Information Processing System, Information Processing Apparatus, and Data Communication Method
The information processing system securely updates non-volatile memory data by employing cryptographic key management and Diffie-Hellman key exchange, addressing vulnerabilities in conventional methods and ensuring secure data transmission.
Patent Information
- Application Number
- JP2024138976
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-08-20
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-08-20
AI Technical Summary
Conventional methods for updating data in non-volatile memory, such as BIOS in a PC, are vulnerable to unauthorized data transmission and illegal program modifications, compromising security.
An information processing system that utilizes a rewritable non-volatile storage unit, a server apparatus, and a host apparatus to manage and securely update data by generating and sharing cryptographic keys through elliptic curve cryptography, ensuring legitimacy and secure data communication using the Diffie-Hellman key exchange method.
The system enables secure and appropriate updating of data in non-volatile memory while ensuring security, preventing unauthorized updates and maintaining system integrity.
Smart Images

Figure 0007698119000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing apparatus, and a data communication method.
Background Art
[0002] An information processing apparatus such as a PC (Personal Computer) includes an internal non-volatile memory (for example, a flash ROM (Read Only Memory)) in which a program for executing a system such as a BIOS (Basic Input Output System) is stored. The information processing apparatus starts the system by executing this program and executes various information processes (for example, see Patent Document 1).
[0003] When the data of the program written in this non-volatile memory is corrupted, or when an incorrect program is written to the memory, the system cannot be started normally. In such a case, as a method for repairing the data in the non-volatile memory, a host device such as a ROM writer and the non-volatile memory are connected by a predetermined interface, and repair data is transmitted to the non-volatile memory to repair the data.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the above-described conventional technology, for example, there is a possibility that unauthorized data is transmitted from an unauthorized host device to the non-volatile memory and the program is illegally modified.
[0006] The present invention has been made to solve the above problems, and an object thereof is to provide an information processing system, an information processing apparatus, and a data communication method capable of appropriately updating data in a non-volatile memory while ensuring security.
Means for Solving the Problems
[0007] In order to solve the above problems, one aspect of the present invention includes an information processing apparatus having a rewritable non-volatile storage unit that stores a program for starting an operating system (OS), and that executes processing based on the OS, a server apparatus that manages the information processing apparatus, and a host apparatus that can communicate with the information processing apparatus and the server apparatus and that transmits update data of the program to the information processing apparatus. The information processing apparatus includes a registered public key storage unit that stores the first public key of a first key pair that is the first public key and the first secret key held by the server apparatus, and that corresponds to the information processing apparatus. The information processing apparatus generates a second key pair that is a second public key and a second secret key, and performs a first process of transmitting the second public key of the second key pair to the host apparatus. The host apparatus generates a third key pair that is a third public key and a third secret key, and performs a second process of transmitting the third public key of the third key pair and the second public key to the server apparatus. When the legitimacy of the user of the host apparatus is confirmed, the server apparatus generates encrypted data obtained by encrypting the third public key based on the first secret key and the second public key, and performs a third process of transmitting the encrypted data to the information processing apparatus via the host apparatus. The information processing apparatus decrypts the encrypted data based on the first public key and the second secret key, and performs a fourth process of generating the third public key. The host apparatus generates a common key for data communication based on the second public key and the third secret key, encrypts the update data based on the common key for data communication to generate encrypted update data, and performs a fifth process of transmitting the encrypted update data to the information processing apparatus. The information processing apparatus generates the common key for data communication based on the second secret key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate the update data, and performs a sixth process of updating the program stored in the non-volatile storage unit based on the update data. The present invention relates to an information processing system that executes these processes.
[0008] Also, in one aspect of the present invention, in the information processing system described above, in the third process, the server device generates a first shared secret key based on the first secret key and the second public key, and encrypts the third public key based on the generated first shared secret key to generate the encrypted data. In the fourth process, the information processing device may generate a second shared secret key based on the first public key and the second secret key, and decrypt the encrypted data based on the generated second shared secret key to generate the third public key.
[0009] Also, in one aspect of the present invention, in the information processing system described above, the first key pair, the second key pair, and the third key pair are key pairs of a public key and a secret key in elliptic curve cryptography, the first shared secret key and the second shared secret key are equal common keys, and a common key is shared between the server device and the information processing device using the elliptic curve Diffie-Hellman key exchange method, and the common key for data communication may be shared between the upper device and the information processing device using the elliptic curve Diffie-Hellman key exchange method.
[0010] Also, in one aspect of the present invention, in the information processing system described above, the server device may encrypt the third public key using common key cryptography, and the upper device may encrypt the updated data using common key cryptography.
[0011] Also, in one aspect of the present invention, in the information processing system described above, the information processing device includes a main control unit that starts the OS and executes processing based on the OS by executing the program stored in the non-volatile storage unit, and is communicable with the upper device and operable independently of the main control unit, and a sub-control unit that executes the first process, the fourth process, and the sixth process.
[0012] Also, in one aspect of the present invention, in the information processing system described above, the program includes a BIOS (Basic Input Output System) program, the non-volatile storage unit is a flash memory having an SPI (Serial Peripheral Interface) bus, and the sub-control unit may update the BIOS program of the flash memory using the SPI bus.
[0013] Also, in one aspect of the present invention, there is provided an information processing apparatus having a rewritable non-volatile storage unit that stores a program for starting an OS (Operating System), the information processing apparatus that executes processing based on the OS, a server apparatus that manages the information processing apparatus, and a host apparatus that is communicable with the information processing apparatus and the server apparatus and transmits update data of the program to the information processing apparatus. The information processing apparatus includes a registration public key storage unit that stores the first public key of a first key pair, which is the first public key and the first private key held by the server apparatus, and corresponds to the information processing apparatus; a key pair generation unit that generates a second key pair, which is a second public key and a second private key; after transmitting the second public key of the second key pair to the host apparatus, the information processing apparatus obtains encrypted data generated by encrypting the third public key of a third key pair, which is the third public key and the third private key generated by the host apparatus, based on the first private key and the second public key, and decrypts the encrypted data based on the first public key and the second private key stored in the registration public key storage unit to generate the third public key; a common key generation unit that generates a common key for data communication based on the third public key decrypted by the public key exchange unit and the second private key; an update processing unit that decrypts the encrypted update data received from the host apparatus based on the common key for data communication generated by the common key generation unit, and updates the program stored in the non-volatile storage unit based on the decrypted update data.
[0014] Also, one aspect of the present invention is an information processing system data communication method including a rewritable non-volatile storage unit that stores a program for starting an OS (Operating System), an information processing device that executes processing based on the OS, a server device that manages the information processing device, and a higher-level device that can communicate with the information processing device and the server device and transmits update data of the program to the information processing device. The information processing device includes a registered public key storage unit that stores the first public key of the first key pair, which is the first public key and the first secret key held by the server device and corresponds to the information processing device. The information processing device generates a second key pair, which is a second public key and a second secret key, and transmits the second public key of the second key pair to the higher-level device in a first processing step. The higher-level device generates a third key pair, which is a third public key and a third secret key, and transmits the third public key of the third key pair and the second public key to the server device in a second processing step. When the legitimacy of the user of the higher-level device is confirmed, the server device generates encrypted data obtained by encrypting the third public key based on the first secret key and the second public key, and transmits the encrypted data to the information processing device via the higher-level device in a third processing step. The information processing device decrypts the encrypted data based on the first public key and the second secret key to generate the third public key in a fourth processing step. The higher-level device generates a common key for data communication based on the second public key and the third secret key, encrypts the update data based on the common key for data communication to generate encrypted update data, and transmits the encrypted update data to the information processing device in a fifth processing step. The information processing device generates the common key for data communication based on the second secret key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate the update data, and updates the program stored in the non-volatile storage unit based on the update data in a sixth processing step.
