Information processing device, information processing system, and program

The information processing system addresses the memory and storage limitations of low-end devices by using an edge server to manage software versions and initiate rollbacks, ensuring effective rollback processes and system stability.

JP7675638B2Active Publication Date: 2025-05-13KK TOSHIBA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021203627
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-15
Publication Date
2025-05-13
Estimated Expiration
2041-12-15

AI Technical Summary

Technical Problem

Low-end devices, such as smart meters, face challenges in securing sufficient memory and storage to implement rollback processes due to memory and storage restrictions.

Method used

An information processing system comprising an edge server and low-end devices, where the edge server manages software versions and rollback information, allowing it to detect abnormalities and initiate a software rollback on the low-end device by requesting the necessary rollback software.

Benefits of technology

This solution enables appropriate execution and management of rollback processes on low-end devices, ensuring system stability and security by allowing for timely recovery from software updates that cause abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007675638000001
    Figure 0007675638000001
  • Figure 0007675638000002
    Figure 0007675638000002
  • Figure 0007675638000003
    Figure 0007675638000003
Patent Text Reader

Abstract

To properly perform rollback processing.SOLUTION: An information processing system includes an edge server and a low-end device. A processing circuit of the low-end device transmits abnormality information for detecting its own abnormality to the edge server. A storage unit of the edge server stores information on the software for each version and low-end device information including the version of the software that runs on the low-end device. A processing circuit of the edge server detects an abnormality in the low-end device based on the abnormality information acquired from the low-end device, acquires version information of the software of the low-end device stored in the storage unit based on the detected abnormality, acquires rollback software information, which is software of a version older than the version in the version information running on the low-end device, from the storage unit, and requests the low-end device to roll back the software based on the rollback software information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] An embodiment of the present invention relates to an information processing device, an information processing system, and a program. [Background technology]

[0002] As various information processing systems become more sophisticated, software has become more complex and the use of open source software (OSS) has become widespread. This has also increased the risk of vulnerabilities being introduced into the system. Since there is a possibility of being subject to so-called zero-day attacks that exploit vulnerabilities immediately after they are discovered, it is desirable to quickly apply updates to fix vulnerabilities.

[0003] On the other hand, when an update is performed, there is a risk that the behavior of the software will change, causing an abnormality in the system. Even if it is confirmed that no abnormality will occur at the unit or module unit test level, there is a risk that an abnormality will occur in the production environment depending on the software combination, hardware, environment, etc. For this reason, while there is a demand to fix vulnerabilities as soon as possible, there is also a demand to perform updates only after sufficient testing. One method to alleviate or resolve the dilemma between a prompt update and the possibility of an abnormality occurring due to insufficient testing is rollback technology, which reverts to the software before the update when an abnormality occurs.

[0004] However, low-end devices, which are various edge devices such as smart meters, often have restrictions on memory and storage size due to factors such as device size, power consumption, use of special interfaces that depend on the device, costs, etc. For this reason, there is a problem in that low-end devices cannot secure sufficient memory and storage to record rollback software in the low-end devices in order to realize rollback. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] JP 2014-130585 A Summary of the Invention [Problem to be solved by the invention]

[0006] The present disclosure proposes an information processing device, an information processing system, and a program that appropriately execute or manage rollback processing. [Means for solving the problem]

[0007] According to one embodiment, an information processing system includes an edge server and a low-end device. A processing circuit of the low-end device transmits anomaly information for detecting anomaly in itself to the edge server. A storage unit of the edge server stores information on the software for each version and low-end device information including the version of the software operating on the low-end device. The processing circuit of the edge server detects an anomaly in the low-end device based on the anomaly information acquired from the low-end device, acquires version information of the software of the low-end device stored in the storage unit based on the detected anomaly, acquires rollback software information from the storage unit that is an older version of software than the version in the version information operating on the low-end device, and requests the low-end device to roll back the software based on the rollback software information. [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating an information processing system according to an embodiment. [Diagram 2] FIG. 1 is a diagram illustrating an information processing system according to an embodiment. [Diagram 3] 10 is a flowchart showing an abnormality detection process of an information processing system according to an embodiment. [Figure 4] FIG. 13 is a diagram showing an example of a response to a response confirmation communication according to an embodiment. [Diagram 5] 11 is a flowchart illustrating an example of processing a rollback request according to an embodiment. [Figure 6] FIG. 13 is a diagram illustrating an example of a software change information header according to an embodiment. [Figure 7] 10 is a flowchart illustrating an example of processing a software update request according to an embodiment. [Figure 8] FIG. 1 is a diagram illustrating an information processing system according to an embodiment. [Figure 9] FIG. 1 is a diagram illustrating an information processing system according to an embodiment. [Figure 10] FIG. 1 is a diagram illustrating an information processing system according to an embodiment. [Figure 11] 11 is a flowchart illustrating an example of a process of a duplicate rollback determination unit according to an embodiment. [Figure 12] 10 is a flowchart illustrating an example of a process by a software update request unit according to an embodiment. [Figure 13] 10 is a flowchart illustrating an example of a process of a software verification unit according to an embodiment. [Figure 14] 11 is a flowchart illustrating an example of a process of a rollback request unit according to an embodiment. [Figure 15] 11 is a flowchart illustrating an example of a process of a rollback determination unit according to an embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Hereinafter, an embodiment will be described with reference to the drawings.

