Unauthorized use prevention system and unauthorized use prevention method
The control device periodically checks for license data and allows a stop mode to continue control without the removable media, addressing the need for continuous socket occupancy in existing systems.
Patent Information
- Application Number
- JP2024036068
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-08
- Publication Date
- 2025-09-19
AI Technical Summary
Existing systems require a removable media containing license data to be constantly inserted for control application execution, occupying the socket and limiting flexibility in control processes.
A control device with an RM socket that periodically checks for license data and allows execution in a stop mode where license checks are halted, enabling control continuation without the media being present.
Enables uninterrupted control processes even when the removable media is not inserted, enhancing flexibility and reducing socket occupancy requirements.
Smart Images

Figure 2025137074000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention generally relates to preventing program fraud. [Background technology]
[0002] There is a control device (e.g., an industrial controller) that controls a controlled device such as an industrial device (e.g., an industrial motor or compressor). The control device controls the controlled device by executing a control application. The control application can perform control by calling one or more program modules (e.g., one or more libraries such as one or more function blocks) in the course of a control process.
[0003] An implementing entity, which is an entity (typically an organization such as a company) that implements control of a controlled device, and a providing entity, which is an entity that provides a control application or at least one program module, may be different. It is desirable for the providing entity to be able to prevent the implementing entity from misusing the control application or program module (e.g., from viewing the source code of the control application or program module).
[0004] Known technology for preventing unauthorized use of programs is disclosed in, for example, Patent Document 1. According to Patent Document 1, if a valid license corresponding to an application program does not exist in a portable memory device, execution of the application program is stopped. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-73002 Summary of the Invention [Problem to be solved by the invention]
[0006] Based on the technology disclosed in Patent Document 1, it is possible to prevent unauthorized use of a control application or a program module, for example, as follows. That is, a control device has a socket for an RM (removable media) such as a portable memory device, and determines whether license data for the control application or program module exists in the RM connected to the socket. If such license data does not exist, the control device prohibits (e.g., suspends) the use of the control application or program module.
[0007] However, with this technology, an RM containing the license data for the control application or program module must always be inserted into the RM's socket during the period in which control is being performed, which means that the RM's socket is occupied by the RM containing the license data during the period in which control is being performed. [Means for solving the problem]
[0008] There is a control device that periodically performs control processing of a controlled device and is provided with an RM socket and an RM I / F 53. The control device accepts a mode specification and sets the specified mode. The control device periodically performs a license check to determine whether an RM that stores license data representing the license of a protected program is inserted into the socket and connected to the RM I / F 53. If the result of the license check is not false, the control device executes the protected program in the control processing. If the set mode is a stop mode, which means that license checks are stopped, the control device stops performing license checks. [Effects of the Invention]
[0009] During the control period, even if the RM containing the license data is not inserted into the RM socket, the control can be continued. Problems, configurations, and effects other than those described above will become clear from the following explanation. [Brief explanation of the drawings]
[0010] [Figure 1] 1 shows an example of the physical configuration of the entire system including the control system according to an embodiment. [Figure 2] 1 shows an example of the logical configuration of a control device. [Figure 3] 10 shows an example of a mode setting screen. [Figure 4] 10 shows an example of the flow of license protection control. [Figure 5] 1 shows an example of the flow of program execution control in normal mode. [Figure 6] 10 shows an example of the flow of program execution control in a log collection mode. [Figure 7] 1 shows an example of the flow of program execution control in a simulation. [Figure 8] 1 shows an example of the flow of program execution control during debugging. [Figure 9] 1 shows an example of the flow of program execution control when building / downloading a program to be protected. DETAILED DESCRIPTION OF THE INVENTION
[0011] In the following description, an "interface apparatus" may refer to one or more interface devices, which may be one or more homogeneous communication interface devices or two or more heterogeneous communication interface devices.
[0012] In the following description, "memory" refers to one or more memory devices, typically a primary storage device. At least one of the memory devices may be a volatile memory device or a non-volatile memory device.
[0013] In the following description, a "persistent storage device" refers to one or more persistent storage devices. A persistent storage device is typically a non-volatile storage device (e.g., an auxiliary storage device), and specifically, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive).
[0014] In the following description, the term "storage device" may refer to at least one of memory and persistent storage device.