Effect of the Invention
[0015] According to the above aspect of the present invention, it is possible to appropriately update the data in the non-volatile memory while ensuring security.
Brief Description of the Drawings
[0016]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Embodiments for Carrying Out the Invention
[0017] Hereinafter, an information processing system, an information processing apparatus, and a data communication method according to an embodiment of the present invention will be described with reference to the drawings.
[0018] FIG. 1 is a configuration diagram showing an example of the information processing system 100 according to the present embodiment. As shown in FIG. 1, the information processing system 100 includes a notebook PC 1, a host device 2, and a management server 4.
[0019] The notebook PC 1 is an information processing device that has a rewritable non-volatile storage unit for storing a program (e.g., BIOS) for starting an OS (Operating System) and executes processing based on the OS. The notebook PC 1 is a target device in the information processing system 100, and for example, when the BIOS data is corrupted and the notebook PC 1 cannot be started, it is a device to be repaired and updated for the BIOS. The detailed configuration of the notebook PC 1 will be described later.
[0020] The host device 2 (an example of a higher-level device) is an information processing device that can communicate with the notebook PC 1 and the management server 4, and is used, for example, to update the BIOS of the notebook PC 1 (e.g., repair the program of the BIOS with corrupted data). The host device 2 is, for example, a notebook-type PC or a desktop PC similar to the notebook PC 1. The host device 2 is a higher-level device used by a maintenance worker when, for example, the data in the BIOS memory 32 of the notebook PC 1 is corrupted and the notebook PC 1 cannot be started.
[0021] The management server 4 is, for example, a server device managed by the manufacturer of the notebook PC 1, and can be connected to the host device 2 via the network NW1. The management server 4 holds a private key and a public key corresponding to each notebook PC 1. The management server 4 is used for the update process of the BIOS program (hereinafter sometimes referred to as the BIOS program).
[0022] Next, with reference to FIG. 2, the main hardware configuration of the notebook PC 1 will be described. FIG. 2 is a diagram showing an example of the main hardware configuration of the notebook PC 1 according to the present embodiment.
[0023] As shown in FIG. 2, the notebook PC 1 includes a CPU 11, a main memory 12, a video subsystem 13, a display unit 14, a chipset 21, an SSD 22, a USB connector 23, an audio system 24, a WLAN card 25, an embedded controller 31, a BIOS memory 32, an input unit 33, and a power supply circuit 34.
[0024] In this embodiment, the CPU 11 and the chipset 21 correspond to the main control unit 10. The main control unit 10 is an example of a processor (main processor) that executes a program stored in a memory (main memory 12).
[0025] The CPU (Central Processing Unit) 11 executes various arithmetic processes under program control and controls the entire notebook PC 1. The main memory 12 is a writable memory that is used as a loading area for the execution program of the CPU 11 or as a working area for writing the processing data of the execution program. The main memory 12 is composed of, for example, a plurality of DRAM (Dynamic Random Access Memory) chips. This execution program includes BIOS, OS, various drivers for operating peripheral devices in hardware, various services / utilities, application programs, and the like.
[0026] The main memory 12 is an example of a system memory that stores programs and data, and is mounted on the notebook PC 1 by a DIMM on which a plurality of DRAMs are mounted.
[0027] The video subsystem 13 is a subsystem for realizing functions related to image display and includes a video controller. This video controller processes a drawing command from the CPU 11, writes the processed drawing information to the video memory, reads the drawing information from the video memory, and outputs it to the display unit 14 as drawing data (display data).
[0028] The display unit 14 is, for example, a liquid crystal display, and displays a display screen based on the drawing data (display data) output from the video subsystem 13.
[0029] The chipset 21 includes controllers such as a USB, Serial ATA (AT Attachment), SPI (Serial Peripheral Interface) bus, PCI (Peripheral Component Interconnect) bus, PCI-Express bus, and LPC (Low Pin Count) bus, and a plurality of devices are connected thereto. In FIG. 2, as examples of devices, an SSD 22, a USB connector 23, an audio system 24, and a WLAN card 25 are connected to the chipset 21.
[0030] The SSD (Solid State Drive) 22 (an example of a non-volatile memory device) stores an OS, various drivers, various services / utilities, application programs, and various data.
[0031] The USB connector 23 is a connector for connecting peripheral devices using USB. The USB connector 23 includes, for example, a USB Type-C connector. The audio system 24 records, plays back, and outputs audio data.
[0032] The WLAN (Wireless Local Area Network) card 25 connects to a network via a wireless (radio) LAN and performs data communication.
[0033] The embedded controller 31 (an example of a sub-control unit) is a one-chip microcomputer that monitors and controls various devices (peripheral devices, sensors, etc.) regardless of the system state of the notebook PC 1. Further, the embedded controller 31 has a power management function for controlling the power circuit 34. Note that the embedded controller 31 is composed of a CPU, a ROM, a RAM, etc. (not shown), and has a plurality of channels of A / D input terminals, D / A output terminals, timers, and digital input / output terminals. To the embedded controller 31, for example, a BIOS memory 32, an input unit 33, and a power circuit 34 are connected via those input / output terminals, and the embedded controller 31 controls the operations thereof.
[0034] Note that the embedded controller 31 has an SPI bus and is connected to the BIOS memory 32 via the SPI bus. In the present embodiment, for example, the BIOS memory 32 is connected to the embedded controller 31 by the Slave Attached Flash method, and the main control unit 10 can access the BIOS memory 32 via the embedded controller 31 connected by the eSPI bus.
[0035] The embedded controller 31 can operate in a state where power is not supplied to the main control unit 10, can communicate with the host device 2 without going through the main control unit 10, and can access the BIOS memory 32 without going through the main control unit 10.
[0036] The BIOS memory 32 is composed of an electrically rewritable non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read Only Memory) or a flash ROM, for example. The BIOS memory 32 stores a BIOS program and the like. The BIOS memory 32 is connected to the embedded controller 31 via the SPI bus.
[0037] The input unit 33 is an input device such as a keyboard, a pointing device, a touch pad, etc.
[0038] The power supply circuit 34 includes, for example, a DC / DC converter, a charge / discharge unit, a battery unit, an AC / DC adapter, etc., and converts the DC voltage supplied from the AC / DC adapter or the battery unit into a plurality of voltages necessary for operating the notebook PC 1. Further, the power supply circuit 34 supplies power to each part of the notebook PC 1 based on the control from the embedded controller 31.
[0039] Next, with reference to FIG. 3, the functional configuration of the information processing system 100 according to the present embodiment will be described. FIG. 3 is a functional block diagram showing an example of the functional configuration of the information processing system 100 according to the present embodiment. Note that in FIG. 3, only the configurations related to the present invention among the various functional configurations provided in the information processing system 100 are described.
[0040] As shown in FIG. 3, the information processing system 100 includes a notebook PC 1, a host device 2, and a management server 4. The management server 4 includes a NW communication unit 41, a server storage unit 42, and a server control unit 43.
[0041] The NW (Net Work) communication unit 41 is a network adapter that can be connected to the network NW1 by, for example, a wired LAN, and can be connected to the host device 2 via the network NW1.
[0042] The server storage unit 42 is a storage unit realized by, for example, a RAM, an SSD, an HDD, etc., and stores various information used by the management server 4. The server storage unit 42 includes a registration information storage unit 421, an authentication information storage unit 422, a public key storage unit 423, and a common key storage unit 424.
[0043] The registration information storage unit 421 stores the registration information of each notebook PC 1 manufactured and shipped by the manufacturer. The registration information storage unit 421 stores, for example, by associating the manufacturing number of the notebook PC 1, the public key, and the private key.
[0044] Here, the manufacturing number is an example of identification information for identifying the notebook PC 1. Also, the public key and the private key are a key pair (public key and private key) of public-key cryptography assigned to the notebook PC 1. In the present embodiment, one key pair is assigned to one notebook PO1. Further, the public key and the private key stored in the registration information storage unit 421 are referred to as a first public key and a first private key, and the key pair of the first public key and the first private key is referred to as a first key pair.