[0010] (First embodiment) 1 is a diagram showing an outline of an information processing system according to an embodiment. The information processing system 1 includes a low-end device 10 and an edge server 20. Although not shown, the low-end device 10 and the edge server 20 include a memory unit such as a memory circuit or storage, and a processing circuit connected to the memory unit.

[0011] In the following, the operation of the processing circuit will be mainly described, but this circuit may be implemented as an analog circuit or a digital circuit as hardware, or may be implemented so that information processing by software can be specifically realized using a hardware resource called a processing circuit. When operating by software, programs, executable files, etc. for information processing of the software may be stored in each storage unit.

[0012] The information processing system 1 is a system that realizes updating of software including firmware or middleware in low-end equipment 10 including an edge device by using an edge server 20. Although the information processing system 1 is shown in Fig. 1 with one low-end equipment 10 and one edge server 20, this is not limiting, and the system may include a plurality of low-end equipment 10 and / or a plurality of edge servers 20.

[0013] In the information processing system 1, the low-end devices 10 and the edge server 20 are connected to each other in a state in which they can communicate with each other by wire or wirelessly. The connection may be made using a network such as Ethernet (registered trademark), or a bus such as CAN (Controller Area Network) or Modbus (registered trademark). The connection between the low-end devices 10 and the edge server 20 may be made via a network device such as a router or hub, or a switch, a switching hub, or the like.

[0014] The low-end device 10 and the edge server 20 each include, for example, a processing circuit such as a CPU, and a storage unit such as a memory or storage connected to the processing circuit. Each of the components described below may be part of the operation of the processing circuit or the storage unit.

[0015] 2 is a block diagram showing an example of the configuration of a low-end device 10 and an edge server 20 as the information processing system 1 according to this embodiment. The low-end device 10 includes a software update unit 100 and an anomaly information transmission unit 102. The edge server 20 includes a software update request unit 200, a rollback request unit 202, an anomaly detection unit 204, a software information storage unit 206, and a device information storage unit 208.

[0016] The software modification unit 100 modifies the software of the low-end device 10 based on a request from the edge server 20. The software modification includes updating to new software and rolling back to old software. The software modification unit 100 obtains information about the software to be modified from the edge server 20, and updates the software based on this information. The information about the software may include information about the type of software, information about the version of the software, as well as a program, executable file, or batch file required to modify the software.

[0017] When an abnormality occurs in the low-end device 10, the abnormality information transmission unit 102 transmits, to the edge server 20, information for the edge server 20 to detect the abnormality. As a non-limiting example, the abnormality information transmission unit 102 may transmit the abnormality information to the edge server 20 at a predetermined interval, such as every 10 seconds. This predetermined period can be changed to various values ​​depending on the configuration of the information processing system 1. In addition, this period does not have to be a predetermined interval, and the interval may change over time. For example, when a software update or software rollback occurs, the notification period may be set to be short for a while immediately after the occurrence of the software update or software rollback, and if a stable state continues thereafter, the notification period may be changed to be long.

[0018] When the software update request unit 200 acquires update information about software operating in the low-end device 10, it transmits a software update request to the low-end device 10 based on this information. The software update request unit 200 may transmit update data and the like required for the update together with this update request. The software update request unit 200 may acquire the update information from various memories and storages, as described below, for example, or may acquire the update information from other devices via a network. As another example, the user may explicitly notify the software update request unit 200 of the update information, or the software update request unit 200 may acquire the update information by accessing the software information storage unit 206.

[0019] When it is determined that a rollback of the software is necessary in the low-end device 10, the rollback request unit 202 transmits a request to rollback the software to the software modification unit 100. Like the software update request unit 200, the rollback request unit 202 may transmit rollback data and the like required for the rollback together with the rollback request.

[0020] The anomaly detection unit 204 detects an anomaly in the low-end device 10 based on the anomaly information transmitted from the anomaly information transmission unit 102. When the anomaly detection unit 204 detects an anomaly in the low-end device 10 based on the anomaly information, it notifies the rollback request unit 202 that an anomaly has occurred. In the above, the anomaly information transmission unit 102 notifies the anomaly information at predetermined intervals, but this is not limited to the above. The anomaly detection unit 204 may request the anomaly information transmission unit 102 to notify the anomaly information, and the anomaly information transmission unit 102 may notify the anomaly information in response to the request from the anomaly detection unit 204.

[0021] The software information storage unit 206 is provided as a part of the storage unit, and stores information about software for each version. The software information storage unit 206 may directly store an image file or the like for a version, or may store information for accessing the image file or the like. Furthermore, instead of the image file itself, difference information between each version may be stored in the software information storage unit 206. Furthermore, the software information storage unit 206 may also store information indicating a stable version.

[0022] The device information storage unit 208 stores low-end device information including the version of software operating on the low-end device 10. For example, when multiple low-end devices 10 are connected to the edge server 20, the device information storage unit 208 stores information on the software operating on each low-end device 10 and the version of the software.

[0023] When there are multiple edge servers 20, the software information storage unit 206 and the device information storage unit 208 may be managed in a synchronized manner. As another example, a storage, a file server, or the like that can be commonly accessed may be provided for the multiple edge servers 20, and the corresponding edge servers 20 may be connectable to this storage, or the like. That is, in FIG. 2 (as well as in the block diagrams used in the following description), the storage unit is provided within the edge server 20, but this is not limiting, and the storage unit may be located outside the edge server 20. The same applies to the storage unit of the low-end device 10.

