Information Processing Apparatus, Information Processing Method, and Program

The information processing apparatus addresses the challenges of updating and securing BIOS golden copies by allowing secure updates and preventing tampering, ensuring the BIOS is restored to a secure and updated state efficiently.

JP7696707B2Active Publication Date: 2025-06-23CANON KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2020181103
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-10-29
Publication Date
2025-06-23
Estimated Expiration
2040-10-29

AI Technical Summary

Technical Problem

Existing methods for updating and securing BIOS golden copies are inadequate, as they cannot be updated from the CPU and may lead to restoring outdated versions with known vulnerabilities, and the hash value comparison process increases startup time.

Method used

An information processing apparatus that stores the first software in a first storage medium accessible by both the CPU and the embedded controller, and the second software for recovery in a second storage medium accessible only by the embedded controller. This apparatus includes a first update means for updating the second software based on version information comparison, a tampering detection means, and a recovery means to restore the first software when tampering is detected.

Benefits of technology

The solution enables secure updates of the BIOS golden copy while preventing tampering, ensuring that the BIOS is restored to a secure and updated state, and reducing startup time by eliminating unnecessary hash value comparisons.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007696707000001
    Figure 0007696707000001
  • Figure 0007696707000002
    Figure 0007696707000002
  • Figure 0007696707000003
    Figure 0007696707000003
Patent Text Reader

Abstract

To enable both preventing an alteration of second software to be used for recovering first software, and performing secure update of the second software.SOLUTION: Provided is an information processing device which stores first software into a first storage medium accessible by a CPU and an embedded controller, and stores second software used for recovering the first software into a second storage medium accessible only by the embedded controller, including: first update means for, in accordance with a comparison result between version information of the first software and version information of the second software, updating the second software using the first software; alteration detection means for detecting presence / absence of an alteration in the first software; and recovery means for, when the alteration detection means detects the presence of the alteration in the first software, recovering the first software using the second software.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information processing method, and a program.

Background Art

[0002] There are problems with attacks in which a third party illegally modifies software that controls an information processing apparatus to steal information assets within the information processing apparatus, or attacks that use an information processing apparatus with modified software as a stepping stone. In order to prevent such attacks, methods have been devised to verify that the software within the information processing apparatus has not been modified by a third party. Furthermore, methods have also been devised to recover the software when software modification is detected. BIOS (Basic Input Output System) and UEFI (Unified Extensible Firmware Interface) are software that first starts up an information processing apparatus. Since BIOS and UEFI are in the initial startup stage and basic functions such as network functions cannot be used, the recovery means are limited. Note that since BIOS is software related to the startup of an information processing apparatus, it may be referred to as boot code.

[0003] In Patent Document 1, a modification of system firmware (BIOS) held in a first memory by an embedded controller is detected. When the embedded controller determines that it has been modified, it overwrites and recovers the system firmware held in the first memory with the recovery system firmware (BIOS golden copy) held in a second memory in advance. Due to the recovery process, the startup BIOS held in the first memory returns to a state where it has not been modified, so that the information processing apparatus can be normally started up. Note that the first memory is accessible from the CPU, but in order to prevent unauthorized rewriting of the BIOS golden copy, the second memory has a bus configuration that can only be accessed by the embedded controller.

[0004] In Patent Document 1, the BIOS in the first memory and the BIOS golden copy in the second memory are controlled by a policy so that they are the same. For example, in the case where the policy permits rewriting of the BIOS golden copy, the hash values of the BIOS in the first memory and the BIOS golden copy in the second memory are compared. And when the hash values are different, the BIOS golden copy in the second memory is overwritten with the BIOS in the first memory to make them the same.

[0005] Also, as a known technique, there is a technique in which after the OS (Operation System) is started, the CPU starts BIOS update data to update the BIOS.

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] However, Patent Document 1 does not mention a method for updating the BIOS golden copy. Even if we try to update the BIOS golden copy by combining the known BIOS update method with Patent Document 1, the BIOS golden copy cannot be updated because it cannot be accessed from the CPU. If it cannot be updated, the BIOS golden copy will remain old, and there is a risk of restoring the BIOS with an old version that has known vulnerabilities.

[0008] In Patent Document 1, when the policy permits rewriting of the BIOS golden copy, if the BIOS is updated with a known technique and restarted, the BIOS golden copy can also be updated in Patent Document 1. However, it is not always updated to the latest version. For example, when the BIOS is rolled back (rewritten) to an old version and restarted, the BIOS golden copy is also rolled back to the old version. Further, when the policy does not permit rewriting of the BIOS golden copy, conversely, the updated BIOS is overwritten with the old BIOS golden copy.

[0009] Also, in the case of Patent Document 1, in order to make both the BIOS and the BIOS golden copy identical, the hash value calculation and comparison process of the BIOS and the BIOS golden copy are always performed, increasing the startup time (usually increasing by about 1 second).

[0010] An object of the present invention is to enable both prevention of tampering with a second software used for recovery of a first software and secure update of the second software.

Means for Solving the Problems

[0011] The information processing apparatus of the present invention stores a first software in a first storage medium accessible by a CPU and an embedded controller, and stores a second software used for recovery of the first software in a second storage medium accessible only by the embedded controller, the information processing apparatus comprising: a first update means for updating the second software in the second storage medium with the first software in the first storage medium according to a comparison result between version information of the first software and version information of the second software; a tampering detection means for detecting whether or not the first software has been tampered with; and when it is detected by the tampering detection means that the first software has been tampered with, Do not perform the update by the first update means, a recovery means for recovering the first software with the second software.