[0015] Furthermore, in the following description, a "processor" may refer to one or more processor devices. The at least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be another type of processor device such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may also be a processor core. The at least one processor device may also be a processor device in a broader sense, such as a hardware circuit that performs part or all of the processing (for example, an FPGA (Field-Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).
[0016] In the following description, processing may be described using a "program" as the subject; however, since a program is executed by a processor to perform a predetermined process using a storage device and / or an interface device, etc., as appropriate, the subject of the process may also be the processor (or a device such as a controller having the processor). A program may be installed in a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable (e.g., non-transitory) recording medium. In the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.
[0017] Furthermore, in the following description, functions may be described using the expression "yyy unit," but the functions may be realized by one or more computer programs being executed by a processor. When a function is realized by a program being executed by a processor, the specified processing is performed using a storage device and / or an interface device, etc., as appropriate, and therefore the function may be considered to be at least a part of the processor. Processing described using a function as the subject may also be processing performed by a processor or a device having that processor. The description of each function is an example, and multiple functions may be combined into one function, or one function may be divided into multiple functions.
[0018] In the following description, information that provides an output for an input may be described using expressions such as "xxx table." However, this information may be data of any structure (for example, structured data or unstructured data), or may be a neural network that generates an output for an input, or a learning model such as a genetic algorithm or random forest. Therefore, the "xxx table" may be referred to as "xxx information." In the following description, the structure of each table is an example, and one table may be divided into two or more tables, or all or part of two or more tables may be one table.
[0019] In addition, in the following description, an ID, a name, or a number is used as an example of identification information, but the identification information may include other types of elements instead of or in addition to at least one of the ID, name, and number.
[0020] In addition, in the following description, when describing elements of the same type without distinguishing between them, common parts of the reference symbols will be used, and when describing elements of the same type with distinction between them, reference symbols will be used.
[0021] In the following description, an example of a control program is a control app, and an example of an information program is an information app. "App" is an abbreviation for application program, and is an example of a computer program.
[0022] FIG. 1 shows an example of the physical configuration of the entire system including the control system according to the embodiment.
[0023] The control system 109 is installed in a factory 10 where a controlled device 12 is located. The controlled device 12 is, for example, industrial equipment such as an industrial motor or a compressor. The factory 10 is an example of a site where the controlled device 12 is located.
[0024] The management system 101 and the control system 109 are connected to a communication network 108 (e.g., the Internet or a WAN (Wide Area Network)). The control system 109 is connected to, for example, a communication network 19 (e.g., a LAN (Local Area Network)) within the factory 10. The control system 109 can communicate with the management system 101 via the communication networks 19 and 108. The communication networks 108 and 19 are examples of communication networks used for information communication processing performed by an information application (communication processing different from the control processing performed by a control application).
[0025] The control system 109 and one or more I / O modules 119 (an example of an I / O port) are connected to a communication network 118 (for example, Ethernet (registered trademark)). The communication network 118 is an example of a communication network used to transmit control data to the control target device 12 in the control process performed by the control application.
[0026] The communication networks 19, 108, and 118 may be different networks, or two or more of the communication networks 19, 108, and 118 may be the same network.
[0027] One or more peripheral devices 120 are connected to one or more I / O modules 119. The peripheral devices 120 may be devices such as sensors or media drives (e.g., HDDs or SSDs). The I / O modules 119 function as bus slots to which the peripheral devices 120 are detachably attached as needed. The control target devices 12 are connected to the I / O modules 119 with or without the peripheral devices 120. The control target devices 12 and the I / O modules 119 may be connected in a one-to-one, one-to-multiple, multiple-to-one, or multiple-to-multiple configuration. Some of the I / O modules 119 may be connected to the communication network 108 in addition to the communication network 118; that is, some of the I / O modules 119 may be devices shared by the control application and the information application. At least one I / O module 119 may be at least a part of the network I / F device and I / O control device of at least one computing device 40.
[0028] The management system 101 is an example of a host system of the control system 109. The management system 101 includes a nonvolatile storage device 201, a CPU 202, a memory 203, a peripheral control device 205, a UI (User Interface) device 206, and a network I / F device 207. The management system 101 is connected to the communication network 108 via the network I / F device 207. The UI device 206 includes an input device (for example, a keyboard or a pointing device) and a display device.