[0024] 3 is a flowchart showing a non-limiting example of anomaly detection processing of the information processing system 1 according to this embodiment. This flowchart shows processing related to the operation of the anomaly detection unit 204 of the edge server 20, for example.

[0025] First, the anomaly detection unit 204 executes communication regarding the anomaly information with the anomaly information transmission unit 102 (S100). As a non-limiting example, the anomaly detection unit 204 may transmit a response confirmation communication to the anomaly information transmission unit 102, and the anomaly information transmission unit 102 may transmit the anomaly information to the anomaly detection unit 204 in response to the response confirmation communication. As another non-limiting example, the anomaly information transmission unit 102 may transmit the anomaly information to the anomaly detection unit 204 at a fixed or variable period.

[0026] The anomaly detection unit 204 may perform the response confirmation communication, for example, by sending a ping to the anomaly information transmission unit 102. There is no limitation on the communication protocol, and as another example, the response confirmation communication may be performed via communication using a commonly used protocol such as HTTP, HTTPS, Modbus / TCP, or a unique protocol.

[0027] FIG. 4 is a diagram showing an example of a response to the response confirmation communication, that is, anomaly information transmitted from the anomaly information transmission unit 102. In this example, an example of the contents of the anomaly information is described using JSON (JavaScript Object Notation), but the format and description method are not limited to this, and any format that can appropriately describe the necessary contents may be used. As another example, a response confirmation to the response confirmation communication may be implemented in the anomaly detection unit 204 without being filed. Also, the names such as "protocol" and "header" are not limited to these, and the item names may be arbitrary, or the item names may not be defined. As an example, since communication is performed by ping, "protocol" is set to "ping".

[0028] The "source address" in the "header" indicates, for example, the IP address of the sender, and the "destination address" indicates the IP address of the destination. The "header" may contain other header information, for example, header information that depends on the protocol, such as TCP / IP header information, or frame header information, such as the MAC (Media Access Control) address.

[0029] 0:0x1 in "payload" indicates that the 0th byte of the payload is 0x1, 1:0x0 - 0x2 indicates that the 1st byte of the payload is in the range from 0x0 to 0x2, and 2 - 4:0x1 indicates that the 2nd to 4th bytes of the payload are 0x1.

[0030] 3, when anomaly information is received (S102: YES), the anomaly detection unit 204 judges whether or not an anomaly has occurred in the low-end device 10 based on the received anomaly information (S104). The anomaly detection unit 204 checks the contents of the header or payload of the anomaly information and checks whether the contents of the anomaly information are as expected, thereby judging whether or not an anomaly has occurred.

[0031] If no abnormality has occurred (S104: NO), the abnormality detection unit 204 goes into a standby state and continues executing the process from S100.

[0032] If the anomaly detection unit 204 does not receive anomaly information within a predetermined period of time (S102: NO), or if it is determined that an anomaly has occurred based on the received anomaly information (S104: YES), it detects an anomaly (S106). The determination that an anomaly has occurred is performed as follows, as a non-limiting example.

[0033] 4, "timeout" indicates a predetermined period for receiving anomaly information, and indicates a state of waiting for a response for 10 seconds. If the anomaly detection unit 204 does not receive anomaly information as a response from the low-end device 10 within 10 seconds, it determines that an anomaly has occurred (S102: NO).

[0034] The anomaly detection unit 204 refers to the "header" and checks whether the contents of the header of the anomaly information are correct. For example, in the anomaly information in Fig. 4, if the source IP address is different from 192.168.0.1 or the destination IP address is different from 192.168.0.2, the anomaly detection unit 204 determines that an anomaly has occurred (S104: YES). In addition, the anomaly detection unit 204 determines that an anomaly has occurred if the contents of the payload do not match the contents of the above-mentioned "payload" (S104: YES).

[0035] When the anomaly detection unit 204 detects an anomaly (S106), it notifies the rollback request unit 202 of the anomaly. The notification of the anomaly may be, for example, by using a signal, or as another example, by rewriting a value of a pipe, a message queue, a socket, or a memory shared with the rollback request unit 202, or by any other method capable of notifying the rollback request unit 202 of the contents of the anomaly.

[0036] The anomaly detection unit 204 may record the detected anomaly in a file or a database. The anomaly may be recorded and transmitted to the outside via a communication protocol such as HTTP, HTTPS, SMTP, SNMP, etc. As another example, the anomaly detection unit 204 may output the anomaly using various interfaces, for example, displaying the anomaly on an external display device such as a display.

[0037] When notified by the abnormality detection unit 204, the rollback request unit 202 executes a rollback of the software in the low-end device 10.

[0038] FIG. 5 is a flowchart showing an example of the rollback process.

[0039] The rollback request unit 202 starts processing upon receiving a notification that an abnormality has occurred from the abnormality detection unit 204 (S200).

[0040] The rollback request unit 202 acquires information about the low-end device 10 in which the abnormality has occurred from the device information storage unit 208, and also acquires software and a software update information header from the software information storage unit 206 (S202).

[0041] The information about the low-end devices stored in the device information storage unit 208 includes the software running on the low-end devices 10 and version information about the software. This information about the low-end devices may further include information about hardware, such as the CPU type, memory capacity, storage capacity, and memory map, as well as the device name, the OS (Operating System) being used, and the like.

[0042] In the software information storage unit 206, the software and the software change information header are stored in association with the software version described in semantic versioning. The format of the software version is not particularly limited as long as the version can be recognized. The software stored in the software information storage unit 206 may be compressed, encrypted, or variously encoded. In addition, the stored software may be signed, and the differences between versions may be recorded as software.

