Equipment verification system, equipment verification method, and program

The device verification system addresses the challenge of authenticating devices in network-disconnected environments by using hash values to verify component integrity, ensuring secure startup and operation.

JP2026071232APending Publication Date: 2026-04-28NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2026-01-08
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing equipment verification systems are unable to authenticate the authenticity of devices when external networks are interrupted, making them vulnerable to cyberattacks.

Method used

A device verification system that includes security function means to store hash values of device components and programs, and a communication device to verify authenticity based on these hash values even in a network-blocked environment, outputting verification results.

Benefits of technology

Enables authenticating device authenticity up to startup even when external networks are blocked, providing robust security against cyberattacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026071232000001_ABST
    Figure 2026071232000001_ABST
Patent Text Reader

Abstract

This system provides equipment verification capabilities that allow for the verification of the authenticity of equipment up to startup, even when external networks are blocked. [Solution] A device verification system in one aspect of this disclosure comprises a plurality of devices and a communication device, each of which is configured to include security function means, the security function means storing hash values ​​of each device and the programs implemented in each device's components, which are generated when each device is started up, and the communication device comprises verification means for verifying the authenticity of each device at startup based on the hash values ​​stored in the security function means in an environment where the external network is blocked, and output means for outputting the verification results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an equipment verification system, an equipment verification method, and a program.

Background Art

[0002] Cyberattacks on equipment (edge computers) installed at various business sites have become a reality. For example, when a system built by a system vendor is delivered to a customer, a malicious third party may fraudulently alter the equipment, causing the system to malfunction.

[0003] In contrast, in order to prevent the system from malfunctioning, it is known to verify the authenticity of equipment before starting the system. For example, Patent Document 1 discloses a technique in a communication system including equipment and a smart meter, in which an authentication request is sent from the equipment to the smart meter, and after undergoing authentication processing, data of the equipment is read.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, the invention described in Patent Document 1 is verified using an external authentication server located at a location separate from the equipment. Therefore, if the network with the external authentication server is interrupted, verification becomes impossible.

[0006] An example of the object of the present disclosure is to provide an equipment verification system capable of verifying the authenticity of equipment until startup even when an external network is interrupted.

Means for Solving the Problems

[0007] A device verification system in one aspect of this disclosure comprises a plurality of devices and a communication device, each of which is configured to include security function means, the security function means storing hash values ​​of each device and the programs implemented in each device's components, which are generated when each device is started up, and the communication device comprises verification means for verifying the authenticity of each device at startup based on the hash values ​​stored in the security function means in an environment where the external network is blocked, and output means for outputting the verification results.

[0008] A device verification method in one aspect of this disclosure involves a communication device connected to multiple devices that, in an environment where external networks are blocked, verifies the authenticity of each device at startup based on the hash values ​​of programs implemented in each device and its components, which are generated at the time of startup of each device and stored in the security function means of each of the multiple devices, and outputs the verification results.

[0009] A program in one aspect of this disclosure causes a computer to perform the following actions in an environment where the external network is blocked: verify the authenticity of each device at startup based on the hash value of the program implemented in each device and its components, which is generated at the time each device is started and stored in the security function means of each of the multiple devices connected to the communication device, and output the result of the verification. [Effects of the Invention]

[0010] One example of the benefits of this disclosure is the provision of a device verification system that can verify the authenticity of equipment up to startup, even when external networks are blocked. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 shows the configuration of the equipment verification system in the first embodiment. [Figure 2]Figure 2 shows the hardware configuration in which the equipment and communication device in the first embodiment are realized using a computer device and its peripheral devices. [Figure 3] Figure 3 is a flowchart showing the operation of the equipment verification system in the first embodiment. [Figure 4] Figure 4 shows the configuration of the equipment verification system in the second embodiment. [Modes for carrying out the invention]

[0012] Next, embodiments will be described in detail with reference to the drawings.