[0045] The authentication information storage unit 422 stores information for authenticating the user of the host device 2 described later. The authentication information storage unit 422 stores, for example, authentication information such as a user ID and a password for logging in to the management server 4.
[0046] The public key storage unit 423 stores the public key (second public key) generated by the notebook PC 1 and the public key (third public key) generated by the host device 2. The second public key and the third public key are acquired from the host device 2 via the NW communication unit 41.
[0047] The common key storage unit 424 stores a shared secret key (first shared secret key) shared between the management server 4 and the notebook PC 1. The shared secret key (first shared secret key) stored in the common key storage unit 424 is used to distribute the third public key, which is the public key of the host device 2, to the notebook PC 1.
[0048] The server control unit 43 is a functional unit realized, for example, by causing a CPU (not shown) to execute a program stored in the server storage unit 42. The server control unit 43 performs registration processing of the manufacturing number, public key, and private key stored in the registration information storage unit 421, and a process of securely distributing the public key (third public key) of the host device 2 to the notebook PC 1 in order to update (repair) the BIOS program stored in the BIOS memory 32 of the notebook PC 1. The server control unit 43 includes a user authentication unit 431, a public key distribution unit 432, and a common key generation unit 433.
[0049] The user authentication unit 431 executes authentication processing for a user who is a user of the host device 2 based on the authentication information stored in the authentication information storage unit 422. For example, the user authentication unit 431 determines the legitimacy of the user of the host device 2 based on whether the login information (user ID and password) transmitted from the host device 2 matches the user ID and password stored in the authentication information storage unit 422. When the user ID and password transmitted from the host device 2 match the user ID and password stored in the authentication information storage unit 422, the user authentication unit 431 permits the processing of the public key distribution unit 432 and the common key generation unit 433 described later.
[0050] The public key distribution unit 432 receives the public key (second public key) of the notebook PC 1 and the public key (third public key) of the host device 2 from the host device 2 via the NW communication unit 41, and encrypts the public key (third public key) of the host device 2 based on the first secret key stored in the registration information storage unit 421 and the public key (second public key) of the notebook PC 1 to generate encrypted data (encrypted third public key). The public key distribution unit 432 stores the second public key and the third public key received from the host device 2 in the public key storage unit 423.
[0051] For example, the public key distribution unit 432 encrypts the third public key using the shared secret key (first shared secret key) generated by the common key generation unit 433 described later based on the first secret key and the second public key. For example, the public key distribution unit 432 encrypts the third public key with the first shared secret key using AES (Advanced Encryption Standard), which is a common key cipher, to generate encrypted data. Note that the public key distribution unit 432 generates encrypted data when the legitimacy of the user (user) of the host device 2 is confirmed by the user authentication unit 431. The public key distribution unit 432 distributes the encrypted data, which is the encrypted third public key, to the notebook PC 1 via the NW communication unit 41 and the host device 2.
[0052] When the user authentication unit 431 confirms the legitimacy of the user (user) of the host device 2, the common key generation unit 433 generates a shared secret key (first shared secret key) based on the first secret key and the second public key. Here, the first secret key and the second public key are, for example, the secret key and the public key in elliptic curve cryptography.
[0053] Note that the first key pair of the first public key Q1(x1,y1) and the first secret key d1 is represented by the following formula (1).
[0054] Q1(x1,y1)=d1×G(xg,yg) ···(1)
[0055] G(xg,yg) is the base point of the elliptic curve. The first public key Q1(x1,y1), which is a point on the elliptic curve, is generated by multiplying the base point G(xg,yg) by the first secret key d1 d1 times. Also, the second key pair of the second public key Q2(x2,y2) and the second secret key d2 is represented by the following formula (2). Also, the third key pair of the third public key Q3(x3,y3) and the third secret key d3 is represented by the following formula (3).
[0056] Q2(x2,y2)=d2×G(xg,yg) ···(2) Q3(x3,y3)=d3×G(xg,yg) ···(3)
[0057] Based on the first secret key d1 and the second public key Q2(x2,y2), the common key generation unit 433 generates a shared secret key K1 (first shared secret key) using, for example, the following formula (4).
[0058] K1=d1×Q2(x2,y2) =d1×d2×G(xg,yg) ···(4)
[0059] The common key generation unit 433 may use the K1 in the above formula (1) as the first shared secret key as it is, or for example, further process K1 using a hash function or a key derivation function (such as KDF, etc.) to generate the first shared secret key. The common key generation unit 433 stores the generated first shared secret key in the common key storage unit 424.
[0060] Also, the public key distribution unit 432 encrypts the third public key using the first shared secret key generated by the common key generation unit 433. That is, the public key distribution unit 432 encrypts the third public key, for example, with AES or the like using the first shared secret key stored in the common key storage unit 424 to generate encrypted data.
[0061] The notebook PC 1 includes a main control unit 10, an embedded controller 31, and a BIOS memory 32. The BIOS memory 32 includes a BIOS program storage unit 321. Note that the BIOS memory 32 can be accessed from the embedded controller 31 via the SPI bus in the Slave Attached Flash method.
[0062] In the Slave Attached Flash method, with the main control unit 10 as the master, the embedded controller 31 as the slave is connected, and further, the BIOS memory 32 is connected to the embedded controller 31 as a slave. This connection enables access from the embedded controller 31 to the BIOS memory 32 and also enables access from the main control unit 10 to the BIOS memory 32 via the embedded controller 31.
[0063] The BIOS program storage unit 321 stores the BIOS program. If the data of the BIOS program stored in the BIOS program storage unit 321 is corrupted, the main control unit 10 cannot start the OS. In such a case, the BIOS program storage unit 321 uses the host device 2 to write the updated data of the BIOS program, repair the data of the BIOS program, and the notebook PC 1 is restored to a state where the OS can be started.
[0064] The main control unit 10 is a functional unit realized by causing the CPU 11 to execute programs stored in the SSD 22, the BIOS memory 32, the main memory 12, etc. The main control unit 10 executes processes based on the OS and the BIOS. The main control unit 10 includes, for example, a BIOS processing unit 101 and an OS processing unit 102.
[0065] The BIOS processing unit 101 is a functional unit realized by causing the CPU 11 to execute the BIOS program stored in the BIOS memory 32, and executes processes based on the BIOS.
[0066] The OS processing unit 102 is a functional unit realized by causing the CPU 11 to execute the OS program stored in the SSD 22, and executes processes based on the OS.
[0067] The embedded controller 31 is a control unit that can operate in a state where power is not supplied to the main control unit 10, and executes BIOS update processing, etc. when the notebook PC 1 and the host device 2 are connected. The embedded controller 31 includes a registered public key storage unit 322, a cryptographic key storage unit 311, a common key storage unit 312, a key pair generation unit 313, a public key exchange unit 314, a common key generation unit 315, and an update processing unit 316.
[0068] When the notebook PC 1 is shipped, the registered public key storage unit 322 stores the registered first public key. The registered public key storage unit 322 stores the first public key assigned to the notebook PC 1. Note that the registered public key storage unit 322 may store the first public key in association with the serial number of the notebook PC 1.
[0069] Note that the registered public key storage unit 322 is stored in the firmware area of the embedded controller 31 of the BIOS memory 32, and is realized as a storage unit that can be accessed only from the firmware of the embedded controller 31.
[0070] The encryption key storage unit 311 is a storage unit realized by, for example, a RAM (not shown) provided in the embedded controller 31, and stores a second key pair (a key pair of a second private key and a second public key) and a third public key.
[0071] The common key storage unit 312 is a storage unit realized by, for example, a RAM (not shown) provided in the embedded controller 31, and stores a second shared secret key generated by a common key generation unit 315 described later and a common key for data communication.
