Information processing device

The device addresses inefficient updates in nonvolatile memory by using a dual processing unit with a mode switch to securely erase and rewrite information, ensuring efficient operation and security.

JP2025136314APending Publication Date: 2025-09-19JAPAN EM SOLUTIONS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024034785
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing information processing devices face challenges in efficiently updating information stored in nonvolatile memory due to security restrictions, which hinder efficient operation when specific conditions are not met.

Method used

The device incorporates a first and second processing unit with a mode switching unit that allows the nonvolatile memory to be controlled in a second mode for erasure and initialization, enabling updates even when not in the initial state, and a software-based mode switch to facilitate secure rewriting.

Benefits of technology

Enables secure and efficient updating of nonvolatile memory by allowing erasure and rewriting of information, ensuring secure operation and efficient device functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025136314000001_ABST
    Figure 2025136314000001_ABST
Patent Text Reader

Abstract

To provide an information processing device capable of efficiently updating information stored in a nonvolatile memory with a security being taken into consideration.SOLUTION: An information processing device includes: a first processing unit 1; a function unit 2 that is controlled by the first processing unit; a nonvolatile memory 3 that stores information to be utilized by the function unit 2; a second processing unit 4 that is different from the first processing unit; and a mode changing unit 5 that changes a mode between a first mode in which the nonvolatile memory is controlled by the first processing unit and a second mode in which the nonvolatile memory 3 is controlled by the second processing unit 4. In the first mode, the information in the nonvolatile memory 3 is not rewritable other than in the initial state of the nonvolatile memory 3, and in the second mode, the information stored in the nonvolatile memory 3 can be erased so as to return the nonvolatile memory 3 to the initial state.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing apparatus including an arithmetic processing unit, functional devices such as network devices and storage devices controlled by the arithmetic unit, and nonvolatile memory for storing information used by the functional devices. [Background technology]

[0002] In the above-described information processing device, when information for functional devices such as a network controller, for example, firmware, is written in a nonvolatile memory, it may become necessary to rewrite the firmware due to changes in the processing content of the information processing device, changes in the system configuration, etc. Such rewriting may be restricted from being performed through a normal data transmission path from the arithmetic processing unit to the functional devices for security reasons.

[0003] For example, Patent Document 1 discloses a firmware write control technology for writing firmware for causing a card device to execute a predetermined function into a nonvolatile memory provided in a card device that is removably attached to a host device. This firmware write control technology determines whether code data set in a register provided in a card interface unit that can communicate with the host device is a predetermined valid value, and depending on the result of this determination, the operation of writing firmware to the nonvolatile memory is permitted or prohibited.

[0004] Furthermore, Patent Document 2 discloses a memory card provided with a switch used to switch the function of inhibiting writing of data to a nonvolatile memory. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-086353 [Patent Document 2] Japanese Patent Application Laid-Open No. 2002-183700

[0006] In Patent Documents 1 and 2, although information can be stored in the nonvolatile memory in an initial state where no information is stored in the nonvolatile memory, if information has already been stored in the nonvolatile memory, the information can be rewritten or erased from the nonvolatile memory only under specific conditions, such as checking code data or operating a switch provided in the nonvolatile memory. Therefore, even if it becomes necessary to update the information stored in the nonvolatile memory, the update cannot be performed unless specific conditions are met, which may hinder efficient operation of the information processing device.

[0007] In view of the above circumstances, an object of the present invention is to provide an information processing device that can efficiently update information stored in a nonvolatile memory while taking security into consideration. Summary of the Invention [Problem to be solved by the invention]

[0008] In order to achieve the above-mentioned object, an information processing device according to the present invention comprises a first processing unit, a functional unit controlled by the first processing unit, a non-volatile memory that stores information used by the functional unit, a second processing unit different from the first processing unit, and a mode switching unit that switches between a first mode in which the non-volatile memory is controlled by the first processing unit and a second mode in which the non-volatile memory is controlled by the second processing unit, wherein in the first mode, the information in the non-volatile memory cannot be rewritten except in the initial state of the non-volatile memory, and in the second mode, the information stored in the non-volatile memory can be erased to return the non-volatile memory to the initial state.