[0013] [First Embodiment] Figure 1 shows the configuration of the device verification system 10 in the first embodiment. Referring to Figure 1, the device verification system 10 has a plurality of devices 100 (100a, 100b) and a communication device 200. The device verification system 10 verifies the authenticity of a series of startup operations, from power-on of each device 100 to the startup of the OS or other program. In this embodiment, authenticity verification is performed by a higher-level authentication server based on a hash value calculated at startup to verify whether the components of the device 100 or the programs held by the device 100 have not been tampered with. In this embodiment, the communication device 200 verifies the authenticity of each device 100 by verifying the operational status of each device 100 to establish a secure initial state. Authenticity means that in each device 100, only tested and known components and programs are operating, and no unauthorized tampering has occurred during the device supply or system construction process. The device verification system 10 performs device verification, for example, each time the startup operation of a device 100 is initiated.

[0014] The equipment verification system 10 is a system that becomes a closed environment when the network to the data center is cut off, such as a system located in a remote location. The equipment verification system 10 is an equipment system that controls equipment such as vehicles, ships, and aircraft in real time. In the equipment verification system 10, the communication device 200 aggregates the verification results of each piece of equipment 100 and transmits them to the highest-level verification device 300 using satellite communication or wireless communication. Alternatively, the communication device 200 may aggregate the verification results of each piece of equipment 100 and send them to the highest-level verification device 300 via a higher-level verification device (not shown). In this case, the communication device 200 may also send the verification results received from each piece of equipment 100 to the highest-level verification device 300 via another communication device 200 under the management of the same higher-level verification device. In the case of an equipment system, the verification results may also be transmitted wirelessly via a communication device 200 in another vehicle, ship, or aircraft, through a higher-level verification device, to the highest-level verification device 300. Other equipment verification systems 10 include, for example, systems used in connected cars or OT (Operational Technology) within factories. The higher-level verification device includes a verification unit that verifies the authenticity of the communication device 200 located below the higher-level verification device. Similarly, the top-level verification device 300 includes a verification unit that verifies the authenticity of the higher-level verification device located below the top-level verification device 300.

[0015] Figure 2 shows an example of a hardware configuration in which the device 100 and communication device 200 in the first embodiment of this disclosure are each implemented by a computer device 500 including a processor. As shown in Figure 2, the device 100 and communication device 200 each include a CPU (Central Processing Unit) 501, memory such as ROM (Read Only Memory) 502 and RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication I / F (Interface) 508 for network connection, and an input / output interface 511 for input and output of data.

[0016] The CPU 501 controls the entire device 100 and communication device 200 according to the first embodiment of the present invention. The CPU 501 also reads programs and data into memory from a recording medium 506 mounted on, for example, a drive device 507. The CPU 501 also functions as the program execution unit 101, security function unit 102, transmission unit 103, and parts thereof of the device 100 in the first embodiment, and executes processes or instructions in the flowchart shown in Figure 3, which will be described later, based on the program. The CPU 501 also functions as the transmitting / receiving unit 201, authentication information storage unit 202, verification unit 203, output unit 204, control unit 205, and parts thereof of the communication device 200 in the first embodiment, and executes processes or instructions in the flowchart shown in Figure 3, which will be described later, based on the program.

[0017] The recording medium 506 is, for example, an optical disc, a flexible disc, a magneto-optical disc, an external hard disk, or a semiconductor memory. Some of the recording media of the storage device are non-volatile storage devices, on which the program is recorded. The program may also be downloaded from an external computer (not shown) connected to a communication network.

[0018] The input device 509 is implemented, for example, by a mouse, keyboard, or built-in key buttons, and is used for input operations. The input device 509 is not limited to a mouse, keyboard, or built-in key buttons; it may also be a touch panel, for example. The output device 510 is implemented, for example, by a display, and is used to confirm the output.

[0019] As described above, the first embodiment shown in Figure 1 is realized by the computer hardware shown in Figure 2. However, the means of realizing each part of the device 100 and communication device 200 in Figure 1 are not limited to the configuration described above. The communication device 200 may be realized by a single physically coupled device, or by two or more physically separated devices connected by wire or wireless, and realized by these multiple devices. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network.

[0020] <Machine 100> Each of machines 100 (100a, 100b) includes a program execution unit 101 (101a, 101b), a security function unit 102 (102a, 102b), and a transmission unit 103 (103a, 103b). In this embodiment, there are two machines 100, but it is not limited thereto. The number of the plurality of machines 100 is provided only corresponding to the number of machines existing in the device verification system 10.