[0072] The key pair generation unit 313 is a functional unit realized by, for example, causing a CPU (not shown) provided in the embedded controller 31 to execute a program stored in a ROM (not shown). The key pair generation unit 313 generates a second key pair, which is a key pair of elliptic curve cryptography, as a one-time key. The key pair generation unit 313 generates, for example, a second private key d2 based on a random number, and generates a second public key Q2(x2, y2) using the above-described formula (2). The key pair generation unit 313 stores the generated second key pair in the encryption key storage unit 311.
[0073] The common key generation unit 315 is a functional unit realized by causing a CPU (not shown) included in the embedded controller 31 to execute a program stored in a ROM (not shown), for example. The common key generation unit 315 generates a shared secret key (second shared secret key) based on the first public key stored in the registered public key storage unit 322 and the second secret key among the second key pairs stored in the cryptographic key storage unit 311.
[0074] The common key generation unit 315 generates the second shared secret key K2 from the first public key Q1(x1, y1) and the second secret key d2, for example, using the following formula (5).
[0075] K2 = d2 × Q1(x1, y1) ···(5)
[0076] Note that the second shared secret key K2 becomes the same value as the first shared secret key K1 as shown in the following formula (6) by substituting the above-mentioned formula (1). The common key generation unit 315 stores the generated second shared secret key K2 in the common key storage unit 312.
[0077] K2 = d2 × Q1(x1, y1) = d2 × d1 × G(xg, yg) = K1 ···(6)
[0078] This method of sharing the common key (shared secret key) uses the Elliptic curve Diffie-Hellman key exchange method. In this embodiment, the management server 4 and the notebook PC 1 share the common key (shared secret key) using the Elliptic curve Diffie-Hellman key exchange method.
[0079] Also, the common key generation unit 315 generates a data communication common key (shared secret key K4), which is a shared secret key, based on the second secret key among the second key pairs stored in the cryptographic key storage unit 311 and the public key (third public key) of the host device 2. The common key generation unit 315 generates the fourth shared secret key K4 from the third public key Q3(x3, y3) and the second secret key d2, for example, using the following formula (7).
[0080] K4 = d2 × Q3(x3, y3) = d2 × d3 × G(xg, yg) ···(7)
[0081] The common key generation unit 315 may use K4 in the above formula (7) as it is as the common key for data communication, or for example, further process K4 using a hash function or a key derivation function (e.g., KDF, etc.) to generate a common key for data communication. The common key generation unit 315 stores the generated fourth shared secret key K4 in the common key storage unit 312.
[0082] The public key exchange unit 314 is a functional unit realized, for example, by causing a CPU (not shown) provided in the embedded controller 31 to execute a program stored in a ROM (not shown). The public key exchange unit 314 transmits the second public key among the second key pair to the host device 2.
[0083] Also, the public key exchange unit 314 decrypts the encrypted data generated by the management server 4 based on the first public key and the second secret key stored in the encryption key storage unit 311 to generate a third public key. The public key exchange unit 314 decrypts the encrypted data received from the host device 2 using the second shared secret key K2 (= the first shared secret key K1) generated by the common key generation unit 315, for example, using AES or the like, to generate a third public key. The public key exchange unit 314 stores the generated third public key in the encryption key storage unit 311.
[0084] The update processing unit 316 is a functional unit realized, for example, by causing a CPU (not shown) provided in the embedded controller 31 to execute a program stored in a ROM (not shown). The update processing unit 316 decrypts the encrypted update data received from the host device 2 based on the common key for data communication (shared secret key K4) generated by the common key generation unit 315 to generate update data. The update processing unit 316 decrypts the encrypted update data, for example, using AES or the like, using the common key for data communication (shared secret key K4) stored in the common key storage unit 312, for example, to generate update data.
[0085] The update processing unit 316 updates the program stored in the BIOS memory 32 based on the decoded update data. That is, the update processing unit 316 updates and repairs the BIOS program stored in the BIOS program storage unit 321 of the BIOS memory 32 with the update data.
[0086] The host device 2 can be connected to the embedded controller 31 of the notebook PC 1 through a predetermined interface, such as USB or a dedicated connector on the motherboard of the notebook PC 1. The host device 2 includes an NW communication unit 210, a device storage unit 220, and a device control unit 230.
[0087] The NW communication unit 210 is a network adapter that can be connected to the network NW1, for example, through a wired LAN, a wireless KAN, etc., and can be connected to the management server 4 through the network NW1.
[0088] The device storage unit 220 is a storage unit realized by, for example, RAM, SSD, HDD, etc., and stores various information used by the host device 2. The device storage unit 220 includes an encryption key storage unit 221, a common key storage unit 222, and an update program storage unit 223.
[0089] The encryption key storage unit 221 is a storage unit realized by, for example, a non-illustrated RAM provided in the host device 2, and stores a third key pair (a key pair of a third secret key and a third public key) and a second public key.
[0090] The common key storage unit 222 is a storage unit realized by, for example, a non-illustrated RAM provided in the host device 2, and stores a common key for data communication (a third shared secret key) generated by the common key generation unit 233 described later.
[0091] The update program storage unit 223 is a storage unit realized by, for example, RAM, SSD, HDD, etc., and stores update data that is image data of the BIOS program. The update data stored in the update program storage unit 223 is used for repairing the data of the BIOS program.
[0092] The device control unit 230 is a functional unit realized by causing, for example, a CPU (not shown) to execute a program stored in the device storage unit 220. The device control unit 230 executes various processes executed by the host device 2.
[0093] The device control unit 230 controls, for example, the BIOS update process with the notebook PC 1. The device control unit 230 executes a BIOS update process (BIOS program update process) for the notebook PC 1 via the embedded controller 31. The device control unit 230 includes a key pair generation unit 231, a public key exchange unit 232, a common key generation unit 233, and an update processing unit 234.
[0094] The key pair generation unit 231 generates, as a one-time key, a third key pair that is a key pair of elliptic curve cryptography. The key pair generation unit 231 generates, for example, a third private key d3 based on a random number, and generates a third public key Q3(x3, y3) using the above-described formula (3). The key pair generation unit 231 stores the generated third key pair in the cryptographic key storage unit 221.
[0095] The common key generation unit 233 generates a common key for data communication (shared secret key K3) based on the second public key received from the notebook PC 1 and the third private key among the third key pair stored in the cryptographic key storage unit 221.
[0096] The common key generation unit 233 generates, for example, a third shared secret key K3 from the second public key Q2(x2, y2) and the third private key d3 using the following formula (8).
[0097] K3 = d3 × Q2(x2, y2) = d3 × d2 × G(xg, yg) ···(8)
[0098] Note that the common key for data communication (shared secret key K4) generated by the notebook PC 1 described above and the common key for data communication (shared secret key K3) generated by the common key generation unit 233 have the same value.
[0099] The common key generation unit 233 may use K3 in the above formula (8) as it is as the common key for data communication, or for example, further process K3 using a hash function or a key derivation function (such as KDF, etc.) to generate a common key for data communication. The common key generation unit 233 stores the generated third shared secret key K3 in the common key storage unit 222.
[0100] In this way, in this embodiment, the host device 2 and the notebook PC 1 share a common key (common key for data communication) using the elliptic curve Diffie-Hellman key exchange method.
[0101] The public key exchange unit 232 transmits the third public key among the third key pair and the second public key to the management server 4. The public key exchange unit 232 stores the second public key received from the notebook PC 1 in the encryption key storage unit 221, and transmits the second public key and the third public key stored in the encryption key storage unit 221 to the management server 4 via the NW communication unit 210.
[0102] Also, the public key exchange unit 232 receives encrypted data (encrypted third public key) via the NW communication unit 210, and transmits the received encrypted data (encrypted third public key) to the notebook PC 1.