[0043] 6 is a diagram showing a non-limiting example of a software change information header. The software change information header is described using, for example, JSON, but this format is not limited. The software change information header may also have items other than the "start" and "end" shown in the diagram.

[0044] "Start" indicates the start memory address of the software in the low-end device 10 where the software is to be changed. "End" indicates the end memory address of the software in the low-end device 10 where the software is to be changed.

[0045] The "binary" in "software format" indicates, for example, that the software associated with the software update information can be executed in the processing circuitry of the low-end device 10 by placing the software in its original file state in the memory of the low-end device 10.

[0046] The rollback request unit 202 extracts software version information from the information about the low-end device 10 read from the device information storage unit 208. The rollback request unit 202 acquires information about rollback software, which is information about software associated with a version that is one version older than the extracted version or an earlier version, from the software information storage unit 206. The acquired software may be, for example, a stable version.

[0047] 5, after acquiring various pieces of information, the rollback request unit 202 transmits a rollback request to the low-end device 10 (S204). The rollback request unit 202 transmits the software acquired in S202 and a software update information header to the software update unit 100. The rollback request unit 202 may transmit multiple software update information headers and multiple corresponding pieces of software to the low-end device 10.

[0048] The software update unit 100 that has received the software update information header allocates (maps) the software from 0x1000 to 0x2000 in the memory of the low-end device 10 based on the received software update header.

[0049] The rollback request unit 202 may transmit software that has been encrypted using AES, RSA, or the like to the software modification unit 100. Information regarding the encryption may be added to the software modification information header so that the software modification unit 100 can decrypt the encrypted software. The software modification unit 100 may have a function for decrypting the software based on the information regarding the encryption added to the software modification information header, or the low-end device 10 may be provided with a separate decryptor.

[0050] The rollback request unit 202 may transmit software that has been encoded using, for example, base64 to the software modification unit 100. Information regarding decoding may be added to the software modification information header so that the software modification unit 100 can decode the encoded software. The software modification unit 100 may have a function of decoding the software based on the information regarding decoding added to the software modification information header, or the low-end device 10 may be provided with a separate decoder.

[0051] The rollback request unit 202 may transmit software compressed using a format such as zip, 7z, rar, tar, or lha to the software modification unit 100. Information regarding decompression may be added to the software modification information header so that the software modification unit 100 can decompress the compressed software. The software modification unit 100 may have a function of decompressing the software based on the information regarding decompression added to the software modification information header, or the low-end device 10 may be provided with a separate decompression unit.

[0052] In this way, the software update information header may include various format information related to the software. The software update unit 100 may be configured to convert the update software information into software that can be executed by the low-end device 10 based on the software format information.

[0053] The rollback request unit 202 may transmit software that can be authenticated by attaching a certificate such as X.509 to the software modification unit 100. Information about the certificate may be added to the software modification information header so that the software modification unit 100 can verify whether the software can be authenticated based on the certificate. The software modification unit 100 may have a function of verifying the software based on the information about the certificate added to the software modification information header, or the low-end device 10 may be provided with a separate authentication unit.

[0054] The rollback request unit 202 may transmit the software modification information header with the added signature to the software modification unit 100. The software modification unit 100 may have a function of verifying the signature of the software modification information header based on the signature added to the software modification information header, or the low-end device 10 may be provided with a separate signature verification unit.

[0055] If the software modification is completed normally, the software modification unit 100 transmits a software modification completion response to the rollback request unit 202. If the software modification fails, the software modification unit 100 transmits a software modification failure response to the rollback request unit 202. The software modification failure response may include information recording the cause of the failure. The software modification unit 100 may transmit the above information to the software update request unit 200, and in this case, the software update request unit 200 may transmit this information to the rollback request unit 202.

[0056] The rollback request unit 202 waits a predetermined time after making a rollback request for a software update completion response or a software update failure response from the software update unit 100, and judges whether or not there is a response (S206). For example, the predetermined time may be 10 seconds, and similarly to the above, is not limited to this, and may be a fixed or variable time.

[0057] When the rollback request unit 202 receives a response from the software modification unit 100 (S206: YES), the rollback request unit 202 determines whether the response from the software modification unit 100 is a software modification completion response or a software modification failure response (S208).

[0058] When the rollback request unit 202 receives a software completion response from the software modification unit 100 (S208: NO), it determines that the software modification has been normally executed in the software modification unit 100. The rollback request unit 202 changes the operating software version in the low-end device information to the software version transmitted to the software modification unit 100, and updates the information in the device information storage unit 208 (S210). Additionally, the rollback request unit 202 may update the information in the device information storage unit 208 by changing low-end device information other than the software version.

[0059] On the other hand, if there is no response from the software modification unit 100 for a predetermined time (S206: NO) or if a software modification failure response is received (S208: YES), the rollback request unit 202 determines that the software modification has failed. If the rollback request unit 202 detects a failure of the software modification by the software modification unit 100, it may record the failure in a file or database (S212). The record of the failure may be transmitted to the outside via a communication protocol such as HTTP, HTTPS, SMTP, or SNMP, and information regarding the failure may be displayed or output on an external display device or external output device such as a display on the receiving side. Additionally, the cause of the software modification failure may be recorded as a log.

[0060] FIG. 7 is a flow chart showing a non-limiting example of the processing of the software update request unit 200. As shown in FIG.