[0029] The control system 109 includes one or more computing devices 40. Each computing device 40 includes an interface device, a storage device, and a processor connected to the ... At least the control device 40M of the arithmetic device 40 may be called a sequence control device, a motion control device, an industrial controller, or a programmable logic controller (PLC). Control content may be written in a control-specific programming language such as ladder logic (LD language), sequential function chart (SFC language), function block (FBD language), structured text (ST language), or instruction list (IL language). Furthermore, descriptions in a general-purpose programming language such as C language may be replaced in part or in whole with descriptions in a ladder language or the like.
[0030] The system configuration of the control system 109 varies depending on whether an expansion device 40E is present, the type of communication medium to which the expansion device 40E is connected, and which computing device 40 contains an information application that communicates with the control application. In other words, the system configuration depends on the presence or absence of the expansion device 40E, the type of communication medium to which the control device 40M and the expansion device 40E are connected, and the computing device 40 in which each application is located. In the example of FIG. 1 , the expansion device 40E1 is connected to the communication network 118. The expansion device 40E2 is connected to a PIO bus 28 (an example of a bus) ("PIO" stands for Programmed I / O). The PIO bus 28 may be a bus printed on a baseboard. By connecting the control device 40M and the expansion device 40E2 to the baseboard, the control application executed by the control device 40M and the information application executed by the expansion device 40E2 may communicate (share) data via the PIO bus 28.
[0031] In addition, in an embodiment in which the control application can also be placed on the expansion device 40E, or in an embodiment in which any of the computing devices 40 can be expanded or reduced and any of the computing devices 40 can be used to place the control application, the system configuration also depends on the control application.
[0032] As described above, the control system 109 includes at least one control device 40M. The control device 40M is a computing device in which at least one control application is installed. The role of the control device 40M is to periodically execute the control application to control the control target device 12 without delay.
[0033] The control application periodically performs a scan process. The "scan process" may include reading information from devices connected to an I / O (Input / Output) port, calculating the read information, and writing the calculated information. The scan process may be an example of a control process.
[0034] Taking the control device 40M as an example, the hardware configuration of the arithmetic device 40 will be described as follows. That is, the control device 40M includes a memory 169, a peripheral control device 212, an I / O control device 214, a nonvolatile storage device 215, a network I / F 213, an RM I / F 53, and a CPU 209 connected thereto. The I / O control device 214, the network I / F 213, and the RM I / F 53 are examples of interface devices. The memory 169 and the nonvolatile storage device 215 are examples of storage devices. The CPU 209 is an example of a processor. "I / F" is an abbreviation for interface device. "RM" is an abbreviation for removable media. The control device 40M has an RM socket 51 into which an RM 52 is inserted, and the RM 52 inserted into the RM socket 51 is connected to the RM I / F 53. The RM 52 may be a removable memory such as an SD card or a USB (Universal Serial Bus) memory, a dongle, or an HSM (Hardware Security Module). Specifically, in this embodiment, there are RM-L 52L, which is an RM that stores license data, and RM-N 52N, which is a normal RM that does not store license data (see FIG. 8).
[0035] The peripheral control device 212 is connected to a network I / F 213, an I / O control device 214, a nonvolatile storage device 215, and a bus 211. The bus 211 is also connected to a memory 169 and a CPU 209. The memory 169 may include an EPROM and a main memory. The EPROM (or the nonvolatile storage device 215) may store at least one of a control application and an information application in advance, or may store a program downloaded from a program source such as a program distribution server (not shown). The control system 109 may be equipped with not only one control application and one information application, but also multiple control applications and / or multiple information applications by setting the resources that the control system 109 can use for each program.
[0036] The CPU 209 reads the control application (and information application) stored in, for example, an EPROM into the main memory and executes it to control the operation of the control application (and information application). For example, the CPU 209 executes the control application to control multiple peripheral devices 120 via the peripheral control device 212, the I / O control device 214, and multiple I / O modules 119. The peripheral devices 120 may be associated with the I / O modules 119 on a one-to-one basis. The CPU 209 may be either a single-core or multi-core. One core may execute at least one of one or more control applications and one or more information applications. Typically, one core may execute one control application, one control application and one or more information applications, or one or more information applications.