[0103] The update processing unit 234 encrypts the update data based on the common key for data communication (shared secret key K3) generated by the common key generation unit 233 to generate encrypted update data. The update processing unit 234 decrypts the update data stored in the update program storage unit 223 using the common key for data communication (shared secret key K3) stored in the common key storage unit 222, for example, using AES, etc., to generate encrypted update data. The update processing unit 234 transmits the generated encrypted update data to the notebook PC 1 to repair the data of the BIOS program.
[0104] Note that the key pair generation unit 231, the public key exchange unit 232, the shared key generation unit 233, and the update processing unit 234 may be realized, for example, by causing a dedicated application for repairing / updating the BIOS program to be executed by a CPU (not shown).
[0105] Next, with reference to the drawings, the operation of the information processing system 100 according to the present embodiment will be described. FIG. 4 is a diagram showing an example of the BIOS update process of the information processing system 100 according to the present embodiment. FIGS. 5 to 11 are diagrams for explaining each state of the BIOS update process of the information processing system according to the present embodiment.
[0106] As shown in FIG. 4, first, the host device 2 executes a login process for logging in to the management server 4 (step S101). The device control unit 230 of the host device 2 transmits a user ID and a password corresponding to the user of the host device 2 to the management server 4 via the NW communication unit 210 to execute the login process. The user ID and the password are acquired from the user, for example, by an input unit (e.g., a keyboard, etc.) (not shown).
[0107] Further, the user authentication unit 431 of the management server 4 confirms the validity of the user of the host device 2, for example, based on whether the login information (user ID and password) transmitted from the host device 2 matches the user ID and password stored in the authentication information storage unit 422.
[0108] Next, the host device 2 executes a connection process with the notebook PC 1 (step S102). The device control unit 230 of the host device 2 activates a predetermined interface connected to the notebook PC 1 to enable communication between the host device 2 and the notebook PC 1 (embedded controller 31).
[0109] Next, the host device 2 generates a third key pair (a third public key and a third private key) (step S103). The key pair generation unit 231 of the host device 2 generates, as a one-time key, a third key pair which is a key pair of elliptic curve cryptography. The key pair generation unit 231 generates, for example, a third private key d3 based on a random number, and generates a third public key Q3(x3, y3) using the above-described formula (3). The key pair generation unit 231 stores the generated third key pair in the cryptographic key storage unit 221.
[0110] Next, the embedded controller 31 of the notebook PC 1 generates a second key pair (a second public key and a second private key) (step S104). The key pair generation unit 313 of the embedded controller 31 generates, as a one-time key, a second key pair which is a key pair of elliptic curve cryptography. The key pair generation unit 313 generates, for example, a second private key d2 based on a random number, and generates a second public key Q2(x2, y2) using the above-described formula (2). The key pair generation unit 313 stores the generated second key pair in the cryptographic key storage unit 311.
[0111] Note that the state shown in FIG. 5 shows the state of the information processing system 100 in which the processing up to step S104 has been completed. As shown in FIG. 5, in this state, the notebook PC 1 (embedded controller 31) holds the first public key, the second private key, and the second public key, and the host device 2 holds the third private key and the third public key. Further, the management server 4 holds at least the first private key.
[0112] Returning to the description of FIG. 4, next, the embedded controller 31 transmits the second public key to the host device 2 (step S105). The public key exchange unit 314 of the embedded controller 31 transmits the second public key stored in the cryptographic key storage unit 311 to the host device 2.
[0113] Next, the host device 2 transmits the second public key and the third public key to the management server 4 (step S106). The public key exchange unit 232 of the host device 2 stores the second public key received from the embedded controller 31 in the encryption key storage unit 221, and transmits the second public key and the third public key stored in the encryption key storage unit 221 to the management server 4 via the NW communication unit 210. As a result, the server control unit 43 of the management server 4 stores the received second public key and third public key in the public key storage unit 423.
[0114] Note that the state shown in FIG. 6 indicates the state of the information processing system 100 after the processing up to step S106 is completed. As shown in FIG. 6, in this state, the notebook PC 1 (embedded controller 31) holds the first public key, the second secret key, and the second public key, and the host device 2 holds the third secret key, the third public key, and the second public key. Further, the management server 4 holds the first secret key, the second public key, and the third public key.
[0115] Returning again to the description of FIG. 4, next, the management server 4 determines whether user authentication is OK (whether the user is legitimate) (step S107). The public key distribution unit 432 of the management server 4 determines whether the legitimacy of the user of the host device 2 has been confirmed by the user authentication unit 431. When the legitimacy of the user of the host device 2 is confirmed (step S107: YES), the public key distribution unit 432 advances the process to step S108. Also, when the legitimacy of the user of the host device 2 has not been confirmed (step S107: NO), the public key distribution unit 432 returns the process to step S107.
[0116] In step S108, the management server 4 generates a shared secret key from the first secret key and the second public key. The common key generation unit 433 of the management server 4 generates a shared secret key K1 (first shared secret key) using the above-described formula (4). The common key generation unit 433 stores the generated shared secret key K1 (first shared secret key) in the common key storage unit 424.
[0117] Next, the public key distribution unit 432 of the management server 4 encrypts the third public key with the shared secret key (step S109). For example, the public key distribution unit 432 encrypts the third public key with the shared secret key K1 (the first shared secret key) using AES, which is a common key cipher, to generate encrypted data.
[0118] Note that the state shown in FIG. 7 indicates the state of the information processing system 100 after the processing up to step S109 is completed. As shown in FIG. 7, in this state, the notebook PC1 (embedded controller 31) holds the first public key, the second secret key, and the second public key, and the host device 2 holds the third secret key, the third public key, and the second public key. Further, the management server 4 holds the first secret key, the second public key, the third public key, the first shared secret key, and the encrypted data of the third public key.
[0119] Returning again to the description of FIG. 4, next, the public key distribution unit 432 of the management server 4 transmits the encrypted data of the third public key to the host device 2 (step S110). The public key distribution unit 432 transmits the encrypted data of the third public key to the host device 2 via the NW communication unit 41.
[0120] Next, the public key exchange unit 232 of the host device 2 transmits the received encrypted data of the third public key to the embedded controller 31 via the NW communication unit 210 (step S111).
[0121] Next, the embedded controller 31 generates a shared secret key from the first public key and the second secret key (step S112). The common key generation unit 315 of the embedded controller 31 generates a shared secret key K2 (the second shared secret key) using the above-described formula (5). The common key generation unit 315 stores the generated shared secret key K2 (the second shared secret key) in the common key storage unit 312.
[0122] Next, the public key exchange unit 314 of the embedded controller 31 decrypts the encrypted data of the third public key using the shared secret key (step S113). The public key exchange unit 314 generates the third public key by decrypting the encrypted data of the third public key using the shared secret key K2 (the second shared secret key), for example, using AES which is a symmetric key cipher. The public key exchange unit 314 stores the generated third public key in the encryption key storage unit 311.
[0123] Note that the state shown in FIG. 8 indicates the state of the information processing system 100 after the processing up to step S113 is completed. As shown in FIG. 8, in this state, the notebook PC 1 (embedded controller 31) holds the first public key, the second secret key, the second public key, the second shared secret key, the encrypted data of the third public key, and the third public key, and the host device 2 holds the third secret key, the third public key, and the second public key. Also, the management server 4 holds the first secret key, the second public key, the third public key, the first shared secret key, and the encrypted data of the third public key. Also, as shown in the above-described formula (6), the first shared secret key and the second shared secret key have the same value.
[0124] Returning again to the description of FIG. 4, next, the common key generation unit 315 of the embedded controller 31 generates a common key for data communication from the second secret key and the third public key (step S114). The common key generation unit 315 generates a common key for data communication (the fourth shared secret key) using the above-described formula (7). The common key generation unit 315 stores the generated common key for data communication in the common key storage unit 312.