[0021] The program execution unit 101 executes the startup program of the device 100 and generates hash values of component parts and programs. When the power of the device 100 is turned on, for example, the program execution unit 101 executes programs in the order of a bootloader, BIOS (Basic Input Output System) or UEFI (Unified Extensible Firmware Interface), and an OS. However, the configuration of the programs to be executed is not limited to this. There may be only a bootloader, or the bootloader itself may be multi-stage. When the program execution unit 101 generates hash values of component parts such as a CPU and each program at the time of executing the startup program, the generated hash values are input to the security function unit 102. Note that the hash values may be electronically signed to ensure the authenticity of the hash values themselves.

[0022] The security function unit 102 includes a tamper-resistant storage area. The security function unit 102 is an area that is difficult for malicious third parties to modify. The security function unit 102 stores each hash value input from the program execution unit 101 and may also have an encryption key necessary for encryption processing to securely transmit the hash values ​​to the communication device 200, or it may have an attribute certificate that defines the source of the information. The security function unit 102 is composed of, for example, a TPM (Trusted Platform Module), but is not limited to this as long as it can achieve tamper resistance. TPMs have high tamper resistance because they have characteristics that make them difficult to tamper with against the OS, hardware, and external physical hacking.

[0023] The transmitting unit 103 transmits the hash value stored in the security function unit 102 to the communication device 200 and requests verification of the authenticity of the device 100.

[0024] <Communication device 200> The communication device 200 comprises a transmitting / receiving unit 201, an authentication information storage unit 202, a verification unit 203, an output unit 204, and a control unit 205. The communication device 200 may also be configured as a virtualized server that operates as multiple servers.

[0025] The transmitting / receiving unit 201 receives data transmitted from the device 100 and transmits it to the highest-level verification device 300. The transmitting / receiving unit 201 may also have a firewall function within the device verification system 10. That is, the transmitting / receiving unit 201 determines whether to allow network communication with the outside of the device verification system 10, and permits or denies it.

[0026] The authentication information storage unit 202 stores the hash expected values ​​for each component and program of each device 100. The hash expected value is the normal hash value generated when the components and startup programs have not been tampered with. The authentication information storage unit 202 stores the hash expected values ​​that have been received in advance from each device 100 via the transmission / reception unit 201.

[0027] The verification unit 203 verifies the authenticity of the components of each device 100 and the startup program executed on each device 100. The verification unit 203 makes a binary determination, for example, whether or not authenticity is guaranteed. When the verification unit 203 receives a verification request from any of the devices 100, it compares the hash value generated when the startup program is executed with the hash expected value stored in the authentication information storage unit 202. However, the verification method by the verification unit 203 is not limited to this; any method that can confirm that the hash value at the time of startup program execution is the hash value under normal circumstances is acceptable.

[0028] The verification unit 203 determines authenticity if the hash value at the time of startup program execution is the same as the expected hash value, and outputs the verification result to the output unit 204. The verification unit 203 determines that the device is not authentic if the hash value at the time of startup program execution is different from the expected hash value, and outputs the verification result to the output unit 204 and the control unit 205. If the hash value of any of the devices 100 does not match the expected hash value, the verification unit 203 may determine that the device is not authentic at that point and output the verification result to the output unit 204 and the control unit 205.

[0029] The output unit 204 is a means for outputting the authenticity result of the device 100. The output unit 204 outputs the authenticity result to an output device 510 such as a display device. If the output unit 204 receives a verification result indicating that the device is not authentic, it may also notify the system of the abnormality using a lamp or buzzer provided in the communication device 200. The output unit 204 may also transmit the authenticity verification result to the highest-level verification device 300.

[0030] The control unit 205 stops communication with the device 100 that has been determined to be inauthentic by invalidating its certificate information. For example, the control unit 205 invalidates the attribute certificate of the device 100 that has been determined to be inauthentic using the mechanism of RFC5055. The control unit 205 may also reconfigure the device verification system 10 excluding the device 100 that has been determined to be inauthentic and control the device verification system 10 to perform degraded operation.