Advantages of the Invention

[0012] According to the present invention, it is possible to achieve both prevention of forgery of the second software used for recovery of the first software and secure update of the second software.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments according to the present invention will be described in detail with reference to the drawings. In this embodiment, the processing when the information processing apparatus updates the golden copy, which is the software for recovery, will be described. In this embodiment, an MFP (Multi-Function Peripheral), which is an image forming apparatus, will be described as an example of the information processing apparatus, but this embodiment is also applicable to information processing apparatuses other than the multi-function peripheral. Further, BIOS will be described as an example of the software, but it is also applicable to the update of the golden copy of the firmware of, for example, a NIC (Network Interface Card).

[0015] (First Embodiment) [Device Configuration of the First Embodiment] FIG. 1 is a block diagram showing an example of the connection between the MFP 100 and the client PC 110 according to the first embodiment. The MFP 100 is a multifunction device and an example of an information processing apparatus. The client PC 110 is a client personal computer. The MFP 100 and the client PC 110 are connected via the LAN 120. The MFP 100 has an operation unit 102 that performs input / output operations for the user. The MFP 100 has a printer unit 103 that prints electronic data on a paper medium. The MFP 100 has a scanner unit 104 that reads a paper medium and converts it into electronic data. The MFP 100 has a controller unit 101. The operation unit 102, the printer unit 103, and the scanner unit 104 are connected to the controller unit 101 and realize the functions as a multifunction device according to the control of the controller unit 101. The client PC 110 performs processes such as sending a print job to the MFP 100.

[0016] FIG. 2 is a block diagram showing a configuration example of the controller unit 101 of the MFP 100. The controller unit 101 has a CPU 201, a DRAM 202, an I / O controller 203, a network I / F 204, and a SATA (Serial Advanced Technology Attachment) I / F 205. Further, the controller unit 101 has a panel I / F 206, a printer I / F 207, a scanner I / F 208, a USB I / F 209, a wired LAN device 210, and a flash ROM (read-only memory) 211. Further, the controller unit 101 has an embedded controller 212, a first SPI flash memory 213, and a second SPI flash memory 214.

[0017] The CPU 201 performs the main arithmetic processing within the controller unit 101. The CPU 201 is connected to the DRAM 202 via a bus. The DRAM 202 is used by the CPU 201 as a working memory for temporarily storing a program representing an arithmetic instruction and data to be processed during the arithmetic operation by the CPU 201. The CPU 201 is connected to the I / O controller 203 via a bus. The I / O controller 203 performs input / output operations on various devices according to the instructions of the CPU 201.

[0018] The SATA I / F 205 is connected to the I / O controller 203. The flash ROM 211 is connected to the SATA I / F 205. The flash ROM 211 permanently stores a program for realizing the functions of the MFP 100 and document files.

[0019] The network I / F 204 is connected to the I / O controller 203. The wired LAN device 210 is connected to the network I / F 204. The CPU 201 realizes communication on the LAN 120 in FIG. 1 by controlling the wired LAN device 210 via the network I / F 204.

[0020] The panel I / F 206 is connected to the I / O controller 203. The CPU 201 realizes user-oriented input / output operations on the operation unit 102 in FIG. 1 via the panel I / F 206.

[0021] The printer I / F 207 is connected to the I / O controller 203. The CPU 201 realizes printing processing on paper media using the printer unit 103 in FIG. 1 via the printer I / F 207.

[0022] The scanner I / F 208 is connected to the I / O controller 203. The CPU 201 realizes the process of reading a document using the scanner unit 104 in FIG. 1 via the scanner I / F 208. The USB I / F 209 is connected to the I / O controller 203. The CPU 201 controls any device connected to the USB I / F 209.

[0023] The first SPI flash memory 213 is connected to the CPU 201 via a bus and stores the BIOS 360, which will be described later with reference to FIGS. 3 and 4. The second SPI flash memory 214 stores the BIOS golden copy 403, which is the BIOS used for restoring the BIOS 360, which will be described later with reference to FIG. 4. SPI is an abbreviation for Serial Peripheral Interface. The first SPI flash memory 213 is exemplified as the first storage medium, and the second SPI flash memory 214 is exemplified as the second storage medium and will be described. However, the first and second storage media do not necessarily have to be SPI flash memories, and other types of flash memories or storage media having similar functions may be used.

[0024] The embedded controller 212 is the hardware chip that starts up first after the power switch of the MFP 100 is pressed. The embedded controller 212 performs forgery detection of the BIOS 360, restoration of the BIOS 360 using the BIOS golden copy 403, and update processing of the BIOS golden copy 403. The embedded controller 212 is a microcontroller that can operate independently of the CPU 201 and has a CPU, a ROM, a RAM, and other memories separately inside, so it can perform arithmetic processing independently. The embedded controller 212 is connected to the first SPI flash memory 213, the second SPI flash memory 214, and the CPU 201 via a bus. After completion of forgery detection of the BIOS 360, update processing of the BIOS golden copy 403, etc., the embedded controller 212 sends a reset signal to the CPU 201 to wake up the CPU 201 and transfer control. After transferring control to the CPU 201, the embedded controller 212 enters a sleep state.

[0025] When the copy function is executed, the CPU 201 reads program data (module data) from the flash ROM 211 via the SATA I / F 205 and stores it in the DRAM 202. The CPU 201 detects a copy instruction from the user to the operation unit 102 via the panel I / F 206 according to the program (module) stored in the DRAM 202. When the CPU 201 detects the copy instruction, it receives the document from the scanner unit 104 as image data via the scanner I / F 208 and stores it in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207 and performs printing processing on the paper medium.