[0009] With this configuration, even if the nonvolatile memory is no longer in the initial state and it is impossible to control the nonvolatile memory in the first mode by externally issuing a command to the first processing unit, the nonvolatile memory can be controlled by the second processing unit by using the second mode. The second processing unit erases the information stored in the nonvolatile memory and performs processing (control) to return the nonvolatile memory to the initial state, and once the nonvolatile memory is in the initial state, processing (control) of the nonvolatile memory using the first mode becomes possible.

[0010] It is not uncommon for firmware to need to be upgraded due to an error being discovered in a portion of the firmware that realizes the function of a functional unit. When such firmware is stored in a non-volatile memory that the first processing unit cannot reset to an initial state based on an external command other than the initial state, the control of the non-volatile memory in the second mode according to the present invention is preferably used. For this reason, the present invention proposes that the information include the firmware used to operate the functional unit.

[0011] In some cases, the information stored in the non-volatile memory to realize the function of the functional unit is not firmware but circuit program data, and therefore, the present invention proposes that the information includes circuit program data used for the operation of the functional unit.

[0012] As described above, by using the second mode, even a non-volatile memory that is not in its initial state can be processed by the second processing unit. Once the information stored in the non-volatile memory is erased and the non-volatile memory is returned to its initial state, the non-volatile memory can then be controlled in the first mode by externally issuing a command to the first processing unit. Of course, the second mode can be used not only to return the non-volatile memory to its initial state, but also to rewrite it with new information. For this reason, the present invention also proposes a configuration in which the information stored in the non-volatile memory can be rewritten in the second mode.

[0013] In addition, if the first processing unit switches to the second mode using some special command or interface and the nonvolatile memory is returned to its initial state, rewriting the nonvolatile memory becomes easy. For this reason, the present invention also proposes a configuration in which the first processing unit can issue a command to the second processing unit to erase the information stored in the nonvolatile memory. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 2 is a schematic block diagram showing a stage of writing information to a nonvolatile memory of an information processing device. [Figure 2] FIG. 10 is a schematic block diagram showing a process of rewriting new information into a nonvolatile memory in which information has already been written. [Figure 3] FIG. 10 is a schematic block diagram showing another process for rewriting the contents of a nonvolatile memory. [Figure 4] FIG. 1 is a schematic block diagram showing an embodiment of an information processing device. [Figure 5] FIG. 10 is a schematic block diagram showing another embodiment of an information processing device. DETAILED DESCRIPTION OF THE INVENTION

[0015] First, an outline of the present invention used in the information processing device will be described using the schematic block diagrams of the information processing device shown in FIGS.

[0016] First, the basic concept of an information processing device according to the present invention will be described below. This information processing device includes a first processing unit 1, a functional unit 2 that performs a specific function controlled by the first processing unit 1, a nonvolatile memory 3 that stores information used by the functional unit 2, and a second processing unit 4 that is different from the first processing unit 1. The functions performed by the functional unit 2 include, for example, an image acquisition function handled by the first processing unit 1, a communication function for sending and receiving information handled by the first processing unit 1, and a database management function for data handled by the first processing unit 1. The information processing device also includes a mode switching unit 5 that switches the nonvolatile memory 3 between a first mode controlled by the first processing unit 1 and a second mode controlled by the second processing unit 4. This mode switching unit 5 is not like a physical switch, but like a software switch that functions according to a program. Of course, some hardware, such as a circuit, may be involved.

[0017] This nonvolatile memory 3 is under the control of the functional unit 2 and stores information used by the functional unit 2, for example, control software (which may be general firmware or a circuit program for constructing a circuit) for controlling the functional unit 2. From a security standpoint, the control software can be written from the first processing unit 1 via the functional unit 2, but once written, it cannot be changed by rewriting. This ensures that the contents of the nonvolatile memory 3 cannot be illegally rewritten even if the first processing unit 1 is invaded by a virus or the like.