[0037] Information processing terminals such as a development environment terminal 71 and a simulation terminal 72 are connected to a control system 109 (e.g., a control device 40M) via a communication network 19 (or without via the communication network 19). Both the terminals 71 and 72 are, for example, computers (e.g., desktop, laptop, or tablet personal computers, or smartphones) having input devices, display devices, interface devices, storage devices, and processors connected thereto. The development environment terminal 71 is an information processing terminal used to develop a program to be executed on the control device 40M (or the extension device 40E). The simulation terminal 72 is an information processing terminal that simulates the execution of a program on the control device 40M (or the extension device 40E). The development environment terminal 71 may also function as the simulation terminal 72. An RM 52 may be connected to at least one of the terminals 71 and 72.
[0038] FIG. 2 shows an example of the logical configuration of the control device 40M.
[0039] The control device 40M has a program execution unit 251, a Web server 252, a mode setting unit 253, an RM linkage unit 254, and a license confirmation unit 255. At least some of these functions 251 to 255 may be realized by the CPU 209 executing a control application or an information application, or may be realized by the CPU 209 executing a program different from the control application or the information application.
[0040] The program execution unit 251 executes the protection target program 260. The protection target program 260 may be an application program such as a control application or an information application, or alternatively or in addition to the protection target program 260, may be a library, such as an FB (function block), as an example of a program module called from an application program (e.g., a control application).
[0041] The web server 252 communicates with a browser 251 in the management system 101. Information provided by the web server 252 is displayed on the UI device 206 by the browser 251. Instead of the UI device 206, the information may be displayed on a remote information processing terminal connected to the management system 101.
[0042] Mode setting unit 253 displays a mode setting screen, which is an example of a UI (User Interface), on browser 251 via web server 252, accepts a mode selection from the user via the mode setting screen, and sets the selected mode.
[0043] The RM cooperation unit 254 communicates with the connected RM 52. For example, the RM 52 has a memory 275 (for example, a flash memory) and an internal controller 271 (for example, a memory controller) connected to the memory 275, and the RM cooperation unit 254 communicates with the internal controller 271.
[0044] The license confirmation unit 255 confirms whether the license data 272 of the protection target program 260 is stored in the connected RM 52. If the RM 52 is an RM-L52LX in which the license data 272 is stored in the memory 275, the license data 272 is acquired from the RM-L52LX, and it is confirmed that the license data 272 of the protection target program 260 is stored.
[0045] FIG. 3 shows an example of a mode setting screen 300.
[0046] One mode can be selected from a plurality of modes. The plurality of modes include, for example, a normal mode and a log collection mode. As described above, the mode setting screen 300 is provided by the mode setting unit 253 via the Web server 252 and displayed by the browser 251.
[0047] The mode setting screen 300 has, as GUI components, for example, radio buttons 301 and a setting button 302. A radio button 301 is provided for each mode as an option. When either the normal mode radio button 301A or the log collection mode radio button 301B is selected and the setting button 302 is pressed, the mode corresponding to the selected radio button 301 is set by the mode setting unit 253 in, for example, the memory 169.
[0048] Here, "normal mode" refers to a mode in which license data is checked. "Log collection mode" refers to a mode in which license data checking is stopped and log collection is performed. The log collection mode may be an example of a mode in which license checking is stopped.
[0049] 4 shows an example of the flow of license protection control. The license protection control may be performed when a mode is set via the mode setting screen 300, or may be performed periodically. Furthermore, the license protection control may be performed when the license check stop time has elapsed in the case where S403 (license check stop) described below is performed.
[0050] The license confirmation unit 255 confirms the mode set by the mode setting unit 253 (S401).
[0051] If the confirmed mode is the normal mode (S401: normal mode), the license confirmation unit 255 continues the license check (S402). Specifically, as shown in FIG. 5, the license confirmation unit 255 periodically performs a license check via the RM cooperation unit 254 to check whether the RM 52 contains license data 272 representing the license of the protected program 260 (S501). S501 may be performed periodically in S402. The period of the license protection control shown in FIG. 4 and the period of the license check in S501 may be the same or different. The period of the scan process is relatively short, making it unnecessary to perform a license check each time a scan process is performed, so the period of the license protection control and the period of the license check may be longer than the period of the scan process. On the other hand, in order to increase the strictness of prevention of unauthorized use, the period of the license protection control and the period of the license check may be the same as or shorter than the period of the scan process.
