Information processing device, information processing system, and information processing device

By acquiring and verifying the completeness of whitelists using hash values, the device ensures reliable program execution even with low fault tolerance storage, addressing corruption risks and ensuring safe operation.

JP2025185385APending Publication Date: 2025-12-22TOSHIBA TEC KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024093581
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-10
Publication Date
2025-12-22

AI Technical Summary

Technical Problem

Information processing devices using inexpensive storage devices with low fault tolerance, such as HDDs and flash memories, face corruption risks when powered off, leading to unreliable execution of programs due to corrupted whitelists, and downloaded whitelists may not guarantee completeness.

Method used

An information processing device acquires a whitelist from an external storage, verifies its completeness, and stores it for execution determination, ensuring integrity by comparing hash values, even when using low fault tolerance storage.

Benefits of technology

Ensures safe and reliable operation of whitelists, preventing functional shutdowns and ensuring the integrity of program execution even with low fault tolerance storage devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025185385000001_ABST
    Figure 2025185385000001_ABST
Patent Text Reader

Abstract

To safely operate a white list even when using a low price auxiliary storage device having lower failure resistance.SOLUTION: An information processing device according to the embodiment includes: an auxiliary storage device being an inner storage for storing one or more programs; a processor for executing the programs; and an interface with an external storage which stores a white list being a list of discrimination information for discriminating propriety of execution of each of the plurality of programs by the processor. The processor acquires the white list from the external storage via the interface, and verifies integrity of the acquired whitelist. When the acquired whitelist is perfect, the processor stores the acquired white list in the internal storage, as a white list to be used as propriety discrimination for usage of the program when executing one of the programs stored in the inner storage.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] An embodiment of the present invention relates to an information processing device, an information processing system, and an information processing program. [Background technology]

[0002] When an information processing device attempts to execute a program running within the information processing device, the device determines whether the program can be executed using a whitelist. The whitelist is a list of pairs of file path information and hash values ​​calculated from the program files for each program installed in the information processing device.

[0003] An information processing device that controls execution using such a whitelist stores the whitelist in an auxiliary storage device as internal storage. The auxiliary storage device generally uses inexpensive storage devices with low fault tolerance (such as HDDs (Hard Disk Drives) and flash memories known as SD memory cards). In auxiliary storage devices that use such inexpensive storage devices with low fault tolerance, the stored contents may be corrupted if the information processing device is powered off, for example. If the whitelist is corrupted, it becomes impossible to determine whether a program can be executed.

[0004] Patent Document 1 discloses updating a whitelist by downloading it from a server. Therefore, if a whitelist is corrupted in an information processing device, it is conceivable that the whitelist will be downloaded from the server and used. However, even if a whitelist is downloaded, there is no guarantee that the downloaded whitelist itself is complete. Therefore, there remains a risk in using the downloaded whitelist in place of a corrupted whitelist. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-238168 Summary of the Invention [Problem to be solved by the invention]

[0006] The problem that embodiments of the present invention aim to solve is to provide an information processing device, an information processing system, and an information processing program that enable safe operation of a whitelist even when using an inexpensive auxiliary storage device with low fault tolerance. [Means for solving the problem]

[0007] In one embodiment, an information processing device includes an internal storage that stores one or more programs, a processor that executes the programs, and an interface with an external storage that stores a whitelist, which is a list of determination information for determining whether or not the processor can execute each of the one or more programs. The processor acquires the whitelist from the external storage via the interface, verifies the completeness of the acquired whitelist, and, if the acquired whitelist is complete, stores the acquired whitelist in the internal storage as a whitelist to be used for determining whether or not to execute any of the one or more programs stored in the internal storage when the program is executed. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of an information processing system according to the first embodiment. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of an image forming apparatus as an information processing apparatus according to the first embodiment. [Figure 3] FIG. 3 is a schematic diagram showing an example of registered contents of a whitelist file stored in a whitelist file storage unit of an image forming apparatus. [Figure 4]FIG. 4 is a schematic diagram showing an example of the execution permission determination result based on the whitelist when a program is executed in the image forming apparatus. [Figure 5] FIG. 5 is a block diagram showing an example of the configuration of the whitelist server in FIG. [Figure 6] FIG. 6 is a schematic diagram illustrating an example of the contents stored in the model-specific hash value storage unit of the whitelist server. [Figure 7] FIG. 7 is a sequence diagram for explaining the startup operation of each image forming apparatus in the information processing system. [Figure 8] FIG. 8 is a flowchart showing an example of a startup process executed by a processor of the image forming apparatus. [Figure 9] FIG. 9 is a block diagram showing an example of the configuration of an image forming apparatus as an information processing apparatus according to the second embodiment. [Figure 10] FIG. 10 is a sequence diagram for explaining the startup operation of each image forming apparatus in the information processing system according to the second embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of a startup process executed by a processor of the image forming apparatus according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] [First embodiment] FIG. 1 is a block diagram showing an example of the configuration of an information processing system according to a first embodiment. The information processing system includes multiple image forming apparatuses 10, one whitelist server 20, and multiple user terminals 30, all connected via a network NW such as an in-house local area network (LAN). The image forming apparatuses 10 and the user terminals 30 are located in a workplace. The whitelist server 20 is located in an environment with a higher security level than the image forming apparatus 10. The image forming apparatus 10 is an information processing apparatus according to the first embodiment, and may be, for example, a multi-function peripheral (hereinafter abbreviated as MFP) equipped with at least a scanning function and a printing function. The user terminal 30 is a personal computer or the like, which can send a print job to the image forming apparatus 10 to form an image, or receive and display document data scanned by the image forming apparatus 10.