[0018] For this reason, if it becomes necessary to rewrite information that has been written to the functional unit 2, a special measure is required. This measure is realized by mode switching by the mode switching unit 5. In the first mode, which is the initial specification, or in the first mode switched to by the mode switching unit 5, it is impossible to rewrite the control software in the nonvolatile memory 3 except when the nonvolatile memory 3 is in its initial state (a state in which nothing is written), whereas in the second mode switched to by the mode switching unit 5, it is possible to erase the information stored in the nonvolatile memory 3 and return the nonvolatile memory 3 to its initial state. Once the nonvolatile memory 3 is returned to its initial state, it is possible to write new control software to the nonvolatile memory 3.

[0019] The above-mentioned measures will be explained using Figures 1, 2, and 3. Figure 1 shows the stage of writing information to the nonvolatile memory 3 at the time of implementation. The nonvolatile memory 3 at the time of implementation is in an initial state. Therefore, by issuing a memory operation command to the first processing unit 1 to write the write information to the nonvolatile memory 3 via the functional unit 2, the information previously stored in the memory of the first processing unit 1 is written to the nonvolatile memory 3 without any problems. This enables the functional unit 2 to function according to specifications based on the information written to the nonvolatile memory 3.

[0020] FIG. 2 is a schematic block diagram showing the process performed when new information is rewritten to the nonvolatile memory 3, which already has information written thereto. This process involves an initial process (initialization process) and a write process in which new information is written to the reinitialized nonvolatile memory 3. First, the second processing unit 4 is instructed to access the nonvolatile memory 3 and erase its contents (initialization command). This initialization command includes an activation command that activates the mode switching unit 5 and opens a path through which the second processing unit 4 can directly access the nonvolatile memory 3. This activation may be performed by the second processing unit 4 directly on the mode switching unit 5 or via the first processing unit 1. Once the path through which the second processing unit 4 can directly access the nonvolatile memory 3 is opened, the second processing unit 4 erases the contents of the nonvolatile memory 3 and returns the nonvolatile memory 3 to its initial state. Once the nonvolatile memory 3 is returned to its initial state, the mode switching unit 5 is deactivated and the path between the nonvolatile memory 3 and the functional unit 2 is restored. The path between the nonvolatile memory 3 and the functional unit 2 in the mode switching unit 5 may be configured to be always connected regardless of whether the mode switching unit 5 is activated.

[0021] When the nonvolatile memory 3 is returned to its initial state, the first processing unit 1 writes the write information to the nonvolatile memory 3 via the function unit 2. This write process is substantially the same as the write process shown in Fig. 1. However, the first processing unit 1 has been given a memory write command and new write information in advance or at this point.

[0022] 2 shows a process in which the second processing unit 4 initializes the nonvolatile memory 3 and the first processing unit 1 writes new information to the nonvolatile memory 3. Alternatively, as shown in FIG. 3, the first processing unit 1 can initialize the nonvolatile memory 3 and write new information to the nonvolatile memory 3. In this case, a memory erase command, a memory write command, and write information are given to the second processing unit 4 as rewrite information in advance or at this point. As a result, the second processing unit 4 activates the mode switching unit 5, initializes the nonvolatile memory 3, and rewrites the nonvolatile memory 3 with new information.

[0023] Next, one specific embodiment of the information processing device of the present invention will be described with reference to Figure 4. This information processing device is used as an information display device. The first processing unit 1 is a computer unit 10, and includes a CPU 11, a ROM 12, and an I / O 14.