[0125] Next, the common key generation unit 233 of the host device 2 generates a common key for data communication from the second public key and the third secret key (step S115). The common key generation unit 233 generates a common key for data communication (the third shared secret key) using the above-described formula (8). The common key generation unit 233 stores the generated common key for data communication in the common key storage unit 222.
[0126] Note that the state shown in FIG. 9 indicates the state of the information processing system 100 after the processing up to step S115 is completed. As shown in FIG. 9, in this state, the notebook PC1 (embedded controller 31) holds the encrypted data of the first public key, the second secret key, the second public key, the second shared secret key, the third public key, the third public key, and the common key for data communication (fourth shared secret key K4), and the host device 2 holds the third secret key, the third public key, the second public key, and the common key for data communication (third shared secret key K3). Further, the management server 4 holds the first secret key, the second public key, the third public key, the first shared secret key, and the encrypted data of the third public key. Also, as shown in the following formula (9), the third shared secret key K3 and the fourth shared secret key K4 have the same value.
[0127] K3 = d3 × Q2(x2, y2) = d3 × d2 × G(xg, yg) = d2 × Q3(x3, y3) = K4 ···(9)
[0128] Returning again to the description of FIG. 4, next, the update processing unit 234 of the host device 2 encrypts the update data with the common key for data communication (step S116). The update processing unit 234 generates encrypted update data (encrypted data of the update data) by encrypting the update data stored in the update program storage unit 223 with the common key for data communication stored in the common key storage unit 222, using, for example, AES which is a common key encryption.
[0129] Note that the state shown in FIG. 10 indicates the state of the information processing system 100 after the processing up to step S116 is completed. As shown in FIG. 10, in this state, the notebook PC1 (embedded controller 31) holds the first public key, the second secret key, the second public key, the second shared secret key, the encrypted data of the third public key, the third public key, and the common key for data communication, and the host device 2 holds the third secret key, the third public key, the second public key, the common key for data communication, and the encrypted data of the update data. Further, the management server 4 holds the first secret key, the second public key, the third public key, the first shared secret key, and the encrypted data of the third public key.
[0130] Returning to the description of FIG. 4 again, next, the update processing unit 234 of the host device 2 transmits the encrypted data of the update data to the embedded controller 31 (step S117).
[0131] Next, the update processing unit 316 of the embedded controller 31 decrypts the encrypted data of the update data with the common key for data communication (step S118). For example, the update processing unit 316 uses AES which is a common key encryption, etc., and decrypts the encrypted data of the update data received from the host device 2 with the common key for data communication stored in the common key storage unit 312 to generate the update data.
[0132] Note that the state shown in FIG. 11 indicates the state of the information processing system 100 after the processing up to step S118 is completed. As shown in FIG. 11, in this state, the notebook PC 1 (embedded controller 31) holds the encrypted data of the first public key, the second secret key, the second public key, the second shared secret key, the third public key, the third public key, the common key for data communication, the encrypted data of the update data, and the update data, and the host device 2 holds the third secret key, the third public key, the second public key, the common key for data communication, and the encrypted data of the update data. Further, the management server 4 holds the first secret key, the second public key, the third public key, the first shared secret key, and the encrypted data of the third public key.
[0133] Returning to the description of FIG. 4 again, next, the update processing unit 316 of the embedded controller 31 stores the decrypted update data in the BIOS memory 32 (step S119). The update processing unit 316 stores the update data in the BIOS program storage unit 321 to repair the BIOS program.
[0134] In the process shown in FIG. 4 described above, the processes of step S104 and step S105 correspond to the first process by the notebook PC 1, and the processes of step S103 and step S106 correspond to the second process by the host device 2. Further, the processes from step S107 to step S111 correspond to the third process by the management server 4, and the process of step S112 corresponds to the fourth process by the notebook PC 1.
[0135] Also, the processes from step S115 to step S117 correspond to the fifth process by the host device 2, and the processes from step S112 to step S114 and the processes of step S118 and step S119 correspond to the sixth process by the notebook PC 1.
[0136] As described above, the information processing system 100 according to the present embodiment includes a notebook PC 1 (information processing device), a management server 4 (server device), and a host device 2 (higher-level device). The notebook PC 1 (information processing device) has a rewritable BIOS memory 32 (non-volatile storage unit) that stores a program for starting the OS, and executes processing based on the OS. The management server 4 (server device) manages the notebook PC 1. The host device 2 (higher-level device) can communicate with the notebook PC 1 and the management server 4, and transmits update data of the program to the notebook PC 1. The notebook PC 1 includes a registered public key storage unit 322 that stores the first public key of the first key pair, which is the first public key and the first private key held by the management server 4 and corresponds to the notebook PC 1. Further, the information processing system 100 executes a first process, a second process, a third process, a fourth process, a fifth process, and a sixth process. In the first process, the notebook PC 1 generates a second key pair, which is the second public key and the second private key, and transmits the second public key of the second key pair to the host device 2. In the second process, the host device 2 generates a third key pair, which is the third public key and the third private key, and transmits the third public key of the third key pair and the second public key to the management server 4. In the third process, when the legitimacy of the user of the host device 2 is confirmed, the management server 4 generates encrypted data obtained by encrypting the third public key based on the first private key and the second public key, and transmits the encrypted data to the notebook PC 1 via the host device 2. In the fourth process, the notebook PC 1 decrypts the encrypted data based on the first public key and the second private key to generate the third public key. In the fifth process, the host device 2 generates a common key for data communication based on the second public key and the third private key, encrypts the update data based on the common key for data communication to generate encrypted update data, and transmits the encrypted update data to the notebook PC 1. In the sixth process, the notebook PC 1 generates a common key for data communication based on the second private key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate update data, and updates the program stored in the BIOS memory 32 based on the update data.
[0137] As a result, when the legitimacy of the user of the host device 2 is confirmed by the first to fourth processes according to the present embodiment, the notebook PC 1 can obtain the public key (third public key) of the host device 2, so that it is possible to prevent the BIOS program from being updated by an unauthorized user (and the host device 2). Further, the information processing system 100 according to the present embodiment can execute the BIOS program update process more securely by the fifth and sixth processes. Therefore, the information processing system 100 according to the present embodiment can appropriately update the data in the non-volatile memory (BIOS memory 32) while ensuring security.
[0138] Further, even when the data in the non-volatile memory (BIOS memory 32) is damaged and the notebook PC 1 cannot be started, the information processing system 100 according to the present embodiment can appropriately update the data in the non-volatile memory (BIOS memory 32) to safely repair the data in the non-volatile memory (BIOS memory 32).
[0139] Also, in the third process of the present embodiment, the management server 4 generates a first shared secret key based on the first secret key and the second public key, and encrypts the third public key based on the generated first shared secret key to generate encrypted data. Further, in the fourth process, the notebook PC 1 generates a second shared secret key based on the first public key and the second secret key, and decrypts the encrypted data based on the generated second shared secret key to generate the third public key.
[0140] As a result, the information processing system 100 according to the present embodiment can share a common key (the first shared secret key = the second shared secret key) between the management server 4 and the notebook PC 1, and encrypt the third public key with the common key, so that the third public key can be transmitted to the notebook PC 1 more securely.
[0141] In this embodiment, the first key pair, the second key pair, and the third key pair are key pairs of a public key and a private key in elliptic curve cryptography. The first shared secret key and the second shared secret key are equal common keys, and a common key is shared between the management server 4 and the notebook PC 1 using the elliptic curve Diffie-Hellman key exchange method. Also, a common key for data communication is shared between the host device 2 and the notebook PC 1 using the elliptic curve Diffie-Hellman key exchange method.