[0010] The image forming apparatuses 10 may include apparatuses of different models. In the example of FIG. 1, the information processing system includes three models of image forming apparatuses 10: model A image forming apparatus 10A, model B image forming apparatus 10B, and model C image forming apparatus 10C, and shows a case where two model A image forming apparatuses 10A are present. Of course, this is just an example, and the number of models, the number of each model, and the total number of image forming apparatuses 10 are not limited to this. Similarly, although FIG. 1 shows only two user terminals 30, the number is not limited to this.

[0011] Fig. 2 is a block diagram showing an example of the configuration of each image forming apparatus 10. As shown in Fig. 2, the image forming apparatus 10 includes a processor 101, a main memory 102, an auxiliary storage device 103, a communication interface 104, an external storage medium interface 105, an operation panel 106, a scanner 107, an input image processing unit 108, a page memory 109, an output image processing unit 110, and a printer 111. These units are connected to each other via a data bus or the like. Note that the image forming apparatus 10 may include other components as needed in addition to the components shown in Fig. 2, or certain components may be excluded from the components shown in Fig. 2.

[0012] The processor 101 is, for example, a CPU (central processing unit), but is not limited to this. The processor 101 may be a multi-core / multi-thread processor and can execute multiple processes in parallel. The processor 101 may also be an MPU (micro processing unit). The processor 101 has a function of controlling the overall operation of the image forming apparatus 10. The processor 101 may also be equipped with an internal memory and various interfaces. The processor 101 performs various processes by executing programs stored in advance in the internal memory or the auxiliary storage device 103, etc.

[0013] Some of the various functions realized by the processor 101 executing a program may be realized by various types of hardware circuits, including integrated circuits such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), an SoC (System on a Chip), and a PLD (Programmable Logic Device). In this case, the processor 101 controls the functions executed by the hardware circuits.

[0014] The main memory 102 is a volatile memory. The main memory 102 is a working memory or a buffer memory. The main memory 102 can store various application programs based on instructions from the processor 101. The main memory 102 can also have a temporary storage unit 1021 that stores data necessary for executing control programs and application programs stored in the auxiliary storage device 103, as well as the execution results of these programs.

[0015] The auxiliary storage device 103 is a non-volatile internal storage device to which data can be written and rewritten. The auxiliary storage device 103 may be, for example, an inexpensive storage device with low fault tolerance, such as an HDD, a solid-state drive (SSD), or a flash memory. The auxiliary storage device 103 stores control programs, application programs, and various data according to the operational use of the image forming apparatus 10. For example, the auxiliary storage device 103 includes a program storage unit 1031 that stores programs and a whitelist file storage unit 1032 that stores a whitelist file. The whitelist file will be described later. The auxiliary storage device 103 can also store print jobs transmitted from the user terminal 30. The print job includes print target data, such as character data and image data, which are the source of an image to be formed on paper. The print target data may be data for forming an image on one sheet of paper, or data for forming images on multiple sheets of paper. Furthermore, the print job can include, as control data, information indicating whether printing is color or monochrome, the number of copies to be printed (number of page sets), the number of sheets to be printed per copy (number of pages), and so on.

[0016] The communication interface 104 is an interface for communicating with the whitelist server 20 and the user terminal 30, which are external devices on the network NW. The communication interface 104 is configured as, for example, a LAN connector. The communication interface 104 may also be configured to perform wireless communication with other devices in accordance with standards such as Bluetooth (registered trademark) or Wi-fi (registered trademark).

[0017] The external storage medium interface 105 is a reader / writer for a removable computer-readable storage medium such as a USB (Universal Serial Bus) memory.