[0052] If such license data 272 exists (S501: YES), that is, if the RM 52 is an RM-L52LX and such license data 272 has been read from the RM-L52LX, the license confirmation unit 255 permits execution of the protected program 260 (S502). When S502 is performed, the protected program 260 can be executed in the scan process.
[0053] On the other hand, if such license data 272 does not exist (S501: NO), for example, if such license data 272 has not been read or if the read data is not license data 272 representing the license of the protection target program 260, the license confirmation unit 255 prohibits execution of the protection target program 260 (S503). When S503 is performed, execution of the protection target program 260 is not permitted in the scan process, and the license confirmation unit 255 may output a warning of unauthorized use, for example, to the management system 101 via the Web server 252.
[0054] If the confirmed mode is the log collection mode (S401: log collection mode), the license confirmation unit 255 stops the license check (S402). The license check may be stopped for a fixed period of time, or for a period of time set through the mode setting screen 300 (or by another method). This "period" may be defined by a start time and an end time, or may be defined by a length of time. If a length of time is set as the period of time, the license check may be stopped for this length of time after the log collection mode is set.
[0055] In the log collection mode, the program execution control shown in Fig. 6 is performed. That is, the license confirmation unit 255 determines, via the RM linkage unit 254, whether the RM 52 is an RM-L52LX, that is, whether the license data 272 is in the RM 52 (S601).
[0056] If the RM 52 is an RM-L52LX (S601: YES), the license confirmation unit 255 prohibits log collection (S602). When S602 is performed, it is not possible to write a log related to the protected program 260 to the RM 52 via the RM cooperation unit 254.
[0057] If the RM 52 is not an RM-L52LX (S601: NO), the license confirmation unit 255 permits log collection (S603). When S603 is performed, it is possible to write a log related to the protected program 260 to the RM 52 via the RM linkage unit 254. In this case, it means that an RM-N52NX is inserted into the RM socket 51 instead of an RM-L52LX, and the license confirmation unit 255 writes a log related to the protected program 260 to the RM-N52NX via the RM linkage unit 254 during the license check stop time.
[0058] Although one embodiment has been described above, this is merely an example for explaining the present invention, and the scope of the present invention is not limited to this embodiment. The present invention can be implemented in various other forms.
[0059] The above description can be summarized, for example, as follows: The following summary may include supplementary and modified explanations of the above description.
[0060] A control device 40M that periodically performs control processing of the control target device 12 and is provided with an RM 52 socket 51 and an RM I / F 53 is provided with a mode setting unit 253, a license confirmation unit 255, and a program execution unit 251. The unauthorized use prevention system may include at least the mode setting unit 253, the license confirmation unit 255, and the program execution unit 251.
[0061] The mode setting unit 253 accepts the mode designation and sets the designated mode. The license confirmation unit 255 periodically performs a license check to determine whether an RM-L52LX storing license data 272 representing the license of the protected program 260 is inserted into the socket 51 and connected to the RM I / F 53. If the result of the license check is not false, the program execution unit 251 executes the protected program 260 in the control process. If the set mode is a stop mode, which means that the license check is stopped, the license confirmation unit 255 stops performing the license check.
[0062] While the license check is stopped, even if the RM-L52LX is removed from the socket 51 and an RM-N52NX, which is intended for purposes other than license checking, is inserted into the socket 51 and connected to the RM I / F 53, the program execution unit 251 executes the protected program 260 in the control process because there is no false result (negative result) as a result of the license check. As a result, even if the RM-L52LX containing the license data 272 is not inserted into the socket 51 during the period in which control is being performed, control can continue.
[0063] The protected program 260 may be a control application, an information application, or, instead of or in addition to the control application and / or the information application, one or more FBs (function blocks) of the control application and / or the information application. The license data 272 may exist for each FB, or may be data representing the license for each of one or more LBs. An FB is an example of a library, and a library may be an example of a program module.