[0142] As a result, the information processing system 100 according to this embodiment can share a common key more securely between the management server 4 and the notebook PC 1, and can share a common key for data communication more securely between the host device 2 and the notebook PC 1. Therefore, the information processing system 100 according to this embodiment can appropriately update the data in the non-volatile memory (BIOS memory 32) while ensuring security.
[0143] Also, in this embodiment, the management server 4 encrypts the third public key using symmetric key cryptography (for example, AES), and the host device 2 encrypts the update data using symmetric key cryptography (for example, AES).
[0144] As a result, the information processing system 100 according to this embodiment can securely transmit the third public key and the update data to the notebook PC 1 while reducing the processing load of the encryption process.
[0145] Also, in this embodiment, the notebook PC 1 includes a main control unit 10 and an embedded controller 31 (sub-control unit). The main control unit 10 starts the OS and executes processing based on the OS by executing a program stored in the BIOS memory 32. The embedded controller 31 (sub-control unit) can communicate with the host device 2 and can operate independently of the main control unit 10, and executes the first process, the fourth process, and the sixth process.
[0146] As a result, the information processing system 100 according to the present embodiment can execute the update process of the BIOS program without using the main control unit 10 by using the embedded controller 31 (sub-control unit).
[0147] Also, in the present embodiment, the program stored in the BIOS memory 32 includes the BIOS program. The BIOS memory 32 is a flash memory having an SPI bus. The embedded controller 31 updates the BIOS program of the flash memory using the SPI bus.
[0148] As a result, the information processing system 100 according to the present embodiment can appropriately update (repair) the BIOS program from the embedded controller 31 using the SPI bus.
[0149] Also, the notebook PC 1 (information processing apparatus) according to the present embodiment is the notebook PC 1 of the information processing system 100 including the notebook PC 1, the management server 4, and the host device 2, and includes a registered public key storage unit 322, a key pair generation unit 313, a public key exchange unit 314, a common key generation unit 315, and an update processing unit 316. Here, the management server 4 manages the notebook PC 1. The host device 2 can communicate with the notebook PC 1 and the management server 4, and transmits update data of a program to the notebook PC 1. The notebook PC 1 has a rewritable BIOS memory 32 that stores a program for starting the OS, and executes processing based on the OS. The registered public key storage unit 322 stores the first public key of the first key pair that is the first public key and the first secret key held by the management server 4 and corresponds to the notebook PC 1. The key pair generation unit 313 generates a second key pair that is a second public key and a second secret key. After transmitting the second public key of the second key pair to the host device 2, the public key exchange unit 314 obtains encrypted data generated by encrypting the third public key of the third key pair that is the third public key and the third secret key generated by the host device 2 based on the first secret key and the second public key by the management server 4, decrypts the encrypted data based on the first public key and the second secret key stored in the registered public key storage unit 322, and generates the third public key. The common key generation unit 315 generates a common key for data communication based on the third public key decrypted by the public key exchange unit 314 and the second secret key. The update processing unit 316 decrypts the encrypted update data received from the host device 2 based on the common key for data communication generated by the common key generation unit 315, and updates the program stored in the BIOS memory 32 based on the decrypted update data.
[0150] Thereby, the notebook PC 1 (information processing apparatus) according to the present embodiment has the same effect as the above-described information processing system 100, and can appropriately update the data of the non-volatile memory (BIOS memory 32) while ensuring security.
[0151] Also, the data communication method according to the present embodiment includes a rewritable BIOS memory 32 that stores a program for starting the OS, a notebook PC 1 that executes processing based on the OS, a management server 4 that manages the notebook PC 1, and a host device 2 that can communicate with the notebook PC 1 and the management server 4 and transmits update data of the program to the notebook PC 1. The data communication method of the information processing system 100 includes a first processing step, a second processing step, a third processing step, a fourth processing step, a fifth processing step, and a sixth processing step. Note that the notebook PC 1 includes a registered public key storage unit 322 that stores the first public key of the first key pair, which is the first public key and the first private key held by the management server 4, among the first key pairs corresponding to the notebook PC 1. In the first processing step, the notebook PC 1 generates a second key pair that is the second public key and the second private key, and transmits the second public key of the second key pair to the host device 2. In the second processing step, the host device 2 generates a third key pair that is the third public key and the third private key, and transmits the third public key of the third key pair and the second public key to the management server 4. In the third processing step, when the legitimacy of the user of the host device 2 is confirmed, the management server 4 generates encrypted data obtained by encrypting the third public key based on the first private key and the second public key, and transmits the encrypted data to the notebook PC 1 via the host device 2. In the fourth processing step, the notebook PC 1 decrypts the encrypted data based on the first public key and the second private key to generate the third public key. In the fifth processing step, the host device 2 generates a common key for data communication based on the second public key and the third private key, encrypts the update data based on the common key for data communication to generate encrypted update data, and transmits the encrypted update data to the notebook PC 1. In the sixth processing step, the notebook PC 1 generates a common key for data communication based on the second private key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate update data, and updates the program stored in the BIOS memory 32 based on the update data.
[0152] As a result, the data communication method according to the present embodiment has the same effects as the information processing system 100 described above, and can appropriately update the data in the non-volatile memory (BIOS memory 32) while ensuring security.
[0153] Note that the present invention is not limited to the above-described embodiments, and can be modified without departing from the spirit of the present invention. For example, in the above embodiment, an example where the information processing apparatus is a notebook PC 1 has been described, but the present invention is not limited thereto, and other information processing apparatuses such as a tablet terminal device and a desktop PC may be used. Similarly, the host device 2 may be other information processing apparatuses such as a tablet terminal device and a desktop PC in addition to the notebook PC.
[0154] Also, in the above embodiment, an example where the key pair of the public key and the private key is a key pair of elliptic curve cryptography has been described, but the present invention is not limited thereto, and other key pairs of public key cryptography may be used.
[0155] Also, in the above embodiment, an example where the encryption and decryption of the third public key and the update data are performed using AES has been described, but the present invention is not limited thereto, and other common key cryptography or other public key cryptography may be used.
[0156] Also, in the above embodiment, an example where the encrypted data obtained by encrypting the third public key and the update data is transmitted to the notebook PC 1 has been described, but the present invention is not limited thereto, and authentication information such as a digital signature generated from the third public key or the update data may be added to the third public key and the update data using encryption processing and transmitted to the notebook PC 1.
[0157] Also, in the above-described embodiment, an example was described in which the management server 4 encrypts the third public key using the shared secret key and transmits it to the notebook PC 1. However, the present invention is not limited to this. The management server 4 may encrypt the third public key using the first secret key and the second public key, for example, with public key cryptography, and transmit it to the notebook PC 1. In this case, on the notebook PC 1, the encrypted data is decrypted with public key cryptography using the second secret key and the first public key to generate the third public key.
[0158] Also, in the above-described embodiment, an example was described in which the elliptic curve Diffie-Hellman key exchange method is used. However, the present invention is not limited to this. For example, in the case of other public key cryptography such as RSA cryptography, a common secret key may be shared using the normal Diffie-Hellman key exchange method.
[0159] Each component included in the information processing system 100 described above has a computer system inside. Then, a program for realizing the functions of each component included in the information processing system 100 described above is recorded on a computer-readable recording medium, and the program recorded on this recording medium is read into the computer system and executed, whereby the processing in each component included in the notebook PC 1 described above may be performed. Here, "reading the program recorded on the recording medium into the computer system and executing it" includes installing the program in the computer system. The "computer system" here is assumed to include hardware such as an OS and peripheral devices. Also, the "computer system" may include a plurality of computer devices connected via a network including a communication line such as the Internet, WAN, LAN, or dedicated line. The "computer-readable recording medium" refers to a portable medium such as a flexible disk, magneto-optical disk, ROM, CD-ROM, or a storage device such as a hard disk built into the computer system. Thus, the recording medium storing the program may be a non-transitory recording medium such as a CD-ROM.