[0026] When PDL printing is executed, the client PC 110 issues a printing instruction via the LAN 120. The CPU 201 reads module data from the flash ROM 211 via the SATA I / F 205 and stores it in the DRAM 202, and detects the printing instruction via the network I / F 204 according to the module stored in the DRAM 202. When the CPU 201 detects the PDL transmission instruction, it receives the printing data via the network I / F 204 and stores the printing data in the flash ROM 211 via the SATA I / F 205. When the storage of the printing data is completed, the CPU 201 expands the printing data stored in the flash ROM 211 as image data in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207 and performs printing processing on the paper medium.

[0027] Hereinafter, the functional configuration and the update processing flow of the BIOS golden copy in the present embodiment will be described.

[0028] [Functional Configuration of the First Embodiment] FIG. 3 is a diagram showing a functional configuration example realized by software executed by the controller unit 101 of the MFP 100. Note that, among the software executed by the controller unit 101, only the embedded controller software 350 is executed by the embedded controller 212, and the rest are all executed by the CPU 201. The BIOS 360, the loader 370, the initrd 380, the kernel 390, and the controller software 300 are executed by the CPU 201.

[0029] The embedded controller 212 executes the embedded controller software 350. Note that the storage location of the embedded controller software 350 may be any location where the embedded controller 212 can read and execute it. For example, the embedded controller software 350 may be stored in the ROM included in the embedded controller 212, or may be stored in the first SPI flash memory 213 or the second SPI flash memory 214.

[0030] First, the functions of the embedded controller software 350 will be described. The embedded controller software 350 includes a forgery detection unit 351, a recovery unit 352, a version comparison unit 353, a first update unit 354, and an unauthorized rewrite prevention unit 355.

[0031] The forgery detection unit 351 uses the first signature value 402, which will be described later in FIG. 4 and is held by the first SPI flash memory 213, to verify whether the BIOS 360 has been forged. As a signature verification method, for example, a signature verification algorithm using the RSA public key cryptosystem, which is a known technique, or an ECDSA signature verification algorithm using the elliptic curve public key cryptosystem can be used. The public key used for signature verification may be held in the ROM included in the embedded controller 212, or may be held in the first SPI flash memory 213 or the second SPI flash memory 214. In addition, the forgery detection unit 351 also has a function of verifying whether the BIOS golden copy 403 has been forged using the second signature value 405, which will be described later in FIG. 4 and is held by the second SPI flash memory 214.

[0032] When the modification detection unit 351 detects the modification of the BIOS 360, the restoration unit 352 has a function of restoring the BIOS 360 by using the BIOS golden copy 403 held in the second SPI flash memory 214. As a restoration method, for example, it can be realized by erasing the BIOS 360 in the first SPI flash memory 213 and writing the BIOS golden copy 403 read from the second SPI flash memory 214 into the empty area. Since the BIOS golden copy 403 is copy data of the BIOS 360, by overwriting the modified BIOS 360 with the BIOS golden copy 403 in this way, the BIOS 360 can be restored to a normal state. At that time, similarly, the first signature value 402 in the first SPI flash memory 213 is also overwritten with the second signature value 405 in the second SPI flash memory 214.

[0033] The version comparison unit 353 compares the first version information 401 and the second version information 404 in FIG. 4. The first version information 401 is the version information of the BIOS 360 held by the first SPI flash memory 213. The second version information 404 is the version information of the BIOS golden copy 403 held by the second SPI flash memory 214. As the version information, generally used version information can be applied. For example, it can be expressed as an increasing value representing the software update and release history in chronological order. Specifically, when the current version information of the BIOS is "1.0", the version information of the BIOS updated and released due to bugs, function additions, vulnerability fixes, etc. can be realized as a numerical value incremented to "1.1". In this case, as a result of comparing the version information, since "1.1" > "1.0", it can be determined that the BIOS with the version information "1.1" is a newer BIOS. The version comparison unit 353 can determine which version of the BIOS 360 and the BIOS golden copy 403 is newer by comparing the first version information 401 and the second version information 404. The above version information is just an example, and numbers and alphabets can be combined. For example, by setting the current version to "1.0a" and the new version to "1.0b", the order of the alphabets (the magnitude relationship of a < b < c < ··· < z) can also be used as an expression of the chronological update history.

[0034] When the version comparison unit 353 determines that the BIOS 360 is a newer version than the BIOS golden copy 403, the first update unit 354 uses the BIOS 360 to update the BIOS golden copy 403. As a specific update method, for example, it can be realized by erasing the BIOS golden copy 403 in the second SPI flash memory 214 and writing the BIOS 360 read from the first SPI flash memory 213 into the area emptied by the erasure. The first update unit 354 overwrites the second signature value 405 of the second SPI flash memory 214 with the first signature value 402 of the first SPI flash memory 213, thereby rewriting it to the signature value corresponding to the updated BIOS golden copy 403. Similarly, the second version information 404 of the second SPI flash memory 214 is also rewritten to the first version information 401 of the first SPI flash memory 213. In this embodiment, as shown in FIG. 4, the BIOS 360 includes the first version information 401, and the BIOS golden copy 403 includes the second version information 404. Therefore, simultaneously with the rewriting of the BIOS golden copy 403, the second version information 404 is also rewritten with the first version information 401.

