recording medium is read into the computer system and executed, whereby the processes in each component included in the notebook PC 1 described above may be performed. Here, "reading the program recorded on the recording medium into the computer system and executing it" includes installing the program in the computer system. The "computer system" here is assumed to include hardware such as an OS and peripheral devices. Also, the "computer system" may include a plurality of computer devices connected via a network including a communication line such as the Internet, WAN, LAN, or dedicated line. Further, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, magneto-optical disk, ROM, CD-ROM, or a storage device such as a hard disk built into the computer system. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM.

[0137] In addition, the recording medium includes an internal or external recording medium that is accessible from a distribution server for distributing the program. Note that the program may be divided into multiple parts and downloaded at different timings, and then combined by each component included in the information processing system 100, or the distribution servers for distributing each of the divided programs may be different. Further, the "computer-readable recording medium" includes those that hold a program for a certain period of time, such as a volatile memory (RAM) inside a computer system that becomes a server or a client when a program is transmitted via a network. Also, the above program may be for realizing a part of the functions described above. Furthermore, it may be a so-called difference file (difference program) that can realize the above functions in combination with a program already recorded in the computer system.

[0138] In addition, part or all of the functions described above may be realized as an integrated circuit such as an LSI (Large Scale Integration). Each of the functions described above may be made into an individual processor, or part or all of them may be integrated and made into a processor. Also, the method of integrating into an integrated circuit is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. Further, when a technology for integrating into an integrated circuit that replaces LSI appears due to the progress of semiconductor technology, an integrated circuit using such technology may be used.

Explanation of Reference Numerals

[0139] 1 Notebook PC 2 Authentication device 3 USB device 4 Management server 10 Main control unit 11 CPU 12 Main memory 13 Video subsystem 14 Display unit 21 Chipset 22 BIOS memory 23 SSD 24 Audio system 25 WLAN Card 26 USB Connector 31 Embedded Controller (EC) 32 Input Section 33 Power Circuit 34 PD Controller 41, 210 NW Communication Section 42 Server Memory Section 43 Server Control Section 100 Information Processing System 101 BIOS Processing Section 102 OS Processing Section 221 BIOS Program Memory Section 222 Setting Memory Section 223 Lock Information Memory Section 224 Public Key Memory Section 230 Device Memory Section 231 Setting Information Memory Section 232 BIOS Program Memory Section 240 Device Control Section 241, 311 Authentication Processing Section 242, 313 BIOS Setting Section 312 Lock Control Section 421 Registered Information Memory Section NW1 Network

Claims

1. An information processing apparatus that holds the public key among the secret key and the public key of a public key cryptosystem assigned corresponding to the apparatus and is shipped in a locked state in which startup by an OS (Operating System) is prohibited, and a host device connectable to the information processing apparatus via a USB (Universal Serial Bus) Type-C interface comprising: The information processing apparatus includes: a main control unit that executes processing based on the OS and BIOS (Basic Input Output System); a sub-control unit operable in a state where power is not supplied to the main control unit, and when the mutual authenticity between the information processing apparatus and the host device based on the secret key and the public key is confirmed using the USB Type-C, releases the locked state An information processing system comprising:

2. When the mutual authenticity between the information processing apparatus and the host device is confirmed, the sub-control unit further permits the BIOS setting process and the BIOS update process, The host device executes the BIOS setting process and the BIOS update process for the information processing apparatus via the sub-control unit using the USB Type-C The information processing system according to claim 1.

3. In the mutual authentication process for confirming the mutual authenticity between the information processing apparatus and the host device, the sub-control unit transmits, using the USB Type-C, encrypted information obtained by encrypting information including a random number with the public key and a first hash value that is a hash value of the information including the random number to the host device, the host device generates a second hash value that is a hash value of information obtained by decrypting the received encrypted information with the secret key, and determines that the information processing apparatus is legitimate when the received first hash value and the second hash value match, when the host device determines that the information processing apparatus is legitimate, the host device generates a digital signature based on predetermined information with the secret key and transmits the digital signature to the sub-control unit using the USB Type-C, the sub-control unit confirms the authenticity of the host device based on the received digital signature and the public key The information processing system according to claim 1 or claim 2.

4. The upper device generates the digital signature by encrypting a third hash value, which is the hash value of the predetermined information, with the private key. When the third hash value matches a fourth hash value obtained by decrypting the received digital signature with the public key, the sub-control unit determines that the upper device is legitimate. The information processing system according to claim 3.

5. The upper device and the sub-control unit execute the mutual authentication process using the CC signal line of the USB Type-C. The information processing system according to claim 3.

6. Based on the private key stored in the USB device connected to the upper device and the public key held by the information processing device, the legitimacy of both the information processing device and the upper device is confirmed. The information processing system according to claim 1 or claim 2.

7. Based on the private key stored in the server device connected to the upper device via the network and the public key held by the information processing device, the legitimacy of both the information processing device and the upper device is confirmed. The information processing system according to claim 1 or claim 2.

8. An information processing device of an information processing system including an information processing device that holds the public key of a public-private key pair of public-key cryptography assigned corresponding to the device and is shipped in a locked state in which startup by an OS (Operating System) is prohibited, and an upper device connectable to the information processing device by an interface of USB (Universal Serial Bus) Type-C, a main control unit that executes processing based on the OS and BIOS (Basic Input Output System); a sub-control unit operable in a state where power is not supplied to the main control unit, the sub-control unit using the USB Type-C to release the locked state when the mutual legitimacy of the information processing device and the upper device based on the private key and the public key is confirmed; An information processing device comprising:

9. An information processing method for an information processing system including an information processing apparatus having a main control unit that executes processing based on an OS (Operating System) and a BIOS (Basic Input Output System), and a sub-control unit that can operate in a state where power is not supplied to the main control unit, and a host device that can be connected to the information processing apparatus by an interface of a USB (Universal Serial Bus) Type-C, The step of the information processing apparatus holding the public key of the public key and the private key of the public key cryptography assigned corresponding to the apparatus, and being shipped in a locked state in which startup by the OS is prohibited; The step of the information processing apparatus being connected to the host device by the USB Type-C interface; The step of the sub-control unit releasing the locked state when the mutual authenticity of the information processing apparatus and the host device based on the private key and the public key is confirmed using the USB Type-C; An information processing method including the above steps.

Citation Information

Patent Citations

  • Exchange method of confidential information and computer

    JP2014057283A

  • Runtime Device Firmware Verification Using Trust Chaining

    US20210034733A1

  • Remote feature activation

    US9535676B1

  • Information processing device, authentication system, authentication device, information processing method, information processing program, recording medium, and integrated circuit

    WO2010041464A1

  • Information processor and start-up program of the information processor

    JP2010152721A