[0061] The software update request unit 200 acquires the software version, update software, and software change information header via a medium such as a USB memory or an SD card, or via JTAG, a network, etc. (S300).

[0062] The software update request unit 200 sends the acquired software and a software update information header to the software update unit 100, and sends a software rollback request to the low-end device 10 (S302).

[0063] 5, S304 is the same as S206, S208, S308 is the same as S210, and S312 is the same as S212 in Fig. 5, so details will be omitted. Note that the subject of the operation is the software update request unit 200.

[0064] The software update request unit 200 stores and updates the software version, update source software, and software change information header acquired in S300 in the software information storage unit 206 (S310). This process updates information such as the software and software version to be used as the future rollback destination.

[0065] As described above, according to this embodiment, the low-end device 10 can realize appropriate software rollback based on a request from the edge server 20 .

[0066] (Modification) 8 is a block diagram showing an information processing system 1 according to a modified example of the first embodiment. The low-end device 10 further includes a hang-up notification unit 104 in addition to the configuration of the first embodiment.

[0067] If there is no periodic access from the low-end device 10, the hang-up notification unit 104 determines that the software (including the OS) in the low-end device 10 has hung up, and notifies the edge server 20 that the low-end device 10 has hung up.

[0068] The hang-up notification unit 104 may detect an abnormality by using a configuration for detecting an abnormality such as a watchdog, etc. The hang-up notification unit 104 may also attach at least a part of memory data read from the memory of the low-end device 10 or information such as a core dump to the abnormality notification and transmit it.

[0069] As described above, according to this modified example, if the low-end device 10 hangs up, it becomes possible to quickly perform a rollback.

[0070] Second Embodiment 9 is a block diagram showing an information processing system 1 according to the second embodiment. In the first embodiment, the information processing system 1 is configured by a low-end device 10 and an edge server 20. In the present embodiment, the information processing system 1 further includes a software management console 30.

[0071] The low-end device 10A is connected to the edge server 20A, the low-end device 10B is connected to the edge server 20B, and the low-end device 10C is connected to the edge server 20C. More low-end devices 10 and edge servers 20 may be provided. As a non-limiting example, the low-end device 10A and the low-end device 10B may be connected in a communicable manner. Also, the edge server 20A and the edge server 20B may be connected in a communicable manner. Also, the edge server 20B and the low-end device 10C may be connected. In this way, the low-end device 10 and the edge server 20 may be connected in a manner in which they can communicate with each other.

[0072] The software management console 30 includes, for example, a processing circuit such as a CPU, and a storage unit such as a memory or storage connected to the processing circuit. Each component described below may be a part of the operation of the processing circuit or the storage unit. The software management console 30 is connected to the edge servers 20A, 20B, and 20C by any means. Although only one software management console 30 is shown in FIG. 9, multiple software management consoles 30 may be provided.

[0073] 10 is a block diagram showing a non-limiting example of the configuration of the low-end device 10, the edge server 20, and the software management console 30. Note that in this figure, only one each of the low-end device 10, the edge server 20, and the software management console 30 is shown, but as described above, depending on the configuration, multiple of each may be provided.

[0074] The software management console 30 comprises a verification information transmission unit 300 , a software distribution unit 302 , a rollback determination unit 304 , a rollback registration unit 306 , a verification information storage unit 308 , a distributed software storage unit 310 , and an updated device information storage unit 312 .

[0075] The verification information transmission unit 300 transmits meta-information for software verification to the software verification unit 212 .

[0076] The software distribution unit 302 distributes the software to the overlap rollback determination unit 210 .

[0077] The rollback determination unit 304 simultaneously instructs the edge server group including a plurality of edge servers 20 to perform rollback via the software distribution unit 302 .

[0078] The rollback registration unit 306 registers information on the low-end device group including the multiple low-end devices 10 that have been rolled back and that have been notified by the rollback notification unit 214 of the edge server group.

[0079] The verification information storage unit 308 stores meta-information for software verification.

[0080] The distributed software storage unit 310 stores the distributed software by version.

[0081] The updated device information storage unit 312 stores information on the low-end devices that have been rolled back.

[0082] The edge server 20 includes a duplication rollback determination unit 210, a software verification unit 212, and a rollback notification unit 214 in addition to the configuration of the above-described embodiment.

[0083] The duplicate rollback determination unit 210 skips software updates for low-end devices 10 for which rollback has already been performed.

[0084] The software verification unit 212 verifies the correctness of the updated software.

[0085] The rollback notification unit 214 notifies the rollback registration unit 306 of the rollback of the low-end device 10 .

[0086] The software distribution unit 302 obtains, for example, the latest version of software corresponding to the low-end device 10 from a distributed software storage unit 310 in which software is stored by version. The software distribution unit 302 distributes the software to the duplicate rollback determination unit 210 of each edge server 20. The duplicate rollback determination unit 210 receives the software transmitted from the software distribution unit 302.

[0087] The software distribution unit 302 may start distributing software to the edge server 20 when the software management console 30 receives a request from the edge server 20 or an external request via software such as a web browser, or when the latest version of software is stored in the distribution software storage unit 310.

[0088] When the software management console 30 receives a software update completion notification or a software update failure notification from the edge server 20, the software distribution unit 302 may save the notification in a file, output the notification to an external device such as a display, or send the notification to the outside via a protocol such as HTTP, HTTPS, or SMTP.