[0035] The anti-tampering unit 355 protects the BIOS golden copy 403 and the second signature value 405 from unauthorized rewrite commands to the second SPI flash memory 214. If the BIOS golden copy 403 and the second signature value 405 are tampered with by unauthorized rewrite commands, the BIOS 360 cannot be restored properly, so protection is necessary. As a protection method, the Write Protect function provided by a known SPI flash memory can be used. The Write Protect function includes a software Write Protect function that can be controlled at the software level and a hardware Write Protect function that can only be controlled at the hardware level. When protection by Write Protect is set, all Write commands to the second SPI flash memory 214 are rejected on the side of the second SPI flash memory 214, and writing becomes impossible. In the case of protection by the software Write Protect function, commands for setting and releasing protection by Write Protect can be sent from the CPU 201 or the embedded controller 212 to the second SPI flash memory 214. On the other hand, in the case of hardware Write Protect, the setting and release of Write Protect cannot be performed unless the pins of the embedded controller 212 are physically operated. In this embodiment, the anti-tampering unit 355 enables both the update and protection of the BIOS golden copy 403 by transmitting commands for setting and releasing Write Protect to the second SPI flash memory 214 using the software Write Protect function. Specifically, the Write Protect of the second SPI flash memory 214 is released only during the update by the first update unit 354, and after the update is completed, the Write Protect of the second SPI flash memory 214 is reset. Thereby, except during the update, the second SPI flash memory 214 is in a protected state by Write Protect.

[0036] After the processing of the functions described above is completed, the embedded controller software 350 transmits a reset signal to the CPU 201 and enters the sleep state in order to transfer control to the CPU 201.

[0037] Next, the functions executed by the CPU 201 will be described. The CPU 201 executes the BIOS 360 stored in the first SPI flash memory 213. The CPU 201 reads the loader 370, initrd 380, and controller software 300 stored in the flash ROM 211 into the DRAM 202 and then executes them. The BIOS 360 executes basic processes for the CPU 201 to control the I / O controller 203 and the DRAM 202. Further, the BIOS 360 reads the loader 370 from the flash ROM 211 and includes processes to start. The loader 370 reads the kernel 390 of the OS according to the startup mode described later and the initrd 380 from the flash ROM 211 and executes processes to start. The initrd 380 reads the controller software 300 from the flash ROM 211 and executes processes to start.

[0038] The controller software 300 includes an operation control unit 301, a data storage unit 302, a job control unit 303, an image processing unit 304, a printing processing unit 305, and a reading processing unit 306. Further, the controller software 300 includes a network control unit 307, a TCP / IP control unit 308, a USB control unit 309, and a second update unit 310.

[0039] The operation control unit 301 displays a screen image for the user on the operation unit 102 and executes detection of user operations and processes associated with screen components such as buttons displayed on the screen. The data storage unit 302 stores and reads data in the flash ROM 211 in response to requests from other control units. For example, when the user wants to change some device settings, the operation control unit 301 detects the content input by the user on the operation unit 102, and at the request from the operation control unit 301, the data storage unit 302 saves the content as a set value in the flash ROM 211.

[0040] The job control unit 303 controls the execution of jobs according to instructions from other control units. The image processing unit 304 processes image data into a format suitable for each use according to instructions from the job control unit 303. The printing processing unit 305 prints an image on a paper medium via the printer I / F 207 according to instructions from the job control unit 303. The reading processing unit 306 reads the installed document via the scanner I / F 208 according to instructions from the job control unit 303.

[0041] The network control unit 307 performs network settings such as IP addresses on the TCP / IP control unit 308 at the time of system startup or when a setting change is detected according to the set values stored in the data storage unit 302. The TCP / IP control unit 308 performs transmission and reception processing of network packets via the network I / F 204 according to instructions from other control units. The USB control unit 309 controls the USB I / F 209 and controls any device connected via USB.

[0042] The second update unit 310 updates the BIOS 360 held by the first SPI flash memory 213. As a specific update method, for example, it can be realized by overwriting the BIOS 360 in the first SPI flash memory 213 with the update BIOS obtained via the network or via a USB memory. Similarly, the first version information 401 and the first signature value 402 in the first SPI flash memory 213 are also updated with the version information and signature value of the update BIOS attached to the update BIOS. After the BIOS update process is completed, the second update unit 310 requests a restart in order to update the BIOS golden copy 403 by the first update unit 354 described above.

[0043] FIG. 4 is a diagram illustrating data stored in a first SPI flash memory 213 which is a first storage medium and a second SPI flash memory 214 which is a second storage medium. The first SPI flash memory 213 accessible by the CPU 201 and the embedded controller 212 stores a BIOS 360, first version information 401, and a first signature value 402. In the present embodiment, the version information of the BIOS 360 is described as being included in the BIOS 360 as the first version information 401, but this is merely an example. As will be described later in a modified example, the first version information 401 may be held in the first SPI flash memory 213 in a form separate from the BIOS 360 without being included in the BIOS 360. The first signature value 402 is a digital signature value related to the BIOS 360 and is used to verify the presence or absence of forgery of the BIOS 360 by the forgery detection unit 351 as described above. As shown in FIG. 4, by including the first version information 401 in the BIOS 360, the first signature value 402 becomes a signature value for the entire binary data of the BIOS 360 including the first version information 401. Therefore, by verifying the presence or absence of forgery by the forgery detection unit 351, it is also possible to verify the presence or absence of forgery of the first version information 401 included in the BIOS 360.