[0064] When the set mode is the stop mode, the license confirmation unit 255 may determine whether the RM 52 connected to the RM I / F 53 is an RM-L52LX in which the license data 272 is stored (for example, the determination in S601). When the result of this determination is false, the license confirmation unit 255 may write data to an RM-N52NX connected to the RM I / F 53. As a result, the storage area in the RM-L52LX in which the license data 272 is stored may be a logical storage area based on a physical storage area that is a memory (for example, a flash memory) with an upper limit on the number of times it can be written or erased. In other words, if an area of such a logical storage area other than the area in which the license data is stored were a freely available user area, depending on the frequency of writing data to or erasing data from the user area, the upper limit on the number of times the physical storage area can be written or erased might be reached, making the physical storage area unusable and, as a result, making the RM-L52LX unusable. However, because the data is written to the RM-N52NX, the possibility of the RM-L52LX becoming unusable can be reduced.
[0065] When the set mode is the stop mode (e.g., the log collection mode), in debugging a periodic control process, the license confirmation unit 255 may write a log related to the control process at each cycle to the RM 52 connected to the RM I / F 53. In debugging a control process, the cycle of the control process is fixed, and therefore the frequency of writing logs is also fixed. The cycle of the control process is generally relatively short, and therefore the frequency of log output is relatively high. Furthermore, a large amount of information is output as a log (contained in the log) at each cycle. One possible method is to accumulate logs in a temporary area such as a buffer in the memory 169 and output them to external storage such as network storage via the communication network 19, but in this case, the accumulation speed in the temporary area is likely to be faster than the output speed to the external storage. Furthermore, if log accumulation in a temporary area is unnecessary, the process can be simplified compared to when log accumulation in a temporary area is necessary. Therefore, as described above, during debugging, logs are written to the RM 52 at each cycle of the control process.
[0066] Furthermore, during debugging, the control device 40M and a development environment terminal 71 (an example of a first information processing terminal) for the protected program 260 may be communicably connected. The development environment terminal 71 may determine whether or not license data representing the license of the protected program 260 is present. If the result of this determination is true, the development environment terminal 71 may transmit an execution instruction for a test target of the protected program 260 to the control device 40M. When the control device 40M receives this execution instruction from the development environment terminal 71, the program execution unit 251 may execute the protected program 260 without a license check by the license confirmation unit 255, and a log related to the protected program 260 may be written to the RM 52 (preferably an RM-N52NX) connected to the RM I / F 53 of the license confirmation unit 255.
[0067] An example of the flow of program execution control during debugging will be described with reference to Fig. 8. In the description with reference to Fig. 8, the license for the protected program 260 is subdivided, specifically into a build or download license and an execution license. A debug control unit is realized by executing the program on the development environment terminal 71, and the debug control unit may perform the processing of the development environment terminal 71 among the processing exemplified in Fig. 8.
[0068] The control device 40M and the development environment terminal 71 are connected to each other so that they can communicate with each other, and each enters a debug execution state (S801). The development environment terminal 71 stores the source code of the protection target program 260, and the entity of the protection target program 260 resides in the control device 40M.
[0069] The development environment terminal 71 starts debugging (S802). The development environment terminal 71 determines whether or not there is license data representing a license for building or downloading the protected program 260 (S803). Specifically, for example, the development environment terminal 71 determines whether or not an RM-L52LY (see FIG. 1) storing license data representing a license for building or downloading the protected program 260 is inserted into the RM socket of the development environment terminal 71 and connected to the RM-I / F of the development environment terminal 71.
[0070] If such an RM-L52LY is not connected to the development environment terminal 71, or if the license represented by the license data is not a license for building or downloading the protected program 260, the result of S803 is false. In this case (S803: NO), the development environment terminal 71 stops debugging (S804).
[0071] If the result of S803 is true (S803: YES), and if there are still test targets in the source code of the protected program 260 (S804: YES), the development environment terminal 71 continues debugging. That is, the development environment terminal 71 instructs the control device 40M to execute the test target (S805X), and the program execution unit 251 in the control device 40M executes the instructed test target of the protected program 260 (S805Y). Because the build or download license for the protected program 260 has already been checked (S803), S805Y is performed without a license check by the license confirmation unit 255 (i.e., without checking whether or not there is an execution license for the protected program 260). Furthermore, when the program is executed during debugging, a log related to the execution results is output, and the license confirmation unit 255 writes the output log to the RM-N52NX. That is, during debugging, it is not necessary for the RM-L52LX to be inserted into the socket 51; therefore, the RM-N52NX, which is the destination for writing logs during debugging, may be inserted into the socket 51 throughout the debugging process.