[0089] FIG. 11 is a flowchart showing a non-limiting example of the process of the overlap rollback determination unit 210.

[0090] The overlapping rollback determination unit 210 receives the latest version of software from the software distribution unit 302 (S400).

[0091] The overlapping rollback determination unit 210 acquires software version information operating on the low-end device 10 from the low-end device information stored in the device information storage unit 208, and acquires software operating on the low-end device 10 stored in the software information storage unit 206 based on the acquired software version information (S402).

[0092] The duplicate rollback determination unit 210 compares the software acquired in S400 with the software acquired in S402 and determines whether they are the same software (S404). This comparison may be performed using a digest generated for each piece of software using a hash function based on SHA2, SHA3, or the like.

[0093] If the software is different (S404: NO), the software update request unit 200 requests the software update unit 100 to update the software using the software that the overlap rollback determination unit 210 obtained from the software distribution unit 302 (S406).

[0094] If the software is the same (S404: YES), the overlap rollback determination unit 210 may save the fact that the software is the same in a file, or may notify the software management console 30 (software distribution unit 302) or other external devices (S408). In this case, the software update request unit 200 skips the software update.

[0095] FIG. 12 is a flowchart showing a non-limiting example of the processing of the software update request unit 200 according to this embodiment.

[0096] The software update request unit 200 receives the software distributed by the overlap rollback determination unit 210 (S500).

[0097] Next, the software verification unit 212 obtains the software from the software update request unit 200 and verifies the software (S502). The software verification unit 212 may obtain the software from the overlapped rollback determination unit 210.

[0098] If the software verification is successful (S502: YES), the software update request unit 200 notifies the software update unit 100 of the software update request (S504). The subsequent processing is the same as in the previous embodiment. That is, S506 is the same processing as S304, S508 is the same as S306, S510 is the same as S308, and S512 is the same as S310 in FIG. 7.

[0099] On the other hand, if the software verification fails (S502: NO), the rollback request unit 202 may record the failure in a file or database (S514). The process of S514 is similar to the process of S212 in FIG.

[0100] FIG. 13 is a flowchart showing a non-limiting example of the processing of the software verification unit 212 according to this embodiment.

[0101] The software verification unit 212 acquires the software from the software update request unit 200 (S600). As described above, the software verification unit 212 may acquire the software directly from the overlapped rollback determination unit 210.

[0102] The software verification unit 212 requests the verification information transmission unit 300 to send meta-information, which is software verification information (S602). The software verification unit 212 may transmit information such as the software name, the device name of the low-end device 10, or the identification number of the low-end device 10 together with the request. In this case, the verification information transmission unit 300 may obtain information for identifying the software based on the information attached to the request from the verification information storage unit 308 in the following processing, and transmit the information to the software verification unit 212.

[0103] The software verification unit 212 waits to receive software verification information from the verification information transmission unit 300 (S604), and if there is no response within a predetermined period of time, for example 10 seconds, it determines that the software verification has failed (S604: NO) and executes the processing of S610.

[0104] If there is a response (S604: YES), the verification information transmission unit 300 may attempt to acquire software verification information based on the request from the software verification unit 212, and transmit a notification of whether or not the acquisition was successful to the software verification unit 212. The software verification unit 212 receives this notification from the verification information transmission unit 300 and determines whether or not the verification information was successfully acquired (S606).

[0105] If the received notification is a notification that acquisition of software verification information has failed, the software verification unit 212 determines that software verification has failed (S606: YES), and executes the process of S610.

[0106] If the response is not a failure (S606: YES), the software verification unit 212 verifies the software based on the software verification information in, for example, X.509 format received from the verification information transmission unit 300 (S608). The software verification information may be in a format other than X.509 format, and the format is not important as long as it is information for appropriately verifying the validity or integrity of the software.

[0107] The software verification unit 212 may save the verification result or the success or failure of acquiring the software verification information in a file (S610). The verification result, etc. may be notified to the software management console 30 (verification information transmission unit 300) or other external devices via a protocol such as HTTP, HTTPS, SMTP, etc. The verification result, etc. may also be output to an external device such as a display. The process of S610 may be executed only if the verification is successful or only if the verification is unsuccessful.

[0108] The software verification unit 212 transmits the verification result to the software update request unit 200 (S612).

[0109] The verification information transmission unit 300 may acquire software verification information of the latest software from the verification information storage unit 308 in accordance with a request from the software verification unit 212. The verification information transmission unit 300 may send the acquired software verification information to the software verification unit 212. The verification information storage unit 308 may store the software verification information in association with the software name, the device name of the low-end device 10, the identification number of the low-end device 10, etc. The verification information transmission unit 300 may acquire the software verification information in accordance with a request from the software verification unit 212 based on the software name, the device name of the low-end device 10, the identification number of the low-end device 10, etc.

[0110] FIG. 14 is a flowchart showing a non-limiting example of the processing of the rollback request unit 202 in this embodiment.

[0111] The processes from S700 to S710 and S714 are similar to the processes from S200 to S212 in FIG. 5, respectively.

[0112] After the rollback request unit 202 changes the operating software version in the low-end device information to the software version sent to the software update unit 100 and updates the information in the device information storage unit 208 (S710), the following process is executed.

[0113] The rollback request unit 202 notifies the rollback notification unit 214 of the rolled back software version and the identification number of the low-end device 10 that has been rolled back (S712). The identification number of the low-end device 10 may be the name of the low-end device 10, and there are no limitations on the content or format as long as it can identify the low-end device 10.