[0044] On the other hand, the second SPI flash memory 214 that can be accessed only by the embedded controller 212 stores the BIOS golden copy 403, the second version information 404, and the second signature value 405. In the present embodiment, as described above, the version information of the BIOS golden copy 403 is described as being included in the BIOS golden copy 403 as the second version information 404. Similarly, the second signature value 405 is a digital signature value for the entire BIOS golden copy 403 including the second version information 404. Here, the BIOS golden copy 403 is binary data used to restore the BIOS 360 to a normal state in the recovery unit 352 as described above. The BIOS golden copy 403, the second version information 404, and the second signature value 405 are the same binary data as the BIOS 360, the first version information 401, and the first signature value 402 in the first SPI flash memory 213, respectively. Usually, as described above, the two are the same binary data unless there is tampering, data loss, or it is not a startup immediately after a BIOS update.

[0045] [Processing Flow of the First Embodiment] FIG. 5(A) is a flowchart showing an information processing method of the MFP 100 and shows the update process of the BIOS golden copy 403. In step S501, after the power switch of the MFP 100 is pressed, first, the embedded controller 212 starts the embedded controller software 350. Thereafter, the CPU 201 starts the BIOS 360, the loader 370, the initrd 380, and the kernel 390 to start the OS.

[0046] In step S502, after the OS is started, the second update unit 310 acquires the latest BIOS via the network or the like and updates (renews) the BIOS 360. In step S503, the second update unit 310 restarts the MFP 100. In step S504, after the restart, the embedded controller 212 starts.

[0047] In step S505, the forgery detection unit 351 uses the first signature value 402 to detect whether the BIOS 360 has been forged by signature verification. In step S506, if the forgery detection unit 351 succeeds in signature verification, it determines that the BIOS 360 has not been forged and proceeds to step S507. Also, if the forgery detection unit 351 fails in signature verification, it determines that the BIOS 360 has been forged and proceeds to step S509.

[0048] In step S507, the MFP 100 performs an update process on the BIOS golden copy 403 and proceeds to step S508. The details of step S507 will be described later with reference to FIG. 5(B).

[0049] In step S508, the MFP 100 performs a BIOS startup process and ends the process of the flowchart in FIG. 5(A). The details of step S508 will be described later with reference to FIG. 5(C).

[0050] In step S509, the MFP 100 performs a BIOS recovery process. The details of step S509 will be described later with reference to FIG. 5(D).

[0051] FIG. 5(B) is a flowchart showing the details of step S507 in FIG. 5(A). In step S510, the version comparison unit 353 compares the first version information 401 and the second version information 404.

[0052] In step S511, if the first version information 401 is newer than the second version information 404, the version comparison unit 353 proceeds to step S512. Also, if the first version information 401 is not newer than the second version information 404, the version comparison unit 353 determines that it is not necessary to update the BIOS golden copy 403 and ends the process of the flowchart in FIG. 5(B).

[0053] In step S512, the first update unit 354 updates the BIOS golden copy 403 by overwriting the BIOS golden copy 403 with the BIOS 360, and ends the process of the flowchart in Fig. 5(B).

[0054] Fig. 5(C) is a flowchart showing the details of step S508 in Fig. 5(A). In step S513, the embedded controller 212 sends a reset signal to the CPU 201 to transfer control to the CPU 201, and the embedded controller 212 enters the sleep state.

[0055] In step S514, the CPU 201 receives the reset signal and starts up. In step S515, the CPU 201 reads out the BIOS 360 in the first SPI flash memory 213, starts up the BIOS 360, and ends the process of the flowchart in Fig. 5(C).

[0056] Fig. 5(D) is a flowchart showing the details of step S509 in Fig. 5(A). In step S516, the forgery detection unit 351 uses the second signature value 405 to detect whether there is any forgery of the BIOS golden copy 403 in the second SPI flash memory 214 by signature verification.

[0057] In step S517, when the forgery detection unit 351 succeeds in signature verification, it determines that no forgery of the BIOS golden copy 403 is detected and proceeds to step S518. Also, when the forgery detection unit 351 fails in signature verification, it determines that forgery of the BIOS golden copy 403 is detected and proceeds to step S519.

[0058] In step S518, the recovery unit 352 recovers the forged BIOS 360 by overwriting the forged BIOS 360 with the BIOS golden copy 403, and proceeds to step S508 in Fig. 5(A).

[0059] In step S519, the recovery unit 352 does not perform the recovery process of the BIOS 360, but performs error processing and ends the process. As error processing, the recovery unit 352 may leave a log, notify an error via the operation unit 102, or notify the user of the occurrence of an error by blinking an LED or a power lamp provided in the MFP 100 and the embedded controller 212.

[0060] Note that in step S502, if the second update unit 310 does not update the BIOS 360, the first version information 401 of the BIOS 360 and the second version information 404 of the BIOS golden copy 403 remain the same. Therefore, if the BIOS 360 is not updated, in step S511, the version comparison unit 353 determines that the first version information 401 is not newer than the second version information 404 (proceeds to "NO" in step S511). In that case, the BIOS golden copy 403 is not updated.

[0061] As described above, the BIOS golden copy 403 is stored in the second SPI flash memory 214 that cannot be accessed from the CPU 201. Even in that case, the MFP 100 can update the BIOS golden copy 403 to the latest version by using the first version information 401 and the second version information 404.

[0062] The MFP 100 can achieve both prevention of falsification of the BIOS golden copy 403 (including prevention of unauthorized rollback) and secure update of the BIOS golden copy 403.