[0160] In addition, the recording medium includes an internal or external recording medium that can be accessed from a distribution server for distributing the program. Note that the program may be divided into multiple parts and downloaded at different timings, and then combined by each component included in the information processing system 100. Also, the distribution servers for distributing each of the divided programs may be different. Furthermore, the "computer-readable recording medium" includes those that hold a program for a certain period of time, such as a volatile memory (RAM) inside a computer system that serves as a server or a client when the program is transmitted via a network. Also, the above program may be for realizing a part of the above-described functions. Furthermore, it may be a so-called difference file (difference program) that can realize the above-described functions in combination with a program already recorded in the computer system.
[0161] Also, part or all of the above-described functions may be realized as an integrated circuit such as an LSI (Large Scale Integration). Each of the above-described functions may be made into an individual processor, or part or all of them may be integrated and made into a processor. Also, the method of integrating into an integrated circuit is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. Also, when a technology for integrating into an integrated circuit that replaces LSI appears due to the progress of semiconductor technology, an integrated circuit using such technology may be used.
Explanation of Signs
[0162] 1 Notebook PC 2 Host device 4 Management server 10 Main control unit 11 CPU 12 Main memory 13 Video subsystem 14 Display unit 21 Chipset 22 SSD 23 USB connector 24 Audio system 25 WLAN card 31 Embedded Controller (EC) 32 BIOS Memory 33 Input Section 34 Power Supply Circuit 41, 210 NW Communication Section 42 Server Memory Section 43 Server Control Section 100 Information Processing System 101 BIOS Processing Section 102 OS Processing Section 220 Device Memory Section 221, 311 Encryption Key Memory Section 222, 312, 424 Common Key Memory Section 223 Update Program Memory Section 230 Device Control Section 231, 313 Key Pair Generation Section 232, 314 Public Key Exchange Section 233, 315, 433 Common Key Generation Section 234, 316 Update Processing Section 321 BIOS Program Memory Section 322 Registered Public Key Memory Section 421 Registered Information Memory Section 422 Authentication Information Memory Section 423 Public Key Memory Section 431 User Authentication Section 432 Public Key Distribution Section NW1 Network
Claims
1. an information processing device having a rewritable non-volatile storage unit that stores a program for starting an OS (Operating System), and that executes processing based on the OS; A server device that manages the information processing device; a host device capable of communicating with the information processing device and the server device and transmitting update data of the program to the information processing device; Equipped with the information processing device includes a registered public key storage unit configured to store a first key pair, which is a first public key and a first private key held by the server device, the first public key of the first key pair corresponding to the information processing device; a first process in which the information processing device generates a second key pair including a second public key and a second private key, and transmits the second public key of the second key pair to the higher-level device; a second process in which the higher-level device generates a third key pair including a third public key and a third private key, and transmits the third public key and the second public key of the third key pair to the server device; a third process in which the server device generates encrypted data by encrypting the third public key based on the first private key and the second public key when the authenticity of the user of the higher-level device is confirmed, and transmits the encrypted data to the information processing device via the higher-level device; a fourth process in which the information processing device decrypts the encrypted data based on the first public key and the second private key to generate the third public key; a fifth process in which the higher-level device generates a common key for data communication based on the second public key and the third private key, encrypts the update data based on the common key for data communication, generates encrypted update data, and transmits the encrypted update data to the information processing device; a sixth process in which the information processing device generates a common key for data communication based on the second private key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate the update data, and updates the program stored in the non-volatile storage unit based on the update data; An information processing system that executes the above.
2. In the third process, the server device generates a first shared secret key based on the first private key and the second public key, and encrypts the third public key based on the generated first shared secret key to generate the encrypted data; In the fourth process, the information processing device generates a second shared secret key based on the first public key and the second secret key, and decrypts the encrypted data based on the generated second shared secret key to generate the third public key. The information processing system according to claim 1 .
3. the first key pair, the second key pair, and the third key pair are key pairs of a public key and a private key in elliptic curve cryptography; the first shared secret key and the second shared secret key are equal common keys, and the common key is shared between the server device and the information processing device by using an Elliptic curve Diffie-Hellman key exchange technique; The data communication common key is shared between the host device and the information processing device using the elliptic curve Diffie-Hellman key exchange technique. The information processing system according to claim 2 .
4. The server device encrypts the third public key using a common key cipher; The higher-level device encrypts the update data using a common key cipher. The information processing system according to claim 3 .
5. The information processing device includes: a main control unit that starts up the OS and executes processing based on the OS by executing the program stored in the non-volatile storage unit; a sub-controller capable of communicating with the higher-level device and operating independently of the main control unit, and which executes the first process, the fourth process, and the sixth process; The information processing system according to claim 1 , further comprising:
6. The programs include a BIOS (Basic Input Output System) program, the non-volatile storage unit is a flash memory having an SPI (Serial Peripheral Interface) bus, The sub-control unit updates the BIOS program in the flash memory using the SPI bus.
6. The information processing system according to claim 5.
7. An information processing device of an information processing system including: an information processing device having a rewritable non-volatile storage unit that stores a program for starting an OS (Operating System), and executing a process based on the OS; a server device that manages the information processing device; and a host device that is capable of communicating with the information processing device and the server device and transmits update data for the program to the information processing device, a registered public key storage unit configured to store a first key pair, which is a first public key and a first private key held by the server device, the first public key of the first key pair corresponding to the information processing device; a key pair generation unit that generates a second key pair including a second public key and a second private key; a public key exchange unit that, after transmitting the second public key of the second key pair to the higher-level device, acquires encrypted data generated by encrypting the third public key of the third key pair, which is the third public key and third private key generated by the higher-level device, based on the first private key and the second public key, and decrypts the encrypted data based on the first public key and the second private key stored in the registered public key storage unit to generate the third public key; a common key generation unit that generates a common key for data communication based on the third public key and the second private key decrypted by the public key exchange unit; an update processing unit that decrypts the encrypted update data received from the higher-level device based on the common key for data communication generated by the common key generation unit, and updates the program stored in the non-volatile storage unit based on the decrypted update data; An information processing device comprising:
8. A data communication method for an information processing system including: an information processing device having a rewritable non-volatile storage unit that stores a program for starting an OS (Operating System), and that executes processing based on the OS; a server device that manages the information processing device; and a host device that is capable of communicating with the information processing device and the server device and that transmits update data for the program to the information processing device, the information processing device includes a registered public key storage unit configured to store a first key pair, which is a first public key and a first private key held by the server device, the first public key of the first key pair corresponding to the information processing device; a first processing step in which the information processing device generates a second key pair including a second public key and a second private key, and transmits the second public key of the second key pair to the higher-level device; a second processing step in which the higher-level device generates a third key pair including a third public key and a third private key, and transmits the third public key and the second public key of the third key pair to the server device; a third processing step in which the server device generates encrypted data by encrypting the third public key based on the first private key and the second public key when the authenticity of the user of the higher-level device is confirmed, and transmits the encrypted data to the information processing device via the higher-level device; a fourth processing step in which the information processing device decrypts the encrypted data based on the first public key and the second private key to generate the third public key; a fifth processing step in which the higher-level device generates a common key for data communication based on the second public key and the third private key, encrypts the update data based on the common key for data communication, generates encrypted update data, and transmits the encrypted update data to the information processing device; a sixth processing step in which the information processing device generates the common key for data communication based on the second private key and the third public key, decrypts the encrypted update data based on the common key for data communication to generate the update data, and updates the program stored in the non-volatile storage unit based on the update data; A data communication method including:
Citation Information
Patent Citations
Application program upgrading method and system
CN103873440A
Information processing device and start control method
JP2014010492A
Authentication system
JP2020198483A
Programming vehicle modules from remote devices and related methods and systems
US20150121071A1
Data provision system, data security device, data provision method, and computer program
WO2018029893A1