[0024] A display 18 for displaying information is connected to the bus of the computer unit 10. The information displayed on the display 18 is generated by the computer unit 10 or an information generating unit connected via a network controller 20. A keyboard 15 and a communication device 16 are also connected to the bus of the computer unit 10. The computer unit 10 is further connected to a network controller 20 as a functional unit 2, a nonvolatile memory 3 under the control of the network controller 20, and a power supply control unit 40 as a second processing unit 4. A shared memory 17 accessible from both the computer unit 10 and the power supply control unit 40 is also provided. A mode switching unit 5 is interposed between the network controller 20 and the nonvolatile memory 3 on the bus, and enables connection between the power supply control unit 40 and the nonvolatile memory 3 upon activation (program execution). The mode switching unit 5 creates either a first mode or a second mode. In the first mode, which is the normal mode of the mode switching unit 5, the nonvolatile memory 3 is controlled by the computer unit 10. In the second mode, which is realized by activating the mode switching unit 5, the nonvolatile memory 3 is controlled by the power supply control unit 40.

[0025] The nonvolatile memory 3 stores firmware (or circuit program data, or both) that realizes the functions of the network controller 20. When the network specifications change, the firmware in the nonvolatile memory 3 needs to be updated.

[0026] When updating the firmware, a memory erase command is stored in advance in the shared memory 17 as a memory operation command using the keyboard 15 or the communication device 16. This memory operation command is read when the computer unit 10 is started up. Based on the read memory operation command, the mode switching unit 5 is activated, and the second mode is realized. This causes the power supply control unit 40 to erase the contents of the nonvolatile memory 3 and return it to its initial state.

[0027] Once the nonvolatile memory 3 is in its initial state, the computer unit 10 writes the upgraded firmware stored in some storage device to the nonvolatile memory 3 via the network controller 20 in the same way as when the nonvolatile memory 3 was installed, that is, in the first mode. Of course, in the second mode, the power supply control unit 40 as the second processing unit 4 can also write the upgraded firmware stored in some storage device to the nonvolatile memory 3. Thereafter, when the computer unit 10 starts up, the network controller 20 executes the firmware stored in the nonvolatile memory 3, and the network controller 20 operates under the new communication specifications.

[0028] Next, another embodiment of the information processing device of the present invention will be described with reference to Fig. 5. This information processing device is used as an environment monitoring device using a monitoring camera 22. As in the previous embodiment, the first processing unit 1 is a computer unit 10, and includes a CPU 11, a ROM 12, and an I / O 14.

[0029] As in the previous embodiment, a keyboard 15 and a communication device 16 are connected to the bus of the computer unit 10. Furthermore, a camera controller 21 is connected to the computer unit 10 as a functional unit 2, and the nonvolatile memory 3 is under the control of the camera controller 21. A power supply control unit 40 functions as a second processing unit 4 and is also provided with a shared memory 17 accessible from both the computer unit 10 and the power supply control unit 40. A mode switching unit 5 is interposed between the bus between the camera controller 21 and the nonvolatile memory 3. The mode switching unit 5 switches from a first mode to a second mode when activated (program execution), enabling connection between the power supply control unit 40 and the nonvolatile memory 3. The camera controller 21 controls the surveillance camera 22 and processes surveillance images from the surveillance camera 22. The camera controller 21 is controlled by the computer unit 10.

[0030] The nonvolatile memory 3 stores firmware (or circuit program data, or both) that realizes the functions of the camera controller 21. When the specifications of the surveillance camera 22 or the processing specifications of the surveillance images are changed, the firmware in the nonvolatile memory 3 needs to be updated.

[0031] When updating the firmware, a memory erase command is stored in advance in the shared memory 17 as a memory operation command using the keyboard 15 or the communication device 16. This memory operation command is read when the computer unit 10 is started up. Based on the read memory operation command, the mode switching unit 5 is activated, and the second mode is realized. This causes the power supply control unit 40 to erase the contents of the nonvolatile memory 3 and return it to its initial state.