[0114] The rollback notification unit 214 transmits the software version and the identification number of the low-end device 10 that has been rolled back to the rollback registration unit 306. The rollback notification unit 214 may also transmit information such as the details of the abnormality recorded in a file by the abnormality detection unit 204, the type of the low-end device 10, or the service name of the low-end device 10 to the rollback registration unit 306.

[0115] The rollback registration unit 306 stores the software version sent from the rollback notification unit 214 and information about the low-end device 10, such as the identification number of the low-end device 10 that has been rolled back, in the updated device information storage unit 312. Furthermore, the rollback registration unit 306 notifies the rollback determination unit 304 of the occurrence of a rollback.

[0116] FIG. 15 is a flowchart showing a non-limiting example of the process of the rollback determination unit 304 according to this embodiment.

[0117] The rollback determination unit 304 starts operation upon receiving a notification from the rollback registration unit 306 (S800). The rollback determination unit 304 may also be configured to be started periodically, regardless of a notification from the rollback registration unit 306. When started arbitrarily, the rollback determination unit 304 may be started via, for example, a button on a web browser or the like.

[0118] The rollback determination unit 304 acquires rollback device information from the update device information storage unit 312 (S802).

[0119] The rollback determination unit 304 determines the necessity of a rollback instruction for the low-end devices 10 based on the rollback device information (S804). The rollback determination unit 304 may make the determination by, for example, comparing the number of low-end devices 10 that have been rolled back with a predetermined value. For example, when there are three low-end devices 10 as in the configuration shown in Fig. 9, two may be set as the threshold value. In other words, when two of the three low-end devices 10 are listed in the rollback device information, the rollback determination unit 304 may determine that a rollback instruction is necessary.

[0120] The number of low-end devices 10 may be more than or less than 3. The predetermined value used as the threshold may be more than or less than 2, or may be expressed as a percentage. Furthermore, this threshold may be dynamic, changing depending on conditions, etc.

[0121] The rollback determination unit 304 may use information other than the number of rolled back devices to determine the necessity of a rollback instruction. For example, the rollback determination unit 304 may use a model trained by a machine learning algorithm such as deep learning, a decision tree, or a support vector machine that uses information described in the rollback device information to determine the necessity of a rollback.

[0122] If it is determined that rollback is not necessary (S804: NO), the process may end.

[0123] If it is determined that a rollback is necessary (S804: YES), the rollback determination unit 304 updates (S806) the acquired rollback device information by deleting it from the update device information storage unit 312. The rollback determination unit 304 may update the information by adding version information or the like to the rollback device information without deleting it, leaving it in the update device information storage unit 312 as old rollback device information, or as another example, may store the rollback device information in an external storage medium.

[0124] The rollback determination unit 304 updates the distributed software (S808). For example, the rollback determination unit 304 obtains software from the distributed software storage unit 310 based on the software version obtained from the rollback device information, and obtains the latest version of the software registered in the distributed software storage unit 310. For example, the rollback determination unit 304 updates the latest version obtained from the distributed software storage unit 310 to a newer latest version, and stores the software obtained from the distributed software storage unit 310 and the latest version in association with each other in the distributed software storage unit 310.

[0125] The rollback determination unit 304 generates software verification information for the software obtained from the distributed software storage unit 310, and stores the generated software verification information in the verification information storage unit 308 (S810).

[0126] The rollback determination unit 304 requests the software distribution unit 302 to update the software (S812). The rollback determination unit 304 may record in a file that it has determined that a rollback is necessary. The rollback determination unit 304 may also transmit the determination that a rollback is necessary to the outside via a protocol such as HTTP, HTTPS, or SMTP, or may display the result on an external device such as a display. Furthermore, an external device or a person who receives the transmission result may request the software distribution unit 302 to update the software via various interfaces.

[0127] The process of S806 may be executed between or after the processes of S808 to S812, with the order reversed. Also, the process of S810 may be executed before the process of S808 or after the process of S812.

[0128] As described above, according to this embodiment, by providing the software management console 30, when a rollback occurs in a plurality of low-end devices, it is possible to apply a rollback to the low-end devices before the rollback occurs. Also, it is possible to implement a rollback in cooperation with an update system that requests an update to the latest software.

[0129] Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included in the scope and spirit of the invention, and are included in the scope of the invention and its equivalents described in the claims. [Explanation of symbols]

[0130] 1: Information processing system, 10: Low-end equipment, 100: Software Modification Department, 102: Anomaly information transmission unit, 104: Hangup notification section, 20: Edge server, 200: Software update request section, 202: Rollback request section, 204: Anomaly detection unit, 206: Software information storage unit, 208: Device information storage section, 210: duplicate rollback determination unit, 212: Software Verification Department, 214: Rollback notification section, 30: Software Management Console, 300: Verification information transmission unit, 302: Software Distribution Division, 304: Rollback decision unit, 306: Rollback registration unit, 308: Verification information storage unit, 310: distribution software storage unit, 312: Update device information storage section

Claims

1. one or more edge servers having a storage unit and a processing circuit; one or more low-end devices having a storage unit and a processing circuit, the low-end devices being coupled to at least one of the edge servers and configured to change software upon request from the edge server; Equipped with The processing circuit of the low-end device Transmitting anomaly information for detecting anomalies in the device to the edge server; The storage unit of the edge server Information regarding the software by version; low-end device information including a version of the software running on the low-end device; Store the The processing circuit of the edge server includes: Detecting an abnormality in the low-end device based on the abnormality information acquired from the low-end device; acquiring version information of the software of the low-end device stored in the storage unit based on the detected abnormality, and acquiring information on rollback software, which is software of an older version than the version in the version information and which operates on the low-end device, from the storage unit; requesting the low-end device to roll back the software based on information about the rollback software; The information about the software includes memory information about where the software is located, The processing circuit of the low-end device mapping the software into memory based on the memory information; Information processing system.