[0018] Various instructions are input to the operation panel 106 by the operator of the image forming apparatus 10. The operation panel 106 transmits signals indicating the instructions input by the operator to the processor 101. The operation panel 106 includes, as an operation unit, for example, a keyboard, a numeric keypad, and a touch panel. The operation panel 106 also displays various information to the operator of the image forming apparatus 10. That is, the operation panel 106 displays a screen showing various information based on a signal from the processor 101. The operation panel 106 includes, as a display unit, a monitor such as a liquid crystal display.

[0019] The scanner 107 optically scans an original document and reads the image of the original document as image data. The scanner 107 reads the original document as a color image. The scanner 107 is composed of a sensor array formed in the main scanning direction. The scanner 107 moves the sensor array in the sub-scanning direction to read the entire original document.

[0020] The input image processing unit 108 processes image data read by the scanner 107. The input image processing unit 108 may also process image data read from a removable computer-readable storage medium via the external storage medium interface 105. Furthermore, the input image processing unit 108 converts print target data, such as character data and image data, included in a print job stored in the auxiliary storage device 103 into image data representing the image to be formed.

[0021] The page memory 109 stores the image data processed by the input image processing unit 108 .

[0022] An output image processor 110 processes the image data stored in the page memory 109 so that a printer 111 can print the image data on paper.

[0023] The printer 111 prints the image data processed by the output image processing unit 110 onto paper under the control of the processor 101. The printer 111 prints the image data onto paper using, for example, an electrophotographic method.

[0024] FIG. 3 is a schematic diagram showing an example of the registered contents of a whitelist file stored in the whitelist file storage unit 1032. The whitelist file may be realized, for example, as a CSV-format text file, with information about a program stored in the program storage unit 1031 as one record. Each record includes file path information in the program storage unit 1031, which is the storage destination of the program file for the corresponding program, and a hash value calculated from the program file. The hash value data may be a value calculated using a general hash function such as MD5, with the program file as input. The example in FIG. 3 shows a case where three programs (program A, program B, and program C) are stored in the program storage unit 1031.

[0025] As will be described later, the whitelist file stored in the whitelist file storage unit 1032 is downloaded from the whitelist server 20 when the image forming apparatus is powered on and started up.

[0026] 4 is a schematic diagram showing an example of the result of a determination as to whether or not a program can be executed based on a whitelist when the processor 11 executes the program. When the processor 11 attempts to execute a program of a program file stored in the program storage unit 1031, the processor 11 determines whether or not the program can be executed based on the registered contents of the whitelist file stored in the whitelist file storage unit 1032. Specifically, the processor 11 calculates a hash value from the program file of the program to be started, and checks whether or not the calculated hash value matches the hash value corresponding to the program file stored in the whitelist file storage unit 1032. If the two match, the program is permitted to be executed; if they do not match, the program is denied to be executed.

[0027] Fig. 5 is a block diagram showing an example of the configuration of the whitelist server 20. As shown in Fig. 5, the whitelist server 20 includes a processor 201, a main memory 202, an auxiliary storage device 203, a communication interface 204, etc. These components are connected to each other via a data bus or the like.

[0028] In addition, the whitelist server 20 may be provided with configurations other than those shown in FIG. 5 as needed, or specific configurations may be excluded from the configuration shown in FIG. 5.

[0029] The processor 201 is, for example, a CPU, but is not limited to this. The processor 201 may be multi-core / multi-threaded and can execute multiple processes in parallel. The processor 201 may also be an MPU. The processor 201 has a function of controlling the overall operation of the whitelist server 20. The processor 201 may be equipped with an internal memory and various interfaces. The processor 201 performs various processes by executing programs stored in advance in the internal memory or the auxiliary storage device 203. Note that some of the various functions realized by the processor 201 executing the programs may be realized by various types of hardware circuits, including integrated circuits such as ASICs, DSPs, FPGAs, GPUs, SoCs, and PLDs. In this case, the processor 201 controls the functions executed by the hardware circuits.

[0030] The main memory 202 is a volatile memory. The main memory 202 is a working memory. The main memory 202 can store various application programs based on instructions from the processor 201. The main memory 202 can also store data necessary for executing control programs and application programs stored in the auxiliary storage device 203, as well as the execution results of these programs.

[0031] The auxiliary storage device 203 is a non-volatile internal storage device that can write and rewrite data. The auxiliary storage device 203 uses expensive storage devices with excellent fault tolerance. For example, the auxiliary storage device 203 can be made highly fault-tolerant by adopting high-quality storage devices for servers or by using multiple inexpensive storage devices with low fault tolerance in a RAID configuration. The auxiliary storage device 203 stores control programs, application programs, various data, etc. depending on the operational use of the whitelist server 20. For example, the auxiliary storage device 203 includes a program storage unit (not shown) that stores programs, as well as a model-specific whitelist storage unit 2031 and a model-specific hash value storage unit 2032.