[0031] The device verification system 10 only needs to include, as a minimum configuration, a security function unit 102 for device 100, a verification unit 203 and an output unit 204 for communication device 200. In this case, the security function unit 102 may also generate hash values ​​for the components of device 100 and the hash values ​​for the program executed by device 100.

[0032] The operation of the equipment verification system 10 configured as described above will be explained with reference to the flowchart in Figure 3.

[0033] Figure 3 is a flowchart outlining the operation of the equipment verification system 10 in the first embodiment. Note that the processing shown in this flowchart may be executed based on program control by the processor described above.

[0034] As shown in Figure 3, first, the program execution unit 101 of the device 100 executes a program and generates hash values ​​for the components of the device 100 and the program (step S101), and stores the generated hash values ​​in the security function unit 102 (step S102). The transmission unit 103 transmits the hash values ​​stored in the security function unit 102 to the communication device 200 (step S103). Next, the transmitting / receiving unit 201 of the communication device 200 receives the generated hash values ​​(step S104). Then, the verification unit 203 compares the generated hash values ​​with the hash expected values ​​stored in the authentication information storage unit 202 (step S105). If the generated hash values ​​and the hash expected values ​​match (S105; YES), the verification unit 203 determines that it is authentic (step S106) and terminates the flow. On the other hand, if the generated hash value does not match the expected hash value (S105; NO), the verification unit 203 determines that the device is not authentic (step S107), and the output unit 204 generates an alert (step S108). Next, the control unit 205 stops communication with the device 100 that has been determined to be not authentic (step S109). With this, the device verification system 10 terminates its device verification operation.

[0035] In this embodiment, the device verification system 10 determines authenticity by verifying, using the verification unit 203 of the communication device 200, whether the hash value generated when the startup program of the device 100 is executed is the same as the hash value under normal circumstances. This allows the authenticity of the device 100 up to the OS startup to be verified even if the network connection between the device verification system 10 and the outside world is cut off.

[0036] Conventional commercially available antivirus software used for authenticity verification could not be installed depending on the program implemented in the device 100. For example, in the case of low-power devices that require the installation of a power-saving OS such as an embedded OS, installing commercially available antivirus software is extremely impractical from the standpoint of performance and capacity. Also, in the case of devices that burn the implemented program into flash memory, it is difficult to install the software itself. In contrast, in the device verification system 10 of this disclosure, the verification unit 203 in the communication device 200 verifies the authenticity of the device 100 based on the hash values ​​of the device's components and programs. Therefore, it can be installed regardless of the OS or other programs that are implemented.

[0037] [Second Embodiment] Next, a second embodiment of the present disclosure will be described. To the extent that the description of this embodiment does not become unclear, any content that overlaps with the previous description will be omitted. Each component in each embodiment of the present disclosure, similar to the computer device shown in Figure 2, can implement its function not only in hardware but also in a computer device or software based on program control.

[0038] Figure 4 shows the configuration of the device verification system 11 in the second embodiment. Referring to Figure 4, the device verification system 11 in the second embodiment will be described, focusing on the differences from the device verification system 10 in the first embodiment. Device 110 has the same configuration as device 100. The communication device 210 includes a transmitting / receiving unit 211, an authentication information storage unit 202, a verification unit 203, an output unit 204, a control unit 205, and a network monitoring unit 206. In other words, this embodiment differs from the first embodiment in that the communication device 210 includes a network monitoring unit 206.

[0039] In the second embodiment, the network monitoring unit 206 monitors the network of the device verification system 11 during application execution after the OS has started. The network monitoring unit 206 verifies whether there are any abnormalities in the network based on the difference from the normal operating pattern of the device verification system 11. The communication device 210 stores a model (not shown) that was generated by learning operational data, such as communication log information during normal operation, for a certain period (e.g., 1 to 3 months). This model takes operational data as input and outputs whether the network is normal or not. Using this model, the network monitoring unit 206 raises an alert through the output unit 204 if it detects operation that differs from the normal operating pattern.