2. a software management console having a storage unit and a processing circuit, the software management console being coupled to the edge server; Further equipped with When a rollback of the low-end device is requested, The processing circuit of the edge server transmits rollback device information including information about the rolled back low-end device to the software management console; the processing circuit of the software management console stores the received rollback device information in a storage unit of the software management console; 2. The information processing system according to claim 1.

3. The processing circuit of the edge server includes: when a request is made to update the software of the low-end device to update software, a version of the update software, software information of the update software, and information on the low-end device based on the update software are stored in a storage unit of the edge server; 3. The information processing system according to claim 2.

4. The storage unit of the software management console includes: Store distribution software by version, The processing circuitry of the software management console includes: Distributing the distribution software to the edge server; determining the necessity of rollback for the low-end device based on the rollback device information acquired from the storage unit of the software management console; 4. An information processing system according to claim 3.

5. The processing circuitry of the software management console further comprises: storing the distributed software as the update software in a storage unit of the software management console for the low-end device for which it has been determined that rollback is necessary; 5. An information processing system according to claim 4.

6. The processing circuitry of the software management console further comprises: determining whether or not rollback is necessary when the number of the low-end devices that have been rolled back exceeds a predetermined value; 6. An information processing system according to claim 5.

7. The processing circuit of the edge server includes: In response to a software update request for the low-end device from the software management console, verifying the update software based on software verification information having information for verifying software including software signature information for the update software; The storage unit of the software management console includes: storing the software verification information; The processing circuitry of the software management console includes: Sending the software verification information to the edge server; if it is determined that a rollback is necessary, storing software verification information of the rollback software in a storage unit of the software management console; 7. An information processing system according to claim 5 or 6.

8. The processing circuit of the edge server includes: performing a duplicate rollback determination for skipping a software update in response to a software update request from the software management console to the low-end device when the same software as that requested for the software update is already running in the low-end device; 8. An information processing system according to claim 7.

9. The information about the software includes software signature information; The processing circuit of the low-end device verifying information about the software based on the software signature information; An information processing system according to any one of claims 1 to 8.

10. The information about the software includes software format information; The processing circuit of the low-end device converting information about the software into software executable on the low-end device based on the software format information; An information processing system according to any one of claims 1 to 9.

11. The software format information is information regarding encryption, encoding, or compression.

11. The information processing system according to claim 10.

12. The processing circuit of the low-end device When an abnormal state occurs, notify the edge server of the occurrence of the abnormality. An information processing system according to any one of claims 1 to 11.

13. The processing circuit of the low-end device Transmitting memory data read from the memory of the low-end device at the timing of notification of the occurrence of an abnormality.

13. An information processing system according to claim 12.

14. the abnormality information is a TCP / IP protocol message, The storage unit of the edge server Stores anomaly detection configuration files that describe TCP / IP header information, TCP / IP payload information, and timeout times. The processing circuit of the edge server includes: Detecting an anomaly when the header information and the payload information of the anomaly information are different from those in the anomaly detection setting file, or when a period for receiving the anomaly information is different from the period described in the anomaly detection setting file. An information processing system according to any one of claims 1 to 13.

15. The processing circuit of the edge server includes: The cause of the abnormality is stored as a log in a storage unit of the edge server. An information processing system according to any one of claims 1 to 14.

16. a storage unit that stores information about software for each version that operates in a connected low-end device, and low-end device information including the version of the software that operates in the low-end device; A processing circuit connected to the storage unit; Equipped with The processing circuitry includes: Acquiring abnormality information from the low-end device; Detecting an abnormality in the low-end device based on the abnormality information acquired from the low-end device; acquiring version information of the software of the low-end device stored in the storage unit based on the detected abnormality, and acquiring information on rollback software, which is software of an older version than the version in the version information and which operates on the low-end device, from the storage unit; requesting the low-end device to roll back the software based on information about the rollback software; The information about the software includes memory information about a memory in which the software is arranged, and the software is mapped to a memory in the low-end device based on the memory information. Information processing device.

17. a storage unit that stores information about software for each version that operates in a connected low-end device, and low-end device information including the version of the software that operates in the low-end device; A processing circuit connected to the storage unit; In an information processing device comprising: The processing circuitry includes: Acquiring abnormality information from the low-end device; Detecting an abnormality in the low-end device based on the abnormality information acquired from the low-end device; acquiring version information of the software of the low-end device stored in the storage unit based on the detected abnormality, and acquiring information on rollback software, which is software of an older version than the version in the version information and which operates on the low-end device, from the storage unit; requesting the low-end device to roll back the software based on information about the rollback software; The information about the software includes memory information about a memory in which the software is arranged, and the software is mapped to a memory in the low-end device based on the memory information. A program that executes a process.

Citation Information

Patent Citations

  • Equipment management system

    JP2001282544A

  • Firmware upgrade error detection and automatic rollback

    JP2014130585A

  • Communication system, communication device, communication method, and program

    JP2018014629A