[0032] The model-specific whitelist storage unit 2031 stores different whitelist files for each model, such as a whitelist file for model A image forming device 10A, a whitelist file for model B image forming device 10B, and a whitelist file for model C image forming device 10C. In other words, the same whitelist file is used for devices of the same model. That is, for devices of the same model, the file path of the program storage unit 1031, which is the storage destination for program files, is the same. The registered contents of the whitelist files for each model are the same as those described with reference to FIG. 3.

[0033] The model-specific hash value storage unit 2032 stores hash values ​​for each model. Fig. 6 is a schematic diagram showing an example of the storage contents of this model-specific hash value storage unit 2032. As shown in Fig. 6, the model-specific hash value storage unit 2032 stores whitelist file hash values, which are hash values ​​of whitelist files for each model stored in the model-specific whitelist storage unit 2031, as hash values ​​for each model. The data of these whitelist file hash values ​​may be values ​​calculated using a general hash function such as MD5, with the model-specific whitelist file as input.

[0034] The contents stored in the model-specific whitelist storage unit 2031 and the model-specific hash value storage unit 2032 can be updated by an administrator of the information processing system. For example, when installing a program in one of the image forming devices 10, i.e., when storing a new program file in the program storage unit 1031 of the image forming device 10, the administrator creates the corresponding model-specific whitelist file and model-specific hash value and stores them in the model-specific whitelist storage unit 2031 and the model-specific hash value storage unit 2032 of the whitelist server 20. However, if the same program is already installed in an image forming device 10 of the same model, this process is unnecessary. Furthermore, this process is required not only when installing a new program but also when updating an already installed program. This is because updating the contents of the program file requires updating the hash value even if the file path remains unchanged.

[0035] The communication interface 204 is an interface for communicating with each image forming apparatus 10, which is an external device on the network NW. The communication interface 204 is configured as, for example, a LAN connector. The communication interface 204 may also be configured to perform wireless communication with other devices in accordance with standards such as Bluetooth or Wi-Fi.

[0036] The start-up operation of each image forming apparatus 10 in the information processing system having such a configuration will be described below.

[0037] 7 is a sequence diagram for explaining the startup operation of each image forming apparatus 10 in the information processing system. When the image forming apparatus 10 is started by turning on the power, it first makes a download request to the whitelist server 20 via the network NW (step S10).

[0038] In response to this download request, the whitelist server 20 identifies the requested data to be downloaded to the requesting image forming device 10 (step S11). Specifically, the whitelist server 20 identifies the whitelist file stored in the model-specific whitelist storage unit 2031 and the whitelist file hash value stored in the model-specific hash value storage unit 2032 based on the model of the requesting image forming device 10. Then, the whitelist server 20 transmits the identified whitelist file together with the identified whitelist file hash value to the requesting image forming device 10 (step S12).

[0039] The requesting image forming device 10 downloads the whitelist file and the whitelist file hash value transmitted from the whitelist server 20 (step S13). Then, the image forming device 10 verifies the integrity of the downloaded whitelist file (step S14). Specifically, the image forming device 10 calculates a hash value from the downloaded whitelist file and compares it with the downloaded whitelist file hash value to verify the integrity of the downloaded whitelist file.

[0040] If the hash value calculated from the downloaded whitelist file does not match the downloaded whitelist file hash value (step S15: NO), that is, if the downloaded whitelist file is not complete, the image forming device 10 repeats from step S10.

[0041] If the hash value calculated from the downloaded whitelist file matches the downloaded whitelist file hash value (step S15: YES), that is, if the downloaded whitelist file is complete, the image forming device 10 stores the downloaded whitelist file in the whitelist file memory unit 1032 (step S16).

[0042] Then, the image forming device 10 uses the whitelist file stored in the whitelist file memory unit 1032 to determine whether to allow execution of each of the programs to be executed that are stored in the program memory unit 1031 (step S17).

[0043] The operation of the image forming apparatus 10 for realizing such an operation will be described below. FIG. 8 is a flowchart showing an example of a startup processing operation executed by the processor 101 of the image forming apparatus 10. The processor 101 can perform this startup processing operation by executing an information processing program according to the first embodiment, which is a control program stored in the auxiliary storage device 103. Unless otherwise specified, the processing operation of the processor 101 shown in FIG. 8 transitions from ACTn (n is a natural number) to ACT(n+1). The procedure shown in FIG. 8 is an example. The procedure is not particularly limited as long as similar results can be obtained.