[0063] (First Modification Example) In the first embodiment, the MFP 100 performs the recovery process of the BIOS 360 in step S509 only when the falsification detection unit 351 detects falsification of the BIOS 360. In the first modification example, the MFP 100 also performs the recovery process of the BIOS 360 in step S509 when the second version information 404 is newer than the first version information 401.

[0064] If the second version information 404 is newer than the first version information 401 in the MFP100, it can be determined that the BIOS 360 has been rolled back to an older version. Even if there is no tampering with the BIOS 360 itself, if the BIOS 360 remains in an older version, there may be known vulnerabilities. Therefore, the MFP100 overwrites the BIOS 360 with the BIOS golden copy 403, which is a newer version.

[0065] FIG. 6(A) is a flowchart showing the details of step S507 in FIG. 5(A) according to the first modification example. Hereinafter, the differences between the first modification example (FIG. 6(A)) and the first embodiment (FIG. 5(B)) will be described.

[0066] In step S510, the version comparison unit 353 compares the first version information 401 and the second version information 404. In step S601, if the first version information 401 and the second version information 404 match, the version comparison unit 353 ends the process of FIG. 6(A). Further, if the first version information 401 and the second version information 404 do not match, the version comparison unit 353 proceeds to step S602.

[0067] In step S602, the version comparison unit 353 determines whether the first version information 401 is newer than the second version information 404. If the first version information 401 is newer than the second version information 404, the version comparison unit 353 proceeds to step S512. If the first version information 401 is older than the second version information 404, the version comparison unit 353 proceeds to step S509.

[0068] In step S512, the first update unit 354 updates the BIOS golden copy 403 by overwriting the BIOS golden copy 403 with the BIOS 360, and ends the process of the flowchart in FIG. 6(A). In step S509, the MFP100 performs a BIOS recovery process in the same manner as in FIG. 5(D).

[0069] As described above, even if there is no tampering with the BIOS 360 itself, the MFP 100 restores the older version of the BIOS 360 that has become obsolete through rollback to the newer version of the BIOS golden copy 403. Therefore, the MFP 100 can be started with a newer version of the BIOS with fewer known vulnerabilities.

[0070] (Second Modification Example) In the second modification example, the MFP 100 prevents unauthorized rewriting (write command) to the BIOS golden copy 403 by appropriately setting or releasing the write protection for the BIOS golden copy 403 via the unauthorized rewriting prevention unit 355. The write protection is set for the BIOS golden copy 403 of the second SPI flash memory 214.

[0071] FIG. 6(B) is a flowchart showing the details of step S512 in FIGS. 5(B) and 6(A) according to the second modification example. Hereinafter, the differences between the second modification example and the first embodiment and the first modification example will be described.

[0072] In step S610, the unauthorized rewriting prevention unit 355 releases the write protection of the BIOS golden copy 403. Thereafter, in step S611, the first update unit 354 updates the BIOS golden copy 403 by overwriting the BIOS golden copy 403 with the BIOS 360. Thereafter, in step S612, the unauthorized rewriting prevention unit 355 sets the write protection of the BIOS golden copy 403 and ends the processing of the flowchart in FIG. 6(B).

[0073] Note that it is necessary to set the write protection of the BIOS golden copy 403 first somewhere. The write protection of the BIOS golden copy 403 may be set at the factory when the MFP 100 is shipped from the factory, or the unauthorized rewriting prevention unit 355 may set the write protection of the BIOS golden copy 403 at the first startup of the MFP 100.

[0074] In addition, the anti-tampering prevention unit 355 can determine the set or released state of the write protection of the BIOS golden copy 403 by referring to the state of the registers included in the second SPI flash memory 214. When the write protection of the BIOS golden copy 403 is released, the anti-tampering prevention unit 355 dynamically controls to set the write protection of the BIOS golden copy 403. Thereby, the write protection of the first BIOS golden copy 403 can be set. Also, in the second modification example, the case where the anti-tampering prevention unit 355 sets write protection only for the BIOS golden copy 403 has been described, but this is merely an example, and write protection may be set for the entire second SPI flash memory 214.

[0075] As described above, since the MFP 100 sets or releases write protection, which is a function of the SPI flash memory, as needed, it is possible to achieve both protection and update of the BIOS golden copy 403.

[0076] (Third Modification Example) In the above first embodiment, first modification example, and second modification example, the data configurations in the first SPI flash memory 213 and the second SPI flash memory 214 have been described with the configurations illustrated in FIG. 4, but this is merely an example, and different data configurations may be used. Other data configuration examples will be described with reference to FIGS. 7(A), (B) and FIGS. 8(A), (B).

[0077] FIG. 7(A) is a diagram illustrating data stored in the first SPI flash memory 213 and the second SPI flash memory 214. The first SPI flash memory 213 stores, in addition to the BIOS 360, the first version information 401, and the first signature value 402, a first version information signature value 701 as the signature value of the first version information 401. The BIOS 360 includes the first version information 401 and the first version information signature value 701. The forgery detection unit 351 can verify the presence or absence of forgery of the first version information 401 by performing signature verification using the first version information signature value 701.

[0078] The second SPI flash memory 214 stores, in addition to the BIOS golden copy 403, the second version information 404, and the second signature value 405, a second version information signature value 702 as the signature value of the second version information 404. The BIOS golden copy 403 includes the second version information 404 and the second version information signature value 702. The forgery detection unit 351 can verify the presence or absence of forgery of the second version information 404 by performing signature verification using the second version information signature value 702.