[0072] If there is no test target in the source code of the protected program 260 (S804: NO), the debugging ends. That is, the control device 40M and the development environment terminal 71 each release the debugging execution state (S806).
[0073] Note that the ability to execute the protected program 260 without a license check on the control device 40M does not need to be limited to debugging. The development environment terminal 71 may determine whether license data representing the license of the protected program 260 is present. If the result of this determination is true, the development environment terminal 71 may transmit permission information, which is information indicating that the license is present, to the control device 40M. If the mode set in the control device 40M is normal mode (an example of a license mode that indicates a license check), the license confirmation unit 255 may allow the program execution unit 251 to execute the protected program 260 without a license check by the license confirmation unit 255, provided that the control device 40M has received the permission information from the development environment terminal 71. A specific example of this will be described with reference to FIG. 9. A build / download control unit is realized by executing a program on the development environment terminal 71, and the build / download control unit may perform the processing of the development environment terminal 71 among the processing illustrated in FIG. 9. Furthermore, in FIG. 9 (and FIGS. 8 and 1), the development environment terminal 71 and the management system 101 may be integrated.
[0074] The control device 40M and the development environment terminal 71 are connected so as to be able to communicate with each other. The development environment terminal 71 may determine whether a predetermined condition is met (S901). The "predetermined condition" referred to in this paragraph may be that the number of control devices 40M on which the protected program 260 is built / downloaded (built or downloaded) is equal to or greater than a predetermined number. That is, in a case where the protected program 260 is executed on each of multiple control devices 40M, the development environment terminal 71 may perform the license check instead of all control devices 40M performing the license check. This eliminates the need for an RM-L52LX for each development environment terminal 71.
[0075] If the result of the determination in S901 is true (S901: YES), or if the determination in S901 is not made, the development environment terminal 71 determines whether or not license data indicating a license for the protected program 260 is present (S902). If the result of the determination in S902 is true (S902: YES), the development environment terminal 71 outputs permission information indicating that a license is present (S903). The development environment terminal 71 builds or downloads the protected program 260 to the control device 40M (S904). If permission information is present, the permission information is also transmitted from the development environment terminal 71 to the control device 40M in S904.
[0076] The control device 40M receives the protection target program 260 (and the permission information) (S911), and installs the protection target program 260 (S912).
[0077] The license confirmation unit 255 confirms the mode set by the mode setting unit 253 (S913). If the confirmed mode is the log collection mode (S913: log collection mode), the license confirmation unit 255 stops the license check (S915).
[0078] If the confirmed mode is the normal mode (S401: normal mode), the license confirmation unit 255 determines whether or not permission information has been received (S914).
[0079] If the determination result in S914 is true (S914: YES), the license confirmation unit 255 permits execution of the protected program 260 (S916). When S916 is performed, the protected program 260 can be executed.
[0080] If the determination result in S914 is false (S914: NO), the license confirmation unit 255 prohibits the execution of the protected program 260 (S917).
[0081] The control device 40M and the simulation terminal 72 (an example of a second information processing terminal as a simulation execution environment) may be communicatively connected. If the result of the license check is true, the simulation terminal 72 may perform a simulation of the protected program 260 without determining whether or not license data representing the license of the protected program 260 is present. In this way, if the result of the license check by the control device 40M is true, an RM-L52LZ (see FIG. 1) may be connected to the simulation terminal 72, eliminating the need for the simulation terminal 72 to perform a license check. This makes it possible to execute a simulation while maintaining prevention of unauthorized use. A specific example of this will be described with reference to FIG. 7. A simulation control unit may be implemented by executing a program on the simulation terminal 72, and the simulation control unit may perform the processing illustrated in FIG. 7.
[0082] The simulation terminal 72 determines whether the result of the license check of the protected program 260 in the control device 40M is true and whether a true result (that is, licensed) has been received from the license confirmation unit 255 of the control device 40M (S701).
[0083] If the determination result of S701 is false (S701: NO), the simulation terminal 72 determines (S702) whether or not there is license data representing the license of the protection target program 260. Specifically, for example, the simulation terminal 72 determines whether or not an RM-L52LZ (see FIG. 1) storing license data representing the license of the protection target program 260 is inserted into the RM socket of the simulation terminal 72 and connected to the RM-I / F of the simulation terminal 72.