[0044] In ACT 11, the processor 101 initializes the value of a counter n (not shown) provided inside the processor 101 or in the main memory 102 to "1."

[0045] In ACT12, the processor 101 transmits a download request for the whitelist file to the whitelist server 20 via the communication interface 104 and the network NW.

[0046] In ACT13, the processor 101 downloads data transmitted from the whitelist server 20 via the network NW in response to the download request via the communication interface 104. Specifically, the processor 101 receives a whitelist file for the model of the image forming device 10 and a whitelist file hash value corresponding to the whitelist file, and temporarily stores them in the temporary storage unit 1021.

[0047] In ACT 14 , the processor 101 calculates a hash value from the whitelist file temporarily stored in the temporary storage unit 1021 .

[0048] In ACT15, the processor 101 compares this calculated hash value with the whitelist file hash value temporarily stored in the temporary storage unit 1021 and determines whether they match. By comparing these hash values, the processor 101 verifies the integrity of the downloaded whitelist file. If the two hash values ​​match, the processor 101 determines YES in ACT15 and proceeds to processing in ACT18. If the two hash values ​​do not match, the processor 101 determines NO in ACT15 and proceeds to processing in ACT16. For example, a situation may occur in which the whitelist file or whitelist file hash value is not completely downloaded due to a problem such as noise on the network NW.

[0049] In ACT16, the processor 101 determines whether the value of counter n is equal to or greater than the specified value N, i.e., whether downloads have been performed a specified number of times or more. If the value of counter n is still less than the specified value N, the processor 101 determines NO in ACT16 and proceeds to the processing of ACT17. If the value of counter n is equal to or greater than the specified value N, the processor 101 determines YES in ACT16 and terminates the startup processing operation shown in this flowchart. If the integrity of the downloaded whitelist file cannot be verified even after repeated downloads a specified number of times, this is likely not a problem with the network NW but a problem with the whitelist server 20. If the integrity of the downloaded whitelist file cannot be verified even after repeated downloads a specified number of times, the processor 101 may perform a predetermined error process, such as displaying an error message on the operation panel 106.

[0050] In ACT17, the processor 101 increments the value of the counter n by 1. After that, the processor 101 proceeds to the processing of ACT12.

[0051] In ACT18, the processor 101 saves the whitelist file temporarily stored in the temporary storage unit 1021 in the whitelist file storage unit 1032.

[0052] In ACT19, the processor 101 executes a program startup process. In this program startup process, the processor 101 uses the whitelist file stored in the whitelist file storage unit 1032 to determine whether each program to be executed stored in the program storage unit 1031 is permitted to run. The processor 101 then starts the program for which it has determined that execution is permitted. Furthermore, the processor 101 does not start the program for which it has determined that execution is denied. At this time, the processor 101 can display an error message on the operation panel 106 indicating the program that did not start.

[0053] When the processing for all programs to be executed stored in program storage unit 1031 is completed, processor 101 ends the startup processing operation shown in this flowchart.

[0054] As described above, the information processing system according to the first embodiment includes an image forming apparatus 10 having a program storage unit 1031 of an auxiliary storage device 103 that stores one or more programs, a processor 101 that executes the programs, and a communication interface 104, and a whitelist server 20 that stores a whitelist, which is a list of pairs of file path information of programs and hash values ​​calculated from the programs, for determining whether or not each of the one or more programs stored in the program storage unit 1031 of the image forming apparatus 10 can be executed by the processor 101 of the image forming apparatus 10. As described above, the image forming apparatus 10 is an example of an information processing apparatus according to the first embodiment, the program storage unit 1031 is an example of internal storage, the pairs of file path information and hash values ​​are an example of determination information, the whitelist server 20 is an example of external storage, and the communication interface 104 of the image forming apparatus 10 is an example of an interface with external storage. Then, the processor 101 of the image forming device 10 acquires a whitelist from the whitelist server 20 via the communication interface 104, verifies the completeness of the acquired whitelist, and if the acquired whitelist is complete, stores the acquired whitelist in the whitelist file memory unit 1032 of the auxiliary storage device 103 as a whitelist to be used to determine whether or not to execute one or more programs stored in the program memory unit 1031 when executing the program. As described above, the information processing system and information processing device according to the first embodiment use a whitelist downloaded from the whitelist server 20 after verifying its integrity, rather than a whitelist stored in the image forming device 10 serving as an information processing device. This allows the whitelist to be safely used even if the image forming device 10 uses an inexpensive auxiliary storage device 103 with low fault tolerance. Note that the term "inexpensive auxiliary storage device" here refers to an auxiliary storage device for non-server use that is prone to data loss due to a power outage. Therefore, the information processing system and information processing device according to the first embodiment can prevent a functional shutdown even if the whitelist stored in the auxiliary storage device 103 is tampered with or corrupted.