[0079] FIG. 7(B) is a diagram illustrating other data stored in the first SPI flash memory 213 and the second SPI flash memory 214. The first SPI flash memory 213 stores the BIOS 360, the first version information 401, the first version information signature value 701, and the first signature value 402 separately. The second SPI flash memory 214 stores the BIOS golden copy 403, the second version information 404, the second version information signature value 702, and the second signature value 405 separately. The first signature value 402 is the signature value for the BIOS 360 alone. The second signature value 405 is the signature value for the BIOS golden copy 403 alone.

[0080] FIG. 8(A) is a diagram illustrating other data stored in the first SPI flash memory 213 and the second SPI flash memory 214. The first SPI flash memory 213 stores the BIOS 360. The BIOS 360 includes first version information 401 and a first signature value 402. The first signature value 402 is a digital signature value for a partial area 801 excluding the first signature value 402 itself in the binary data of the BIOS 360. That is, the first signature value 402 is a signature value for binary data including the first version information 401 and the actual code area of the BIOS 360 (partial binary data of the BIOS 360 excluding the first version information 401 and the first signature value 402).

[0081] The second SPI flash memory 214 stores the BIOS golden copy 403. The BIOS golden copy 403 includes second version information 404 and a second signature value 405. The second signature value 405 is a digital signature value for a partial area 802 excluding the second signature value 405 itself in the binary data of the BIOS golden copy 403. That is, the second signature value 405 is a signature value for binary data including the second version information 404 and the actual code area of the BIOS golden copy 403. The binary data including the actual code area of the BIOS golden copy 403 is partial binary data of the BIOS golden copy 403 excluding the second version information 404 and the second signature value 405.

[0082] As described above, the BIOS 360 includes not only the first version information 401 but also the first signature value 402 in the free area. The BIOS golden copy 403 includes not only the second version information 404 but also the second signature value 405 in the free area. Thereby, the MFP 100 can achieve both capacity savings of the first SPI flash memory 213 and the second SPI flash memory 214 and detection of forgery by signature verification.

[0083] FIG. 8(B) is a diagram illustrating other data stored in the first SPI flash memory 213 and the second SPI flash memory 214. The first SPI flash memory 213 stores the BIOS 360. The BIOS 360 includes first version information 401, a first version information signature value 701, and a first signature value 402. The forgery detection unit 351 can verify the presence or absence of forgery of the first version information 401 by using the first version information signature value 701 and performing signature verification. Since the BIOS 360 includes the first version information 401, the first version information signature value 701, and the first signature value 402 in the free area, it is possible to save the capacity of the first SPI flash memory 213. The first signature value 402 is a digital signature value for a partial area 803 excluding the first signature value 402 itself from the binary data of the BIOS 360.

[0084] The second SPI flash memory 214 stores the BIOS golden copy 403. The BIOS golden copy 403 includes second version information 404, a second version information signature value 702, and a second signature value 405. The forgery detection unit 351 can verify the presence or absence of forgery of the second version information 404 by using the second version information signature value 702 and performing signature verification. Since the BIOS golden copy 403 includes the second version information 404, the second version information signature value 702, and the second signature value 405 in the free area, it is possible to save the capacity of the second SPI flash memory 214. The second signature value 405 is a digital signature value for a partial area 804 excluding the second signature value 405 itself from the binary data of the BIOS golden copy 403.

[0085] (Other variations) In the above-described first embodiment and the first to third modifications, the forgery detection unit 351 performed signature verification of the BIOS golden copy 403 to verify whether the BIOS golden copy 403 had been forged. Here, the forgery detection unit 351 may determine that the possibility of the BIOS golden copy 403 being forged is extremely low and may not perform signature verification of the BIOS golden copy 403. Since the BIOS golden copy 403 is stored in the second SPI flash memory 214 that cannot be accessed from the CPU 201, it can be considered that the risk of being attacked (forged) is low. Thereby, the time required for signature verification of the BIOS golden copy 403 can be omitted.

[0086] Also, in the above-described first embodiment and the first to third modifications, after successful signature verification in step S506, the MFP 100 performed the update process of the BIOS golden copy 403 in step S507. Here, the timing of the update process of the BIOS golden copy 403 is not limited to this. For example, the MFP 100 may perform the update process of the BIOS golden copy 403 in step S507 after step S504 and before step S505. Further, the MFP 100 may perform only the update process of the BIOS golden copy 403 in step S507 without performing steps S505 and S506. Additionally, the MFP 100 can perform the update process of the BIOS golden copy 403 in step S507 after step S513. For example, at an arbitrary timing, the MFP 100 can cause the embedded controller 212 to wake up from the sleep state by the CPU 201 sending an interrupt command to the embedded controller 212. Then, the woken-up embedded controller 212 can implement the update process of the BIOS golden copy 403 in step S507.

[0087] Also, in the above-described first embodiment and the first to third modification examples, the first update unit 354 performs the update process of the BIOS golden copy 403 in step S512 only when the first version information 401 is newer than the second version information 404. Here, the first update unit 354 may always perform the update process of the BIOS golden copy 403 in step S512 when the first version information 401 and the second version information 404 do not match. That is, the first update unit 354 can update the BIOS golden copy 403 in the BIOS 360 according to the comparison result between the first version information 401 and the second version information 404.