[0084] If the determination result of S702 is true (S702: YES), the simulation terminal 72 executes (S703) a simulation of the protected program 260. Note that if the determination result of S701 is true (S701: YES), S703 is performed without S702.
[0085] If the determination result in S702 is false (S702: NO), the simulation terminal 72 does not execute the simulation of the protected program 260.
[0086] The control device 40M may have a retention mechanism (e.g., a latch mechanism). The retention mechanism may be a mechanism that locks the RM 52 inserted into the socket 51 and connected to the RM I / F 53, and releases the lock when a predetermined unlocking operation is performed. Examples of the RM 52 that can be locked by the retention mechanism include an SD card and an HSM. At a site (e.g., a factory 10) where the control device 40M is installed, vibrations from the controlled device 12 can have an effect, and without a retention mechanism, the RM 52 may fall out of the control device 40M. Furthermore, it is not easy to increase the number of sockets with a retention mechanism using a device such as a hub. Therefore, depending on the environment of the site where the control device 40M is installed, it is highly technically significant to be able to use the limited number of sockets 51 for multiple purposes without occupying them. [Explanation of symbols]
[0087] 109...Control System
Claims
1. The control device periodically controls a controlled device and includes a mode setting unit, a license confirmation unit, and a program execution unit, the mode setting unit being provided in the control device and having an RM (removable media) insertion port and an RM I / F (removable media interface device), the mode setting unit accepts a mode designation and sets the designated mode; the license confirmation unit periodically performs a license check to determine whether an RM storing license data representing a license for a protected program is inserted into the socket and connected to the RM I / F; If the result of the license check is not false, the program execution unit executes the protected program in the control process; the license confirmation unit stops performing the license check when the set mode is a stop mode which means stopping the license check. Fraud prevention system.
2. When the set mode is the stop mode, the license confirmation unit: determining whether the RM connected to the RM I / F is an RM in which license data is stored; If the result of the determination is false, write the data to the RM connected to the RM I / F. The fraud prevention system according to claim 1 .
3. When the set mode is the stop mode, in debugging related to periodic control processing, the license confirmation unit writes a log related to the control processing in each cycle of the control processing to the RM connected to the RM I / F. The fraud prevention system according to claim 1 .
4. In the debugging, the control device and a first information processing terminal serving as a development environment for the protected program are communicably connected; the first information processing terminal determines whether or not there is license data representing a license for the protected program; If the result of the determination is true, the first information processing terminal transmits an execution instruction for the test target of the protection target program to the control device; When the control device receives the execution instruction from the first information processing terminal, the program execution unit executes the protected program without the license check by the license confirmation unit, and the license confirmation unit writes a log related to the protected program to an RM connected to the RM I / F. The fraud prevention system according to claim 3.
5. a plurality of control devices including the control device and a first information processing terminal are communicably connected; the first information processing terminal determines whether or not there is license data representing a license for the protected program; If the result of the determination is true, the first information processing terminal transmits permission information, which is information indicating that a license is present, to the control device; When the set mode is a license mode which means the license check, if the control device receives the permission information from the first information processing terminal, the license confirmation unit causes the program execution unit to execute the protected program without the license check by the license confirmation unit. The fraud prevention system according to claim 1 .
6. the control device and a second information processing terminal as a simulation execution environment are communicably connected; If the result of the license check is true, the second information processing terminal performs a simulation of the protected program without determining whether or not license data representing a license for the protected program is present. The fraud prevention system according to claim 1 .
7. The control device has a retention mechanism; the holding mechanism is a mechanism that locks the RM inserted into the socket and connected to the RM I / F, and releases the lock when a predetermined unlocking operation is performed. The fraud prevention system according to claim 1 .
8. The control device periodically controls the controlled device and is equipped with an RM (removable media) slot and an RM I / F (removable media interface device). Accepts the mode specification, sets the specified mode, periodically performing a license check to determine whether an RM storing license data representing a license for a protected program is inserted into the socket and connected to the RM I / F; If the result of the license check is not false, the control process executes the protected program; If the set mode is a stop mode which means that the license check is stopped, the license check is stopped. How to prevent unauthorized use.
Citation Information
Patent Citations
Method and system providing portable application and data
JP2006073002A