[0055] Here, when acquiring a whitelist, the processor 101 acquires a whitelist file hash value, which is a hash value of the whitelist, from the whitelist server 20, which is external storage, via the communication interface 104. The whitelist file hash value is an example of verification information for verifying the integrity of the whitelist, generated based on the contents of the whitelist. When verifying the integrity of the whitelist, the processor 101 generates a whitelist file hash value, which is verification information, based on the contents of the acquired whitelist, and determines the integrity of the whitelist based on whether the generated whitelist file hash value matches the acquired whitelist file hash value. Therefore, according to the first embodiment, the integrity can be easily determined using the hash value.

[0056] Furthermore, when the image forming apparatus 10 is started up, the processor 101 acquires a whitelist and verifies the acquired whitelist. Therefore, according to the first embodiment, it is possible to ensure safe operation of the whitelist when starting to use the information processing device.

[0057] [Second embodiment] In the first embodiment, the whitelist file is downloaded every time the image forming apparatus 10, which is an information processing apparatus, is powered on and started up, but it may be downloaded as needed. This will be described below as the second embodiment. Note that the same configurations and operations as those in the first embodiment are denoted by the same reference numerals as those in the first embodiment, and description thereof will be omitted.

[0058] 9 is a block diagram showing an example of the configuration of an image forming apparatus 10 as an information processing apparatus according to the second embodiment in an information processing system according to the second embodiment. As shown in FIG. 9, the image forming apparatus 10 of this embodiment further includes a whitelist hash value storage unit 1033 in the auxiliary storage device 103. This whitelist hash value storage unit 1033 stores whitelist file hash values ​​calculated from whitelist files stored in a whitelist file storage unit 1032.

[0059] The start-up operation of each image forming apparatus 10 in the information processing system having such a configuration will be described below.

[0060] 10 is a sequence diagram illustrating the startup operation of each image forming apparatus 10 according to the second embodiment. When the image forming apparatus 10 is started by powering on, in this embodiment, it first verifies the integrity of the whitelist file stored in the whitelist file storage unit 1032 (step S21). Specifically, the image forming apparatus 10 calculates a hash value from the whitelist file stored in the whitelist file storage unit 1032. The image forming apparatus 10 then compares this calculated hash value with the whitelist file hash value stored in the whitelist hash value storage unit 1033, thereby verifying the integrity of the whitelist file stored in the whitelist file storage unit 1032.

[0061] If the hash value calculated from the whitelist file stored in the whitelist file memory unit 1032 matches the whitelist file hash value stored in the whitelist hash value memory unit 1033 (step S22: YES), that is, if the whitelist file stored in the whitelist file memory unit 1032 is complete, the image forming device 10 proceeds to step S17.

[0062] On the other hand, if the hash value calculated from the whitelist file stored in the whitelist file memory unit 1032 does not match the whitelist file hash value stored in the whitelist hash value memory unit 1033 (step S22: NO), that is, if the whitelist file stored in the whitelist file memory unit 1032 is not complete, the image forming device 10 performs the operations of steps S10 to S15 as described in the first embodiment.

[0063] If the hash value calculated from the downloaded whitelist file matches the downloaded whitelist file hash value (step S15: YES), that is, if the downloaded whitelist file is complete, the image forming device 10 stores the downloaded whitelist file in the whitelist file storage unit 1032 in step S16. The image forming device 10 also stores the downloaded whitelist file hash value or the hash value calculated to verify the integrity of the downloaded whitelist file in step S14 as a whitelist file hash value in the whitelist hash value storage unit 1033 (step S23). The whitelist file storage unit 1032 and the whitelist hash value storage unit 1033 store the whitelist file and the whitelist file hash value in a non-volatile manner. Therefore, the whitelist file and the whitelist file hash value stored in the image forming device 10 upon power-on are the data stored in steps S16 and S23. The image forming device 10 then proceeds to step S17.

[0064] The operation of the image forming apparatus 10 for realizing such an operation will be described below. Fig. 11 is a flowchart showing an example of a startup processing operation executed by the processor 101 of the image forming apparatus 10 of the second embodiment.

[0065] In this embodiment, the processor 101 first calculates a hash value as ACT 21. Specifically, the processor 101 calculates the hash value from the whitelist file stored in the whitelist file storage unit 1032.