[0040] In a second embodiment of this disclosure, the network monitoring unit 206 verifies whether the network of the device verification system 11 is abnormal during application execution based on the difference from the normal operating pattern. This makes it possible to detect unknown malware that cannot be detected by antivirus software. The network monitoring unit 206 can detect abnormalities, for example, caused by tampering with the dynamic link library, during application execution on the device 110. Furthermore, in a device verification system 11 where application control is limited to specific operations, such as in an equipment system, it is easier to extract characteristic points of the operating pattern. Therefore, the accuracy of network abnormality detection by the network monitoring unit 206 can be improved. In addition, by combining the second embodiment with the first embodiment of this disclosure, it becomes possible to detect abnormalities both during startup and operation of the device 110.

[0041] Although the present invention has been described above with reference to the embodiments described, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention can be made that will be understood by those skilled in the art within the scope of the present invention.

[0042] For example, although multiple actions are described sequentially in flowchart format, the order in which they are described does not limit the order in which the actions must be performed. Therefore, when implementing each embodiment, the order of the multiple actions can be changed as long as it does not impair the content. [Explanation of Symbols]

[0043] 10, 11 Equipment Verification System 100, 110 equipment 101, 111 Program Execution Unit 102, 112 Security Function Section 103, 113 Transmitter 200, 210 communications devices 201, 211 Transceiver Unit 202, 212 Authentication information storage unit 203, 213 Verification Department 204, 214 Output section 205, 215 Control Unit 216 Network Monitoring Department 300, 310 Top-level verification equipment

Claims

1. A device verification system having multiple devices and a communication device, Each of the aforementioned devices is configured to include security function means, and each security function means stores the hash values ​​of the programs implemented in each device and its components, which are generated when each device is started up. The aforementioned communication device is In an environment where the external network is blocked, a verification means verifies the authenticity of each device at startup based on the hash value stored in the security function means, The system includes an output means for outputting the results of the verification described above. Equipment verification system.

2. The aforementioned communication device determines whether to allow communication between the equipment verification system and the external network, and permits or denies it. The equipment verification system according to claim 1.

3. A device verification system having multiple devices and a communication device, Each of the aforementioned devices is configured to include security function means, and each security function means stores the hash values ​​of the programs implemented in each device and its components, which are generated when each device is started up. The aforementioned communication device is Verification means for verifying the authenticity of each device at startup based on the hash value stored in the security function means, The system includes an output means for outputting the results of the verification, The output means transmits the verification results to the higher-level verification device via another communication device connected to the higher-level verification device. Equipment verification system.

4. A communication device that connects to multiple devices, Based on the hash values ​​of the programs implemented in each device and its components, which are stored in the security function means of each of the aforementioned multiple devices and generated when each device is started up, the authenticity of each device at the time of startup is verified in an environment where the external network is blocked. A device verification method that outputs the results of the verification described above.

5. The aforementioned communication device determines whether or not to allow communication between the equipment verification system and the external network. If communication is permitted, output the results of the verification. The device verification method according to claim 4.

6. A communication device that connects to multiple devices, Based on the hash values ​​of the programs implemented in each device and its components, which are generated when each device is started and stored in the security function means of each of the aforementioned plurality of devices, the authenticity of each device at the time of startup is verified. A device verification method comprising transmitting the results of the verification described above to a higher-level verification device via another communication device connected to the said higher-level verification device.

7. Based on the hash values ​​of the programs implemented in each device and its components, which are generated at the time of startup of each device and stored in the security function means of each of the multiple devices connected to the communication device, the authenticity of each device at the time of startup is verified in an environment where the external network is blocked. A program that causes a computer to output the results of the verification described above.

8. Regarding communication between the equipment verification system and the external network, a decision is made as to whether or not to allow communication. The program according to claim 7, which causes a computer to output the results of the verification if it is permitted to communicate.

9. Based on the hash values ​​of the programs implemented in each device and its components, which are generated when each device is started up and stored in the security function means of each of the multiple devices connected to the communication device, the authenticity of each device at the time of startup is verified. A program that causes a computer to transmit the results of the verification described above to the higher-level verification device via another communication device connected to the higher-level verification device to which the communication device is connected.

Citation Information

Patent Citations

  • Communication system and equipment

    JP2016039564A