[0032] Once the nonvolatile memory 3 is in the initial state, in the second mode, the power supply control unit 40 as the second processing unit 4 writes the upgraded firmware stored in some kind of storage device to the nonvolatile memory 3. Of course, it is also possible to return to the first mode and have the computer unit 10 write the upgraded firmware stored in some kind of storage device to the nonvolatile memory 3 via the camera controller 21 in the same way as when the nonvolatile memory 3 was installed. Thereafter, when the computer unit 10 starts up, the camera controller 21 executes the firmware stored in the nonvolatile memory 3, and the camera controller 21 operates according to the new specifications.

[0033] [Another embodiment] (1) In the above embodiment, the information processing device is an information display device or an environmental monitoring device, but instead, it can be applied to a data processing device with a database or an information display device with a group of displays. (2) In the above embodiment, a network controller 20 or a camera controller 21 was used as the functional section 2 of the first processing unit 1, but instead, various computer peripheral devices such as a database controller or an obstacle detection controller may be used. (3) In the above embodiment, a power supply control unit 40 was used as the second processing unit 4, but other computer-integrated devices connected to the first processing unit 1 via a bus or the like, such as a printer control device or an external memory control device, may also be used. (4) In a configuration in which switching to the second mode is performed from the first processing unit 1 using a special command or interface and the nonvolatile memory 3 is returned to its initial state, the nonvolatile memory 3 can be rewritten by familiar operations on the first processing unit 1, which has the advantage of simplifying the rewriting of the nonvolatile memory 3. For example, if a private hidden mode (command) is used to switch to the second mode, only those who know the operation in the hidden mode (command) can issue a command to the second processing unit 4 via the second mode to erase information stored in the nonvolatile memory 3. In other words, the process of returning the nonvolatile memory 3 to its initial state is performed via the second processing unit 4 under the security of only those who know the private hidden mode (command) being able to operate it.

[0034] The configurations disclosed in the above embodiments (including other embodiments, the same applies below) can be applied in combination with configurations disclosed in other embodiments, as long as no contradiction arises. Furthermore, the embodiments disclosed in this specification are examples, and the embodiments of the present invention are not limited to these, and can be modified as appropriate within the scope that does not deviate from the purpose of the present invention. [Industrial Applicability]

[0035] The present invention is applicable to an information processing device in which the nonvolatile memory storing the control software for the functional unit, which is a peripheral device of the computer, cannot be directly rewritten from the computer side. [Explanation of symbols]

[0036] 1: First processing unit 2: Functional section 3: Non-volatile memory 4: Second processing unit 5: Mode switching section 10: Computer unit 11: CPU 14: I / O 15: Keyboard 16: Communication equipment 17: Shared memory 18: Display 20: Network Controller 21: Camera controller 22: Surveillance camera 40: Power supply control unit

Claims

1. a first processing unit; a functional unit controlled by the first processing unit; a non-volatile memory that stores information used by the functional unit; a second processing unit different from the first processing unit; a mode switching unit that switches between a first mode in which the nonvolatile memory is controlled by the first processing unit and a second mode in which the nonvolatile memory is controlled by the second processing unit; In the first mode, the information in the nonvolatile memory cannot be rewritten except when the nonvolatile memory is in an initial state; In the second mode, the information processing apparatus is capable of erasing the information stored in the nonvolatile memory and returning the nonvolatile memory to the initial state.

2. The information processing apparatus according to claim 1 , wherein the information includes firmware used for the operation of the functional unit.

3. The information processing device according to claim 1 , wherein the information includes circuit program data used for the operation of the functional unit.

4. 2. The information processing apparatus according to claim 1, wherein in the second mode, the information stored in the nonvolatile memory is rewritable.

5. The information processing apparatus according to claim 1 , wherein the first processing unit is capable of issuing a command to the second processing unit to erase the information stored in the nonvolatile memory.

Citation Information

Patent Citations

  • Memory card, control device, data processing system and data processing method

    JP2002183700A

  • Firmware write control method and card device to which same write control method is applied

    JP2004086353A