[0066] In ACT22, the processor 101 compares this calculated hash value with the whitelist file hash value stored in the whitelist hash value storage unit 1033, and determines whether the two match. By comparing these hash values, the processor 101 verifies the integrity of the whitelist file stored in the whitelist file storage unit 1032. If the two hash values ​​match, the processor 101 determines YES in ACT22 and proceeds to the processing of ACT19.

[0067] On the other hand, if the two hash values ​​do not match, the processor 101 determines NO in ACT 22 and proceeds to the processing of ACT 11. For example, the whitelist file or the whitelist file hash value stored in the whitelist file storage unit 1032 or the whitelist hash value storage unit 1033 may be tampered with or corrupted.

[0068] Furthermore, if the hash value calculated from the downloaded whitelist file matches the downloaded whitelist file hash value, ACT15 is judged as YES, and processing proceeds to ACT18, the whitelist file downloaded in processing ACT18 is saved in the whitelist file memory unit 1032, and then in this embodiment, processing proceeds to ACT23.

[0069] In ACT23, the processor 101 stores the whitelist file hash value that has been downloaded and temporarily stored in the temporary storage unit 1021, or a hash value calculated from the whitelist file that has been downloaded in ACT14 and temporarily stored in the temporary storage unit 1021, in the whitelist hash value storage unit 1033. The whitelist file hash value stored in the whitelist hash value storage unit 1033 is an example of verification information for verifying the integrity of the whitelist file stored in the whitelist file storage unit 1032.

[0070] In this way, by the processing of ACT18 and ACT23, the whitelist file and the whitelist file hash value stored non-volatilely in the whitelist file storage unit 1032 and the whitelist hash value storage unit 1033 are updated. After that, the processor 101 proceeds to the processing of ACT19.

[0071] As described above, in the information processing system and information processing device according to the second embodiment, the image forming device 10, which is an example of an information processing device, stores a whitelist file hash value, which is verification information for verifying the integrity of a whitelist generated based on the whitelist stored in the whitelist file storage unit 1032, in the whitelist hash value storage unit 1033 of the auxiliary storage device 103, which is internal storage. When the image forming device 10 is started, the processor generates a whitelist file hash value based on the whitelist stored in the whitelist file storage unit 1032, and if this generated whitelist file hash value does not match the whitelist file hash value stored in the whitelist hash value storage unit 1033, obtains a whitelist from the whitelist server 20 via the communication interface 104 and verifies the integrity of the obtained whitelist. If the acquired whitelist is complete, the processor 101 updates the whitelist and whitelist file hash value stored in the whitelist file memory unit 1032 and the whitelist hash value memory unit 1033 using the acquired whitelist and the generated whitelist file hash value or the generated whitelist file hash value. As described above, according to the second embodiment, when the image forming device 10 starts up, the integrity of the whitelist stored in the whitelist file storage unit 1032 is verified using a hash value calculated from the whitelist file and a whitelist file hash value stored in the whitelist hash value storage unit 1033, and only if the verification fails are the whitelist file and the whitelist file hash value downloaded from the whitelist server 20. Therefore, according to the second embodiment, communication with the whitelist server 20 is performed only if the whitelist in the image forming device 10 is corrupted, thereby shortening the startup time when the whitelist is not corrupted.

[0072] In this second embodiment, as in the first embodiment, the whitelist downloaded from the whitelist server 20 is used after verifying its integrity, so that the whitelist can be operated safely even if the image forming device 10 uses an inexpensive auxiliary storage device 103 with low fault tolerance.

[0073] [Other embodiments] Although the embodiments of the information processing system and the information processing device have been described above, the embodiments are not limited to these.

[0074] For example, the image forming apparatus 10, which is an MFP, has been described as an example of an information processing apparatus, but the information processing apparatus may also be an office machine such as a POS (Point of Sale) terminal.

[0075] Furthermore, when the image forming device 10 obtains the whitelist file and the whitelist file hash value from the external storage, the image forming device 10 obtains them from the whitelist server 20 as the external storage via the network NW via the communication interface 104. The external storage that holds the whitelist file and the whitelist file hash value may be any of the user terminals 30.

[0076] Furthermore, the external storage may be a removable computer-readable storage medium such as a USB memory. In this case, the processor 101 can obtain the whitelist file and the whitelist file hash value by reading them from the computer-readable storage medium via the external storage medium interface 105, which serves as an interface with the external storage.

[0077] The external storage may also be a paper medium on which the whitelist file and the whitelist file hash value are written as text or as a symbol image such as a barcode. In this case, the processor 101 can obtain the whitelist file and the whitelist file hash value by reading them from the paper medium using the scanner 107, which serves as an interface with the external storage.