[0088] Also, in the above-described first embodiment and the first to third modification examples, the BIOS has been described as an example, but the present invention is also applicable to firmware and software (programs) other than the BIOS. For example, when the MFP 100 is equipped with a NIC, a bus is connected so that the embedded controller 212 can access the NIC firmware. Then, the golden copy of the NIC firmware is stored in the second SPI flash memory 214 that can be accessed only from the embedded controller 212. Thereby, recovery of the NIC firmware and update of the golden copy of the NIC firmware can be realized.

[0089] Also, in the above-described first embodiment and the first to third modifications, an example has been described in which the embedded controller 212 directly activates the embedded controller software 350. However, the embedded controller software 350 may be activated in multiple stages. For example, it can be achieved in multiple stages by storing forgery detection (signature verification) of the embedded controller software 350 and startup software for performing the activation in the ROM of the embedded controller 212. First, the startup software stored in the ROM of the embedded controller 212 starts up and verifies the presence or absence of forgery of the embedded controller software 350 stored in the first SPI flash memory 213 or the second SPI flash memory 214. Then, control can be performed to activate the embedded controller software 350 only when there is no forgery. In this case, separately, the digital signature value of the embedded controller software 350 will be held in the first SPI flash memory 213 or the second SPI flash memory 214.

[0090] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.

[0091] Note that the above embodiments are merely specific examples for implementing the present invention, and the technical scope of the present invention should not be construed in a limited manner by these. That is, the present invention can be implemented in various forms without departing from its technical idea or its main features.

Explanation of Reference Numerals

[0092] 351 Forgery Detection Unit, 352 Recovery Unit, 353 Version Comparison Unit, 354 First Update Unit, 355 Unauthorized Rewriting Prevention Unit

Claims

1. An information processing apparatus that stores first software in a first storage medium accessible by a CPU and an embedded controller, and stores second software used for restoring the first software in a second storage medium accessible only by the embedded controller, a first update means for updating the second software in the second storage medium with the first software in the first storage medium according to a comparison result between the version information of the first software and the version information of the second software; a forgery detection means for detecting whether the first software has been forged; and a recovery means for not performing the update by the first update means and recovering the first software with the second software when it is detected by the forgery detection means that the first software has been forged. An information processing apparatus characterized by having the above.

2. The embedded controller has the first update means, the forgery detection means, and the recovery means, After the recovery by the recovery means, the CPU starts the first software. The information processing apparatus according to claim 1.

3. When it is detected by the forgery detection means that the first software has not been forged, the first update means updates the second software in the second storage medium with the first software in the first storage medium according to a comparison result between the version information of the first software and the version information of the second software. The information processing apparatus according to claim 1 or 2, characterized by the above.

4. The embedded controller has the first update means, the forgery detection means, and the recovery means, The information processing apparatus according to claim 3, wherein after the update by the first update means, the CPU activates the first software.

5. The information processing apparatus according to claim 1 or 2, wherein the first update means updates the second software on the second storage medium with the first software on the first storage medium according to a comparison result between the version information of the first software and the version information of the second software before detection by the forgery detection means and recovery by the recovery means.

6. The embedded controller has the first update means, the forgery detection means, and the recovery means. The information processing apparatus according to claim 5, wherein when it is detected by the forgery detection means that there is no forgery of the first software, the CPU activates the first software.

7. The information processing apparatus according to any one of claims 1 to 6, wherein the first update means updates the second software on the second storage medium with the first software on the first storage medium when the version information of the first software is newer than the version information of the second software.

8. The information processing apparatus according to claim 7, wherein the recovery means recovers the first software with the second software when the version information of the first software is older than the version information of the second software.

9. The information processing apparatus according to any one of claims 1 to 6, wherein the first update means updates the second software on the second storage medium with the first software on the first storage medium when the version information of the first software and the version information of the second software do not match.

10. The built-in controller includes the first update means, the forgery detection means, and the recovery means, The CPU has second update means for updating the first software of the first storage medium before the update by the first update means, the detection by the forgery detection means, and the recovery by the recovery means. The information processing apparatus according to any one of claims 1 to 9, characterized in that.

11. The forgery detection means detects whether or not the second software has been forged, The recovery means restores the first software with the second software when it is detected by the forgery detection means that the first software has been forged and it is detected by the forgery detection means that the second software has not been forged. The information processing apparatus according to any one of claims 1 to 10, characterized in that.

12. The second software of the second storage medium has write protection set, The information processing apparatus according to any one of claims 1 to 11, further comprising rewrite prevention means for releasing the write protection of the second software before the update by the first update means and setting the write protection of the second software after the update by the first update means.

13. The information processing apparatus according to any one of claims 1 to 12, further comprising printer means for printing.

14. An information processing method of an information processing apparatus that stores first software in a first storage medium accessible by a CPU and a built-in controller and stores second software used for restoring the first software in a second storage medium accessible only by the built-in controller, A first update step of updating the second software on the second storage medium with the first software on the first storage medium according to a comparison result between the version information of the first software and the version information of the second software; A forgery detection step of detecting whether there is forgery of the first software; If it is detected in the forgery detection step that there is forgery of the first software, a recovery step of recovering the first software with the second software without performing the update by the first update step; An information processing method characterized by comprising:

15. A program for causing a computer to function as each means of the information processing apparatus according to any one of Claims 1 to 13.

Citation Information

Patent Citations

  • Image processing device and method of backing up program

    JP2016103159A

  • Information processing apparatus and method of controlling the same, and program

    JP2020067904A

  • Recovering from Compromised System Boot Code

    US20160055068A1

  • Recovering from compromised system boot code

    US9880908B2