[0078] Thus, in this specification, obtaining from external storage such as a whitelist means not only downloading but also reading or retrieving.

[0079] In addition, although the programs stored in the program storage unit 1031 have been described as being stored in the same file path for image forming devices 10 of the same model, they may be stored in different file paths for individual devices. In this case, it is sufficient to store the whitelist file and the whitelist file hash value for each individual device in an external storage, linked to information that identifies the device.

[0080] Furthermore, the flow of the information processing performed by the processor 101 described with reference to the flowchart is an example, and is not limited to this order. The order of the processing may be changed or multiple processes may be performed in parallel, as long as there is no discrepancy with the preceding or subsequent processing.

[0081] In the above embodiment, an information processing program serving as a control program is pre-stored in the auxiliary storage device 103 of the image forming apparatus 10. In this regard, a control program transferred separately from the image forming apparatus 10 may be written to a writable storage device provided in the image forming apparatus 10 in response to an operation by an administrator or the like. The transfer of such a control program may be performed by storing it in a removable computer-readable storage medium or by communication via a network. The form of the computer-readable storage medium is not important as long as it can store a program and is readable by the device, such as a CD-ROM or memory card.

[0082] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments are included within the scope of the invention and the scope of the inventions and their equivalents as defined in the claims. [Explanation of symbols]

[0083] 10...image forming device, 10A...model A image forming device, 10B...model B image forming device, 10C...model C image forming device, 20...whitelist server, 30...user terminal, 101,201...processor, 1021...temporary memory unit, 103,203...auxiliary memory device, 1031...program memory unit, 1032...whitelist file memory unit, 1033...whitelist hash value memory unit, 2031...model-specific whitelist memory unit, 2032...model-specific hash value memory unit, 104,204...communication interface, 105...external memory medium interface, 106...operation panel, 107...scanner, 108...input image processing unit, 109...page memory, 110...output image processing unit, 111...printer, NW...network.

Claims

1. An apparatus comprising: an internal storage that stores one or more programs; a processor that executes the programs; and an interface with an external storage that stores a whitelist, which is a list of determination information for determining whether or not each of the one or more programs can be executed by the processor; The processor: Obtaining the whitelist from the external storage via the interface; Verifying the integrity of the obtained whitelist; If the acquired whitelist is complete, the acquired whitelist is stored in the internal storage as a whitelist to be used for determining whether or not to execute any of the one or more programs stored in the internal storage when the program is executed. Information processing device.

2. The processor: When acquiring the whitelist, verification information for verifying the integrity of the whitelist is also acquired from the external storage via the interface, the verification information being generated based on the contents of the whitelist; When verifying the completeness of the whitelist, generating the verification information based on the content of the acquired whitelist; determining the completeness of the whitelist based on whether the generated verification information matches the acquired verification information; The information processing device according to claim 1 .

3. The information processing device according to claim 1 , wherein the processor acquires the whitelist and verifies the acquired whitelist when the information processing device is started up.

4. The internal storage further stores verification information for verifying the integrity of the whitelist stored in the internal storage; The processor: When the information processing device is started, generating the verification information based on the whitelist stored in the internal storage; If the generated verification information does not match the verification information stored in the internal storage, the whitelist is obtained from the external storage via the interface, and the integrity of the obtained whitelist is verified; If the acquired whitelist is complete, update the whitelist and the verification information stored in the internal storage using the acquired whitelist and the generated verification information or the generated verification information. The information processing device according to claim 2 .

5. an information processing device including an internal storage for storing one or more programs and a processor for executing the programs; an external storage that stores a whitelist, which is a list of determination information for determining whether or not each of the one or more programs stored in the internal storage can be executed by the processor of the information processing device; Equipped with The processor of the information processing device Obtaining the whitelist from the external storage; Verifying the integrity of the obtained whitelist; If the acquired whitelist is complete, the acquired whitelist is stored in the internal storage as a whitelist to be used for determining whether or not to execute any of the one or more programs stored in the internal storage when the program is executed. Information processing system.

6. When executed by a processor of an information processing device including an internal storage that stores one or more programs, a processor that executes the programs, and an interface with an external storage that stores a whitelist, which is a list of determination information for determining whether or not the processor can execute each of the one or more programs, the processor, Acquiring the whitelist from the external storage via the interface; Verifying the integrity of the obtained whitelist; If the acquired whitelist is complete, the acquired whitelist is stored in the internal storage as a whitelist to be used for determining whether or not to allow execution of any of the one or more programs stored in the internal storage when the program is executed. Information processing program.

Citation Information

Patent Citations

  • Execution control program and information processing system

    JP2010238168A